{"catalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","kind":"record","record":{"attributes":{"category":"administrative","domain":"Governance, Policy & Oversight","type":"preventive"},"canonicalUrl":"https://controlsmap.com/?v=1&node=uc%3AUC-GOV-26","description":"Adopt and enforce policies and procedures requiring that personal data is processed lawfully, fairly, and transparently; collected for specified, explicit purposes; limited to what is necessary; kept accurate through defined quality-management checks and correction procedures; stored no longer than needed; and protected — with accountability demonstrable through documentation. Minimize or use de-identified personally identifiable information in testing, training, and research, applying documented techniques where full data is not required.","details":{"control_category":"administrative","control_type":"preventive","domain":"Governance, Policy & Oversight","guidance":[],"members":[{"control_id":"GDPR-Art5","coverage":"partial","delta":"operational enforcement of principles sits in data-protection, retention, and security controls","framework":"gdpr","relationship":"intersects_with"},{"control_id":"PT-1","coverage":"partial","delta":"PT-family policy governance of transparency mechanisms - consent, privacy notices, and system-of-records notices - satisfied by the companion notice and consent controls","framework":"nist-800-53","relationship":"intersects_with"},{"control_id":"PM-22","coverage":"full","framework":"nist-800-53","relationship":"superset_of"},{"control_id":"PM-25","coverage":"full","framework":"nist-800-53","relationship":"superset_of"}],"statement":"Adopt and enforce policies and procedures requiring that personal data is processed lawfully, fairly, and transparently; collected for specified, explicit purposes; limited to what is necessary; kept accurate through defined quality-management checks and correction procedures; stored no longer than needed; and protected — with accountability demonstrable through documentation. Minimize or use de-identified personally identifiable information in testing, training, and research, applying documented techniques where full data is not required.","title":"Enforce personal-data processing principles and minimization","unified_id":"UC-GOV-26"},"id":"uc:UC-GOV-26","mapUrl":"https://controlsmap.com/?v=1&node=uc%3AUC-GOV-26","sourceIds":["gdpr","nist-800-53"],"sourceUrl":null,"title":"UC-GOV-26 — Enforce personal-data processing principles and minimization","type":"unified"},"relationships":[{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:1aa4f3767c74099cc2148c324c307a85d0098b8dbc967e0b96ac6f6a29f7819c","properties":{"control_id":"PM-25","coverage":"full","delta":null,"framework":"nist-800-53","provenance":{"defaultConfidence":"medium","defaultStatus":"active","direction":"canonical_to_source","mapper":"coworkcanvas-compliance-graph","note":"Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.","reviewDate":"2026-09-07"},"relationship":"superset_of","source_version":"Rev. 5"},"sourceDetailPath":"/data/v1/records/uc-uc-gov-26-3952a3ca.json","sourceId":"uc:UC-GOV-26","targetDetailPath":"/data/v1/records/ctrl-nist-800-53-pm-25-cddcfe11.json","targetId":"ctrl:nist-800-53:PM-25","type":"maps_to"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:44a783c0681fd9d954b59659de9e9f362dce42f65b9e47d5f9b98cb386abce52","properties":{"rationale":"Enforcing lawful, purpose-limited, minimized data processing (GDPR Art5) directly reduces data-protection enforcement exposure.","strength":"primary"},"sourceDetailPath":"/data/v1/records/uc-uc-gov-26-3952a3ca.json","sourceId":"uc:UC-GOV-26","targetDetailPath":"/data/v1/records/risk-compliance-litigation-enforcement-25e7935d.json","targetId":"risk:compliance-litigation-enforcement","type":"mitigates"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:59ae5d4cc92a49d40595086e2801ef0d5d37288a0bc7b8040a38b3fed8470739","properties":{"control_id":"PT-1","coverage":"partial","delta":"PT-family policy governance of transparency mechanisms - consent, privacy notices, and system-of-records notices - satisfied by the companion notice and consent controls","framework":"nist-800-53","provenance":{"defaultConfidence":"medium","defaultStatus":"active","direction":"canonical_to_source","mapper":"coworkcanvas-compliance-graph","note":"Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.","reviewDate":"2026-09-07"},"relationship":"intersects_with","source_version":"Rev. 5"},"sourceDetailPath":"/data/v1/records/uc-uc-gov-26-3952a3ca.json","sourceId":"uc:UC-GOV-26","targetDetailPath":"/data/v1/records/ctrl-nist-800-53-pt-1-2cb8292c.json","targetId":"ctrl:nist-800-53:PT-1","type":"maps_to"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:5e43c5990acbfbf7423db23ac8507eb93161eca655188b4332fe428d1894b749","properties":{"control_id":"PM-22","coverage":"full","delta":null,"framework":"nist-800-53","provenance":{"defaultConfidence":"medium","defaultStatus":"active","direction":"canonical_to_source","mapper":"coworkcanvas-compliance-graph","note":"Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.","reviewDate":"2026-09-07"},"relationship":"superset_of","source_version":"Rev. 5"},"sourceDetailPath":"/data/v1/records/uc-uc-gov-26-3952a3ca.json","sourceId":"uc:UC-GOV-26","targetDetailPath":"/data/v1/records/ctrl-nist-800-53-pm-22-3de12d70.json","targetId":"ctrl:nist-800-53:PM-22","type":"maps_to"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:75934d360a1405917deff9c9d662d247eff523fda2de95d9e7260901e7977aca","properties":{"control_id":"GDPR-Art5","coverage":"partial","delta":"operational enforcement of principles sits in data-protection, retention, and security controls","framework":"gdpr","provenance":{"defaultConfidence":"medium","defaultStatus":"active","direction":"canonical_to_source","mapper":"coworkcanvas-compliance-graph","note":"Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.","reviewDate":"2026-09-07"},"relationship":"intersects_with","source_version":"Regulation (EU) 2016/679"},"sourceDetailPath":"/data/v1/records/uc-uc-gov-26-3952a3ca.json","sourceId":"uc:UC-GOV-26","targetDetailPath":"/data/v1/records/ctrl-gdpr-gdpr-art5-7b2df9a9.json","targetId":"ctrl:gdpr:GDPR-Art5","type":"maps_to"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:7ec2bdfd72e89c41afa9f03f4fa9089a590736667af217833a8f177635b1d2c9","properties":{"rationale":"Fair, transparent, minimized data handling sustains individual and stakeholder trust.","strength":"related"},"sourceDetailPath":"/data/v1/records/uc-uc-gov-26-3952a3ca.json","sourceId":"uc:UC-GOV-26","targetDetailPath":"/data/v1/records/risk-reputational-stakeholder-trust-23d21e70.json","targetId":"risk:reputational-stakeholder-trust","type":"mitigates"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:afc210bafbc4d1530c9e939558478b52a5b449cfeec2ec4488740f7eed08977c","properties":{},"sourceDetailPath":"/data/v1/records/wf-r11-a48dfcd0.json","sourceId":"wf:R11","targetDetailPath":"/data/v1/records/uc-uc-gov-26-3952a3ca.json","targetId":"uc:UC-GOV-26","type":"operates"}],"schemaVersion":1}
