Personal data shall be protected by appropriate technical and organisational measures. Where personal data is transmitted between a device and a service, it shall be transmitted using best-practice cryptography. Devices shall provide cryptographic mechanisms with adequate cryptographic strength.
The graph holds this control, the 0 it maps to, and the evidence behind each claim, over MCP and REST.