Controllers must notify ANSPDCP of a personal data breach without undue delay and, where feasible, within 72 hours of becoming aware of it, unless the breach is unlikely to result in a risk to natural persons. Affected individuals must be notified where the breach is likely to result in a high risk.
The graph holds this control, the 0 it maps to, and the evidence behind each claim, over MCP and REST.