Where a significant security breach affects personal data, a controller gives notice, as appropriate, to privacy enforcement authorities or other relevant authorities. Where the breach is likely to adversely affect data subjects, it also notifies them. The threshold is risk-based, and adverse effect is read broadly beyond financial loss.
The graph holds this control, the 0 it maps to, and the evidence behind each claim, over MCP and REST.