In addition to the Article 9 obligations, the DPO of the controller or processor must follow and implement the security policies and procedures necessary to avoid any breach or infringement of sensitive personal data.
The graph holds this control, the 0 it maps to, and the evidence behind each claim, over MCP and REST.