Sets controller/processor obligations: identification of the controller (§29), processor designation and obligations (§30), joint controllers (§31), processing in the controller's/processor's name (§32), data protection by design and by default (§33), processing requirements (§34), transmission requirements (§35), logging (§36), records of processing activities (§37), data protection impact assessment (§38), and prior consultation with the Estonian Data Protection Inspectorate (§39).
The graph holds this control, the 0 it maps to, and the evidence behind each claim, over MCP and REST.