Maintain Records of Processing Activities (Verwerkingsregister) per GDPR Article 30. Conduct Data Protection Impact Assessments (DPIA / Gegevensbeschermingseffectbeoordeling DPIA) for high-risk processing per GDPR Article 35 + AP DPIA list (publication October 2018 + revisions including biometric processing + employee monitoring + healthcare processing + connected vehicles). Consult AP for prior consultation per GDPR Article 36 where DPIA indicates high residual risk. Implement security of processing per GDPR Article 32 + AP Cybersecurity guidance (Richtsnoeren).
The graph holds this control, the 0 it maps to, and the evidence behind each claim, over MCP and REST.