Competent authorities as controllers apply the Part II duties on appropriate measures, review and cooperation (Article 22(1), (2) and (4)) and on data protection by design and default (Article 23(1) and (2)); joint controllers apply Article 24(1) and (3) with the Part III rights; processors are engaged under the processor rules of Part II applied to Part III (the English version cross-refers to Article 25, the processor provisions sitting in Article 26), and any processor or person acting under authority processes only on the controller's instructions unless law provides otherwise. Every controller and processor keeps records of processing activities under Article 27, and the controller's records also state the use of profiling where applicable.
The graph holds this control, the 0 it maps to, and the evidence behind each claim, over MCP and REST.