Article 15(1) allows Member States to adopt legislative measures to restrict the scope of the rights and obligations provided for in Articles 5, 6, 8(1)-(4), and 9, when such restriction constitutes a necessary, appropriate and proportionate measure within a democratic society to safeguard national security (i.e. State security), defence, public security, the prevention, investigation, detection and prosecution of criminal offences or unauthorised use of the electronic communication system. Article 15(2) requires the cooperation of providers in the investigation of breaches of confidentiality. Article 15(3) provides for the application of Directive 95/46/EC (now the GDPR) more generally.
The graph holds this control, the 0 it maps to, and the evidence behind each claim, over MCP and REST.