Each controller and processor must develop, maintain and implement the policies and practices needed to comply, have a process to receive and respond to privacy complaints, communicate these to staff, and make information about them available to any member of the public on request.
The graph holds this control, the 0 it maps to, and the evidence behind each claim, over MCP and REST.