Where appropriate, controllers and processors must comply with the organizational security guidelines: designate a data protection or compliance officer (21(b)); implement data protection policies providing for organizational, physical and technical measures that account for the nature, scope, context and purposes of processing and the risks to data subjects, implement the principles at the time the means of processing are determined and at processing, ensure by default that only necessary personal data is processed as to amount, extent, storage period and accessibility, and provide for documentation, regular review, evaluation and updating; maintain records of processing activities describing the processing system and the duties of those with access (purposes including intended future processing and sharing, categories of data subjects, data and recipients, data flow from collection to disposal with time limits, a description of security measures, and the controller's, joint controller's, representative's and officer's details); select and supervise personnel with access, bind them to confidentiality and train them; develop, implement and review procedures for collection and consent, for limiting processing, for access management, system monitoring and incident protocols, for data subjects' exercise of rights, and a data retention schedule; and bind processors by contract to the security measures.
The graph holds this control, the 0 it maps to, and the evidence behind each claim, over MCP and REST.