Implementing GDPR art. 9(4), genetic, biometric and health data may be processed only where one of the conditions of GDPR art. 9(2) applies and in accordance with the safeguard measures (misure di garanzia) set by the Garante. The measures are adopted at least every two years after public consultation, per category of data and purpose, and cover security (including encryption and pseudonymisation), minimisation, selective access, information to data subjects and other measures; for genetic data they may require consent in high-risk cases.
This control maps to 1 controls across 1 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.
Every mapping shown was judged rather than inferred from wording similarity, and the ones that failed review are published too. See the coverage reports and what was rejected.
The graph holds this control, the 1 it maps to, and the evidence behind each claim, over MCP and REST.