When collecting directly, the controller must tell the data subject its identity and contact details, that information is being collected and why (including direct marketing), whether sensitive information is collected, the intended recipients, whether supply is voluntary or legally required, the consequences of not providing it, whether it will be further processed, usual disclosees, rights of access, correction and deletion and the direct marketing opt-out, and likely overseas disclosure and countries. Indirect collection requires the same notice as soon as reasonably practicable unless the data subject consented to the transfer or it came from a related body corporate; clear instructions on how to obtain the information can suffice.
The graph holds this control, the 0 it maps to, and the evidence behind each claim, over MCP and REST.