Articles 63 and 64: access bodies may request information, notify findings and hear the party within four weeks, inform data protection authorities of possible GDPR breaches, revoke permits and stop processing, exclude users for up to five years, impose periodic penalty payments on holders that withhold data or miss deadlines and exclude repeat offenders from applying for up to five years; administrative fines reach 10 million euro or 2 percent of worldwide turnover for breaches of Articles 60 and 61(1), (5) and (6), and 20 million euro or 4 percent for prohibited uses, extracting personal data from secure environments, re-identification and ignoring enforcement measures.
The graph holds this control, the 0 it maps to, and the evidence behind each claim, over MCP and REST.