Develop and maintain processes that make the handling of personal information consistent with the entity's obligations. The processes cover the whole information lifecycle (before collection, after collection, while held and once no longer needed), give extra attention to higher-risk areas such as sensitive information, service providers, contractors, outsourcing and offshore storage, and state clearly how staff are expected to handle personal information in their everyday work, tailored to how each part of the business uses it.
The graph holds this control, the 0 it maps to, and the evidence behind each claim, over MCP and REST.