Article 4 establishes the PRINCIPLES for processing: (a) processed in a fair + transparent + lawful manner; (b) collected for specified + clear + legitimate purposes (purpose limitation); (c) limited to what is necessary (data minimization); (d) accurate + kept up to date (accuracy); (e) retained only as long as necessary (storage limitation); (f) processed with appropriate security measures (integrity + confidentiality). Article 5 establishes the LAWFUL BASES for processing: (a) data subject CONSENT; (b) performance of a CONTRACT or pre-contractual steps; (c) compliance with a LEGAL OBLIGATION; (d) protection of VITAL INTERESTS; (e) performance of a TASK IN THE PUBLIC INTEREST; (f) LEGITIMATE INTERESTS of the controller / processor or a third party (balanced against data subject rights); (g) processing of personal data necessary for the realisation of historical / statistical / scientific RESEARCH purposes. Consent (Article 5(a)) must be freely given + specific + informed + explicit + revocable.
This control maps to 440 controls across 185 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.
Every mapping shown was judged rather than inferred from wording similarity, and the ones that failed review are published too. See the coverage reports and what was rejected.
The graph holds this control, the 440 it maps to, and the evidence behind each claim, over MCP and REST.