Where a breach of data security and integrity is likely to cause serious harm to the data subject, the controller must notify the data subjects whose data were affected within 24 hours of discovering the breach and give them the measures needed to avoid its consequences.
The graph holds this control, the 0 it maps to, and the evidence behind each claim, over MCP and REST.