A controller must conduct and document a data protection assessment for processing that presents a heightened risk of harm: targeted advertising, sale, profiling with specified risks, and processing sensitive data; the AG may require its disclosure.
The graph holds this control, the 0 it maps to, and the evidence behind each claim, over MCP and REST.