Designate a data protection officer where the processing is carried out by a public authority or body, except for courts acting in their judicial capacity, where the core activities consist of processing operations which by their nature, scope or purposes require regular and systematic monitoring of data subjects on a large scale, or where the core activities consist of processing on a large scale of special category data or of personal data relating to criminal convictions and offences. A group of undertakings may appoint a single data protection officer provided that officer is easily accessible from each establishment. Designate on the basis of professional qualities, in particular expert knowledge of data protection law and practice and the ability to fulfil the Article 39 tasks. The officer may be a staff member or fulfil the tasks under a service contract. Publish the officer's contact details and communicate them to the supervisory authority.
GDPR GDPR-Art.37 is one control. If you already hold one of the frameworks below, a reviewed crosswalk already says how much of GDPR your existing evidence covers. Hold ISO 27701:2019 and 21 of 40 GDPR controls already carry evidence.
Each report names every control your existing framework evidences, every one it does not, the reasoning behind each claim, and the claims that were argued against and rejected. 0 were rejected on the ISO 27701:2019 pair alone.
The graph holds this control, the 0 it maps to, and the evidence behind each claim, over MCP and REST.