Both when designing processing tools and during processing, the controller must implement appropriate technical and organisational measures, such as pseudonymisation, that give effect to the principles (data minimisation in particular) and build the needed safeguards into processing, considering the state of technology, cost, the nature, scope, context and purposes and the risk to rights. By default, only data necessary for each specific purpose may be processed, which governs the amount collected, the extent of processing, the storage period and accessibility; in particular data must not be made accessible to an indefinite number of persons without the individual's intervention. An approved certification may be used to demonstrate compliance.
The graph holds this control, the 0 it maps to, and the evidence behind each claim, over MCP and REST.