Sets twelve controller obligations: obtain data lawfully after consent; ensure validity/sufficiency for purpose; set processing method/standards; ensure purpose applicability; refrain from unlawful disclosure; adopt technical and regulatory security measures preventing hacking/alteration; delete or anonymise data once the purpose is satisfied; correct errors promptly; maintain a record of processing; obtain a Licence or Permit from the Centre; appoint an Egyptian representative if established abroad; and enable Centre inspection. Each of multiple controllers is bound by all obligations.
The graph holds this control, the 0 it maps to, and the evidence behind each claim, over MCP and REST.