Each controller (and its representative) must keep a written, including electronic, record of processing activities with its and any joint controller's, representative's and DPO's contact details, the purposes, categories of data subjects and data, categories of recipients including abroad, transfers with the documentation of safeguards for Article 50(2) transfers, erasure time limits where possible and a general description of security measures; each processor must keep a record of the categories of processing carried out for each controller, transfers and security measures. Records must be provided to the Agency on request. Organisations with fewer than 250 employees are exempt unless the processing is likely to result in a risk, is not occasional, or includes special category or criminal data.
The graph holds this control, the 0 it maps to, and the evidence behind each claim, over MCP and REST.