The controller must notify data subjects without delay, and within 3 working days of learning of the risk, of a breach that creates a risk to their fundamental rights and freedoms, with the same contents as the notice to the Authority, in clear and simple language. Notice is not required where effective protective measures were applied to the affected data, where measures ensure the risk will not materialise (both to be qualified by the Authority once informed within the Art. 43 terms), or where individual notice would require disproportionate effort, in which case a public communication must be made. Late or unjustified failure to notify is sanctioned; timely notice and response count as mitigating factors.
The graph holds this control, the 0 it maps to, and the evidence behind each claim, over MCP and REST.