A processor must tell the engaging controller or processor of a breach within 72 hours of becoming aware and answer its information requests. A controller must notify the Commission within 72 hours of becoming aware of a breach likely to risk individuals' rights and freedoms (extendable for law enforcement needs or scoping, with grounds and evidence), and communicate high-risk breaches to affected data subjects without undue delay in plain language with mitigation advice (or by public communication if direct contact is disproportionate). Notices give a contact point, likely consequences and measures taken; information may be phased. Controllers and processors must keep a record of all breaches, effects and remedies. This section applies only from the second anniversary of the Act's commencement.
The graph holds this control, the 0 it maps to, and the evidence behind each claim, over MCP and REST.