Controllers and processors must notify the Centre of any personal data infringement within 72 hours (immediately where national security is concerned). The notification must describe the nature, form and reasons of the infringement, the approximate number of records, DPO information, potential consequences, mitigation procedures, documentation/corrective evidence and any data the Centre requests. The data subject must be notified within three days of notifying the Centre.
The graph holds this control, the 0 it maps to, and the evidence behind each claim, over MCP and REST.