Georgia DPL Controller + Processor + Security obligations. CONTROLLER ACCOUNTABILITY (Art. 27): demonstrate compliance through documented policies + records + impact assessments + reviews. PROCESSOR REQUIREMENTS (Art. 28 - GDPR Art. 28 aligned): written contract + processing scope + duration + categories + sub-processor authorisation + return/deletion + audit cooperation. RECORDS OF PROCESSING ACTIVITIES (RoPA, Art. 29 - GDPR Art. 30 aligned): controllers + processors maintain RoPA including categories + purposes + recipients + cross-border + retention + technical/organisational measures. DATA PROTECTION OFFICER (DPO, Art. 30 - 2023 NEW MANDATORY): for (a) public authorities + bodies; (b) controllers/processors whose core activities require regular + systematic monitoring on large scale; (c) controllers/processors processing special-category data on large scale + criminal data on large scale; independence + adequate resources + direct reporting + DPO contact published. DATA PROTECTION IMPACT ASSESSMENT (DPIA, Art. 31): mandatory for high-risk processing including systematic + extensive evaluation of natural persons + automated processing + large-scale special-category + large-scale public-area systematic monitoring + emerging technologies + AI/ML systems + biometric identification + children + cross-border. SECURITY OF PROCESSING (Art. 32 - GDPR Art. 32 aligned): appropriate technical + organisational measures considering state-of-the-art + risk including: pseudonymisation + encryption + ongoing CIA + restore-availability + regular testing + assessing.
The graph holds this control, the 0 it maps to, and the evidence behind each claim, over MCP and REST.