The officer must hold political rights, be of age, have a third-level degree in law, information systems, communication or technology and at least five years' professional experience, and (from 1 January 2029) complete the Superintendencia's professionalising programme. Members of the controller's or processor's management and control bodies, partners or shareholders, spouses and close relatives of directors, persons with conflicts of interest, the organisation's information security officer or compliance officer, special attorneys of foreign controllers, and senior public officials may not be officers; candidates declare any real, potential or apparent conflict before accepting, and conflicts arising later lead to corrective action. The officer signs a confidentiality agreement that cannot limit access to needed information and survives the relationship. The appointment is made by the controller or processor through its legal representative or highest authority, contains the elements of Art. 4 of the resolution (date, organisation and tax number or foreign details, representative, officer, functions, signatures, acceptance, supporting documents) and must be registered with the Superintendencia within 15 working days (late registration counts as a breach of a legal security measure); private-sector officers had to be registered between 1 November and 31 December 2025; the Superintendencia publishes a list of officers.
The graph holds this control, the 0 it maps to, and the evidence behind each claim, over MCP and REST.