The controller must respond without undue delay and within 45 days (extendable once by 45 days on notice with reasons given in the first period), explain any refusal with appeal instructions within 45 days, respond free of charge at least twice a year (charging or refusing only manifestly unfounded, excessive or repetitive requests, which it must prove), may seek more information when it cannot authenticate with commercially reasonable effort, and meets deletion requests for data obtained from other sources by keeping a minimal suppression record or opting the consumer out of non-exempt processing.
The graph holds this control, the 0 it maps to, and the evidence behind each claim, over MCP and REST.