Data Protection by Design and by Default (GDPR Article 25) requires that, at the time of determining the means for processing and at the time of the processing itself, the controller implements appropriate technical and organisational measures designed to implement the data protection principles in an effective manner and to integrate the necessary safeguards into the processing.
The graph holds this control, the 0 it maps to, and the evidence behind each claim, over MCP and REST.