Per Thailand PDPA cross-border transfer + processor provisions. Requirements include (a) implement Cross-Border Data Transfer restrictions - transfer personal data outside Thailand only where destination provides adequate protection (per PDPC determination) + binding corporate rules + standard contractual clauses + explicit consent + or other conditions per PDPA + (b) implement Cross-Border Transfer Safeguards documentation + transfer impact assessments + (c) implement Processor Engagement and Oversight via Data Processing Agreements ensuring processors process only on documented instructions + maintain security + assist with rights + breach notification + (d) maintain inventory of cross-border flows + recipients + safeguards + (e) implement supplier + processor + sub-processor due diligence + (f) cooperate with PDPC on transfer matters.
The graph holds this control, the 0 it maps to, and the evidence behind each claim, over MCP and REST.