Processing must be for a lawful purpose related to the controller's function, use reasonably accurate, complete and current data (backups excepted), and be adequate, relevant and limited to the minimum necessary. Sensitive data may not be used for direct marketing without consent. Further processing must be compatible with the original purpose (assessed by the link between purposes, the nature of the data, the consequences, how it was collected and safeguards), be a disclosure to a related body corporate, or be otherwise authorised; further use of sensitive data must be directly related to the original purpose.
The graph holds this control, the 0 it maps to, and the evidence behind each claim, over MCP and REST.