A controller may subcontract the processing of personal information provided it remains responsible for ensuring proper safeguards are in place to keep the personal information confidential, prevent its use for unauthorized purposes and generally comply with the Act and other laws; the personal information processor must itself comply with all requirements of the Act and other applicable laws. The IRR (sections 43 to 45) requires the arrangement to be governed by a contract or other legal act (modelled at R.44) and binds the processor directly.
The graph holds this control, the 0 it maps to, and the evidence behind each claim, over MCP and REST.