Personal data must be processed lawfully, fairly and transparently; collected for a specified and legitimate purpose defined at collection and not further processed for an incompatible purpose; adequate, necessary and limited to what the purpose needs; accurate and up to date, with every necessary step taken to erase or rectify inaccurate or incomplete data; kept in identifiable form no longer than the purpose requires (longer only for public interest archiving, research, scientific, historical or statistical purposes with technical and organisational safeguards); and processed with appropriate security against unauthorised or unlawful processing and accidental loss, destruction or damage. The controller is responsible for, and must be able to demonstrate, compliance with these principles.
The graph holds this control, the 0 it maps to, and the evidence behind each claim, over MCP and REST.