{"catalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","kind":"record","record":{"attributes":{"category":"administrative","domain":"Governance, Policy & Oversight","type":"preventive"},"canonicalUrl":"https://controlsmap.com/?v=1&node=uc%3AUC-GOV-25","description":"Establish and maintain a privacy program and program plan defining the technical and organisational measures by which the organization ensures, and is able to demonstrate, compliance with privacy requirements. Designate a qualified, appropriately independent privacy leader (a Data Protection Officer where required) with defined tasks, adequate resources, and direct reporting to the highest level of management. Disseminate privacy program information to the workforce and the public, and report on privacy posture and program effectiveness at defined intervals.","details":{"control_category":"administrative","control_type":"preventive","domain":"Governance, Policy & Oversight","guidance":[],"members":[{"control_id":"PM-18","coverage":"full","framework":"nist-800-53","relationship":"superset_of"},{"control_id":"PM-19","coverage":"full","framework":"nist-800-53","relationship":"superset_of"},{"control_id":"PM-20","coverage":"full","framework":"nist-800-53","relationship":"superset_of"},{"control_id":"PM-27","coverage":"full","framework":"nist-800-53","relationship":"superset_of"},{"control_id":"GDPR-Art37-39","coverage":"partial","delta":"DPO contact details must be published and communicated to the supervisory authority","framework":"gdpr","relationship":"intersects_with"},{"control_id":"GDPR-Art24","coverage":"partial","delta":"implementing operational technical and organisational protection measures across all processing","framework":"gdpr","relationship":"intersects_with"}],"statement":"Establish and maintain a privacy program and program plan defining the technical and organisational measures by which the organization ensures, and is able to demonstrate, compliance with privacy requirements. Designate a qualified, appropriately independent privacy leader (a Data Protection Officer where required) with defined tasks, adequate resources, and direct reporting to the highest level of management. Disseminate privacy program information to the workforce and the public, and report on privacy posture and program effectiveness at defined intervals.","title":"Operate a privacy program with accountable leadership","unified_id":"UC-GOV-25"},"id":"uc:UC-GOV-25","mapUrl":"https://controlsmap.com/?v=1&node=uc%3AUC-GOV-25","sourceIds":["gdpr","nist-800-53"],"sourceUrl":null,"title":"UC-GOV-25 — Operate a privacy program with accountable leadership","type":"unified"},"relationships":[{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:2e2200cf7c9c42699b2dcb0b4d1193497790e85e7441d5bd59d7ae0c1de31269","properties":{"control_id":"GDPR-Art24","coverage":"partial","delta":"implementing operational technical and organisational protection measures across all processing","framework":"gdpr","provenance":{"defaultConfidence":"medium","defaultStatus":"active","direction":"canonical_to_source","mapper":"coworkcanvas-compliance-graph","note":"Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.","reviewDate":"2026-09-07"},"relationship":"intersects_with","source_version":"Regulation (EU) 2016/679"},"sourceDetailPath":"/data/v1/records/uc-uc-gov-25-7960cafc.json","sourceId":"uc:UC-GOV-25","targetDetailPath":"/data/v1/records/ctrl-gdpr-gdpr-art24-063cd42d.json","targetId":"ctrl:gdpr:GDPR-Art24","type":"maps_to"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:64551a76ab797d15863c7f587c79e31eb9302eb72df868e9a33674e9de93abba","properties":{"control_id":"GDPR-Art37-39","coverage":"partial","delta":"DPO contact details must be published and communicated to the supervisory authority","framework":"gdpr","provenance":{"defaultConfidence":"medium","defaultStatus":"active","direction":"canonical_to_source","mapper":"coworkcanvas-compliance-graph","note":"Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.","reviewDate":"2026-09-07"},"relationship":"intersects_with","source_version":"Regulation (EU) 2016/679"},"sourceDetailPath":"/data/v1/records/uc-uc-gov-25-7960cafc.json","sourceId":"uc:UC-GOV-25","targetDetailPath":"/data/v1/records/ctrl-gdpr-gdpr-art37-39-f756de70.json","targetId":"ctrl:gdpr:GDPR-Art37-39","type":"maps_to"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:81b0c91efc2a28b672c0564ac43522d22a352c500b9b0917b99e0f7685d7bb48","properties":{"rationale":"A DPO advising on and monitoring privacy-policy compliance addresses undefined roles and privacy-policy gaps.","strength":"primary"},"sourceDetailPath":"/data/v1/records/uc-uc-gov-25-7960cafc.json","sourceId":"uc:UC-GOV-25","targetDetailPath":"/data/v1/records/risk-gov-policy-absent-cf76dbbf.json","targetId":"risk:gov-policy-absent","type":"mitigates"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:9439efa7236a47eebf298a22c7ba06e8c7cd3e7cbd50056754e79133fec2436a","properties":{"control_id":"PM-19","coverage":"full","delta":null,"framework":"nist-800-53","provenance":{"defaultConfidence":"medium","defaultStatus":"active","direction":"canonical_to_source","mapper":"coworkcanvas-compliance-graph","note":"Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.","reviewDate":"2026-09-07"},"relationship":"superset_of","source_version":"Rev. 5"},"sourceDetailPath":"/data/v1/records/uc-uc-gov-25-7960cafc.json","sourceId":"uc:UC-GOV-25","targetDetailPath":"/data/v1/records/ctrl-nist-800-53-pm-19-0a30c684.json","targetId":"ctrl:nist-800-53:PM-19","type":"maps_to"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:9dffbad918d7b29fae5097c96338fad617d3ce65812074e4179b6417036d83bb","properties":{},"sourceDetailPath":"/data/v1/records/wf-c9-75fb1752.json","sourceId":"wf:C9","targetDetailPath":"/data/v1/records/uc-uc-gov-25-7960cafc.json","targetId":"uc:UC-GOV-25","type":"tests"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:b8046a342ac481ac3331018529a5627b550fc293df7b0de18d532b3ead55f8ae","properties":{"control_id":"PM-27","coverage":"full","delta":null,"framework":"nist-800-53","provenance":{"defaultConfidence":"medium","defaultStatus":"active","direction":"canonical_to_source","mapper":"coworkcanvas-compliance-graph","note":"Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.","reviewDate":"2026-09-07"},"relationship":"superset_of","source_version":"Rev. 5"},"sourceDetailPath":"/data/v1/records/uc-uc-gov-25-7960cafc.json","sourceId":"uc:UC-GOV-25","targetDetailPath":"/data/v1/records/ctrl-nist-800-53-pm-27-19be9144.json","targetId":"ctrl:nist-800-53:PM-27","type":"maps_to"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:b9cdb7728148e892209633b56ce9552539b1691ac4b46ca99062f9fe23e1a793","properties":{"rationale":"A privacy program that ensures and demonstrates compliance directly reduces privacy regulatory enforcement (GDPR).","strength":"primary"},"sourceDetailPath":"/data/v1/records/uc-uc-gov-25-7960cafc.json","sourceId":"uc:UC-GOV-25","targetDetailPath":"/data/v1/records/risk-compliance-litigation-enforcement-25e7935d.json","targetId":"risk:compliance-litigation-enforcement","type":"mitigates"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:c704d2ac1c62215ae4b86bf5c801083515eb4a0c162ac64659cd293d569d271c","properties":{"rationale":"Demonstrable privacy stewardship sustains customer and regulator trust.","strength":"related"},"sourceDetailPath":"/data/v1/records/uc-uc-gov-25-7960cafc.json","sourceId":"uc:UC-GOV-25","targetDetailPath":"/data/v1/records/risk-reputational-stakeholder-trust-23d21e70.json","targetId":"risk:reputational-stakeholder-trust","type":"mitigates"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:cd6528d9fb036659204dc297a038d1036678849f12b63fa13874776f210ba458","properties":{"control_id":"PM-18","coverage":"full","delta":null,"framework":"nist-800-53","provenance":{"defaultConfidence":"medium","defaultStatus":"active","direction":"canonical_to_source","mapper":"coworkcanvas-compliance-graph","note":"Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.","reviewDate":"2026-09-07"},"relationship":"superset_of","source_version":"Rev. 5"},"sourceDetailPath":"/data/v1/records/uc-uc-gov-25-7960cafc.json","sourceId":"uc:UC-GOV-25","targetDetailPath":"/data/v1/records/ctrl-nist-800-53-pm-18-ea7b6f04.json","targetId":"ctrl:nist-800-53:PM-18","type":"maps_to"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:e13c69d9475c363547df76ae0fde8b9656075cfc4e5b71d4f8d6c12dbf82380d","properties":{},"sourceDetailPath":"/data/v1/records/wf-r11-a48dfcd0.json","sourceId":"wf:R11","targetDetailPath":"/data/v1/records/uc-uc-gov-25-7960cafc.json","targetId":"uc:UC-GOV-25","type":"operates"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:ebb664d97fc8b7331f3289449185f55aa5fae6a8a454547743762135642c6dfc","properties":{"control_id":"PM-20","coverage":"full","delta":null,"framework":"nist-800-53","provenance":{"defaultConfidence":"medium","defaultStatus":"active","direction":"canonical_to_source","mapper":"coworkcanvas-compliance-graph","note":"Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.","reviewDate":"2026-09-07"},"relationship":"superset_of","source_version":"Rev. 5"},"sourceDetailPath":"/data/v1/records/uc-uc-gov-25-7960cafc.json","sourceId":"uc:UC-GOV-25","targetDetailPath":"/data/v1/records/ctrl-nist-800-53-pm-20-5df8f32d.json","targetId":"ctrl:nist-800-53:PM-20","type":"maps_to"}],"schemaVersion":1}
