The controller must appoint a data protection officer where: its main activity is processing personal data; it processes sensitive personal data; it processes data of persons lacking legal capacity; it processes data that include financial information; it transfers databases outside the Kingdom; or in any other case the Council decides.
The graph holds this control, the 0 it maps to, and the evidence behind each claim, over MCP and REST.