Regulation 11 requires the database owner to document every security event and to notify the Privacy Protection Authority immediately of a severe security event. The PPA may also direct the owner to notify affected data subjects. A severe security event is one that materially compromises confidentiality, integrity, or availability of personal data. Industry practice and PPA guidance treat 'immediately' as within 24 hours of discovery for severe events.
The graph holds this control, the 0 it maps to, and the evidence behind each claim, over MCP and REST.