Implement security of processing + privacy by design + DPIA per Oman PDPL Articles 19 + 20. Security must (a) implement appropriate technical and organisational measures considering state of the art + cost + nature/scope/purpose of processing + risk to data subjects + (b) include encryption + pseudonymisation + access control + integrity + availability + resilience + regular testing + (c) integrate with broader cybersecurity programme aligned with Oman National Cybersecurity Framework. Privacy by Design requires (a) embedding privacy considerations into system design + procurement + change management, (b) maintaining privacy default settings, (c) maintaining data minimisation by design. DPIA (Data Protection Impact Assessment) must be conducted for high-risk processing per Article 20 + criteria similar to GDPR Article 35 (large-scale processing of sensitive data + systematic monitoring + automated decision-making affecting individuals + similar) + with consultation of supervisory authority where high residual risk identified.
The graph holds this control, the 0 it maps to, and the evidence behind each claim, over MCP and REST.