When collecting data from the data subject, the controller must provide its identity and contact details (and those of any representative and data protection officer); the purposes and legal basis; the existence and logic of automated decisions and profiling and their consequences; the storage period or the criteria for it; the right to withdraw consent (and, for legitimate interest processing, that basis); whether providing the data is a legal or contractual requirement and the consequences of not providing it; recipients or categories of recipients; any transfer abroad and how adequate protection is ensured, with how to obtain a copy of the safeguards; and the rights under Articles 14 to 20 and to complain to the Commissioner. When data are obtained elsewhere, it must also give the data categories and the source, including whether publicly available, unless impossible or disproportionate with safeguards in place, expressly provided by law, or barred by professional secrecy. Information is due before collection, or for indirect collection within 30 days, at the first communication or at first disclosure; a new purpose needs prior information. A processor may inform on the controller's behalf if authorised, naming the controller.
The graph holds this control, the 0 it maps to, and the evidence behind each claim, over MCP and REST.