Organisations using drones are controllers. They should confirm a genuine need, carry out a DPIA covering recording at altitude and capture of people who are not the focus, register with the Civil Aviation Authority where the criteria apply, have policies and trained, credentialled operators, and inform people where possible (signage in the area, a web privacy notice). Recording should not be continuous without strong justification, should be switchable, and designed to limit intrusion (restricted field of view, recording only at altitude); data should be stored securely (encryption, given loss risk) and kept for the shortest time.
This control maps to 1 controls across 1 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.
Every mapping shown was judged rather than inferred from wording similarity, and the ones that failed review are published too. See the coverage reports and what was rejected.
The graph holds this control, the 1 it maps to, and the evidence behind each claim, over MCP and REST.