Controllers, processors and anyone who learns the content of processed data in the course of their duties remain bound by confidentiality and credibility after their functions end, must not disclose the data except where the law provides, and must not process data they can access without the controller's authorisation unless the law makes it mandatory.
The graph holds this control, the 0 it maps to, and the evidence behind each claim, over MCP and REST.