While Law 2008-12 does not codify a specific breach notification regime, controllers must apply security obligations and CDP guidance encourages notification of significant incidents affecting personal data.
The graph holds this control, the 0 it maps to, and the evidence behind each claim, over MCP and REST.