The controller must report to the Authority, and keep up to date, for each database or processing: its identification; the name, legal address and contact details of controller and processor; the characteristics and purpose of the processing; the nature of the data; the identity and contact details of recipients including processors and third parties; how the registered information is interrelated; the means used to implement the Act's principles, rights and obligations; the administrative, technical, physical, organisational and legal measures for security; and the retention period. The report covers each database separately, does not include the data themselves, and must be made within 10 working days of the start of processing, following the Authority's procedures.
The graph holds this control, the 0 it maps to, and the evidence behind each claim, over MCP and REST.