A controller may collect personal data only for a lawful purpose related to its functions and where collection is necessary for it, never by unlawful means; it must collect directly from the data subject unless the data is public, the subject authorised third-party collection, compliance is impracticable or would prejudice the purpose, or other law requires otherwise; and before collecting it must make the subject aware of the purpose, that the collection is authorised, and the intended recipients.
The graph holds this control, the 0 it maps to, and the evidence behind each claim, over MCP and REST.