Conduct and document Data Protection Assessments (DPAs) for high-risk processing including: (a) sale of personal data, (b) targeted advertising, (c) profiling presenting reasonably foreseeable risk of unfair or deceptive treatment + financial or physical injury + intrusion upon solitude + other substantial injury, (d) processing of sensitive data, (e) processing for which the risk of harm is reasonably foreseeable. Document risk vs benefit analysis. Make assessments available to AG upon request. Maintain processor contracts with required clauses (instructions + duration + nature + purpose + types of data + obligations + return/delete on termination + audit rights + subprocessor consent + confidentiality).
The graph holds this control, the 0 it maps to, and the evidence behind each claim, over MCP and REST.