GDPR¶
Framework version: Regulation (EU) 2016/679.
GDPR compliance belongs to the controller and the processor. passmcp produces inputs for the record of processing (Art. 30) and the DPIA (Art. 35), and evidences the technical side of security of processing (Art. 32).
Every finding in a JSON report carries the controls it evidences under
controls.gdpr. passmcp verify --framework gdpr reads an attestation offline
and reports each one below as evidenced, failing or not assessed, and passmcp evidence --framework gdpr
builds a dated evidence bundle from attestations over an audit period.
Controls¶
| Control | Title | Evidenced by |
|---|---|---|
| Art. 5(1)(c) | Data minimisation | Not covered by passmcp: Whether the controller collects only the personal data it needs is a property of its purposes, not of a server's behaviour. passmcp's own minimisation (redaction, no telemetry) is documented in the manual. |
| Art. 25 | Data protection by design and by default | auth.token.scope, catalog.tools.annotation_honesty, catalog.tools.annotations, catalog.tools.idempotency, discovery.challenge.scope |
| Art. 28 | Processor | Not covered by passmcp: Contracts between controller and processor are legal documents, not server behaviour. |
| Art. 30 | Records of processing activities | catalog.personal_data, egress.hosts, egress.undeclared_host |
| Art. 32 | Security of processing | a2a.transport, a2a.unauthenticated, auth.rejects_garbage, auth.token, auth.token.expiry, auth.token.type, auth.unauthenticated_tools, auth.wrong_audience, catalog.text.secret_paths, catalog.toxic_combination, discovery.as, discovery.as.https, discovery.as.pkce, discovery.challenge, discovery.dpop, discovery.first_contact, discovery.prm, discovery.prm.resource, egress.hosts, egress.undeclared_host, fs.canary_exfiltrated, fs.credential_probe, net.scheme, net.tls, net.tls.cert, net.tls.version, protocol.origin, stdio.bind_all, stdio.environment, stdio.launch_config, stdio.post_init_connections |
| Art. 33 | Notification of a personal data breach to the supervisory authority | Not covered by passmcp: Breach notification is an organisational process. |
| Art. 35 | Data protection impact assessment | catalog.personal_data |
| Art. 44 | General principle for transfers | egress.hosts, egress.undeclared_host |
Checks¶
| Check | Controls |
|---|---|
a2a.card_schema |
None: protocol conformance and interoperability: it shows the agent card is valid A2A, which no control in this framework requires |
a2a.card_signature |
None: no data protection obligation is evidenced by this check |
a2a.transport |
Art. 32 |
a2a.unauthenticated |
Art. 32 |
auth.mode |
None: records how passmcp ran (its configuration, mode or the credentials it was given), which says nothing about the server's controls |
auth.registration |
None: no data protection obligation is evidenced by this check |
auth.rejects_garbage |
Art. 32 |
auth.source.* |
None: records how passmcp ran (its configuration, mode or the credentials it was given), which says nothing about the server's controls |
auth.token |
Art. 32 |
auth.token.expiry |
Art. 32 |
auth.token.scope |
Art. 25 |
auth.token.type |
Art. 32 |
auth.unauthenticated_tools |
Art. 32 |
auth.wrong_audience |
Art. 32 |
catalog.baseline |
None: no data protection obligation is evidenced by this check |
catalog.budget.tokens |
None: catalogue or response quality: it affects how well an agent can use the server, not a security or privacy control |
catalog.cache_hints |
None: catalogue or response quality: it affects how well an agent can use the server, not a security or privacy control |
catalog.empty |
None: catalogue or response quality: it affects how well an agent can use the server, not a security or privacy control |
catalog.names.confusable |
None: no data protection obligation is evidenced by this check |
catalog.personal_data |
Art. 30, Art. 35 |
catalog.prompts.descriptions |
None: catalogue or response quality: it affects how well an agent can use the server, not a security or privacy control |
catalog.prompts.list |
None: catalogue or response quality: it affects how well an agent can use the server, not a security or privacy control |
catalog.resources.list |
None: catalogue or response quality: it affects how well an agent can use the server, not a security or privacy control |
catalog.resources.mime |
None: catalogue or response quality: it affects how well an agent can use the server, not a security or privacy control |
catalog.resources.templates |
None: catalogue or response quality: it affects how well an agent can use the server, not a security or privacy control |
catalog.resources.uris |
None: catalogue or response quality: it affects how well an agent can use the server, not a security or privacy control |
catalog.semantic.ambiguity |
None: catalogue or response quality: it affects how well an agent can use the server, not a security or privacy control |
catalog.text.comments |
None: no data protection obligation is evidenced by this check |
catalog.text.cross_server_shadowing |
None: no data protection obligation is evidenced by this check |
catalog.text.encoded |
None: no data protection obligation is evidenced by this check |
catalog.text.hidden |
None: no data protection obligation is evidenced by this check |
catalog.text.instructions |
None: no data protection obligation is evidenced by this check |
catalog.text.secret_paths |
Art. 32 |
catalog.text.shadowing |
None: no data protection obligation is evidenced by this check |
catalog.tools.annotation_honesty |
Art. 25 |
catalog.tools.annotations |
Art. 25 |
catalog.tools.descriptions |
None: catalogue or response quality: it affects how well an agent can use the server, not a security or privacy control |
catalog.tools.idempotency |
Art. 25 |
catalog.tools.input_schema |
None: catalogue or response quality: it affects how well an agent can use the server, not a security or privacy control |
catalog.tools.list |
None: catalogue or response quality: it affects how well an agent can use the server, not a security or privacy control |
catalog.tools.output_schema |
None: catalogue or response quality: it affects how well an agent can use the server, not a security or privacy control |
catalog.tools.title |
None: catalogue or response quality: it affects how well an agent can use the server, not a security or privacy control |
catalog.tools.unique |
None: catalogue or response quality: it affects how well an agent can use the server, not a security or privacy control |
catalog.toxic_combination |
Art. 32 |
discovery.as |
Art. 32 |
discovery.as.grants |
None: no data protection obligation is evidenced by this check |
discovery.as.https |
Art. 32 |
discovery.as.pkce |
Art. 32 |
discovery.assemble |
None: records how passmcp ran (its configuration, mode or the credentials it was given), which says nothing about the server's controls |
discovery.challenge |
Art. 32 |
discovery.challenge.scope |
Art. 25 |
discovery.creds_unused |
None: records how passmcp ran (its configuration, mode or the credentials it was given), which says nothing about the server's controls |
discovery.dpop |
Art. 32 |
discovery.enterprise_managed |
None: no data protection obligation is evidenced by this check |
discovery.first_contact |
Art. 32 |
discovery.override |
None: records how passmcp ran (its configuration, mode or the credentials it was given), which says nothing about the server's controls |
discovery.override.build |
None: records how passmcp ran (its configuration, mode or the credentials it was given), which says nothing about the server's controls |
discovery.prm |
Art. 32 |
discovery.prm.resource |
Art. 32 |
discovery.registration |
None: no data protection obligation is evidenced by this check |
egress.hosts |
Art. 30, Art. 32, Art. 44 |
egress.undeclared_host |
Art. 30, Art. 32, Art. 44 |
execution.content |
None: catalogue or response quality: it affects how well an agent can use the server, not a security or privacy control |
execution.error_guidance |
None: catalogue or response quality: it affects how well an agent can use the server, not a security or privacy control |
execution.output_injection |
None: no data protection obligation is evidenced by this check |
execution.payload_size |
None: no data protection obligation is evidenced by this check |
execution.policy |
None: records how passmcp ran (its configuration, mode or the credentials it was given), which says nothing about the server's controls |
execution.prompts |
None: catalogue or response quality: it affects how well an agent can use the server, not a security or privacy control |
execution.resources |
None: catalogue or response quality: it affects how well an agent can use the server, not a security or privacy control |
execution.tools |
None: catalogue or response quality: it affects how well an agent can use the server, not a security or privacy control |
execution.validation |
None: catalogue or response quality: it affects how well an agent can use the server, not a security or privacy control |
fs.canary_exfiltrated |
Art. 32 |
fs.credential_probe |
Art. 32 |
handshake.capabilities |
None: protocol conformance and interoperability: it shows the server speaks MCP correctly, which no control in this framework requires |
handshake.initialize |
None: protocol conformance and interoperability: it shows the server speaks MCP correctly, which no control in this framework requires |
handshake.instructions |
None: no data protection obligation is evidenced by this check |
handshake.protocol_era |
None: protocol conformance and interoperability: it shows the server speaks MCP correctly, which no control in this framework requires |
handshake.protocol_version |
None: protocol conformance and interoperability: it shows the server speaks MCP correctly, which no control in this framework requires |
handshake.server_info |
None: protocol conformance and interoperability: it shows the server speaks MCP correctly, which no control in this framework requires |
handshake.session |
None: no data protection obligation is evidenced by this check |
handshake.stateless |
None: protocol conformance and interoperability: it shows the server speaks MCP correctly, which no control in this framework requires |
net.dns |
None: a connectivity precondition for every other check, not evidence of a control |
net.scheme |
Art. 32 |
net.tcp |
None: a connectivity precondition for every other check, not evidence of a control |
net.tls |
Art. 32 |
net.tls.cert |
Art. 32 |
net.tls.version |
Art. 32 |
performance.concurrency |
None: no data protection obligation is evidenced by this check |
performance.ping |
None: no data protection obligation is evidenced by this check |
performance.rate_limit |
None: no data protection obligation is evidenced by this check |
performance.throttle |
None: no data protection obligation is evidenced by this check |
performance.tools |
None: no data protection obligation is evidenced by this check |
performance.warmup |
None: no data protection obligation is evidenced by this check |
protocol.accept_header |
None: protocol conformance and interoperability: it shows the server speaks MCP correctly, which no control in this framework requires |
protocol.bogus_session |
None: no data protection obligation is evidenced by this check |
protocol.deprecated_features |
None: protocol conformance and interoperability: it shows the server speaks MCP correctly, which no control in this framework requires |
protocol.extensions |
None: protocol conformance and interoperability: it shows the server speaks MCP correctly, which no control in this framework requires |
protocol.get_stream |
None: protocol conformance and interoperability: it shows the server speaks MCP correctly, which no control in this framework requires |
protocol.id_echo |
None: protocol conformance and interoperability: it shows the server speaks MCP correctly, which no control in this framework requires |
protocol.invalid_params |
None: no data protection obligation is evidenced by this check |
protocol.malformed_json |
None: no data protection obligation is evidenced by this check |
protocol.mrtr |
None: protocol conformance and interoperability: it shows the server speaks MCP correctly, which no control in this framework requires |
protocol.origin |
Art. 32 |
protocol.ping |
None: protocol conformance and interoperability: it shows the server speaks MCP correctly, which no control in this framework requires |
protocol.routing_headers |
None: protocol conformance and interoperability: it shows the server speaks MCP correctly, which no control in this framework requires |
protocol.tasks.capability |
None: protocol conformance and interoperability: it shows the server speaks MCP correctly, which no control in this framework requires |
protocol.tasks.lifecycle |
None: protocol conformance and interoperability: it shows the server speaks MCP correctly, which no control in this framework requires |
protocol.tasks.undeclared |
None: protocol conformance and interoperability: it shows the server speaks MCP correctly, which no control in this framework requires |
protocol.tasks.unknown_id |
None: protocol conformance and interoperability: it shows the server speaks MCP correctly, which no control in this framework requires |
protocol.unknown_method |
None: no data protection obligation is evidenced by this check |
protocol.unknown_tool |
None: no data protection obligation is evidenced by this check |
protocol.version_header |
None: protocol conformance and interoperability: it shows the server speaks MCP correctly, which no control in this framework requires |
resilience.session_reinit |
None: no data protection obligation is evidenced by this check |
resilience.soak_memory |
None: no data protection obligation is evidenced by this check |
resilience.stateless |
None: no data protection obligation is evidenced by this check |
resilience.token_refresh |
None: no data protection obligation is evidenced by this check |
resilience.upstream_down |
None: no data protection obligation is evidenced by this check |
stdio.alive |
None: process hygiene of the server as a child program: it matters for running it reliably, not for a control in this framework |
stdio.bind_all |
Art. 32 |
stdio.clean_exit |
None: process hygiene of the server as a child program: it matters for running it reliably, not for a control in this framework |
stdio.environment |
Art. 32 |
stdio.launch_config |
Art. 32 |
stdio.no_zombie |
None: process hygiene of the server as a child program: it matters for running it reliably, not for a control in this framework |
stdio.post_init_connections |
Art. 32 |
stdio.post_init_processes |
None: no data protection obligation is evidenced by this check |
stdio.post_init_writes |
None: no data protection obligation is evidenced by this check |
stdio.process |
None: process hygiene of the server as a child program: it matters for running it reliably, not for a control in this framework |
stdio.stderr |
None: process hygiene of the server as a child program: it matters for running it reliably, not for a control in this framework |
stdio.stdout_clean |
None: process hygiene of the server as a child program: it matters for running it reliably, not for a control in this framework |
supply.buildinfo |
None: no data protection obligation is evidenced by this check |
supply.provenance |
None: no data protection obligation is evidenced by this check |