Controllers must notify the Commissioner of personal data breaches without undue delay and where feasible within 72 hours of becoming aware, unless the breach is unlikely to result in risk to rights and freedoms.
The graph holds this control, the 0 it maps to, and the evidence behind each claim, over MCP and REST.