{"catalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","contextIds":["risk:access-privilege-abuse-repudiation","risk:access-unauthorized-use-equipment","risk:asset-inventory-gap","risk:aware-user-error-mishandling","risk:compliance-litigation-enforcement","risk:compliance-sector-regulatory-breach","risk:cyber-adversary-threat-sources","risk:data-breach-unauthorized-disclosure","risk:data-excessive-collection-purpose-creep","risk:data-exfiltration-espionage","risk:data-inventory-flows-unmapped","risk:data-privacy-harms-to-individuals","risk:data-privacy-program-noncompliance","risk:data-retention-noncompliance","risk:data-transparency-notice-dark-patterns","risk:fin-segregation-of-duties","risk:gov-policy-absent","risk:hr-missing-security-terms-discipline","risk:ir-breach-notification-failure","risk:log-no-monitoring-supervision","risk:ops-documentation-account-management","risk:privacy-cross-border-transfer","risk:privacy-loss-of-trust","risk:privacy-power-imbalance-self-determination"],"directIds":["ctrl:gdpr:GDPR-Art12-14","ctrl:gdpr:GDPR-Art15-22","ctrl:gdpr:GDPR-Art24","ctrl:gdpr:GDPR-Art25","ctrl:gdpr:GDPR-Art28","ctrl:gdpr:GDPR-Art30","ctrl:gdpr:GDPR-Art32","ctrl:gdpr:GDPR-Art33","ctrl:gdpr:GDPR-Art34","ctrl:gdpr:GDPR-Art35","ctrl:gdpr:GDPR-Art37-39","ctrl:gdpr:GDPR-Art44-49","ctrl:gdpr:GDPR-Art5","ctrl:gdpr:GDPR-Art6","ctrl:gdpr:GDPR-Art7","ctrl:gdpr:GDPR-Art9"],"kind":"bundle","metadata":"/assets/agent_metadata.5c7612c9c5b0b455.json","name":"EU GDPR","next":"/assets/agent_sources-gdpr-2.f8242d0fcd98291c.json","page":1,"pageSize":40,"records":[{"attributes":{"category":"administrative","framework":"gdpr","type":"preventive"},"canonicalUrl":"https://controlsmap.com/frameworks/gdpr/","description":"Transparency and information to data subjects","details":{"automation":"manual","control_category":"administrative","control_id":"GDPR-Art12-14","control_type":"preventive","domains":["Data Protection & Privacy","Governance, Policy & Oversight","Incident Management & Response","Third-Party / Supply-Chain Risk","Risk Assessment & Management"],"framework":"gdpr","group":"EU GDPR","key_control":false,"requirement_frequency":null,"requirement_status":null,"risk_count":4,"source_pages":null,"source_url":null},"direct":true,"htmlUrl":"/agents/records/ctrl-gdpr-gdpr-art12-14-51a7eca7.html","id":"ctrl:gdpr:GDPR-Art12-14","mapUrl":"https://controlsmap.com/?v=1&node=ctrl%3Agdpr%3AGDPR-Art12-14","sourceIds":["gdpr"],"sourceUrl":null,"title":"GDPR-Art12-14 — Transparency and information to data subjects","type":"control","url":"/assets/agent_record-ctrl-gdpr-gdpr-art12-14-51a7eca7.443bcfb1c9d586c8.json"},{"attributes":{"category":"administrative","framework":"gdpr","type":"corrective"},"canonicalUrl":"https://controlsmap.com/frameworks/gdpr/","description":"Data subject rights (access, rectification, erasure, portability, objection, automated decisions)","details":{"automation":"manual","control_category":"administrative","control_id":"GDPR-Art15-22","control_type":"corrective","domains":["Data Protection & Privacy","Governance, Policy & Oversight","Incident Management & Response","Third-Party / Supply-Chain Risk","Risk Assessment & Management"],"framework":"gdpr","group":"EU GDPR","key_control":false,"requirement_frequency":null,"requirement_status":null,"risk_count":4,"source_pages":null,"source_url":null},"direct":true,"htmlUrl":"/agents/records/ctrl-gdpr-gdpr-art15-22-256fff35.html","id":"ctrl:gdpr:GDPR-Art15-22","mapUrl":"https://controlsmap.com/?v=1&node=ctrl%3Agdpr%3AGDPR-Art15-22","sourceIds":["gdpr"],"sourceUrl":null,"title":"GDPR-Art15-22 — Data subject rights (access, rectification, erasure, portability, objection, automated decisions)","type":"control","url":"/assets/agent_record-ctrl-gdpr-gdpr-art15-22-256fff35.aa389b31c0e1ea3f.json"},{"attributes":{"category":"administrative","framework":"gdpr","type":"preventive"},"canonicalUrl":"https://controlsmap.com/frameworks/gdpr/","description":"Responsibility of the controller","details":{"automation":"manual","control_category":"administrative","control_id":"GDPR-Art24","control_type":"preventive","domains":["Data Protection & Privacy","Governance, Policy & Oversight","Incident Management & Response","Third-Party / Supply-Chain Risk","Risk Assessment & Management"],"framework":"gdpr","group":"EU GDPR","key_control":false,"requirement_frequency":null,"requirement_status":null,"risk_count":3,"source_pages":null,"source_url":null},"direct":true,"htmlUrl":"/agents/records/ctrl-gdpr-gdpr-art24-063cd42d.html","id":"ctrl:gdpr:GDPR-Art24","mapUrl":"https://controlsmap.com/?v=1&node=ctrl%3Agdpr%3AGDPR-Art24","sourceIds":["gdpr"],"sourceUrl":null,"title":"GDPR-Art24 — Responsibility of the controller","type":"control","url":"/assets/agent_record-ctrl-gdpr-gdpr-art24-063cd42d.abcf2d84e9dbe2e8.json"},{"attributes":{"category":"administrative","framework":"gdpr","type":"preventive"},"canonicalUrl":"https://controlsmap.com/frameworks/gdpr/","description":"Data protection by design and by default","details":{"automation":"manual","control_category":"administrative","control_id":"GDPR-Art25","control_type":"preventive","domains":["Data Protection & Privacy","Governance, Policy & Oversight","Incident Management & Response","Third-Party / Supply-Chain Risk","Risk Assessment & Management"],"framework":"gdpr","group":"EU GDPR","key_control":false,"requirement_frequency":null,"requirement_status":null,"risk_count":4,"source_pages":null,"source_url":null},"direct":true,"htmlUrl":"/agents/records/ctrl-gdpr-gdpr-art25-ccf26a83.html","id":"ctrl:gdpr:GDPR-Art25","mapUrl":"https://controlsmap.com/?v=1&node=ctrl%3Agdpr%3AGDPR-Art25","sourceIds":["gdpr"],"sourceUrl":null,"title":"GDPR-Art25 — Data protection by design and by default","type":"control","url":"/assets/agent_record-ctrl-gdpr-gdpr-art25-ccf26a83.b61830414c6ac681.json"},{"attributes":{"category":"administrative","framework":"gdpr","type":"preventive"},"canonicalUrl":"https://controlsmap.com/frameworks/gdpr/","description":"Processor obligations and data processing agreements","details":{"automation":"manual","control_category":"administrative","control_id":"GDPR-Art28","control_type":"preventive","domains":["Data Protection & Privacy","Governance, Policy & Oversight","Incident Management & Response","Third-Party / Supply-Chain Risk","Risk Assessment & Management"],"framework":"gdpr","group":"EU GDPR","key_control":false,"requirement_frequency":null,"requirement_status":null,"risk_count":5,"source_pages":null,"source_url":null},"direct":true,"htmlUrl":"/agents/records/ctrl-gdpr-gdpr-art28-e21fee94.html","id":"ctrl:gdpr:GDPR-Art28","mapUrl":"https://controlsmap.com/?v=1&node=ctrl%3Agdpr%3AGDPR-Art28","sourceIds":["gdpr"],"sourceUrl":null,"title":"GDPR-Art28 — Processor obligations and data processing agreements","type":"control","url":"/assets/agent_record-ctrl-gdpr-gdpr-art28-e21fee94.5ea41d93b9f5d85d.json"},{"attributes":{"category":"administrative","framework":"gdpr","type":"preventive"},"canonicalUrl":"https://controlsmap.com/frameworks/gdpr/","description":"Records of processing activities (RoPA)","details":{"automation":"manual","control_category":"administrative","control_id":"GDPR-Art30","control_type":"preventive","domains":["Data Protection & Privacy","Governance, Policy & Oversight","Incident Management & Response","Third-Party / Supply-Chain Risk","Risk Assessment & Management"],"framework":"gdpr","group":"EU GDPR","key_control":false,"requirement_frequency":null,"requirement_status":null,"risk_count":2,"source_pages":null,"source_url":null},"direct":true,"htmlUrl":"/agents/records/ctrl-gdpr-gdpr-art30-e7db10f3.html","id":"ctrl:gdpr:GDPR-Art30","mapUrl":"https://controlsmap.com/?v=1&node=ctrl%3Agdpr%3AGDPR-Art30","sourceIds":["gdpr"],"sourceUrl":null,"title":"GDPR-Art30 — Records of processing activities (RoPA)","type":"control","url":"/assets/agent_record-ctrl-gdpr-gdpr-art30-e7db10f3.1bae307ce9713d40.json"},{"attributes":{"category":"technical","framework":"gdpr","type":"preventive"},"canonicalUrl":"https://controlsmap.com/frameworks/gdpr/","description":"Security of processing","details":{"automation":"hybrid","control_category":"technical","control_id":"GDPR-Art32","control_type":"preventive","domains":["Data Protection & Privacy","Governance, Policy & Oversight","Incident Management & Response","Third-Party / Supply-Chain Risk","Risk Assessment & Management"],"framework":"gdpr","group":"EU GDPR","key_control":true,"requirement_frequency":null,"requirement_status":null,"risk_count":4,"source_pages":null,"source_url":null},"direct":true,"htmlUrl":"/agents/records/ctrl-gdpr-gdpr-art32-63aa3290.html","id":"ctrl:gdpr:GDPR-Art32","mapUrl":"https://controlsmap.com/?v=1&node=ctrl%3Agdpr%3AGDPR-Art32","sourceIds":["gdpr"],"sourceUrl":null,"title":"GDPR-Art32 — Security of processing","type":"control","url":"/assets/agent_record-ctrl-gdpr-gdpr-art32-63aa3290.135b09987bf85085.json"},{"attributes":{"category":"administrative","framework":"gdpr","type":"corrective"},"canonicalUrl":"https://controlsmap.com/frameworks/gdpr/","description":"Notification of a personal data breach to the supervisory authority","details":{"automation":"manual","control_category":"administrative","control_id":"GDPR-Art33","control_type":"corrective","domains":["Data Protection & Privacy","Governance, Policy & Oversight","Incident Management & Response","Third-Party / Supply-Chain Risk","Risk Assessment & Management"],"framework":"gdpr","group":"EU GDPR","key_control":true,"requirement_frequency":null,"requirement_status":null,"risk_count":3,"source_pages":null,"source_url":null},"direct":true,"htmlUrl":"/agents/records/ctrl-gdpr-gdpr-art33-a2a440c2.html","id":"ctrl:gdpr:GDPR-Art33","mapUrl":"https://controlsmap.com/?v=1&node=ctrl%3Agdpr%3AGDPR-Art33","sourceIds":["gdpr"],"sourceUrl":null,"title":"GDPR-Art33 — Notification of a personal data breach to the supervisory authority","type":"control","url":"/assets/agent_record-ctrl-gdpr-gdpr-art33-a2a440c2.047194a4abc43d41.json"},{"attributes":{"category":"administrative","framework":"gdpr","type":"corrective"},"canonicalUrl":"https://controlsmap.com/frameworks/gdpr/","description":"Communication of a breach to the data subject","details":{"automation":"manual","control_category":"administrative","control_id":"GDPR-Art34","control_type":"corrective","domains":["Data Protection & Privacy","Governance, Policy & Oversight","Incident Management & Response","Third-Party / Supply-Chain Risk","Risk Assessment & Management"],"framework":"gdpr","group":"EU GDPR","key_control":false,"requirement_frequency":null,"requirement_status":null,"risk_count":1,"source_pages":null,"source_url":null},"direct":true,"htmlUrl":"/agents/records/ctrl-gdpr-gdpr-art34-6e2bfc74.html","id":"ctrl:gdpr:GDPR-Art34","mapUrl":"https://controlsmap.com/?v=1&node=ctrl%3Agdpr%3AGDPR-Art34","sourceIds":["gdpr"],"sourceUrl":null,"title":"GDPR-Art34 — Communication of a breach to the data subject","type":"control","url":"/assets/agent_record-ctrl-gdpr-gdpr-art34-6e2bfc74.d7048e8b489ba26d.json"},{"attributes":{"category":"administrative","framework":"gdpr","type":"preventive"},"canonicalUrl":"https://controlsmap.com/frameworks/gdpr/","description":"Data protection impact assessment (DPIA)","details":{"automation":"manual","control_category":"administrative","control_id":"GDPR-Art35","control_type":"preventive","domains":["Data Protection & Privacy","Governance, Policy & Oversight","Incident Management & Response","Third-Party / Supply-Chain Risk","Risk Assessment & Management"],"framework":"gdpr","group":"EU GDPR","key_control":false,"requirement_frequency":null,"requirement_status":null,"risk_count":2,"source_pages":null,"source_url":null},"direct":true,"htmlUrl":"/agents/records/ctrl-gdpr-gdpr-art35-4314d563.html","id":"ctrl:gdpr:GDPR-Art35","mapUrl":"https://controlsmap.com/?v=1&node=ctrl%3Agdpr%3AGDPR-Art35","sourceIds":["gdpr"],"sourceUrl":null,"title":"GDPR-Art35 — Data protection impact assessment (DPIA)","type":"control","url":"/assets/agent_record-ctrl-gdpr-gdpr-art35-4314d563.f684ce8653a753ae.json"},{"attributes":{"category":"administrative","framework":"gdpr","type":"preventive"},"canonicalUrl":"https://controlsmap.com/frameworks/gdpr/","description":"Designation and tasks of the Data Protection Officer","details":{"automation":"manual","control_category":"administrative","control_id":"GDPR-Art37-39","control_type":"preventive","domains":["Data Protection & Privacy","Governance, Policy & Oversight","Incident Management & Response","Third-Party / Supply-Chain Risk","Risk Assessment & Management"],"framework":"gdpr","group":"EU GDPR","key_control":false,"requirement_frequency":null,"requirement_status":null,"risk_count":3,"source_pages":null,"source_url":null},"direct":true,"htmlUrl":"/agents/records/ctrl-gdpr-gdpr-art37-39-f756de70.html","id":"ctrl:gdpr:GDPR-Art37-39","mapUrl":"https://controlsmap.com/?v=1&node=ctrl%3Agdpr%3AGDPR-Art37-39","sourceIds":["gdpr"],"sourceUrl":null,"title":"GDPR-Art37-39 — Designation and tasks of the Data Protection Officer","type":"control","url":"/assets/agent_record-ctrl-gdpr-gdpr-art37-39-f756de70.fe73383a4d8531ae.json"},{"attributes":{"category":"administrative","framework":"gdpr","type":"preventive"},"canonicalUrl":"https://controlsmap.com/frameworks/gdpr/","description":"International transfers of personal data","details":{"automation":"manual","control_category":"administrative","control_id":"GDPR-Art44-49","control_type":"preventive","domains":["Data Protection & Privacy","Governance, Policy & Oversight","Incident Management & Response","Third-Party / Supply-Chain Risk","Risk Assessment & Management"],"framework":"gdpr","group":"EU GDPR","key_control":false,"requirement_frequency":null,"requirement_status":null,"risk_count":5,"source_pages":null,"source_url":null},"direct":true,"htmlUrl":"/agents/records/ctrl-gdpr-gdpr-art44-49-8ad28202.html","id":"ctrl:gdpr:GDPR-Art44-49","mapUrl":"https://controlsmap.com/?v=1&node=ctrl%3Agdpr%3AGDPR-Art44-49","sourceIds":["gdpr"],"sourceUrl":null,"title":"GDPR-Art44-49 — International transfers of personal data","type":"control","url":"/assets/agent_record-ctrl-gdpr-gdpr-art44-49-8ad28202.5b6cd8ca6d1807c9.json"},{"attributes":{"category":"administrative","framework":"gdpr","type":"preventive"},"canonicalUrl":"https://controlsmap.com/frameworks/gdpr/","description":"Principles relating to processing of personal data","details":{"automation":"manual","control_category":"administrative","control_id":"GDPR-Art5","control_type":"preventive","domains":["Data Protection & Privacy","Governance, Policy & Oversight","Incident Management & Response","Third-Party / Supply-Chain Risk","Risk Assessment & Management"],"framework":"gdpr","group":"EU GDPR","key_control":false,"requirement_frequency":null,"requirement_status":null,"risk_count":2,"source_pages":null,"source_url":null},"direct":true,"htmlUrl":"/agents/records/ctrl-gdpr-gdpr-art5-7b2df9a9.html","id":"ctrl:gdpr:GDPR-Art5","mapUrl":"https://controlsmap.com/?v=1&node=ctrl%3Agdpr%3AGDPR-Art5","sourceIds":["gdpr"],"sourceUrl":null,"title":"GDPR-Art5 — Principles relating to processing of personal data","type":"control","url":"/assets/agent_record-ctrl-gdpr-gdpr-art5-7b2df9a9.c38e68ebfa02ec90.json"},{"attributes":{"category":"administrative","framework":"gdpr","type":"preventive"},"canonicalUrl":"https://controlsmap.com/frameworks/gdpr/","description":"Lawfulness of processing","details":{"automation":"manual","control_category":"administrative","control_id":"GDPR-Art6","control_type":"preventive","domains":["Data Protection & Privacy","Governance, Policy & Oversight","Incident Management & Response","Third-Party / Supply-Chain Risk","Risk Assessment & Management"],"framework":"gdpr","group":"EU GDPR","key_control":false,"requirement_frequency":null,"requirement_status":null,"risk_count":4,"source_pages":null,"source_url":null},"direct":true,"htmlUrl":"/agents/records/ctrl-gdpr-gdpr-art6-cbe66aa0.html","id":"ctrl:gdpr:GDPR-Art6","mapUrl":"https://controlsmap.com/?v=1&node=ctrl%3Agdpr%3AGDPR-Art6","sourceIds":["gdpr"],"sourceUrl":null,"title":"GDPR-Art6 — Lawfulness of processing","type":"control","url":"/assets/agent_record-ctrl-gdpr-gdpr-art6-cbe66aa0.b28f5e1b1bc8659e.json"},{"attributes":{"category":"administrative","framework":"gdpr","type":"preventive"},"canonicalUrl":"https://controlsmap.com/frameworks/gdpr/","description":"Conditions for consent","details":{"automation":"manual","control_category":"administrative","control_id":"GDPR-Art7","control_type":"preventive","domains":["Data Protection & Privacy","Governance, Policy & Oversight","Incident Management & Response","Third-Party / Supply-Chain Risk","Risk Assessment & Management"],"framework":"gdpr","group":"EU GDPR","key_control":false,"requirement_frequency":null,"requirement_status":null,"risk_count":5,"source_pages":null,"source_url":null},"direct":true,"htmlUrl":"/agents/records/ctrl-gdpr-gdpr-art7-218fdd35.html","id":"ctrl:gdpr:GDPR-Art7","mapUrl":"https://controlsmap.com/?v=1&node=ctrl%3Agdpr%3AGDPR-Art7","sourceIds":["gdpr"],"sourceUrl":null,"title":"GDPR-Art7 — Conditions for consent","type":"control","url":"/assets/agent_record-ctrl-gdpr-gdpr-art7-218fdd35.f32ec1f060af891d.json"},{"attributes":{"category":"administrative","framework":"gdpr","type":"preventive"},"canonicalUrl":"https://controlsmap.com/frameworks/gdpr/","description":"Processing of special categories of data","details":{"automation":"manual","control_category":"administrative","control_id":"GDPR-Art9","control_type":"preventive","domains":["Data Protection & Privacy","Governance, Policy & Oversight","Incident Management & Response","Third-Party / Supply-Chain Risk","Risk Assessment & Management"],"framework":"gdpr","group":"EU GDPR","key_control":false,"requirement_frequency":null,"requirement_status":null,"risk_count":3,"source_pages":null,"source_url":null},"direct":true,"htmlUrl":"/agents/records/ctrl-gdpr-gdpr-art9-0813ab56.html","id":"ctrl:gdpr:GDPR-Art9","mapUrl":"https://controlsmap.com/?v=1&node=ctrl%3Agdpr%3AGDPR-Art9","sourceIds":["gdpr"],"sourceUrl":null,"title":"GDPR-Art9 — Processing of special categories of data","type":"control","url":"/assets/agent_record-ctrl-gdpr-gdpr-art9-0813ab56.36120ac99d1d4774.json"},{"attributes":{"category":"cyber_security","domain":["Access Control & Identity Management","Logging, Monitoring & Detection"],"inherent_rating":"high","taxonomy":["iso-27005-threat","nist-800-30-threat-event","nist-800-30-threat-source"]},"canonicalUrl":"https://controlsmap.com/?v=1&node=risk%3Aaccess-privilege-abuse-repudiation","description":"Authorized users or administrators exploit legitimate access beyond permitted scope, fabricate or forge credentials/rights to gain privileges, and repudiate performed actions — undermining accountability and audit-trail integrity.","details":{"category":"cyber_security","impact":"high","inherent_rating":"high","likelihood":"medium","risk_id":"access-privilege-abuse-repudiation","taxonomies":["iso-27005-threat","nist-800-30-threat-event","nist-800-30-threat-source"],"treatment":"mitigate"},"direct":false,"htmlUrl":"/agents/records/risk-access-privilege-abuse-repudiation-343a8917.html","id":"risk:access-privilege-abuse-repudiation","mapUrl":"https://controlsmap.com/?v=1&node=risk%3Aaccess-privilege-abuse-repudiation","sourceIds":["aiuc-1","gdpr","hipaa","iso-27001","nist-800-53","nist-ai-agent-identity","nist-csf-2","nydfs-500","pci-dss","soc1","soc2","sox"],"sourceUrl":null,"title":"Abuse of rights, forged rights, and repudiation of actions","type":"risk","url":"/assets/agent_record-risk-access-privilege-abuse-repudiation-343a8917.5dfe55c5d06b0530.json"},{"attributes":{"category":"cyber_security","domain":["Access Control & Identity Management"],"inherent_rating":"medium","taxonomy":["iso-27005-threat","nist-800-30-threat-event"]},"canonicalUrl":"https://controlsmap.com/?v=1&node=risk%3Aaccess-unauthorized-use-equipment","description":"Use of systems, networks, or devices without authorization, and users with authorized access reaching resources that exceed their authorization, potentially to exfiltrate data or conduct attacks.","details":{"category":"cyber_security","impact":"medium","inherent_rating":"medium","likelihood":"medium","risk_id":"access-unauthorized-use-equipment","taxonomies":["iso-27005-threat","nist-800-30-threat-event"],"treatment":"mitigate"},"direct":false,"htmlUrl":"/agents/records/risk-access-unauthorized-use-equipment-d2082944.html","id":"risk:access-unauthorized-use-equipment","mapUrl":"https://controlsmap.com/?v=1&node=risk%3Aaccess-unauthorized-use-equipment","sourceIds":["aiuc-1","gdpr","hipaa","iso-27001","nist-800-53","nist-ai-agent-identity","nist-csf-2","pci-dss","soc1","soc2","sox"],"sourceUrl":null,"title":"Unauthorized use of equipment and unauthorized access escalation","type":"risk","url":"/assets/agent_record-risk-access-unauthorized-use-equipment-d2082944.659ef798ce61ee67.json"},{"attributes":{"category":"operational","domain":["Asset Management & Inventory","Data Protection & Privacy"],"inherent_rating":"medium","taxonomy":["iso-27005-vulnerability"]},"canonicalUrl":"https://controlsmap.com/?v=1&node=risk%3Aasset-inventory-gap","description":"No authoritative inventory of information and associated assets, missing ownership, acceptable-use, classification, labelling, or handling rules — preventing effective protection, risk assessment, and secure disposal.","details":{"category":"operational","impact":"medium","inherent_rating":"medium","likelihood":"high","risk_id":"asset-inventory-gap","taxonomies":["iso-27005-vulnerability"],"treatment":"mitigate"},"direct":false,"htmlUrl":"/agents/records/risk-asset-inventory-gap-e18c7e73.html","id":"risk:asset-inventory-gap","mapUrl":"https://controlsmap.com/?v=1&node=risk%3Aasset-inventory-gap","sourceIds":["coso-ic","gdpr","iso-27001","nist-800-53","nist-csf-2","soc2"],"sourceUrl":null,"title":"Incomplete asset inventory and classification","type":"risk","url":"/assets/agent_record-risk-asset-inventory-gap-e18c7e73.eff694953485c2c6.json"},{"attributes":{"category":"operational","domain":["Awareness & Training","Data Protection & Privacy","Logging, Monitoring & Detection"],"inherent_rating":"high","taxonomy":["iso-27005-threat","nist-800-30-threat-event","nist-800-30-threat-source","iso-27005-vulnerability"]},"canonicalUrl":"https://controlsmap.com/?v=1&node=risk%3Aaware-user-error-mishandling","description":"Authorized users make mistakes — incorrect data entry, misconfiguration, improper procedures, incorrect privilege settings, or spilling/mishandling sensitive information — causing harm to information assets without malicious intent.","details":{"category":"operational","impact":"medium","inherent_rating":"high","likelihood":"high","risk_id":"aware-user-error-mishandling","taxonomies":["iso-27005-threat","nist-800-30-threat-event","nist-800-30-threat-source","iso-27005-vulnerability"],"treatment":"mitigate"},"direct":false,"htmlUrl":"/agents/records/risk-aware-user-error-mishandling-149a1d3b.html","id":"risk:aware-user-error-mishandling","mapUrl":"https://controlsmap.com/?v=1&node=risk%3Aaware-user-error-mishandling","sourceIds":["aiuc-1","gdpr","iso-27001","nist-800-53","nist-ai-agent-identity","nist-ai-tevv-athlon","nist-csf-2","nydfs-500","soc1","soc2"],"sourceUrl":null,"title":"User error and mishandling of sensitive information","type":"risk","url":"/assets/agent_record-risk-aware-user-error-mishandling-149a1d3b.111c3fa544df22a0.json"},{"attributes":{"category":"compliance_regulatory","domain":["Compliance, Audit & Assurance","Governance, Policy & Oversight"],"inherent_rating":"high","taxonomy":["enterprise-risk","coso-erm-risk"]},"canonicalUrl":"https://controlsmap.com/?v=1&node=risk%3Acompliance-litigation-enforcement","description":"Adverse judgments, class actions, contract/IP disputes, government subpoenas, DOJ/FTC/SEC investigations, consent decrees, or deferred-prosecution agreements imposing penalties, remediation, and management distraction.","details":{"category":"compliance_regulatory","impact":"high","inherent_rating":"high","likelihood":"medium","risk_id":"compliance-litigation-enforcement","taxonomies":["enterprise-risk","coso-erm-risk"],"treatment":"transfer"},"direct":false,"htmlUrl":"/agents/records/risk-compliance-litigation-enforcement-25e7935d.html","id":"risk:compliance-litigation-enforcement","mapUrl":"https://controlsmap.com/?v=1&node=risk%3Acompliance-litigation-enforcement","sourceIds":["cobit-2019","gdpr","hipaa","iso-27001","nis2","nist-800-53","nist-csf-2","nydfs-500","pci-dss","soc2"],"sourceUrl":null,"title":"Litigation, investigation and enforcement exposure","type":"risk","url":"/assets/agent_record-risk-compliance-litigation-enforcement-25e7935d.963b6cccfc52b94e.json"},{"attributes":{"category":"compliance_regulatory","domain":["Compliance, Audit & Assurance","Risk Assessment & Management"],"inherent_rating":"high","taxonomy":["enterprise-risk","coso-erm-risk"]},"canonicalUrl":"https://controlsmap.com/?v=1&node=risk%3Acompliance-sector-regulatory-breach","description":"Non-compliance with sector regimes — banking prudential rules, consumer-lending laws, payment-network rules, healthcare (FDA/HIPAA/CMS, Anti-Kickback/Stark, False Claims), export controls (EAR/ITAR), antitrust, and environmental/labor rules — triggering fines, sanctions, or loss of license.","details":{"category":"compliance_regulatory","impact":"high","inherent_rating":"high","likelihood":"medium","risk_id":"compliance-sector-regulatory-breach","taxonomies":["enterprise-risk","coso-erm-risk"],"treatment":"mitigate"},"direct":false,"htmlUrl":"/agents/records/risk-compliance-sector-regulatory-breach-5eb29698.html","id":"risk:compliance-sector-regulatory-breach","mapUrl":"https://controlsmap.com/?v=1&node=risk%3Acompliance-sector-regulatory-breach","sourceIds":["aiuc-1","cobit-2019","eu-ai-act","gdpr","iso-27001","nist-800-53"],"sourceUrl":null,"title":"Sector regulatory non-compliance (financial, healthcare, trade)","type":"risk","url":"/assets/agent_record-risk-compliance-sector-regulatory-breach-5eb29698.f5bea48f81eeab11.json"},{"attributes":{"category":"cyber_security","domain":["Risk Assessment & Management","Logging, Monitoring & Detection"],"inherent_rating":"high","taxonomy":["nist-800-30-threat-source"]},"canonicalUrl":"https://controlsmap.com/?v=1&node=risk%3Acyber-adversary-threat-sources","description":"Because capable, motivated threat actors - outsiders, privileged and non-privileged insiders, organized groups, competitors, malicious partners or suppliers, and nation-states - actively target the organization's cyber resources, deliberate attacks are attempted against its systems and data, resulting in compromise, disruption, or theft when defenses are outmatched.","details":{"category":"cyber_security","impact":"high","inherent_rating":"high","likelihood":"high","risk_id":"cyber-adversary-threat-sources","taxonomies":["nist-800-30-threat-source"],"treatment":"mitigate"},"direct":false,"htmlUrl":"/agents/records/risk-cyber-adversary-threat-sources-fa9e3003.html","id":"risk:cyber-adversary-threat-sources","mapUrl":"https://controlsmap.com/?v=1&node=risk%3Acyber-adversary-threat-sources","sourceIds":["aiuc-1","cobit-2019","coso-ic","gdpr","iso-27001","iso-31000","nist-800-53","nist-csf-2","nydfs-500","soc1","soc2","sox"],"sourceUrl":null,"title":"Attacks by capable, motivated threat actors","type":"risk","url":"/assets/agent_record-risk-cyber-adversary-threat-sources-fa9e3003.8ace32770a775a42.json"},{"attributes":{"category":"privacy","domain":["Data Protection & Privacy","Incident Management & Response"],"inherent_rating":"high","taxonomy":["iso-27005-threat","nist-800-30-threat-event","nist-privacy-risk"]},"canonicalUrl":"https://controlsmap.com/?v=1&node=risk%3Adata-breach-unauthorized-disclosure","description":"Unauthorized disclosure of information to parties not entitled to receive it, whether by insecure controls (insecurity), spillage, or authorized users induced to expose data — resulting in identity theft, economic loss, and loss of trust.","details":{"category":"privacy","impact":"high","inherent_rating":"high","likelihood":"medium","risk_id":"data-breach-unauthorized-disclosure","taxonomies":["iso-27005-threat","nist-800-30-threat-event","nist-privacy-risk"],"treatment":"mitigate"},"direct":false,"htmlUrl":"/agents/records/risk-data-breach-unauthorized-disclosure-3b1c296c.html","id":"risk:data-breach-unauthorized-disclosure","mapUrl":"https://controlsmap.com/?v=1&node=risk%3Adata-breach-unauthorized-disclosure","sourceIds":["aiuc-1","ccpa","gdpr","hipaa","iso-27001","nist-800-53","nist-ai-agent-identity","nist-ai-tevv-athlon","nist-csf-2","soc2"],"sourceUrl":null,"title":"Unauthorized disclosure / breach of sensitive information","type":"risk","url":"/assets/agent_record-risk-data-breach-unauthorized-disclosure-3b1c296c.8431603df36984c8.json"},{"attributes":{"category":"privacy","domain":["Data Protection & Privacy"],"inherent_rating":"high","taxonomy":["nist-privacy-risk"]},"canonicalUrl":"https://controlsmap.com/?v=1&node=risk%3Adata-excessive-collection-purpose-creep","description":"Collecting more personal data than necessary (data-minimization failure) and using it for purposes materially different from those disclosed without fresh notice/consent, expanding attack surface and violating purpose-limitation.","details":{"category":"privacy","impact":"medium","inherent_rating":"high","likelihood":"high","risk_id":"data-excessive-collection-purpose-creep","taxonomies":["nist-privacy-risk"],"treatment":"mitigate"},"direct":false,"htmlUrl":"/agents/records/risk-data-excessive-collection-purpose-creep-4a691595.html","id":"risk:data-excessive-collection-purpose-creep","mapUrl":"https://controlsmap.com/?v=1&node=risk%3Adata-excessive-collection-purpose-creep","sourceIds":["ccpa","gdpr","hipaa","iso-27001","nist-800-53","soc2"],"sourceUrl":null,"title":"Excessive collection, purpose creep and secondary use","type":"risk","url":"/assets/agent_record-risk-data-excessive-collection-purpose-creep-4a691595.e19f1e2bcd3171d8.json"},{"attributes":{"category":"cyber_security","domain":["Data Protection & Privacy","Network & Communications Security","Logging, Monitoring & Detection"],"inherent_rating":"critical","taxonomy":["nist-800-30-threat-event","nist-800-30-threat-source","basel-operational-risk","coso-erm-risk"]},"canonicalUrl":"https://controlsmap.com/?v=1&node=risk%3Adata-exfiltration-espionage","description":"Adversary (outsider, insider, nation-state, or competitor) installs malware or sniffers to locate and exfiltrate sensitive/proprietary information, or steals data by external actors — including systems-security losses from hacking.","details":{"category":"cyber_security","impact":"critical","inherent_rating":"critical","likelihood":"medium","risk_id":"data-exfiltration-espionage","taxonomies":["nist-800-30-threat-event","nist-800-30-threat-source","basel-operational-risk","coso-erm-risk"],"treatment":"mitigate"},"direct":false,"htmlUrl":"/agents/records/risk-data-exfiltration-espionage-74803ebc.html","id":"risk:data-exfiltration-espionage","mapUrl":"https://controlsmap.com/?v=1&node=risk%3Adata-exfiltration-espionage","sourceIds":["aiuc-1","cobit-2019","gdpr","hipaa","iso-27001","nist-800-53","nist-ai-agent-identity","nist-ai-tevv-athlon","nist-csf-2","nydfs-500","pci-dss","soc2"],"sourceUrl":null,"title":"Data exfiltration and theft of information by attackers","type":"risk","url":"/assets/agent_record-risk-data-exfiltration-espionage-74803ebc.a1ef3e79ab006192.json"},{"attributes":{"category":"privacy","domain":["Data Protection & Privacy","Asset Management & Inventory"],"inherent_rating":"medium","taxonomy":["nist-privacy-risk"]},"canonicalUrl":"https://controlsmap.com/?v=1&node=risk%3Adata-inventory-flows-unmapped","description":"No authoritative record of what personal data is held, where, who accesses it, and how it flows to processors/sub-processors and across borders — preventing risk assessment, DSR fulfilment, and enforcement of privacy obligations.","details":{"category":"privacy","impact":"medium","inherent_rating":"medium","likelihood":"high","risk_id":"data-inventory-flows-unmapped","taxonomies":["nist-privacy-risk"],"treatment":"mitigate"},"direct":false,"htmlUrl":"/agents/records/risk-data-inventory-flows-unmapped-fd7746f8.html","id":"risk:data-inventory-flows-unmapped","mapUrl":"https://controlsmap.com/?v=1&node=risk%3Adata-inventory-flows-unmapped","sourceIds":["coso-ic","gdpr","nist-800-53","nist-csf-2","soc2"],"sourceUrl":null,"title":"Undocumented data inventory and unmapped data flows","type":"risk","url":"/assets/agent_record-risk-data-inventory-flows-unmapped-fd7746f8.a02a8c6342331cd0.json"},{"attributes":{"category":"privacy","domain":["Data Protection & Privacy","AI Governance"],"inherent_rating":"medium","taxonomy":["nist-privacy-risk"]},"canonicalUrl":"https://controlsmap.com/?v=1&node=risk%3Adata-privacy-harms-to-individuals","description":"Processing inaccurate/out-of-context data (distortion), attaching negative social labels (stigmatization), or denying services based on personal data without justification (unwarranted restriction / algorithmic gatekeeping) — causing discrimination and economic loss.","details":{"category":"privacy","impact":"medium","inherent_rating":"medium","likelihood":"medium","risk_id":"data-privacy-harms-to-individuals","taxonomies":["nist-privacy-risk"],"treatment":"mitigate"},"direct":false,"htmlUrl":"/agents/records/risk-data-privacy-harms-to-individuals-510e65af.html","id":"risk:data-privacy-harms-to-individuals","mapUrl":"https://controlsmap.com/?v=1&node=risk%3Adata-privacy-harms-to-individuals","sourceIds":["aiuc-1","ccpa","eu-ai-act","gdpr","hipaa","iso-42001","nist-800-53","nist-ai-agent-identity","soc2"],"sourceUrl":null,"title":"Privacy harms: distortion, stigmatization, unwarranted restriction","type":"risk","url":"/assets/agent_record-risk-data-privacy-harms-to-individuals-510e65af.a2f2b4ad6db96f69.json"},{"attributes":{"category":"privacy","domain":["Data Protection & Privacy","Compliance, Audit & Assurance"],"inherent_rating":"high","taxonomy":["nist-privacy-risk","enterprise-risk"]},"canonicalUrl":"https://controlsmap.com/?v=1&node=risk%3Adata-privacy-program-noncompliance","description":"Failure to honour data-subject rights (access, deletion, portability, restriction) on time, missing lawful-basis/consent documentation, defective consent mechanisms, invalid cross-border transfer mechanisms, or inadequate notices — driving fines and private rights of action.","details":{"category":"privacy","impact":"high","inherent_rating":"high","likelihood":"high","risk_id":"data-privacy-program-noncompliance","taxonomies":["nist-privacy-risk","enterprise-risk"],"treatment":"mitigate"},"direct":false,"htmlUrl":"/agents/records/risk-data-privacy-program-noncompliance-ec6178fa.html","id":"risk:data-privacy-program-noncompliance","mapUrl":"https://controlsmap.com/?v=1&node=risk%3Adata-privacy-program-noncompliance","sourceIds":["aiuc-1","ccpa","gdpr","hipaa","iso-27001","nist-800-53","nist-ai-agent-identity","nist-ai-tevv-athlon","soc2"],"sourceUrl":null,"title":"Privacy-program non-compliance (GDPR, CCPA, state laws)","type":"risk","url":"/assets/agent_record-risk-data-privacy-program-noncompliance-ec6178fa.f8a5498a8697316f.json"},{"attributes":{"category":"privacy","domain":["Data Protection & Privacy","Compliance, Audit & Assurance"],"inherent_rating":"medium","taxonomy":["nist-privacy-risk","enterprise-risk"]},"canonicalUrl":"https://controlsmap.com/?v=1&node=risk%3Adata-retention-noncompliance","description":"Retaining personal data beyond necessity/mandated schedules (privacy and breach risk) or deleting records before required retention periods (litigation-hold, regulatory, tax risk); records-management policy not enforced technically.","details":{"category":"privacy","impact":"medium","inherent_rating":"medium","likelihood":"medium","risk_id":"data-retention-noncompliance","taxonomies":["nist-privacy-risk","enterprise-risk"],"treatment":"mitigate"},"direct":false,"htmlUrl":"/agents/records/risk-data-retention-noncompliance-ec7b8dbc.html","id":"risk:data-retention-noncompliance","mapUrl":"https://controlsmap.com/?v=1&node=risk%3Adata-retention-noncompliance","sourceIds":["ccpa","gdpr","iso-27001","nist-800-53","soc2"],"sourceUrl":null,"title":"Unlawful retention or premature deletion of records","type":"risk","url":"/assets/agent_record-risk-data-retention-noncompliance-ec7b8dbc.36421190fb2586f6.json"},{"attributes":{"category":"privacy","domain":["Data Protection & Privacy","Awareness & Training"],"inherent_rating":"medium","taxonomy":["nist-privacy-risk"]},"canonicalUrl":"https://controlsmap.com/?v=1&node=risk%3Adata-transparency-notice-dark-patterns","description":"Failure to give clear, timely notice of collection, use, retention, and sharing; misleading or dark-pattern consent flows; and failure to disclose automated decision-making — undermining meaningful consent and compounding power imbalance.","details":{"category":"privacy","impact":"medium","inherent_rating":"medium","likelihood":"medium","risk_id":"data-transparency-notice-dark-patterns","taxonomies":["nist-privacy-risk"],"treatment":"mitigate"},"direct":false,"htmlUrl":"/agents/records/risk-data-transparency-notice-dark-patterns-9326fdf0.html","id":"risk:data-transparency-notice-dark-patterns","mapUrl":"https://controlsmap.com/?v=1&node=risk%3Adata-transparency-notice-dark-patterns","sourceIds":["ccpa","gdpr","hipaa","nist-800-53","nist-csf-2","soc2"],"sourceUrl":null,"title":"Inadequate transparency, notice and deceptive privacy communications","type":"risk","url":"/assets/agent_record-risk-data-transparency-notice-dark-patterns-9326fdf0.86b6f27e81ff4310.json"},{"attributes":{"category":"financial_reporting","domain":["Financial Reporting Controls (SOX)","Access Control & Identity Management","Compliance, Audit & Assurance"],"inherent_rating":"high","taxonomy":["coso-erm-risk","sox-rmm-assertion"]},"canonicalUrl":"https://controlsmap.com/?v=1&node=risk%3Afin-segregation-of-duties","description":"Incompatible duties (initiate, approve, record, and custody) concentrated in one role or via broad system access enable unauthorized or fraudulent transactions to be recorded and concealed.","details":{"category":"financial_reporting","impact":"high","inherent_rating":"high","likelihood":"medium","risk_id":"fin-segregation-of-duties","taxonomies":["coso-erm-risk","sox-rmm-assertion"],"treatment":"mitigate"},"direct":false,"htmlUrl":"/agents/records/risk-fin-segregation-of-duties-eb7ee015.html","id":"risk:fin-segregation-of-duties","mapUrl":"https://controlsmap.com/?v=1&node=risk%3Afin-segregation-of-duties","sourceIds":["aiuc-1","cobit-2019","gdpr","hipaa","iso-27001","nist-800-53","nist-ai-agent-identity","nist-csf-2","nydfs-500","pci-dss","soc2","sox"],"sourceUrl":null,"title":"Segregation-of-duties conflicts in financial processes","type":"risk","url":"/assets/agent_record-risk-fin-segregation-of-duties-eb7ee015.da25c6668c301894.json"},{"attributes":{"category":"compliance_regulatory","domain":["Governance, Policy & Oversight","Data Protection & Privacy"],"inherent_rating":"medium","taxonomy":["iso-27005-vulnerability","nist-privacy-risk"]},"canonicalUrl":"https://controlsmap.com/?v=1&node=risk%3Agov-policy-absent","description":"Because documented, approved, and enforced security and privacy policies are missing and roles and duties are undefined, personnel operate without guidance on required controls and behaviours, so controls are applied inconsistently and accountability gaps leave violations undetected and unaddressed.","details":{"category":"compliance_regulatory","impact":"medium","inherent_rating":"medium","likelihood":"medium","risk_id":"gov-policy-absent","taxonomies":["iso-27005-vulnerability","nist-privacy-risk"],"treatment":"mitigate"},"direct":false,"htmlUrl":"/agents/records/risk-gov-policy-absent-cf76dbbf.html","id":"risk:gov-policy-absent","mapUrl":"https://controlsmap.com/?v=1&node=risk%3Agov-policy-absent","sourceIds":["cobit-2019","coso-erm","coso-ic","gdpr","hipaa","iso-27001","nis2","nist-800-53","nist-csf-2","nydfs-500","pci-dss","soc2"],"sourceUrl":null,"title":"Missing or insufficient security and privacy policies","type":"risk","url":"/assets/agent_record-risk-gov-policy-absent-cf76dbbf.643fca249d5d0d9c.json"},{"attributes":{"category":"compliance_regulatory","domain":["Human Resources / Personnel Security","Governance, Policy & Oversight","Third-Party / Supply-Chain Risk"],"inherent_rating":"medium","taxonomy":["iso-27005-vulnerability"]},"canonicalUrl":"https://controlsmap.com/?v=1&node=risk%3Ahr-missing-security-terms-discipline","description":"Employment and supplier contracts omit security/confidentiality obligations, and there is no disciplinary process for security violations — removing legal recourse and the deterrent effect against repeat offenders.","details":{"category":"compliance_regulatory","impact":"medium","inherent_rating":"medium","likelihood":"medium","risk_id":"hr-missing-security-terms-discipline","taxonomies":["iso-27005-vulnerability"],"treatment":"mitigate"},"direct":false,"htmlUrl":"/agents/records/risk-hr-missing-security-terms-discipline-0a47163d.html","id":"risk:hr-missing-security-terms-discipline","mapUrl":"https://controlsmap.com/?v=1&node=risk%3Ahr-missing-security-terms-discipline","sourceIds":["ccpa","coso-ic","gdpr","hipaa","iso-27001","nist-800-53","nist-csf-2","soc2"],"sourceUrl":null,"title":"Missing security terms in contracts and no disciplinary process","type":"risk","url":"/assets/agent_record-risk-hr-missing-security-terms-discipline-0a47163d.8fa26facc260e210.json"},{"attributes":{"category":"privacy","domain":["Incident Management & Response","Data Protection & Privacy","Compliance, Audit & Assurance"],"inherent_rating":"high","taxonomy":["nist-privacy-risk","enterprise-risk"]},"canonicalUrl":"https://controlsmap.com/?v=1&node=risk%3Air-breach-notification-failure","description":"Failure to detect, assess, and notify affected individuals and regulators of personal-data breaches within required timeframes and content (GDPR Art.33/34, HIPAA breach rule), resulting in sanctions and compounded individual harm.","details":{"category":"privacy","impact":"high","inherent_rating":"high","likelihood":"medium","risk_id":"ir-breach-notification-failure","taxonomies":["nist-privacy-risk","enterprise-risk"],"treatment":"mitigate"},"direct":false,"htmlUrl":"/agents/records/risk-ir-breach-notification-failure-1f01c218.html","id":"risk:ir-breach-notification-failure","mapUrl":"https://controlsmap.com/?v=1&node=risk%3Air-breach-notification-failure","sourceIds":["gdpr","hipaa","iso-27001","nist-800-53","nist-csf-2","soc2"],"sourceUrl":null,"title":"Failure to detect, assess, and notify breaches on time","type":"risk","url":"/assets/agent_record-risk-ir-breach-notification-failure-1f01c218.ed732937f488e857.json"},{"attributes":{"category":"cyber_security","domain":["Logging, Monitoring & Detection","Incident Management & Response"],"inherent_rating":"high","taxonomy":["iso-27005-vulnerability"]},"canonicalUrl":"https://controlsmap.com/?v=1&node=risk%3Alog-no-monitoring-supervision","description":"Absence of monitoring mechanisms and supervision of personnel actions (especially privileged users) allows undetected misuse, and no process exists to supervise and escalate detected security breaches.","details":{"category":"cyber_security","impact":"high","inherent_rating":"high","likelihood":"medium","risk_id":"log-no-monitoring-supervision","taxonomies":["iso-27005-vulnerability"],"treatment":"mitigate"},"direct":false,"htmlUrl":"/agents/records/risk-log-no-monitoring-supervision-712fe573.html","id":"risk:log-no-monitoring-supervision","mapUrl":"https://controlsmap.com/?v=1&node=risk%3Alog-no-monitoring-supervision","sourceIds":["cobit-2019","gdpr","hipaa","iso-27001","nist-800-53","nist-ai-agent-identity","nist-csf-2","pci-dss","soc1","soc2"],"sourceUrl":null,"title":"No security monitoring or supervision of privileged activity","type":"risk","url":"/assets/agent_record-risk-log-no-monitoring-supervision-712fe573.f68630a803345471.json"},{"attributes":{"category":"operational","domain":["Risk Assessment & Management","Access Control & Identity Management"],"inherent_rating":"medium","taxonomy":["basel-operational-risk"]},"canonicalUrl":"https://controlsmap.com/?v=1&node=risk%3Aops-documentation-account-management","description":"Missing signed agreements, incomplete legal/ISDA documentation, unretained KYC/AML records, misfiled client files, unauthorized access to client accounts, and negligent loss of client assets held in custody.","details":{"category":"operational","impact":"medium","inherent_rating":"medium","likelihood":"medium","risk_id":"ops-documentation-account-management","taxonomies":["basel-operational-risk"],"treatment":"mitigate"},"direct":false,"htmlUrl":"/agents/records/risk-ops-documentation-account-management-d25eb1fe.html","id":"risk:ops-documentation-account-management","mapUrl":"https://controlsmap.com/?v=1&node=risk%3Aops-documentation-account-management","sourceIds":["aiuc-1","gdpr","hipaa","iso-27001","iso-31000","nist-800-53","nist-ai-agent-identity","nist-csf-2"],"sourceUrl":null,"title":"Client intake, documentation and account-management failures","type":"risk","url":"/assets/agent_record-risk-ops-documentation-account-management-d25eb1fe.77187893f2bb342b.json"},{"attributes":{"category":"privacy","domain":["Data Protection & Privacy","Compliance, Audit & Assurance","Third-Party / Supply-Chain Risk"],"inherent_rating":"medium","taxonomy":["nist-privacy-risk","enterprise-risk"]},"canonicalUrl":"https://controlsmap.com/?v=1&node=risk%3Aprivacy-cross-border-transfer","description":"Transferring personal data to jurisdictions lacking equivalent protection without SCCs, BCRs, adequacy decisions, or other recognized mechanisms, exposing individuals and the organization to legal risk.","details":{"category":"privacy","impact":"medium","inherent_rating":"medium","likelihood":"medium","risk_id":"privacy-cross-border-transfer","taxonomies":["nist-privacy-risk","enterprise-risk"],"treatment":"mitigate"},"direct":false,"htmlUrl":"/agents/records/risk-privacy-cross-border-transfer-8fb379b5.html","id":"risk:privacy-cross-border-transfer","mapUrl":"https://controlsmap.com/?v=1&node=risk%3Aprivacy-cross-border-transfer","sourceIds":["aiuc-1","ccpa","gdpr","hipaa","iso-27001","nist-800-53","nist-ai-agent-identity","nist-ai-tevv-athlon","nist-csf-2"],"sourceUrl":null,"title":"Cross-border personal-data transfer without safeguards","type":"risk","url":"/assets/agent_record-risk-privacy-cross-border-transfer-8fb379b5.e026bee45d4ef5d1.json"},{"attributes":{"category":"privacy","domain":["Data Protection & Privacy","Awareness & Training"],"inherent_rating":"medium","taxonomy":["nist-privacy-risk"]},"canonicalUrl":"https://controlsmap.com/?v=1&node=risk%3Aprivacy-loss-of-trust","description":"Systemic failure to meet reasonable privacy expectations undermines confidence in products and institutions, causing disengagement, reputational damage, and reduced adoption — an organizational as well as individual harm.","details":{"category":"privacy","impact":"medium","inherent_rating":"medium","likelihood":"medium","risk_id":"privacy-loss-of-trust","taxonomies":["nist-privacy-risk"],"treatment":"mitigate"},"direct":false,"htmlUrl":"/agents/records/risk-privacy-loss-of-trust-a4d1142c.html","id":"risk:privacy-loss-of-trust","mapUrl":"https://controlsmap.com/?v=1&node=risk%3Aprivacy-loss-of-trust","sourceIds":["ccpa","gdpr","hipaa","nist-800-53","soc2","sox"],"sourceUrl":null,"title":"Erosion of individual trust and confidence in data practices","type":"risk","url":"/assets/agent_record-risk-privacy-loss-of-trust-a4d1142c.89dc33b8371b5f90.json"},{"attributes":{"category":"privacy","domain":["Data Protection & Privacy","AI Governance"],"inherent_rating":"medium","taxonomy":["nist-privacy-risk"]},"canonicalUrl":"https://controlsmap.com/?v=1&node=risk%3Aprivacy-power-imbalance-self-determination","description":"Structural informational asymmetry (take-it-or-leave-it consent, opaque algorithmic decisions) and inability to correct, delete, or restrict processing deprive individuals of meaningful control over their own data and narrative.","details":{"category":"privacy","impact":"medium","inherent_rating":"medium","likelihood":"medium","risk_id":"privacy-power-imbalance-self-determination","taxonomies":["nist-privacy-risk"],"treatment":"mitigate"},"direct":false,"htmlUrl":"/agents/records/risk-privacy-power-imbalance-self-determination-9112ad1d.html","id":"risk:privacy-power-imbalance-self-determination","mapUrl":"https://controlsmap.com/?v=1&node=risk%3Aprivacy-power-imbalance-self-determination","sourceIds":["aiuc-1","ccpa","eu-ai-act","gdpr","hipaa","iso-42001","nist-800-53","soc2"],"sourceUrl":null,"title":"Power imbalance and loss of self-determination over personal data","type":"risk","url":"/assets/agent_record-risk-privacy-power-imbalance-self-determination-9112ad1d.1354cb678bdbd7b3.json"}],"relationships":[{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:000f475b9e2aaee45057529f174e6d8be84da02fd57d61a31efc660d84336ba6","properties":{},"sourceDetailPath":"/data/v1/records/ctrl-gdpr-gdpr-art5-7b2df9a9.json","sourceId":"ctrl:gdpr:GDPR-Art5","targetDetailPath":"/data/v1/records/std-gdpr-17d65d0b.json","targetId":"std:gdpr","type":"belongs_to"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:08ecff12261a3a3aff991e1d5c92545f9d51ff8832b3a40eee13455fa6368b8e","properties":{"rationale":"Data-leakage-prevention on systems/channels plus technical flow-control directly block exfiltration of sensitive data.","strength":"primary"},"sourceDetailPath":"/data/v1/records/uc-uc-data-11-baf71fe4.json","sourceId":"uc:UC-DATA-11","targetDetailPath":"/data/v1/records/risk-data-exfiltration-espionage-74803ebc.json","targetId":"risk:data-exfiltration-espionage","type":"mitigates"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:0b37871dfe670524271af2e8e52d54d39f56878f71fd8973afdb4830c6b0f784","properties":{"rationale":"Role- and attribute-based enforcement applies the SoD separations defined for sensitive financial and administrative functions.","strength":"related"},"sourceDetailPath":"/data/v1/records/uc-uc-access-05-9b7f3e34.json","sourceId":"uc:UC-ACCESS-05","targetDetailPath":"/data/v1/records/risk-fin-segregation-of-duties-eb7ee015.json","targetId":"risk:fin-segregation-of-duties","type":"mitigates"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:0b6a063f429cabad5d3ba85857b4eaa9eec0c6399f8ddbd5aa5c4c32b8e505d1","properties":{},"sourceDetailPath":"/data/v1/records/ctrl-gdpr-gdpr-art25-ccf26a83.json","sourceId":"ctrl:gdpr:GDPR-Art25","targetDetailPath":"/data/v1/records/std-gdpr-17d65d0b.json","targetId":"std:gdpr","type":"belongs_to"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:0d04968156b772bf7a410f5f378671c49da4e7a97a6afdf67647fdce31650c41","properties":{"rationale":"Ensuring agreements satisfy the contractual clauses mandated by privacy regulations (e.g., GDPR transfer clauses/SCCs) directly enables safeguarded cross-border transfer.","strength":"primary"},"sourceDetailPath":"/data/v1/records/uc-uc-tprm-03-c9edcf93.json","sourceId":"uc:UC-TPRM-03","targetDetailPath":"/data/v1/records/risk-privacy-cross-border-transfer-8fb379b5.json","targetId":"risk:privacy-cross-border-transfer","type":"mitigates"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:1034a1bf8aadb88c03724051eb8a21ece1a44c8b14c592c16dc9039e08476a12","properties":{},"sourceDetailPath":"/data/v1/records/ctrl-gdpr-gdpr-art44-49-8ad28202.json","sourceId":"ctrl:gdpr:GDPR-Art44-49","targetDetailPath":"/data/v1/records/std-gdpr-17d65d0b.json","targetId":"std:gdpr","type":"belongs_to"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:147626ba946de1899cd5ca17cf9b036bdbfe4f62009292be05b5143cb0cdec82","properties":{"control_id":"GDPR-Art7","coverage":"full","delta":null,"framework":"gdpr","provenance":{"defaultConfidence":"medium","defaultStatus":"active","direction":"canonical_to_source","mapper":"coworkcanvas-compliance-graph","note":"Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.","reviewDate":"2026-09-07"},"relationship":"superset_of","source_version":"Regulation (EU) 2016/679"},"sourceDetailPath":"/data/v1/records/uc-uc-data-02-56e3d60a.json","sourceId":"uc:UC-DATA-02","targetDetailPath":"/data/v1/records/ctrl-gdpr-gdpr-art7-218fdd35.json","targetId":"ctrl:gdpr:GDPR-Art7","type":"maps_to"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:16c299d41edf19be14879b87685497d898252c077ecae6454388362bb74bb506","properties":{"control_id":"GDPR-Art34","coverage":"full","delta":null,"framework":"gdpr","provenance":{"defaultConfidence":"medium","defaultStatus":"active","direction":"canonical_to_source","mapper":"coworkcanvas-compliance-graph","note":"Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.","reviewDate":"2026-09-07"},"relationship":"superset_of","source_version":"Regulation (EU) 2016/679"},"sourceDetailPath":"/data/v1/records/uc-uc-ir-08-01afe3d1.json","sourceId":"uc:UC-IR-08","targetDetailPath":"/data/v1/records/ctrl-gdpr-gdpr-art34-6e2bfc74.json","targetId":"ctrl:gdpr:GDPR-Art34","type":"maps_to"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:180cd078fc831b671b5afb4ab1987c145fe458af88d172f34c611ab5240242d8","properties":{},"sourceDetailPath":"/data/v1/records/ctrl-gdpr-gdpr-art30-e7db10f3.json","sourceId":"ctrl:gdpr:GDPR-Art30","targetDetailPath":"/data/v1/records/std-gdpr-17d65d0b.json","targetId":"std:gdpr","type":"belongs_to"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:196ceefc0745c6ddc8a3f0db75c1ea4386ea6dd54352a7744060fe898f7b82cc","properties":{"control_id":"GDPR-Art32","coverage":"partial","delta":"also requires encryption, resilience, and effectiveness testing addressed in other domains","framework":"gdpr","provenance":{"defaultConfidence":"medium","defaultStatus":"active","direction":"canonical_to_source","mapper":"coworkcanvas-compliance-graph","note":"Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.","reviewDate":"2026-09-07"},"relationship":"intersects_with","source_version":"Regulation (EU) 2016/679"},"sourceDetailPath":"/data/v1/records/uc-uc-access-05-9b7f3e34.json","sourceId":"uc:UC-ACCESS-05","targetDetailPath":"/data/v1/records/ctrl-gdpr-gdpr-art32-63aa3290.json","targetId":"ctrl:gdpr:GDPR-Art32","type":"maps_to"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:199e523235255b49f7b7f37170eadd985d243e5d71a80080efd22243a1989120","properties":{},"sourceDetailPath":"/data/v1/records/ctrl-gdpr-gdpr-art32-63aa3290.json","sourceId":"ctrl:gdpr:GDPR-Art32","targetDetailPath":"/data/v1/records/std-gdpr-17d65d0b.json","targetId":"std:gdpr","type":"belongs_to"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:2197453a5f72d08e056274c107712e69d0bc55d818d6145e05c90a85813b2be6","properties":{"rationale":"Declaring incidents when criteria are met triggers the response that contains and limits attack impact.","strength":"related"},"sourceDetailPath":"/data/v1/records/uc-uc-log-06-735bbc3e.json","sourceId":"uc:UC-LOG-06","targetDetailPath":"/data/v1/records/risk-cyber-adversary-threat-sources-fa9e3003.json","targetId":"risk:cyber-adversary-threat-sources","type":"mitigates"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:222485699e5aa15a7b48e94d74daca13a0118401649ec0e8b44ab7b96cb53e09","properties":{},"sourceDetailPath":"/data/v1/records/ctrl-gdpr-gdpr-art24-063cd42d.json","sourceId":"ctrl:gdpr:GDPR-Art24","targetDetailPath":"/data/v1/records/std-gdpr-17d65d0b.json","targetId":"std:gdpr","type":"belongs_to"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:2ce39baacf4e08681a6e141f99447226f227084a6d955c5b9f97cc90a6558291","properties":{"rationale":"Maintaining legally-required notices and registrations addresses the inadequate-notice driver of regulatory non-compliance.","strength":"related"},"sourceDetailPath":"/data/v1/records/uc-uc-data-05-3244ac25.json","sourceId":"uc:UC-DATA-05","targetDetailPath":"/data/v1/records/risk-data-privacy-program-noncompliance-ec6178fa.json","targetId":"risk:data-privacy-program-noncompliance","type":"mitigates"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:2d1cb49f8be93fa020dfdf4ce80b246cbfca057da0774a463d8a1f9903a873aa","properties":{"rationale":"Mediating every access attempt against approved authorizations directly blocks users reaching resources exceeding their authorization.","strength":"primary"},"sourceDetailPath":"/data/v1/records/uc-uc-access-05-9b7f3e34.json","sourceId":"uc:UC-ACCESS-05","targetDetailPath":"/data/v1/records/risk-access-unauthorized-use-equipment-d2082944.json","targetId":"risk:access-unauthorized-use-equipment","type":"mitigates"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:2e2200cf7c9c42699b2dcb0b4d1193497790e85e7441d5bd59d7ae0c1de31269","properties":{"control_id":"GDPR-Art24","coverage":"partial","delta":"implementing operational technical and organisational protection measures across all processing","framework":"gdpr","provenance":{"defaultConfidence":"medium","defaultStatus":"active","direction":"canonical_to_source","mapper":"coworkcanvas-compliance-graph","note":"Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.","reviewDate":"2026-09-07"},"relationship":"intersects_with","source_version":"Regulation (EU) 2016/679"},"sourceDetailPath":"/data/v1/records/uc-uc-gov-25-7960cafc.json","sourceId":"uc:UC-GOV-25","targetDetailPath":"/data/v1/records/ctrl-gdpr-gdpr-art24-063cd42d.json","targetId":"ctrl:gdpr:GDPR-Art24","type":"maps_to"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:311f1c9e910cf8d774d86a7bd67c2a5b53ae07067c13a3b348efe6d898619609","properties":{"rationale":"Publishing clear, timely, plain-language notices at/before collection directly counters inadequate/late transparency and non-disclosure of practices.","strength":"primary"},"sourceDetailPath":"/data/v1/records/uc-uc-data-05-3244ac25.json","sourceId":"uc:UC-DATA-05","targetDetailPath":"/data/v1/records/risk-data-transparency-notice-dark-patterns-9326fdf0.json","targetId":"risk:data-transparency-notice-dark-patterns","type":"mitigates"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:3169f2abc7f4fe1d152757d80f0cb5ad870bd962db2898bc84fe7d135ea5f6f1","properties":{"control_id":"GDPR-Art33","coverage":"full","delta":null,"framework":"gdpr","provenance":{"defaultConfidence":"medium","defaultStatus":"active","direction":"canonical_to_source","mapper":"coworkcanvas-compliance-graph","note":"Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.","reviewDate":"2026-09-07"},"relationship":"superset_of","source_version":"Regulation (EU) 2016/679"},"sourceDetailPath":"/data/v1/records/uc-uc-log-06-735bbc3e.json","sourceId":"uc:UC-LOG-06","targetDetailPath":"/data/v1/records/ctrl-gdpr-gdpr-art33-a2a440c2.json","targetId":"ctrl:gdpr:GDPR-Art33","type":"maps_to"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:3dbe3964977b4cc816ce754ffec4cea6127c59fb731a7a2e69d01a9587f38f1e","properties":{"rationale":"Maintaining and annually reviewing a processing register creates the authoritative record of processing activities and purposes the risk says is missing.","strength":"primary"},"sourceDetailPath":"/data/v1/records/uc-uc-data-01-9fcf72e8.json","sourceId":"uc:UC-DATA-01","targetDetailPath":"/data/v1/records/risk-data-inventory-flows-unmapped-fd7746f8.json","targetId":"risk:data-inventory-flows-unmapped","type":"mitigates"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:404449c161c2b2e1eb98e5875c84937f0cb1f6cb211b8cf3fe87f135c184d0cd","properties":{"rationale":"The data/information inventory component contributes to overall asset accountability; the systems inventory itself is UC-01.","strength":"related"},"sourceDetailPath":"/data/v1/records/uc-uc-asset-02-6c6ac61b.json","sourceId":"uc:UC-ASSET-02","targetDetailPath":"/data/v1/records/risk-asset-inventory-gap-e18c7e73.json","targetId":"risk:asset-inventory-gap","type":"mitigates"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:41280e986145674087f4497ff33260f1d466fb931a9cec5de5003fdfc2bdbd8c","properties":{"rationale":"Disclosing purposes, recipients, retention, and rights reduces the informational asymmetry between organization and individual.","strength":"related"},"sourceDetailPath":"/data/v1/records/uc-uc-data-05-3244ac25.json","sourceId":"uc:UC-DATA-05","targetDetailPath":"/data/v1/records/risk-privacy-power-imbalance-self-determination-9112ad1d.json","targetId":"risk:privacy-power-imbalance-self-determination","type":"mitigates"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:441b56af734fa537c487b57bc4694e1671b1ca528484f2bd9b33e2792c7f488f","properties":{},"sourceDetailPath":"/data/v1/records/ctrl-gdpr-gdpr-art15-22-256fff35.json","sourceId":"ctrl:gdpr:GDPR-Art15-22","targetDetailPath":"/data/v1/records/std-gdpr-17d65d0b.json","targetId":"std:gdpr","type":"belongs_to"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:44a783c0681fd9d954b59659de9e9f362dce42f65b9e47d5f9b98cb386abce52","properties":{"rationale":"Enforcing lawful, purpose-limited, minimized data processing (GDPR Art5) directly reduces data-protection enforcement exposure.","strength":"primary"},"sourceDetailPath":"/data/v1/records/uc-uc-gov-26-3952a3ca.json","sourceId":"uc:UC-GOV-26","targetDetailPath":"/data/v1/records/risk-compliance-litigation-enforcement-25e7935d.json","targetId":"risk:compliance-litigation-enforcement","type":"mitigates"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:463c2c0034411e95da828e0cd200cc1c3bf15c1d2d2c8b4d54c69b3c52e59697","properties":{"rationale":"The notification matrix, statutory-window notifications to regulators/individuals, and retained evidence directly defend against late or incomplete breach notification (GDPR/HIPAA).","strength":"primary"},"sourceDetailPath":"/data/v1/records/uc-uc-ir-08-01afe3d1.json","sourceId":"uc:UC-IR-08","targetDetailPath":"/data/v1/records/risk-ir-breach-notification-failure-1f01c218.json","targetId":"risk:ir-breach-notification-failure","type":"mitigates"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:46649b5491420104088389b6488bcc81c25e0f04301e1b993c9c416d4ab952b2","properties":{"control_id":"GDPR-Art44-49","coverage":"full","delta":null,"framework":"gdpr","provenance":{"defaultConfidence":"medium","defaultStatus":"active","direction":"canonical_to_source","mapper":"coworkcanvas-compliance-graph","note":"Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.","reviewDate":"2026-09-07"},"relationship":"superset_of","source_version":"Regulation (EU) 2016/679"},"sourceDetailPath":"/data/v1/records/uc-uc-data-11-baf71fe4.json","sourceId":"uc:UC-DATA-11","targetDetailPath":"/data/v1/records/ctrl-gdpr-gdpr-art44-49-8ad28202.json","targetId":"ctrl:gdpr:GDPR-Art44-49","type":"maps_to"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:48afab00c51493858a3017cec2c5da651d09307c8cebd4c0f6bd1d3b157630e4","properties":{"control_id":"GDPR-Art35","coverage":"full","delta":null,"framework":"gdpr","provenance":{"defaultConfidence":"medium","defaultStatus":"active","direction":"canonical_to_source","mapper":"coworkcanvas-compliance-graph","note":"Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.","reviewDate":"2026-09-07"},"relationship":"superset_of","source_version":"Regulation (EU) 2016/679"},"sourceDetailPath":"/data/v1/records/uc-uc-risk-16-81243062.json","sourceId":"uc:UC-RISK-16","targetDetailPath":"/data/v1/records/ctrl-gdpr-gdpr-art35-4314d563.json","targetId":"ctrl:gdpr:GDPR-Art35","type":"maps_to"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:4a230971ca35f4362a01c4861ad078e87bea0a79bdaac6d7720dda0f8cc8d033","properties":{"control_id":"GDPR-Art25","coverage":"partial","delta":"Art.25(2) data-protection-by-default applies organization-wide beyond software design; this control covers the by-design engineering arm","framework":"gdpr","provenance":{"defaultConfidence":"medium","defaultStatus":"active","direction":"canonical_to_source","mapper":"coworkcanvas-compliance-graph","note":"Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.","reviewDate":"2026-09-07"},"relationship":"intersects_with","source_version":"Regulation (EU) 2016/679"},"sourceDetailPath":"/data/v1/records/uc-uc-config-04-ed033b30.json","sourceId":"uc:UC-CONFIG-04","targetDetailPath":"/data/v1/records/ctrl-gdpr-gdpr-art25-ccf26a83.json","targetId":"ctrl:gdpr:GDPR-Art25","type":"maps_to"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:4ebb462736549fe5c4013f5292120153ba58ef9fb4116e749bb347215ab570db","properties":{},"sourceDetailPath":"/data/v1/records/ctrl-gdpr-gdpr-art35-4314d563.json","sourceId":"ctrl:gdpr:GDPR-Art35","targetDetailPath":"/data/v1/records/std-gdpr-17d65d0b.json","targetId":"std:gdpr","type":"belongs_to"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:5522ed4a796ef520de6c41be5b2f846782fa1694b789f63a2f7d8da09f23d2cf","properties":{"rationale":"Valid, documented transfer mechanisms remove the invalid-cross-border-transfer driver of non-compliance.","strength":"related"},"sourceDetailPath":"/data/v1/records/uc-uc-data-11-baf71fe4.json","sourceId":"uc:UC-DATA-11","targetDetailPath":"/data/v1/records/risk-data-privacy-program-noncompliance-ec6178fa.json","targetId":"risk:data-privacy-program-noncompliance","type":"mitigates"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:64551a76ab797d15863c7f587c79e31eb9302eb72df868e9a33674e9de93abba","properties":{"control_id":"GDPR-Art37-39","coverage":"partial","delta":"DPO contact details must be published and communicated to the supervisory authority","framework":"gdpr","provenance":{"defaultConfidence":"medium","defaultStatus":"active","direction":"canonical_to_source","mapper":"coworkcanvas-compliance-graph","note":"Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.","reviewDate":"2026-09-07"},"relationship":"intersects_with","source_version":"Regulation (EU) 2016/679"},"sourceDetailPath":"/data/v1/records/uc-uc-gov-25-7960cafc.json","sourceId":"uc:UC-GOV-25","targetDetailPath":"/data/v1/records/ctrl-gdpr-gdpr-art37-39-f756de70.json","targetId":"ctrl:gdpr:GDPR-Art37-39","type":"maps_to"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:6d99f965983a2fe511395722ced4825b21f49f51932d6e6c7c5a24f90f48fd7d","properties":{"rationale":"Always-invoked, tamper-resistant authorization enforcement blocks access beyond permitted scope and resists forged rights.","strength":"primary"},"sourceDetailPath":"/data/v1/records/uc-uc-access-05-9b7f3e34.json","sourceId":"uc:UC-ACCESS-05","targetDetailPath":"/data/v1/records/risk-access-privilege-abuse-repudiation-343a8917.json","targetId":"risk:access-privilege-abuse-repudiation","type":"mitigates"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:6e0b91b6945069b7e7edae111d475c5e13cc043c1d41718d123a918a403bef97","properties":{"rationale":"DPIA/PIA (GDPR Art 35) before high-risk processing is a direct data-protection compliance control identifying and mitigating privacy-law violations before they occur.","strength":"primary"},"sourceDetailPath":"/data/v1/records/uc-uc-risk-16-81243062.json","sourceId":"uc:UC-RISK-16","targetDetailPath":"/data/v1/records/risk-compliance-sector-regulatory-breach-5eb29698.json","targetId":"risk:compliance-sector-regulatory-breach","type":"mitigates"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:6e698f51122da358e41d03754dbc5e23ac7673ae295346f1230660e00e330a57","properties":{"rationale":"Restricting processing of race/health/religion/orientation data reduces the stigmatization and discrimination such data enables.","strength":"related"},"sourceDetailPath":"/data/v1/records/uc-uc-data-04-2a08628d.json","sourceId":"uc:UC-DATA-04","targetDetailPath":"/data/v1/records/risk-data-privacy-harms-to-individuals-510e65af.json","targetId":"risk:data-privacy-harms-to-individuals","type":"mitigates"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:6e6b074dacca375c431c27e3bc8f8677f0f0d41ce5d70d05ee64f8283b855053","properties":{"rationale":"Enforcing approved information-flow authorizations and DLP directly prevents data leaking to parties not entitled to it.","strength":"primary"},"sourceDetailPath":"/data/v1/records/uc-uc-data-11-baf71fe4.json","sourceId":"uc:UC-DATA-11","targetDetailPath":"/data/v1/records/risk-data-breach-unauthorized-disclosure-3b1c296c.json","targetId":"risk:data-breach-unauthorized-disclosure","type":"mitigates"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:6ea2241cc7573102a2aa155e24e4f6d70ec70c02aab173cecabbec89872ced48","properties":{"control_id":"GDPR-Art6","coverage":"full","delta":null,"framework":"gdpr","provenance":{"defaultConfidence":"medium","defaultStatus":"active","direction":"canonical_to_source","mapper":"coworkcanvas-compliance-graph","note":"Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.","reviewDate":"2026-09-07"},"relationship":"superset_of","source_version":"Regulation (EU) 2016/679"},"sourceDetailPath":"/data/v1/records/uc-uc-data-01-9fcf72e8.json","sourceId":"uc:UC-DATA-01","targetDetailPath":"/data/v1/records/ctrl-gdpr-gdpr-art6-cbe66aa0.json","targetId":"ctrl:gdpr:GDPR-Art6","type":"maps_to"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:6fd598b196e61c1753b0491a313d783c4e6647f9346bee365fd94eca69bf0ba5","properties":{"rationale":"Including required security and confidentiality obligations in supplier agreements directly fixes the missing-security-terms facet in supplier contracts.","strength":"primary"},"sourceDetailPath":"/data/v1/records/uc-uc-tprm-03-c9edcf93.json","sourceId":"uc:UC-TPRM-03","targetDetailPath":"/data/v1/records/risk-hr-missing-security-terms-discipline-0a47163d.json","targetId":"risk:hr-missing-security-terms-discipline","type":"mitigates"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:70081ea4eb13d7d16bfbbf89a74550126570253d10451979276233dce6a37009","properties":{},"sourceDetailPath":"/data/v1/records/ctrl-gdpr-gdpr-art12-14-51a7eca7.json","sourceId":"ctrl:gdpr:GDPR-Art12-14","targetDetailPath":"/data/v1/records/std-gdpr-17d65d0b.json","targetId":"std:gdpr","type":"belongs_to"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:75934d360a1405917deff9c9d662d247eff523fda2de95d9e7260901e7977aca","properties":{"control_id":"GDPR-Art5","coverage":"partial","delta":"operational enforcement of principles sits in data-protection, retention, and security controls","framework":"gdpr","provenance":{"defaultConfidence":"medium","defaultStatus":"active","direction":"canonical_to_source","mapper":"coworkcanvas-compliance-graph","note":"Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.","reviewDate":"2026-09-07"},"relationship":"intersects_with","source_version":"Regulation (EU) 2016/679"},"sourceDetailPath":"/data/v1/records/uc-uc-gov-26-3952a3ca.json","sourceId":"uc:UC-GOV-26","targetDetailPath":"/data/v1/records/ctrl-gdpr-gdpr-art5-7b2df9a9.json","targetId":"ctrl:gdpr:GDPR-Art5","type":"maps_to"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:797932c738f5104f8f4a01aeb7695575ad4d9d28a420458b926f15caabec88ef","properties":{"rationale":"Transparent, current notices meet reasonable privacy expectations, sustaining confidence in data practices.","strength":"related"},"sourceDetailPath":"/data/v1/records/uc-uc-data-05-3244ac25.json","sourceId":"uc:UC-DATA-05","targetDetailPath":"/data/v1/records/risk-privacy-loss-of-trust-a4d1142c.json","targetId":"risk:privacy-loss-of-trust","type":"mitigates"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:7aa69c83502aa3c57c2105fbc3bdea5adaba879e297214818886752faa90e9d2","properties":{"rationale":"Freely-given consent with withdrawal/opt-out as easy as opt-in partly counters take-it-or-leave-it asymmetry.","strength":"related"},"sourceDetailPath":"/data/v1/records/uc-uc-data-02-56e3d60a.json","sourceId":"uc:UC-DATA-02","targetDetailPath":"/data/v1/records/risk-privacy-power-imbalance-self-determination-9112ad1d.json","targetId":"risk:privacy-power-imbalance-self-determination","type":"mitigates"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:7f3ec345be8a53799972255fcf0841ea74170cd05f5c38778ad918f03cecce68","properties":{},"sourceDetailPath":"/data/v1/records/ctrl-gdpr-gdpr-art9-0813ab56.json","sourceId":"ctrl:gdpr:GDPR-Art9","targetDetailPath":"/data/v1/records/std-gdpr-17d65d0b.json","targetId":"std:gdpr","type":"belongs_to"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:8128919760953d7828feeb87b5db14481385836b29b030959426bbee184dcbf5","properties":{},"sourceDetailPath":"/data/v1/records/ctrl-gdpr-gdpr-art7-218fdd35.json","sourceId":"ctrl:gdpr:GDPR-Art7","targetDetailPath":"/data/v1/records/std-gdpr-17d65d0b.json","targetId":"std:gdpr","type":"belongs_to"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:81b0c91efc2a28b672c0564ac43522d22a352c500b9b0917b99e0f7685d7bb48","properties":{"rationale":"A DPO advising on and monitoring privacy-policy compliance addresses undefined roles and privacy-policy gaps.","strength":"primary"},"sourceDetailPath":"/data/v1/records/uc-uc-gov-25-7960cafc.json","sourceId":"uc:UC-GOV-25","targetDetailPath":"/data/v1/records/risk-gov-policy-absent-cf76dbbf.json","targetId":"risk:gov-policy-absent","type":"mitigates"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:838acb68e5edfaa0371e73a93223c2f4b3eb67d38a4f0e5cc32f8e51aee7b4c3","properties":{"control_id":"GDPR-Art12-14","coverage":"partial","delta":"controller/DPO identity, complaint right, transfer info, automated-decision disclosures, Art 14 source omitted","framework":"gdpr","provenance":{"defaultConfidence":"medium","defaultStatus":"active","direction":"canonical_to_source","mapper":"coworkcanvas-compliance-graph","note":"Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.","reviewDate":"2026-09-07"},"relationship":"intersects_with","source_version":"Regulation (EU) 2016/679"},"sourceDetailPath":"/data/v1/records/uc-uc-data-05-3244ac25.json","sourceId":"uc:UC-DATA-05","targetDetailPath":"/data/v1/records/ctrl-gdpr-gdpr-art12-14-51a7eca7.json","targetId":"ctrl:gdpr:GDPR-Art12-14","type":"maps_to"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:88ce1cc28f79db491c622197df631497ee89a669b669c4d16605501f16ebc046","properties":{"rationale":"Recording the lawful basis in a register removes the 'missing lawful-basis documentation' driver of regulatory fines and private actions.","strength":"primary"},"sourceDetailPath":"/data/v1/records/uc-uc-data-01-9fcf72e8.json","sourceId":"uc:UC-DATA-01","targetDetailPath":"/data/v1/records/risk-data-privacy-program-noncompliance-ec6178fa.json","targetId":"risk:data-privacy-program-noncompliance","type":"mitigates"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:8971794847ccd5035c53cd286df2473e21d22b664f87028844a75bd655b59b86","properties":{},"sourceDetailPath":"/data/v1/records/ctrl-gdpr-gdpr-art28-e21fee94.json","sourceId":"ctrl:gdpr:GDPR-Art28","targetDetailPath":"/data/v1/records/std-gdpr-17d65d0b.json","targetId":"std:gdpr","type":"belongs_to"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:900f2470ca4c4df7af12d284683862a42ee705902d2e28bfa5295b4ffbc5620f","properties":{"rationale":"Presenting choices/consequences clearly and capturing freely-given, specific, informed consent directly counters misleading dark-pattern consent flows.","strength":"primary"},"sourceDetailPath":"/data/v1/records/uc-uc-data-02-56e3d60a.json","sourceId":"uc:UC-DATA-02","targetDetailPath":"/data/v1/records/risk-data-transparency-notice-dark-patterns-9326fdf0.json","targetId":"risk:data-transparency-notice-dark-patterns","type":"mitigates"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:91009775ad3f068d3dc9c55e3e41cb9b4a1800e0aff8127b232b2f778cb7108b","properties":{"rationale":"Valid consent capture, records, and honored withdrawals/opt-outs remove the defective-consent-mechanism driver of fines and private actions.","strength":"primary"},"sourceDetailPath":"/data/v1/records/uc-uc-data-02-56e3d60a.json","sourceId":"uc:UC-DATA-02","targetDetailPath":"/data/v1/records/risk-data-privacy-program-noncompliance-ec6178fa.json","targetId":"risk:data-privacy-program-noncompliance","type":"mitigates"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:9387bf3aecebd66c898fb6fc60db46dff95ce2c5438599450f2b5a61afb74c98","properties":{},"sourceDetailPath":"/data/v1/records/ctrl-gdpr-gdpr-art37-39-f756de70.json","sourceId":"ctrl:gdpr:GDPR-Art37-39","targetDetailPath":"/data/v1/records/std-gdpr-17d65d0b.json","targetId":"std:gdpr","type":"belongs_to"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:960d0f0d80955dfcf6ff9d5494af149cc09ad90267ced52de0c441b7a6fa5258","properties":{"control_id":"GDPR-Art30","coverage":"full","delta":null,"framework":"gdpr","provenance":{"defaultConfidence":"medium","defaultStatus":"active","direction":"canonical_to_source","mapper":"coworkcanvas-compliance-graph","note":"Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.","reviewDate":"2026-09-07"},"relationship":"superset_of","source_version":"Regulation (EU) 2016/679"},"sourceDetailPath":"/data/v1/records/uc-uc-asset-02-6c6ac61b.json","sourceId":"uc:UC-ASSET-02","targetDetailPath":"/data/v1/records/ctrl-gdpr-gdpr-art30-e7db10f3.json","targetId":"ctrl:gdpr:GDPR-Art30","type":"maps_to"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:9675e11635b80d5c85fe22d26aa4c26e65d945d72c3bf7c0a25dd9f24d02e0cb","properties":{"rationale":"No-discrimination/retaliation rules and automated-decision-making rights curb algorithmic gatekeeping and unwarranted restriction.","strength":"related"},"sourceDetailPath":"/data/v1/records/uc-uc-data-08-794007b4.json","sourceId":"uc:UC-DATA-08","targetDetailPath":"/data/v1/records/risk-data-privacy-harms-to-individuals-510e65af.json","targetId":"risk:data-privacy-harms-to-individuals","type":"mitigates"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:9aa7e9a60eb81da8ccb00e16574c965bdbcf79b6aef58e060f1d3616b366beab","properties":{"rationale":"Enforced authorization restricts access to client accounts and data, countering the unauthorized-access-to-client-accounts component.","strength":"related"},"sourceDetailPath":"/data/v1/records/uc-uc-access-05-9b7f3e34.json","sourceId":"uc:UC-ACCESS-05","targetDetailPath":"/data/v1/records/risk-ops-documentation-account-management-d25eb1fe.json","targetId":"risk:ops-documentation-account-management","type":"mitigates"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:ad33ac7214bf5abb5e5dd0089a9c14fc9612faa45a4d37273341850d8bc9bbee","properties":{"rationale":"Honoring consent choices and opt-outs meets privacy expectations, sustaining individual trust.","strength":"related"},"sourceDetailPath":"/data/v1/records/uc-uc-data-02-56e3d60a.json","sourceId":"uc:UC-DATA-02","targetDetailPath":"/data/v1/records/risk-privacy-loss-of-trust-a4d1142c.json","targetId":"risk:privacy-loss-of-trust","type":"mitigates"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:afb35d46fe00047a2b4dd91d40ed59ad27aca67fbfc4e7a9f3e23434d3dcf2dc","properties":{"rationale":"Heightened safeguards on special-category data reduce the likelihood and impact of exposing the most sensitive records.","strength":"related"},"sourceDetailPath":"/data/v1/records/uc-uc-data-04-2a08628d.json","sourceId":"uc:UC-DATA-04","targetDetailPath":"/data/v1/records/risk-data-breach-unauthorized-disclosure-3b1c296c.json","targetId":"risk:data-breach-unauthorized-disclosure","type":"mitigates"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:b38b8f6520f03a9348578e342869825ce8fd97358def7a6558068131911f0f98","properties":{"rationale":"Transferring personal data only under a valid mechanism (adequacy/SCC/BCR/derogation) with recorded safeguards directly prevents unsafeguarded cross-border transfers.","strength":"primary"},"sourceDetailPath":"/data/v1/records/uc-uc-data-11-baf71fe4.json","sourceId":"uc:UC-DATA-11","targetDetailPath":"/data/v1/records/risk-privacy-cross-border-transfer-8fb379b5.json","targetId":"risk:privacy-cross-border-transfer","type":"mitigates"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:b942e1c5dad608655084fe8b0a63671d65b2e2b08497f85ac6f1be23fd85e28a","properties":{"control_id":"GDPR-Art28","coverage":"full","delta":null,"framework":"gdpr","provenance":{"defaultConfidence":"medium","defaultStatus":"active","direction":"canonical_to_source","mapper":"coworkcanvas-compliance-graph","note":"Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.","reviewDate":"2026-09-07"},"relationship":"superset_of","source_version":"Regulation (EU) 2016/679"},"sourceDetailPath":"/data/v1/records/uc-uc-tprm-03-c9edcf93.json","sourceId":"uc:UC-TPRM-03","targetDetailPath":"/data/v1/records/ctrl-gdpr-gdpr-art28-e21fee94.json","targetId":"ctrl:gdpr:GDPR-Art28","type":"maps_to"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:b9cdb7728148e892209633b56ce9552539b1691ac4b46ca99062f9fe23e1a793","properties":{"rationale":"A privacy program that ensures and demonstrates compliance directly reduces privacy regulatory enforcement (GDPR).","strength":"primary"},"sourceDetailPath":"/data/v1/records/uc-uc-gov-25-7960cafc.json","sourceId":"uc:UC-GOV-25","targetDetailPath":"/data/v1/records/risk-compliance-litigation-enforcement-25e7935d.json","targetId":"risk:compliance-litigation-enforcement","type":"mitigates"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:baaaaa8d759ae4bf52b2d5f55d12b851386e7e17eba2c7717b63e8850555e773","properties":{"rationale":"Collecting personal data only for the documented purposes constrains over-collection and purpose creep at the point of collection.","strength":"related"},"sourceDetailPath":"/data/v1/records/uc-uc-data-01-9fcf72e8.json","sourceId":"uc:UC-DATA-01","targetDetailPath":"/data/v1/records/risk-data-excessive-collection-purpose-creep-4a691595.json","targetId":"risk:data-excessive-collection-purpose-creep","type":"mitigates"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:bb9ab1025acf6800c2e99cf9e7284c0062c5e338301e2c4cd9b5ed13424002f2","properties":{"rationale":"Maintaining data inventories, RoPA, and data-flow diagrams directly produces the authoritative data-flow record this risk says is absent.","strength":"primary"},"sourceDetailPath":"/data/v1/records/uc-uc-asset-02-6c6ac61b.json","sourceId":"uc:UC-ASSET-02","targetDetailPath":"/data/v1/records/risk-data-inventory-flows-unmapped-fd7746f8.json","targetId":"risk:data-inventory-flows-unmapped","type":"mitigates"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:c6c74ad43ded50d7606418cb4c66907bc7d96670a310f31fd666ed3e9668f9d8","properties":{},"sourceDetailPath":"/data/v1/records/ctrl-gdpr-gdpr-art34-6e2bfc74.json","sourceId":"ctrl:gdpr:GDPR-Art34","targetDetailPath":"/data/v1/records/std-gdpr-17d65d0b.json","targetId":"std:gdpr","type":"belongs_to"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:ca0f131f6e62765d8d0d647f569f09a71c706e4660cac0963b79736bc0db2ad1","properties":{"control_id":"GDPR-Art9","coverage":"full","delta":null,"framework":"gdpr","provenance":{"defaultConfidence":"medium","defaultStatus":"active","direction":"canonical_to_source","mapper":"coworkcanvas-compliance-graph","note":"Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.","reviewDate":"2026-09-07"},"relationship":"superset_of","source_version":"Regulation (EU) 2016/679"},"sourceDetailPath":"/data/v1/records/uc-uc-data-04-2a08628d.json","sourceId":"uc:UC-DATA-04","targetDetailPath":"/data/v1/records/ctrl-gdpr-gdpr-art9-0813ab56.json","targetId":"ctrl:gdpr:GDPR-Art9","type":"maps_to"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:cbf5b1fd90a88dc6e4b251867131daf48c0905ada385c3258cfe4fa4ea7b95e1","properties":{},"sourceDetailPath":"/data/v1/records/ctrl-gdpr-gdpr-art6-cbe66aa0.json","sourceId":"ctrl:gdpr:GDPR-Art6","targetDetailPath":"/data/v1/records/std-gdpr-17d65d0b.json","targetId":"std:gdpr","type":"belongs_to"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:d484e2ed3ffa0ee8b84a73b3cdab3f7f2f7add4484e33c7f473b6266f1802aff","properties":{"rationale":"DLP on exfiltration channels catches inadvertent user spillage of sensitive information.","strength":"related"},"sourceDetailPath":"/data/v1/records/uc-uc-data-11-baf71fe4.json","sourceId":"uc:UC-DATA-11","targetDetailPath":"/data/v1/records/risk-aware-user-error-mishandling-149a1d3b.json","targetId":"risk:aware-user-error-mishandling","type":"mitigates"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:d68b28c66a86af15f0fd0c2760726edeff80a9b09cf987d8124192e19e8ee85c","properties":{"control_id":"GDPR-Art15-22","coverage":"partial","delta":"Art 22 standing automated-decision prohibition and Art 19 recipient notification exceed request handling","framework":"gdpr","provenance":{"defaultConfidence":"medium","defaultStatus":"active","direction":"canonical_to_source","mapper":"coworkcanvas-compliance-graph","note":"Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.","reviewDate":"2026-09-07"},"relationship":"intersects_with","source_version":"Regulation (EU) 2016/679"},"sourceDetailPath":"/data/v1/records/uc-uc-data-08-794007b4.json","sourceId":"uc:UC-DATA-08","targetDetailPath":"/data/v1/records/ctrl-gdpr-gdpr-art15-22-256fff35.json","targetId":"ctrl:gdpr:GDPR-Art15-22","type":"maps_to"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:d87f115fdbef50bd52106f58ee1b2e0ebacdc5a152c961fe436b0015ec9d2659","properties":{"rationale":"Executing erasure requests deletes specific subjects' data, reducing unlawful over-retention.","strength":"related"},"sourceDetailPath":"/data/v1/records/uc-uc-data-08-794007b4.json","sourceId":"uc:UC-DATA-08","targetDetailPath":"/data/v1/records/risk-data-retention-noncompliance-ec7b8dbc.json","targetId":"risk:data-retention-noncompliance","type":"mitigates"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:dbe656ec41a00e61bfd294b0ea18e81c7a16e4ddca41c534718e390300f999c0","properties":{},"sourceDetailPath":"/data/v1/records/ctrl-gdpr-gdpr-art33-a2a440c2.json","sourceId":"ctrl:gdpr:GDPR-Art33","targetDetailPath":"/data/v1/records/std-gdpr-17d65d0b.json","targetId":"std:gdpr","type":"belongs_to"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:eb3246a4e1cba415c2efa0d2ed40ce4947a226ac4a39637acc1c127df8cf7d1b","properties":{"rationale":"Operating deletion, restriction, and objection rights directly restores individuals' ability to delete and restrict processing of their data.","strength":"primary"},"sourceDetailPath":"/data/v1/records/uc-uc-data-08-794007b4.json","sourceId":"uc:UC-DATA-08","targetDetailPath":"/data/v1/records/risk-privacy-power-imbalance-self-determination-9112ad1d.json","targetId":"risk:privacy-power-imbalance-self-determination","type":"mitigates"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:f904d64067d0121654ee8d018acdf44e96484364813f8f3778bfcbc227893874","properties":{"rationale":"A verified process executing erasure/portability/restriction/objection within statutory clocks is the core defense against failing to honor DSRs on time.","strength":"primary"},"sourceDetailPath":"/data/v1/records/uc-uc-data-08-794007b4.json","sourceId":"uc:UC-DATA-08","targetDetailPath":"/data/v1/records/risk-data-privacy-program-noncompliance-ec6178fa.json","targetId":"risk:data-privacy-program-noncompliance","type":"mitigates"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:fb070e6fb79e092e4f8cab56f17580c95828b1f586a1d506487d9fef186e8a0d","properties":{"rationale":"Defined criteria to evaluate events, declare incidents, and initiate response supply the escalation process for detected breaches that was absent.","strength":"primary"},"sourceDetailPath":"/data/v1/records/uc-uc-log-06-735bbc3e.json","sourceId":"uc:UC-LOG-06","targetDetailPath":"/data/v1/records/risk-log-no-monitoring-supervision-712fe573.json","targetId":"risk:log-no-monitoring-supervision","type":"mitigates"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:ffd8d149aaba0da444f2773512dc412cf75c85607cb3711369ba7d2a9447c03e","properties":{"rationale":"Declaring data-breach incidents against defined thresholds and notifying regulators/individuals reduces the impact of data theft.","strength":"related"},"sourceDetailPath":"/data/v1/records/uc-uc-log-06-735bbc3e.json","sourceId":"uc:UC-LOG-06","targetDetailPath":"/data/v1/records/risk-data-exfiltration-espionage-74803ebc.json","targetId":"risk:data-exfiltration-espionage","type":"mitigates"}],"schemaVersion":1,"scope":"sources","total":87}
