Personal data must be processed lawfully, fairly and transparently; collected for specified, explicit and legitimate purposes and not further processed incompatibly (archiving, research and statistics under Article 95 being compatible); adequate, relevant and limited to what is necessary; accurate and kept up to date, with inaccurate data erased or rectified without delay; kept in identifiable form no longer than necessary (longer only for archiving, research or statistics with safeguards); and secured against unauthorised or unlawful processing and accidental loss, destruction or damage. The controller is responsible for, and must be able to demonstrate, compliance with these principles.
The graph holds this control, the 0 it maps to, and the evidence behind each claim, over MCP and REST.