Before processing operations that by nature, scope, context or purpose may pose significant risks to data subjects' rights, the controller must assess their impact on data protection; it is mandatory for (a) systematic and extensive evaluation of personal aspects by automated processing including profiling with legal or similarly significant effects, (b) large-scale processing of sensitive data or data on criminal convictions and offences, and (c) large-scale systematic monitoring of publicly accessible places. The supervisory authority will publish lists of operations that require, and may publish lists that do not require, an assessment; the regulations set its content.
The graph holds this control, the 0 it maps to, and the evidence behind each claim, over MCP and REST.