The officer advises the controller, its staff and processors on the Act and the Authority's rules, supervises compliance, advises on and supervises risk analysis, impact assessments and security measures, and cooperates with and is the contact point for the Authority; resolution 0028-R adds advice or supervision on transfers' security measures, rights requests, breach management and notification, control of measures' effectiveness and records of processing, while forbidding the officer to implement the law directly, carry out risk management or impact assessments, decide purposes or means, represent the organisation as controller, or serve as information security officer, compliance officer or implementer. Controllers and processors must involve the officer properly and in time, give access to data and the resources needed, train the officer, not dismiss or sanction the officer for doing the job, ensure a direct line to the highest executive level, let data subjects contact the officer, and respect the officer's confidentiality; the officer must act with total independence even as an employee (or under a services contract), receive no instructions, and be the subject of an annual institutional (non-hierarchical) evaluation of direct access, resources, the handling of the officer's recommendations and compliance reports. The officer may report interference or retaliation to the Superintendencia; unjustified removal or sanction is penalised. Groups may share one officer; a deputy may be designated; voluntary designation is good practice.
The graph holds this control, the 0 it maps to, and the evidence behind each claim, over MCP and REST.