For the same breaches, the controller must report to the Unit within 72 hours of discovery the source and mechanism of the breach, the data subjects affected and any other information available. A controller whose gross fault or wrongdoing caused the breach must compensate the data subject (Article 20(B)).
The graph holds this control, the 0 it maps to, and the evidence behind each claim, over MCP and REST.