Per RA 10173 + IRR + NPC: cross-border + processor + outsourcing. Requirements include (a) implement Cross-Border Transfer Controls including accountability for personal information transferred abroad + (b) maintain Personal Information Processors Contracts per IRR Section 26 ensuring processors process only on documented instructions + maintain security + assist with rights + breach notification + (c) implement Outsourcing and Subcontracting Agreements per NPC Circulars including specific BPO sector safeguards + (d) maintain inventory of cross-border data flows + recipients + safeguards + (e) implement supplier + processor + sub-processor due diligence.
The graph holds this control, the 0 it maps to, and the evidence behind each claim, over MCP and REST.