On a personal data security incident the controller must notify the supervisory authority and, where applicable, the data subject within a period not exceeding seventy-two hours from becoming aware of it; conditions and requirements will be set in the regulations.
The graph holds this control, the 0 it maps to, and the evidence behind each claim, over MCP and REST.