Where others process on its behalf, the controller remains responsible and data subjects exercise their rights against it. Only processors giving sufficient guarantees of appropriate technical and organisational measures may be used. Sub-processors need prior written authorisation (with notice of changes and a right to object under a general authorisation), must be bound to the same obligations, and the first processor stays liable. Processing is governed by a binding contract or other legal instrument setting out subject matter, duration, nature, purpose, data types, data subject categories and the controller's rights and duties, and requiring the processor to act only on instructions (warning of unlawful ones), ensure confidentiality, assist with data subject rights, delete or return data at the end, provide information and the s 76 logs, allow audits, respect the sub-processor rules, take s 64 security measures and assist with ss 64 to 67 and 69. The contract or instrument is in writing or electronic form. A processor determining purposes and means itself becomes a controller.
This control maps to 1 controls across 1 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.
Every mapping shown was judged rather than inferred from wording similarity, and the ones that failed review are published too. See the coverage reports and what was rejected.
The graph holds this control, the 1 it maps to, and the evidence behind each claim, over MCP and REST.