Liechtenstein DSG Articles 25-31 Security + Processor + Breach Notification. Article 25 Security of Processing (Sicherheit der Verarbeitung) - controllers and processors must implement appropriate technical and organisational measures proportionate to risk + state-of-the-art + including encryption (at rest + in transit) + pseudonymisation + access control + RBAC + MFA + logging + monitoring + secure SDLC + vulnerability management + Liechtenstein financial sector ISO 27001 + ISO 27701 + Banking Act information security requirements + FMA Circular on IT and Cyber Risk Management + DLT/Blockchain Act security requirements for Token Service Providers. Article 26 Processor Engagement (Auftragsverarbeiter) - written contract specifying categories + purposes + duration + obligations including process only on documented instructions + confidentiality + security + sub-processor authorisation + Data Subject Rights support + breach notification + return or deletion at termination + audit rights + flow-down. Article 27 Joint Controllership. Articles 28-29 Personal Data Breach Notification (Meldung von Verletzungen des Schutzes personenbezogener Daten) - controller must notify DSS within 72 hours + notify affected data subjects without undue delay where likely high-risk + content (nature + categories + approximate number + likely consequences + measures taken + DPO contact). Article 30 Records of all breaches. Liechtenstein financial sector additional breach reporting to FMA (Financial Market Authority) under Banking Act + Insurance Supervision Act + parallel to DSS notification + cybersecurity sectoral coordination + Liechtenstein Cyber Security Coordination Centre (CSCC) + EU NIS2 Directive transposition pending. Article 31 Incident response coordination with DSS + FMA + Liechtenstein Police + Federal Office for IT Security (Switzerland - BIT/MELANI coordination via Customs Union arrangements).
The graph holds this control, the 0 it maps to, and the evidence behind each claim, over MCP and REST.