Processing on a controller's behalf may be entrusted only to a party offering sufficient guarantees of appropriate technical and organisational measures, under a contract or other legal act setting at least object, duration, nature and purpose, type of data, categories of data subjects and the controller's obligations and rights. A processor may delegate to another processor on the same terms and stays responsible to the controller for it; a processor that determines purposes and means in breach of the Law is liable as controller for that processing. Hiring a processor without sufficient guarantees is a minor offence (44(7)); processing without a written contract, sub-processing without prior authorisation and a processor failing to report breaches to the controller are serious (45(12) to (14)).
The graph holds this control, the 0 it maps to, and the evidence behind each claim, over MCP and REST.