The controller must: process data strictly under the principles, rights and the Authority's rules; implement administrative, technical, physical, organisational and legal requirements and tools to guarantee and demonstrate compliance; verify and periodically evaluate their efficiency, efficacy and effectiveness; adopt data protection policies suited to each processing; use risk analysis and management methods adapted to the processing and parties; carry out security adequacy assessments before processing; take measures to prevent, reduce, mitigate and control identified risks and breaches; notify breaches to the Authority and data subjects; implement protection by design and by default; sign confidentiality and proper-handling agreements with processors and with staff who process or know the data; ensure its processors offer sufficient guarantees; register and keep up to date its entries in the National Register; designate a data protection officer where required; and allow and contribute to audits or inspections by an auditor accredited by the Authority. Processors have the same obligations where applicable.
The graph holds this control, the 0 it maps to, and the evidence behind each claim, over MCP and REST.