Liechtenstein DSG Articles 32-39 Governance and Accountability. Article 32 Data Protection Officer (Datenschutzbeauftragter - DPO/DSB) - mandatory designation under GDPR Article 37 + Liechtenstein additional requirements for: (a) financial sector entities (banks + asset managers + foundations + trusts above certain threshold); (b) public authorities; (c) core activities consisting of systematic monitoring on large scale; (d) core activities involving processing of special categories on large scale. DPO must be designated on basis of professional qualities + expert knowledge of data protection law and practice in financial sector + Liechtenstein FMA coordination experience + DSS notification + DPO contact publication + reporting to highest management + independence + no conflict of interest + DPO continuing professional development. Article 33 Records of Processing Activities (Verzeichnis von Verarbeitungstatigkeiten - ROPA) - controllers and processors must maintain detailed records + provided to DSS on request. Article 34 Data Protection Impact Assessment (Datenschutz-Folgenabschatzung - DPIA) - mandatory for high-risk processing + systematic monitoring + large-scale special categories + new technologies + financial sector innovation + DLT/Blockchain Act 2019 token service providers. Article 35 Prior Consultation with DSS for residual high risk. Article 36 Data Protection by Design and by Default + Privacy-Engineering principles + financial sector secure-development requirements. Article 37 Codes of Conduct - DSS-approved sectoral codes including Banking Code of Conduct + Trust Code of Conduct + Asset Management Code of Conduct + Foundation Code of Conduct + EU cross-border Codes via EDPB consistency mechanism. Article 38 Certification mechanisms (ISO 27701 + Europrivacy + EDPB-approved schemes). Article 39 Whistleblowing and Internal Reporting (Liechtenstein-specific provision integrating EU Whistleblower Directive 2019/1937 transposed by Liechtenstein Whistleblower Protection Act 2023) - integration with data protection obligations + DSS coordination + confidentiality of whistleblower identity.
The graph holds this control, the 0 it maps to, and the evidence behind each claim, over MCP and REST.