Regulations may require controllers to assess high-risk processing before it starts, covering a systematic description and purpose (including any legitimate interest), necessity and proportionality, risks to data subjects, and the safeguards and measures to address them and demonstrate compliance.
The graph holds this control, the 0 it maps to, and the evidence behind each claim, over MCP and REST.