Employees, agents and representatives of a controller involved in processing must operate and hold personal information under strict confidentiality where it is not intended for public disclosure, an obligation that continues after leaving public service, transfer to another position or termination of employment or contract; the IRR (section 26(d)) adds that the controller is responsible for selecting and supervising such personnel and for capacity building, orientation or training on privacy and security policies.
The graph holds this control, the 0 it maps to, and the evidence behind each claim, over MCP and REST.