The controller must notify the Agency of a personal data breach without undue delay and, where feasible, within 72 hours of becoming aware of it, unless the breach is unlikely to result in a risk to individuals, with reasons for any delay. The notice describes the nature of the breach with approximate numbers of data subjects and records, the DPO or other contact, the likely consequences and the measures taken or proposed; information may be given in phases. A processor must notify the controller without undue delay. The controller must document every breach, its facts, effects and remedial action so the Agency can verify compliance. Failure to notify within 72 hours is also a misdemeanour under Article 89.
The graph holds this control, the 0 it maps to, and the evidence behind each claim, over MCP and REST.