Regulation 2 requires every database owner to maintain a database definition document covering purposes of the database, types of data, types of subjects, recipients of data and purposes of transfer, transfers abroad, data flows in and out, processors used, and primary security risks. The document must be reviewed at least annually and updated on material change. For high-tier databases additional content is required.
The graph holds this control, the 0 it maps to, and the evidence behind each claim, over MCP and REST.