Per Norwegian PDPA + GDPR Chapter V + Article 28: transfer + processor management. Requirements include (a) implement International Transfers restrictions per GDPR including adequacy + appropriate safeguards (SCCs + BCRs + certification) + derogations + (b) maintain Cross-Border Transfer Safeguards documentation + Transfer Impact Assessment (TIA) per Schrems II + (c) maintain Processor Agreements per GDPR Article 28 ensuring processors process only on documented instructions + maintain security + assist with rights + breach notification + (d) maintain inventory of cross-border flows + recipients + safeguards + (e) implement supplier + processor + sub-processor due diligence + (f) cooperate with Datatilsynet on transfer matters.
The graph holds this control, the 0 it maps to, and the evidence behind each claim, over MCP and REST.