Processing by a processor must be governed by a contract or other legal act binding the processor to the controller that sets out the subject matter, duration, nature and purpose of the processing, the type of personal data and categories of data subjects, the obligations and rights of the controller, and the geographic location of the processing, and stipulates that the processor will process only on the controller's documented instructions including transfers abroad unless authorised by law; impose confidentiality on persons authorised to process; implement appropriate security measures and comply with the Act, the IRR and Commission issuances; not engage another processor without prior instruction and flow down the same obligations; assist the controller with technical and organizational measures in responding to data subjects' requests; assist the controller in ensuring compliance taking account of the nature of processing and the information available; delete or return all personal data at the controller's choice at the end of services and delete existing copies unless storage is authorised by law; make available all information necessary to demonstrate compliance and allow and contribute to audits and inspections by the controller or its mandated auditor; and immediately inform the controller if an instruction infringes the Act, the IRR or an issuance.
The graph holds this control, the 0 it maps to, and the evidence behind each claim, over MCP and REST.