Article 38 grants users and other persons concerned the right to lodge a complaint with the competent authority. Article 39 grants the right to an effective judicial remedy against binding decisions of the competent authority and against the data holder's compliance with the Regulation. Article 40 requires Member States to lay down effective, proportionate and dissuasive penalties for breaches; for breaches of Articles 4-7 (user rights) and Chapter VI (cloud switching), the penalty regime aligns with the GDPR Article 83(5) ceilings (administrative fines up to EUR 20 million or 4% of worldwide annual turnover).
The graph holds this control, the 0 it maps to, and the evidence behind each claim, over MCP and REST.