Controllers and processors must establish data protection mechanisms or technical measures that implement the principles, weighing lawfulness factors (necessity, easy consent withdrawal, stopping processing when the legal basis ends), specifying and documenting the purpose of each processing before designing controls, checking compatibility of new purposes, reviewing necessity regularly, and building in human intervention to reduce bias in automated decisions.
The graph holds this control, the 0 it maps to, and the evidence behind each claim, over MCP and REST.