A controller may use only processors providing sufficient guarantees of appropriate technical and organisational measures. A processor may not engage another processor without the controller's prior specific or general written authorisation and, under general authorisation, must inform the controller of intended additions or replacements so it can object. A sub-processor must be bound by the same data protection obligations by contract or legal act, and the initial processor remains fully liable to the controller for the sub-processor's performance. A processor that determines purposes and means is treated as a controller for that processing.
The graph holds this control, the 0 it maps to, and the evidence behind each claim, over MCP and REST.