Regulation 15 governs use of an outsourced data holder. The owner must select a processor with adequate security, sign a written contract specifying purposes, types of data, security obligations, subject rights handling, return or destruction of data, audit rights, and breach notification. The contract must require the processor to comply with the regulations. The owner must supervise the processor including risk-based reviews.
The graph holds this control, the 0 it maps to, and the evidence behind each claim, over MCP and REST.