It is an offence for a controller to disclose data incompatibly with its collection purpose, for a processor to disclose without the controller's authority, for anyone to obtain or pass on data without the keeper's authority or to offer unlawfully obtained data for sale, and for anyone to unlawfully destroy, delete, conceal or alter personal data; organisations need controls that stop these acts by staff and suppliers.
The graph holds this control, the 0 it maps to, and the evidence behind each claim, over MCP and REST.