Processing personal data by automated monitoring or decision-making systems is deemed likely to result in a high risk under GDPR Article 35(1), so a DPIA is always required; in carrying it out, including on the Article 7 limitations, the platform as controller must seek the views of persons performing platform work and their representatives.
The graph holds this control, the 0 it maps to, and the evidence behind each claim, over MCP and REST.