The DPO must be a Jordanian citizen of good conduct with no criminal conviction or conviction for a crime against honour or trust unless rehabilitated, have specialised knowledge of data protection, and not have been dismissed for a data protection violation by final judgment or uncontested disciplinary decision. The DPO may be internal or external; an external DPO may serve several entities and works under a contract setting out their roles and responsibilities.
The graph holds this control, the 0 it maps to, and the evidence behind each claim, over MCP and REST.