Controllers must implement and review proportionate technical and organisational measures and policies that ensure and demonstrate compliance, taking account of risk, context, scope and purpose.
Interpretation and application must be checked against the official text and current version.
