GDPR
Chapter II - Principles

GDPR GDPR-Art.9: Processing of special categories of personal data

Do not process personal data revealing racial or ethnic origin, political opinions, religious or philosophical beliefs or trade union membership, nor genetic data, biometric data processed to uniquely identify a person, data concerning health, or data concerning a person's sex life or sexual orientation, unless one of the Article 9(2) conditions applies: explicit consent, employment and social security law obligations, vital interests where the data subject cannot consent, the legitimate activities of a not-for-profit body, data manifestly made public by the data subject, legal claims or courts acting judicially, substantial public interest under Union or Member State law, preventive or occupational medicine and health or social care under an obligation of professional secrecy, public health, or archiving, research and statistics under Article 89(1). The condition applies in addition to an Article 6 lawful basis, never in place of it.

Maintained by Gerard BlokdykVerified against the published standard Control text last updated

What else in your programme already covers this

This control maps to 361 controls across 140 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.

  • 22 Art. 22 Process special categories only under an exception of the GDPR or the UAVG
  • 23 Art. 23 Rely on the national general exceptions for special categories only in their cases
  • 24 Art. 24 Meet all four conditions before processing special categories for research or statistics
  • 25 Art. 25 Process data revealing racial or ethnic origin only for identification or preferential-treatment policies, within limits
  • 26 Art. 26 Process data revealing political opinions only for requirements of public-body functions
  • 27 Art. 27 Process religious or philosophical data for spiritual care only absent written objection, and do not disclose it
  • 28 Art. 28 Process genetic data only about the person it was obtained from, or on the strict research or medical grounds
  • 29 Art. 29 Use biometric identification (fingerprint or face) only where necessary for authentication or security for a weighty public-interest access need
  • 30(1) Art. 30(1) Process employee health data only as necessary for statutory, pension or collective-agreement entitlements or for reintegration
  • 30(2) Art. 30(2) Process health data in schools, probation, child protection and custody only as necessary for their tasks
  • 30(3) Art. 30(3) Process health data in care and insurance only as necessary for treatment, management, risk assessment or policy administration
  • 30(4) Art. 30(4) Ensure health data are processed only by persons bound to confidentiality
  • 30b Art. 30b Transfer medical records held by non-care providers only to a care provider that will keep them
  • s22 s 22 Process special categories only on a listed national ground and with specific safeguards
  • s26-3 s 26(3) Process employees' special category data only for labour and social law duties, or on explicit consent
  • s27 s 27 Research and statistics: balance interests, safeguard, anonymise early and separate identifiers
  • s28 s 28 Archiving in the public interest: safeguard special categories and record counter-statements
  • s48 s 48 Process special categories only where strictly necessary and with safeguards
  • NISTPF-1 Identify-P - Business Environment, Data Processing Inventory, Ecosystem, and Risk Assessment
  • NISTPF-3 Control-P - Privacy Controls, Data Management, and Disassociated Processing
  • NISTPF-4 Communicate-P - Privacy Notice, Transparency, and Individual Awareness
  • NISTPF-7 Protect-P Maintenance and Protective Technology (PR.MA-P, PR.PT-P)
  • NISTPF-8 Protect-P Information Protection Processes (PR.PO-P)
  • NDPA-1 Applicability, Scope, and Carve-Outs
  • NDPA-2 Consumer Rights - Access, Correct, Delete, Portability, Appeal
  • NDPA-4 Sensitive Data Processing Consent and Childrens Protections
  • NDPA-5 Privacy Notice, Data Minimisation, and Purpose Limitation
  • NDPA-7 Data Protection Assessments and Processor Contracts
  • NG-NDPA-1 Scope, Applicability, and Establishment of Nigeria Data Protection Commission
  • NG-NDPA-2 Lawful Basis, Consent, and Data Protection Principles
  • NG-NDPA-4 Data Subject Rights and Automated Decision-Making
  • NG-NDPA-5 Security of Processing, Breach Notification, and DPIA
  • NG-NDPA-7 Cross-Border Data Transfers and International Cooperation

APPI · 4 controls

  • APPI-A20 Proper Acquisition and Special Care Required Personal Information
  • APPI-A23 Security Control Measures
  • APPI-A24 Supervision of Employees
  • APPI-A33 Request for Disclosure of Retained Personal Data
  • 5(a) 5(a) Special categories: an Article 9 exception plus an Article 6 basis, never 'manifestly made public'
  • 5(c) 5(c) An employer must not use footage of a demonstration to identify strikers
  • 5.1(a) 5.1(a) Biometrics: assess first, and know when Article 9 applies
  • 5.1(b) 5.1(b) Biometrics: never capture people who have not consented; separate entrances and user-triggered capture
  • UAE-PDPL-Art.10 Data Protection Officer (DPO) (UAE PDPL Article 10)
  • UAE-PDPL-Art.18_19_20_21 Security measures, controller/processor relationship, DPIA (UAE PDPL Articles 18-21)
  • UAE-PDPL-Art.4_5 Lawful basis and principles for processing personal data (UAE PDPL Articles 4-5)
  • UAE-PDPL-Art.6_7 Sensitive personal data and children's data (UAE PDPL Articles 6-7)

SOC 2 · 4 controls

  • SOC2-P3.1 P3.1 Collecting personal information consistent with objectives
  • SOC2-P3.2 P3.2 Explicit consent before collecting information that requires it
  • SOC2-P4.3 P4.3 Securely disposing of personal information
  • SOC2-P6.1 P6.1 Disclosure to third parties with consent
  • TANZANIA-1 Scope, Registration, Lawful Basis
  • TANZANIA-3 Data Subject Rights
  • TANZANIA-4 Security and Cross-Border
  • TANZANIA-5 DPO, Governance, Breach
  • TRINIDAD-1 Scope, Definitions, Commission
  • TRINIDAD-3 Data Subject Rights
  • TRINIDAD-4 Security, Accuracy
  • TRINIDAD-5 Enforcement and Sanctions
  • Standard 13 Nudge Techniques
  • Standard 14 Connected Toys and Devices
  • Standard 5 Detrimental Use of Data
  • Standard 8 Data Minimisation
  • MYHR-CUD-1 Authorised collection, use and disclosure only
  • MYHR-CUD-3 Use limited to My Health Record purposes
  • MYHR-CUD-6 Prohibition on use for a prohibited purpose
  • APP-1 APP 1 - Open and transparent management of personal information
  • APP-3 APP 3 - Collection of solicited personal information
  • APP-5 APP 5 - Notification of the collection of personal information
  • AT-DSG-11 Sections 42-45 - Data subject rights (law enforcement)
  • AT-DSG-13 Section 36 - Scope of law enforcement processing
  • AT-DSG-14 Section 38 - Lawfulness of law enforcement processing
  • AZ-DPA-12 Article 13 - Cross-border transfer
  • AZ-DPA-14 Article 16 - Liability for violations
  • AZ-DPA-15 Article 17 - Dispute resolution

Bahrain PDPL · 3 controls

  • BB-DPA-14 Section 15 - Right to Data Portability
  • BB-DPA-16 Section 22 - General Principle for Transfers
  • BB-DPA-21 Sections 61-69 - Data Privacy Officer
  • BW-DPA-s20 Prohibition for processing of sensitive personal data
  • BW-DPA-s21 Safeguards for processing sensitive personal data
  • BW-DPA-s25 Processing of genetic and biometric data
  • PIPL-Art28 Sensitive PI Definition and Threshold
  • PIPL-Art29 Separate Consent for Sensitive PI
  • PIPL-Art32 Sectoral and Administrative Restrictions
  • IVDR-Art.102_103_104 Confidentiality, data protection and Medical Device Coordination Group cooperation (Articles 102-104)
  • IVDR-Art.4 Genetic information, counselling and informed consent for genetic tests (Article 4)
  • IVDR-Art.59_60_61_62 Informed consent + protection of subjects + emergency situations (Articles 59-62)
  • EPDPA-1 Scope of Regulation (§1)
  • EST-IKS-§14-21 Principles of processing by law enforcement authorities
  • EST-IKS-§6 Processing for scientific and historical research and official statistics

ISO/IEC 29100:2024 · 3 controls

  • 29100-6.10 Information security
  • 29100-6.5 Use, retention and disclosure limitation
  • 29100-6.9 Accountability

ISO/IEC 29134:2023 · 3 controls

  • 29134-1 Scope
  • 29134-3 Terms and definitions
  • 29134-9.1 PIA report structure
  • IsraelPPL-CrossBorder-Transfer-Sec36-EU-Adequacy-Israel-Adequacy-SCCs-Reciprocity-Foreign-Recipient Israel POPL Cross-Border Transfer + Section 36 + Privacy Protection (Transfer of Data to Databases Abroad) Regulations 5761-2001 + EU Adequacy Decision (2011) + SCCs + Foreign Recipient Obligations + Reciprocity
  • IsraelPPL-DataSubjectRights-Access-Correction-Information-Delivery-Sec13-14-23A-23C-Subject-Notification Israel POPL Data Subject Rights - Section 13 Right of Access + Section 14 Right of Correction + Section 23A-C Prohibition on Information Delivery + Notice Obligation + Right to Object + Amendment 13 Enhancements
  • IsraelPPL-Database-Registration-Definition-Document-Security-Level-Classification-Sec7-8-PPA-Registry Israel POPL Database Registration + Section 7 Database Definitions + Section 8 Registration Requirement + Database Definition Document + Security Level Classification + PPA Public Registry + Amendment 13 Threshold Changes
  • Art. 2-septies(1) Art. 2-septies(1) Process genetic, biometric and health data only under an art. 9(2) condition and the Garante's safeguard measures
  • Art. 2-septies(8) Art. 2-septies(8) Never disseminate genetic, biometric or health data
  • Art. 2-sexies Art. 2-sexies Process special categories for substantial public interest only where law specifies the safeguards

Malaysia PDPA 2010 · 3 controls

  • MY-PDPA-Cross-Border-Transfer-Section-129-Whitelist-Abolition-2024-Adequacy-SCC-BCR-Processor-Direct-Marketing Malaysia PDPA Cross-Border + Section 129 + Whitelist Abolition 2024 + Adequacy + SCC + BCR + Processor + Marketing
  • MY-PDPA-Data-Subject-Rights-Access-Correction-Portability-Withdraw-Consent-Prevent-Marketing-Sections-30-43 Malaysia PDPA Subject Rights + Access + Correction + Portability + Withdraw Consent + Prevent Marketing + Sections 30 to 43
  • MY-PDPA-Seven-Personal-Data-Protection-Principles-General-Notice-Choice-Disclosure-Security-Retention-Data-Integrity-Access Malaysia PDPA Seven Principles + General + Notice and Choice + Disclosure + Security + Retention + Data Integrity + Access

NIST SP 800-122 · 3 controls

  • NISTSP122-4 PII Minimisation, Purpose Limitation, and Pseudonymisation
  • NISTSP122-5 PII Security Controls - Encryption, Access Control, Storage, Audit
  • NISTSP122-6 PII Breach Response and Incident Handling
  • NHPA-5 Privacy Notice, Data Minimisation, and Purpose Limitation
  • NHPA-6 Reasonable Data Security and Breach Response
  • NHPA-7 Data Protection Assessments and Processor Contracts
  • NGOB-1 Open Banking Registry Participation, Tiered Categorisation, and KYP
  • NGOB-2 Customer Consent Management and Lifecycle
  • NGOB-5 Fraud Monitoring, Incident Notification, and Reporting to CBN
  • OREGONCPA-3 Consent, Sensitive Data, Children and Teen Protections
  • OREGONCPA-5 Data Protection Assessments, Privacy by Design, Security Practices
  • OREGONCPA-7 Processor Contracts, Cross-Border Transfers, DPAs

SASB Standards · 3 controls

  • SASB-4 Social Capital (SC)
  • SASB-SC-1 Customer Privacy and Data Security
  • SASB-SOC-2 Customer Privacy

Saudi Arabia PDPL · 3 controls

  • SA-PDPL-13 Encryption of personal data
  • SA-PDPL-15 Access control for personal data
  • SA-PDPL-22 Privacy by design and default

South Korea ISMS-P · 3 controls

  • ISMSP-PI-01 Personal Information Collection
  • ISMSP-PI-04 Cross-Border Transfer
  • ISMSP-SYS-02 Encryption Implementation
  • SWE-1 Scope and Purpose
  • SWE-11 Integritetsskyddsmyndigheten (IMY)
  • SWE-2 Relationship to GDPR
  • UK-DPA18-GEN-04 UK-Specific Exemptions
  • UK-DPA18-LE-02 Data Subject Rights (Law Enforcement)
  • UK-DPA18-LE-03 International Transfers (Law Enforcement)
  • AL-DPA-12 International Data Transfers
  • AL-DPA-4 Sensitive Data
  • 5.4.4 5.4.4 Wearables: health and activity data stay with the employee
  • 5.6 5.6 Video monitoring: no video analytics of expressions or movements, no facial recognition
  • BE-DPA-5 Processing of special categories for substantial public interest
  • BE-DPA-6 Genetic, biometric and health data safeguards
  • ACC-1 ACC-1 Do not use biometric or photo-taking time clocks to control working hours
  • ACC-8 ACC-8 Use biometric access control only as a subsidiary measure, justified, with the template held on an individual medium
  • MDR-Art.109_110_111_112_113_115 Confidentiality, data protection, funding, civil liability and penalties (Articles 109-115)
  • MDR-Art.61_62 Clinical evaluation and clinical investigations general requirements (Articles 61-62)
  • EGY-PDPL-Art.12 Processing of sensitive personal data and children's data
  • EGY-PDPL-Art.41 Penalty for unlawful sensitive-data processing
  • FDBR-ControllerObligations-DPA-Notice Controller + Processor Obligations + Data Protection Assessments (Fla. Stat. 501.707, 501.708, 501.71, 501.711)
  • FDBR-Scope-Defs Scope, Applicability Thresholds and Definitions (Fla. Stat. 501.701, 501.702, 501.703, 501.704)
  • 6.5 6.5 No data on sex life, beliefs or convictions, save exceptionally
  • 6.7 6.7 Medical data only as needed and lawful

ISO 27701:2019 · 2 controls

  • 6.5.2 Information classification
  • 7.2.2 Identify lawful basis

ISO/IEC 27400:2022 · 2 controls

  • 27400-5.4 Data and privacy risks
  • 27400-7.3 Data minimization and purpose limitation
  • 27557-3 Terms and definitions
  • 27557-4.3 Individual impact consideration
  • Art. 5 Art. 5 Do not check workers' health or sickness directly
  • Art. 8 Art. 8 Do not investigate workers' opinions or facts irrelevant to their professional aptitude

Liechtenstein DPA · 2 controls

Mauritius DPA · 2 controls

  • MU-DPA-Data-Subject-Rights-Sections-26-33-Access-Rectification-Erasure-Restriction-Portability-Objection Mauritius DPA Subject Rights + Sections 26 to 33 + Access + Rectification + Erasure + Restriction + Portability + Objection
  • MU-DPA-Seven-Principles-Section-21-Lawfulness-Purpose-Minimisation-Accuracy-Storage-Integrity-Accountability Mauritius DPA Seven Principles + Section 21 + Lawfulness + Purpose + Minimisation + Accuracy + Storage + Integrity + Accountability

Mexico LFPDPPP · 2 controls

  • MX-LFPDPPP-Governance-Officer-Reglamento-47-50-Security-Manual-57-Risk-Assessment-61-Self-Regulation-Parameters-2014 Mexico LFPDPPP Governance + Officer + Reglamento 47 + Security Manual 50 + Risk Assessment 57 + Self-Regulation Parameters 2014
  • MX-LFPDPPP-Sensitive-Article-3-VI-Genetic-Health-Sexual-Religious-Article-9-Minors-18-Parental-Consent Mexico LFPDPPP Sensitive Data + Article 3 Section VI + Genetic + Health + Sexual + Religious + Article 9 Minors + Parental Consent
  • MN-CDPA-Enforcement-AG-Ellison-Section-325O-10-USD-7500-Per-Violation-Data-Broker-Registration-325O-13-Sunset-25-Jan-2026 Minnesota CDPA Enforcement + AG Ellison + Section 325O.10 + USD 7,500 Per Violation + Data Broker Registration + Sunset 25 January 2026
  • MN-CDPA-Processor-Contract-Security-Section-325O-08-Pseudonymisation-Section-325O-09-De-Identification Minnesota CDPA Processor + Section 325O.08 + Security + Pseudonymisation + Section 325O.09 + De-Identification
  • MT-CDPA-Privacy-Notice-MCA-30-14-2806-Categories-Purposes-Rights-Email-Online-Mechanism-Appeal Montana CDPA Privacy Notice + MCA 30-14-2806 + Categories + Purposes + Rights + Online Mechanism + Appeal
  • MT-CDPA-Scope-SB-384-Gianforte-19-May-2023-Effective-1-October-2024-MCA-30-14-2801-AG-Knudsen-50K-Threshold Montana CDPA Scope + SB 384 + Gianforte 19 May 2023 + Effective 1 October 2024 + MCA 30-14-2801 + AG Knudsen + 50K Threshold

NIST SP 800-53 Rev 5 · 2 controls

  • NIST800-PT-2 PT-2 Authority to Process Personally Identifiable Information
  • NIST800-PT-7 PT-7 Specific Categories of Personally Identifiable Information
  • NJDPA-2 Consumer Rights - Access, Correct, Delete, Portability, Appeal
  • NJDPA-8 AG Platkin Enforcement, 18-Month Cure Sunset, and Division of Consumer Affairs

PDPA Singapore · 2 controls

  • PDPASG-2 Notification, Consent, Purpose Limitation, and Lawful Basis
  • PDPASG-5 Protection, Accuracy, and Security of Personal Data

PDPA Thailand · 2 controls

  • PDPATH-5 Security Measures and Data Protection
  • PDPATH-8 Data Breach Notification, Complaints, Compliance, Enforcement

POPIA · 2 controls

  • POPIASA-3 Data Subject Rights (Access, Correction, Objection), Automated Decisions
  • POPIASA-4 Special Personal Information, Children, Information Quality, Documentation
  • NORWAY-5 Security of Processing, Encryption, Pseudonymization, Access Control
  • NORWAY-8 Breach Notification, Complaints, Compliance, Enforcement

Peru DPL · 2 controls

  • PERU-2 Consent, Privacy Notice, Sensitive Data
  • PERU-5 Security of Personal Data and Processor Agreements

Privacy Act 2020 · 2 controls

  • NZPRV-2 IPP 5 Storage and Security of Personal Information
  • NZPRV-6 IPP 13 Unique Identifiers, Privacy Impact Assessment, Privacy by Design

Qatar DPL · 2 controls

  • QATAR-3 Data Subject Rights
  • QATAR-7 DPO, Records, Retention, Marketing, Training
  • RO-LAW190-001 Lawful Basis for Processing Genetic, Biometric and Health Data
  • RO-LAW190-003 Processing of Personal Data by Political Parties and Non Profits
  • SSAE18-P1.1 P1.1 - Privacy Notice
  • SSAE18-P1.2 P1.2 - Choice and Consent

Taiwan PDPA · 2 controls

  • TAIWAN-2 Consent, Notice, Sensitive Data
  • TAIWAN-3 Data Subject Rights
  • UKGDPRREG-2 Data Subject Rights (Articles 12-22)
  • UKGDPRREG-3 Controller and Processor (Articles 24-43)
  • UGA-13 Unlawful Obtaining or Disclosure
  • UGA-15 Unauthorized Sale of Data

Uruguay DPL · 2 controls

  • URUGUAY-1 Scope, Lawful Basis, Consent
  • URUGUAY-5 Database Registration with AGESIC URCDP
  • UZB-DPL-08 Sensitive Categories of Personal Data
  • UZB-DPL-09 Biometric Data Protection
  • AUCDR-PS-9 Privacy Safeguard 9 - Adoption or disclosure of government related identifiers
  • DS-2 Ensure software supply chain security
  • BA-DPA-9 Processing of Special Categories of Personal Data

CCPA/CPRA · 1 control

  • §1798.121 Right to Limit Use and Disclosure of Sensitive Personal Information
  • CA-10 Selects and Develops Control Activities
  • DK-502-§7 Sensitive and special categories of data

EU AI Act · 1 control

  • DGA-Art.5_6 Conditions for re-use and fees (Articles 5-6)
  • PSD2-Art.94 Data protection (PSD2 Article 94) - GDPR alignment
  • FTC-Safeguards-Scope-Defs Scope, Definitions and Financial Institution Applicability (16 CFR 314.1, 314.2)

IEEE 7000 · 1 control

  • IEEE7000-Values-Elicitation-Prioritisation-IEEE7000Family-Bias-Privacy-Transparency IEEE 7000 Clauses 6 + 6.1 - Ethical Values Elicitation + Prioritisation + IEEE 7000 Family Integration (Bias + Privacy + Transparency + Wellbeing)

ISO/IEC 23894:2023 · 1 control

  • ISO23894-A.5 Privacy and Data Protection in AI
  • INCDPA-Controller-PrivacyNotice-PurposeLimitation-DataMinimisation-Transparency-LawfulBasis Indiana CDPA Controller Obligations - Privacy Notice + Purpose Limitation + Data Minimisation + Transparency + Lawful Basis + Reasonable + Adequate + Relevant + Limited to What is Necessary

Indonesia PDP Law · 1 control

Japan AI Guidelines · 1 control

  • JP-AIG-Data-Governance-Training-Data-Quality-Provenance-Lineage-Copyright-APPI-Personal-Information-Protection Japan AI Guidelines Data Governance + Training Data Quality + Provenance + Lineage + Copyright Act 2018 Article 30-4 Text Data Mining Exception + APPI 2022 Amendment + Personal Information Protection + Privacy Principle

LGPD · 1 control

  • LGPD-BR-Security-Article-46-48-Breach-Notification-ANPD-Reasonable-Time-Incident-Response-CSIRT Brazil LGPD Security + Article 46-48 + Breach Notification + ANPD + Incident Response

MARS-E · 1 control

  • NAIC-6 Cybersecurity Event Investigation and Notification - Sections 6 and 7
  • NISTAI600-7 Confabulation, Bias, Information Integrity, Privacy, IP (Risks 2, 4, 5, 6, 7, 8, 10, 11)
  • NRFCS-7 Detection, Logging, Incident Response, Breach Notification, and Fraud Detection
  • NGCB-7 Patron and Employee Data Protection + Data Inventory + Vendor Management
  • NGNDPR-2 Governing Principles, Lawful Basis, and Consent under NDPR Section 2.1-2.3
  • AUNDB-A3 Eligible Data Breach Determination and Serious Harm Threshold

OECD AI Principles · 1 control

  • OECDAI-5 Data Governance, Training Data Quality, Privacy, and Bias Mitigation
  • OWASPLLM-3 Sensitive Information Disclosure and Privacy (LLM02)
  • OMANCS-4 Data Protection, Cryptography, and Privacy Alignment
  • RCEPEC-1 Online Personal Information Protection (12.13)
  • RIDTPPA-11 Data Minimisation and Purpose Limitation
  • SOC-CY-DC2 Nature of Sensitive Information
  • SAPAIA-4 Information Regulator Cooperation and Appeals

South Korea PIPA · 1 control

  • PIPA-Data-Subject-Rights-Access-Correction-Erasure-Portability-Automated-Decisions-Articles-35-37-2 Korea PIPA Data Subject Rights + Access + Correction + Erasure + Portability + Article 35-37
  • STUDPRV-2 Data Subject Rights for Students and Parents
  • TISAXASS-3 Prototype Protection and Confidentiality
  • 503.001(b)(2) 503.001(b)(2) Obtain the individual's consent before capture
  • TEXASTDPSA-3 Sensitive Data, Children, Sale Notice

Turkey KVKK · 1 control

  • TURKEYKVKK-2 Information Notice and Data Subject Rights
  • UKAI-2 Sector-Specific Regulator Engagement
  • OB-CX.2 Granular Consent Management
  • UNICEFAI-4 Transparency, Explanation, Adult Capacity

Vietnam PDPD · 1 control

  • VIETNAMPDP-1 Scope, Categorisation, Lawful Basis

Virginia CDPA · 1 control

  • VIRGINIAVCDPA-1 Scope, Applicability, Definitions
  • SO3.2 Regulatory frameworks for digital health
  • ZDPA-04 Sensitive Information Processing Safeguards

Every mapping shown was judged rather than inferred from wording similarity, and the ones that failed review are published too. See the coverage reports and what was rejected.

Other controls in Chapter II - Principles

You are reading one control. How much of GDPR have you already done?

GDPR GDPR-Art.9 is one control. If you already hold one of the frameworks below, a reviewed crosswalk already says how much of GDPR your existing evidence covers. Hold ISO 27701:2019 and 21 of 41 GDPR controls already carry evidence.

Each report names every control your existing framework evidences, every one it does not, the reasoning behind each claim, and the claims that were argued against and rejected. 0 were rejected on the ISO 27701:2019 pair alone.

Query this from an agent

The graph holds this control, the 361 it maps to, and the evidence behind each claim, over MCP and REST.