A controller must conduct and document a data protection assessment for targeted advertising, sale, profiling with a reasonably foreseeable risk of unfair or deceptive treatment, disparate impact, financial, physical or reputational injury, offensive intrusion or other substantial injury, processing of sensitive data, and any heightened-risk processing, weighing benefits against risks as mitigated by safeguards and factoring in de-identification, consumer expectations, context and the relationship; it must produce relevant assessments to the AG under a civil investigative demand (they stay confidential and privileged). One assessment may cover comparable operations and one done for another law may suffice.
The graph holds this control, the 0 it maps to, and the evidence behind each claim, over MCP and REST.