Where Article 6(1)(a) GDPR applies in relation to the offer of information society services directly to a child, the processing of personal data is lawful where the child is at least 13 years of age (Estonia's exercise of the GDPR Article 8 national-determination option for ages 13-16).
The graph holds this control, the 0 it maps to, and the evidence behind each claim, over MCP and REST.