The organisation should establish who decides what gets recorded, what it is used for and who may receive it: that party is the controller and legally responsible. Joint decisions make joint controllers, each responsible, with responsibilities agreed transparently; processors need written contracts binding them to instructions with guarantees on security, storage and trained staff; shared services (a council-hosted server feeding a police control room, for example) need strict procedures and clarity on who controls which information when. The controller should define and communicate purposes to operators, document handling and disclosure procedures, give responsibility for them to a DPO or named person, and audit compliance regularly.
This control maps to 2 controls across 1 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.
Every mapping shown was judged rather than inferred from wording similarity, and the ones that failed review are published too. See the coverage reports and what was rejected.
The graph holds this control, the 2 it maps to, and the evidence behind each claim, over MCP and REST.