Operators must adopt and publish a document defining the policy on processing personal data, as well as internal documents establishing procedures for protection of personal data, and ensure unrestricted access to the published policy.
The graph holds this control, the 0 it maps to, and the evidence behind each claim, over MCP and REST.