Per Portugal law + GDPR: governance + lifecycle. Requirements include (a) Designation and Notification of Data Protection Officer (DPO) per GDPR Article 37 + national requirements with notification to CNPD (Comissao Nacional de Proteccao de Dados) + (b) cooperate with CNPD (Comissao Nacional de Proteccao de Dados) (CNPD) including responding to inquiries + facilitating audits + (c) implement Retention and Erasure including retention schedules + secure deletion + (d) implement Direct Marketing and Cookies safeguards per national + EU ePrivacy + (e) deliver Training and Awareness programmes including role-based content + national specifics + (f) maintain documented governance + accountability framework.
The graph holds this control, the 0 it maps to, and the evidence behind each claim, over MCP and REST.