Controllers or processors may submit binding corporate rules to the Authority, which authorises them only if they are legally binding, give data subjects enforceable rights and meet the Act's conditions: binding on the controller and the group companies receiving data; mechanisms for data subjects' rights; a detailed list of group affiliates or joint-venture members with structure and contacts; the processors, data categories, types and purposes of processing; the Act's principles, security, transfer and onward-transfer rules; acceptance of liability for breaches by any group member (unless not attributable to it); clear information to data subjects about the rules; the functions of the data protection officers or others supervising compliance and complaint handling; verification mechanisms including data protection audits reported to the officer, the board of the controlling company and the Authority; cooperation with the Authority; and a commitment to continuous staff training. Changes must be notified to the Authority and to data subjects.
The graph holds this control, the 0 it maps to, and the evidence behind each claim, over MCP and REST.