Controllers and processors must ensure personal data is processed lawfully, fairly and transparently; collected for explicit, specified, legitimate purposes; adequate, relevant and limited; accurate and kept current; kept identifiable no longer than needed; processed in line with data subject rights; kept secure by appropriate technical and organisational measures; and not transferred abroad contrary to the Act.
The graph holds this control, the 0 it maps to, and the evidence behind each claim, over MCP and REST.