The controller must give information and communications under Articles 13 to 20 concisely, transparently, intelligibly and in clear and plain language (especially for minors), in writing or by other means including electronic, and orally on request once identity is proven. It must facilitate the exercise of rights, may not refuse a request unless it shows it cannot identify the data subject, and may ask for more information where it reasonably doubts identity. It must act on or reject a request as soon as possible and no later than 30 days from receipt, extendable to 60 days for complexity or volume with the extension and reasons notified within 30 days; electronic requests are answered electronically where possible. A refusal, with reasons and the right to complain to the Commissioner and sue, is due within 30 days. Responses are free; for clearly unfounded or excessive requests the controller may charge a reasonable fee or refuse, and bears the burden of proving that character.
The graph holds this control, the 0 it maps to, and the evidence behind each claim, over MCP and REST.