Processing of personal data may be assigned to third parties by agreement or by law, provided the controller ensures the processor maintains the same security and data protection obligations as the controller.
The graph holds this control, the 0 it maps to, and the evidence behind each claim, over MCP and REST.