The controller must designate an individual or individuals accountable for the organisation's compliance with the Act and make their identity known to any data subject on request; the IRR (section 26(a)) requires every person or body involved in processing to designate an individual who functions as data protection officer or compliance officer, and the officer's name and contact details form part of the records of processing (26(c)) and of any registration (47).
The graph holds this control, the 0 it maps to, and the evidence behind each claim, over MCP and REST.