The FSP must ensure that all access to personal data by employees and by data processors it appoints is logged, with the data access logs recording who accessed the data, when, whose personal data was accessed and what changes, if any, were made.
The graph holds this control, the 0 it maps to, and the evidence behind each claim, over MCP and REST.