Controllers and processors must designate a DPO where processing is carried out by a public authority or body (except courts acting judicially), where core activities require regular and systematic monitoring of data subjects on a large scale, or where core activities involve large-scale processing of sensitive data or criminal records. A group of companies may appoint a single DPO easily accessible from each member, and several public authorities may share one taking account of structure and size.
The graph holds this control, the 0 it maps to, and the evidence behind each claim, over MCP and REST.