Article 4 establishes the PRINCIPLES for processing: (a) processed in a fair + transparent + lawful manner; (b) collected for specified + clear + legitimate purposes (purpose limitation); (c) limited to what is necessary (data minimization); (d) accurate + kept up to date (accuracy); (e) retained only as long as necessary (storage limitation); (f) processed with appropriate security measures (integrity + confidentiality). Article 5 establishes the LAWFUL BASES for processing: (a) data subject CONSENT; (b) performance of a CONTRACT or pre-contractual steps; (c) compliance with a LEGAL OBLIGATION; (d) protection of VITAL INTERESTS; (e) performance of a TASK IN THE PUBLIC INTEREST; (f) LEGITIMATE INTERESTS of the controller / processor or a third party (balanced against data subject rights); (g) processing of personal data necessary for the realisation of historical / statistical / scientific RESEARCH purposes. Consent (Article 5(a)) must be freely given + specific + informed + explicit + revocable.
The graph holds this control, the 0 it maps to, and the evidence behind each claim, over MCP and REST.