Per Peru Law 29733: security + processor management. Requirements include (a) implement Security of Personal Data including organisational + technical + physical measures appropriate to risk per ANPD guidance + (b) maintain Data Processor Agreements ensuring processors process only on documented instructions + maintain security + assist with rights + breach notification + (c) implement supplier + processor + sub-processor due diligence + (d) conduct regular security testing + (e) integrate with broader information security programme + (f) maintain documented security baseline aligned to ANPD minimum standards.
The graph holds this control, the 0 it maps to, and the evidence behind each claim, over MCP and REST.