Sets twelve processor obligations: process only per the Law and written instructions of the Centre/controller; ensure legitimate purpose; not exceed purpose/period and notify of the processing period; delete or return data after the processing period; refrain from unlawful disclosure; not process contrary to the controller's purpose (except not-for-profit statistical/educational); protect and secure processing media and devices; avoid harm to the data subject; maintain a processing-activities record; provide proof of compliance and enable Centre inspection; obtain a Licence or Permit; and appoint an Egyptian representative if established abroad.
The graph holds this control, the 0 it maps to, and the evidence behind each claim, over MCP and REST.