A controller must keep personal data used for a specified purpose for the period set by law or regulation so the subject can access it, and have clear internal procedures and retention statements for deletion and destruction, justify each retention period, set retention for backups and logs, and test that anonymised data cannot be re-identified and deleted data cannot be recovered.
The graph holds this control, the 0 it maps to, and the evidence behind each claim, over MCP and REST.