Every controller, processor and employee must keep confidential the personal data they access for professional reasons and disclose them to third parties only as the law allows; this obligation must be written into every processor contract and every employment contract of a controller or processor. Processors and persons acting under the controller's or processor's authority may process the data only on instructions unless a specific law requires otherwise, and controllers and processors must set written rules on who may give processing instructions and make them known to everyone concerned. Confidentiality continues after the processor contract or the employment relationship ends.
The graph holds this control, the 0 it maps to, and the evidence behind each claim, over MCP and REST.