- Articles 10-12 require security remediation, full-process data-security management, compliance with necessary-information scopes, no forced consent, and continued basic service after refusal of non-necessary information.
References and citations
- Articles 3-5 support field-level mapping to an indispensable basic function and the refusal rule.
- Articles 15-16, 19, 51, and 57 support withdrawal, limits on refusing service, shortest necessary retention, security controls, and incident response.