Per Norwegian PDPA: governance + lifecycle. Requirements include (a) appoint Data Protection Officer where required per GDPR Article 37 with defined responsibilities + reporting to highest management + (b) maintain Cooperation With Datatilsynet (Norwegian Data Protection Authority) including responding to inquiries + facilitating audits + (c) implement Retention and Erasure including retention schedules + secure deletion + anonymisation + (d) implement Direct Marketing and ePrivacy safeguards per Norwegian + EU ePrivacy including consent + opt-out + suppression lists + (e) deliver Training and Awareness programmes including role-based content + GDPR + Norwegian specifics + (f) maintain documented governance + accountability framework.
The graph holds this control, the 0 it maps to, and the evidence behind each claim, over MCP and REST.