A controller with 100 or more workers, and one with fewer whose processing may create a risk under its risk analysis, is not occasional, or includes special categories, must keep a written or electronic record of all its processing activities stating the controller's (and any joint controller's) and the data protection officer's names and contact details, the purposes, the categories of recipients, the data subjects and data categories, any profiling, any transfers to third countries or international organisations, the lawful bases, the retention periods and a general description of the technical, legal, administrative and organisational measures, and make it available to the Authority on request. Processors keep a record where their controller must.
The graph holds this control, the 0 it maps to, and the evidence behind each claim, over MCP and REST.