Criminal-offence data may be processed for the benefit of third parties only by controllers acting under a licence under the Private Security Organisations and Detective Agencies Act; where the third party is a legal person in the same group (art. 2:24b Civil Code); or where the Autoriteit Persoonsgegevens has granted a permit, which it may grant only where processing is necessary for a weighty interest of third parties and safeguards against disproportionate harm to privacy are in place, and to which it may attach conditions (33(6)). Warning lists or blacklists shared between organisations need such a permit (and a DPIA under the AP list).
This control maps to 1 controls across 1 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.
Every mapping shown was judged rather than inferred from wording similarity, and the ones that failed review are published too. See the coverage reports and what was rejected.
The graph holds this control, the 1 it maps to, and the evidence behind each claim, over MCP and REST.