Beyond GDPR Art. 14(5) and s 29(1), the Art. 14(1), (2) and (4) information need not be given by a public body where it would endanger its tasks or public security or order, or by a private body where it would interfere with legal claims, where the data stem from private-law contracts and are used to prevent damage from crime (unless the data subject's interest in being informed prevails), or where the competent public body has found disclosure would endanger public security. If information is withheld the controller protects the data subject, including by publishing the information, and records its reasons in writing. Information about transfers to intelligence and certain defence authorities needs their approval.
This control maps to 1 controls across 1 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.
Every mapping shown was judged rather than inferred from wording similarity, and the ones that failed review are published too. See the coverage reports and what was rejected.
The graph holds this control, the 1 it maps to, and the evidence behind each claim, over MCP and REST.