Designate Chief Privacy Officer (CPO) per **MINNESOTA-UNIQUE** Section 325O.06 requirement among US state privacy laws. Controllers processing personal data of 100,000 or more consumers MUST designate a Chief Privacy Officer or equivalent senior officer responsible for: (a) coordinating overall compliance with Chapter 325O; (b) privacy programme oversight including policies + procedures + training; (c) responding to consumer requests + appeals; (d) Minnesota Attorney General liaison; (e) privacy training programme for workforce including initial training within 90 days of hire + annual refresh; (f) maintaining data inventory of categories + purposes + sources + retention; (g) DPIA programme oversight; (h) breach response coordination. CPO must have sufficient seniority + authority + independence + resources + reporting line to senior management. CPO contact information published in privacy notice. Distinct from DPO under GDPR but parallels EU function. CPO designation in addition to general compliance officer where applicable. Whistleblower protections for CPO exercise of duties.
The graph holds this control, the 0 it maps to, and the evidence behind each claim, over MCP and REST.