On request of the data subject or the Unit, the controller must erase or conceal data and take the necessary measures where: the processing served a purpose other than that of collection or went beyond the consent given; the data subject withdrew the consent on which processing relied (unless other legislation requires otherwise); the data were processed contrary to the Law and its bylaws and instructions; or erasure is required to perform a legal or contractual obligation. This does not apply to processing under Article 6.
The graph holds this control, the 0 it maps to, and the evidence behind each claim, over MCP and REST.