Operate Maryland MODPA controller duties including security + processor contracts + Data Protection Assessment (DPA). Controllers must establish reasonable administrative + technical + physical security practices appropriate to volume and nature of personal data + nature of processing + state-of-the-art. Processor Contracts (Section 14-4608) must include: clear instructions for processing + nature and purpose + type of data + duration + rights and obligations of both parties + processor must (a) ensure confidentiality obligations on persons processing; (b) at controller direction delete or return all personal data at end of provision unless retention required by law; (c) make available to controller all information necessary to demonstrate compliance + cooperate with assessments by controller; (d) engage subprocessors only after providing opportunity to controller to object + flow down same obligations; (e) implement appropriate technical and organisational measures. Data Protection Assessment (Section 14-4609) MANDATORY for: (a) processing for purpose of targeted advertising; (b) sale of personal data; (c) processing for profiling presenting reasonably foreseeable risk of unfair or deceptive treatment + financial physical reputational injury + intrusion + injury; (d) processing of sensitive data; (e) processing presenting heightened risk of harm to consumers including processing for training AI/ML systems. Available to Attorney General upon request. Single assessment may cover comparable processing activities.
The graph holds this control, the 0 it maps to, and the evidence behind each claim, over MCP and REST.