Controllers and processors must appoint a data protection officer, who collaborates in and supervises compliance, in the cases the regulations set, chosen for professional qualities and ability to perform the functions the regulations define; a business group may share one officer easily accessible from each establishment, public bodies may share one according to structure and size, and the officer may be staff or under a service contract. Failing to appoint when required and failing to let the officer take part or interfering with the role are serious offences (45(18) and (19)).
The graph holds this control, the 0 it maps to, and the evidence behind each claim, over MCP and REST.