Per Portugal law + GDPR Chapter V: international transfers. Requirements include (a) implement International Transfers restrictions per GDPR including adequacy + appropriate safeguards (SCCs + BCRs + certification) + derogations + (b) maintain Cross-Border Transfer Safeguards documentation + Transfer Impact Assessment (TIA) per Schrems II + (c) maintain inventory of cross-border flows + recipients + safeguards + (d) implement contractual protections with processors involving international transfer + (e) cooperate with CNPD (Comissao Nacional de Proteccao de Dados) on transfer matters.
The graph holds this control, the 0 it maps to, and the evidence behind each claim, over MCP and REST.