The controller may set aside the obligations and rights of GDPR arts 12 to 21 and 34 insofar as necessary and proportionate to safeguard: national security; defence; public security; preventing, investigating, detecting or prosecuting crime or executing penalties; other important general-interest objectives of the Netherlands or the EU (economic or financial, including monetary, budgetary and tax matters, public health and social security); protection of judicial independence and proceedings; tackling ethics breaches in regulated professions (prevention through prosecution); a supervisory, inspection or regulatory task connected with official authority in those cases; protecting the data subject himself, or protecting other people's rights and freedoms; or the enforcement of civil law claims (41(1)). It takes into account at least the purposes, categories of data, scope of the restriction, safeguards against abuse, the controller, storage periods, risks to data subjects and their right to be informed of the restriction unless that defeats its purpose (41(2)).
The graph holds this control, the 0 it maps to, and the evidence behind each claim, over MCP and REST.