Implement appropriate technical and organisational measures per NDPR Section 2.6-Security including encryption + pseudonymisation + integrity protection + access controls + regular testing. Notify NITDA (now NDPC) of personal data breaches within 72 hours + notify data subjects when high risk. Conduct Data Protection Impact Assessments (DPIA) for high-risk processing including systematic monitoring + large-scale sensitive data processing.
The graph holds this control, the 0 it maps to, and the evidence behind each claim, over MCP and REST.