When determining the means of processing and during processing, the controller must implement appropriate measures, such as pseudonymisation, designed to implement the principles effectively and build in safeguards, taking into account the state of the art, cost, the nature and purposes and the risks. For information society services likely to be accessed by children the controller must take account of the children's higher protection matters: how children can best be protected and supported when using the service, that they merit specific protection because they may be less aware of risks and rights, and that they have different needs at different ages and stages of development. By default only the data necessary for each purpose may be processed, in amount, extent, storage period and accessibility, and data must not by default be made accessible to an indefinite number of people.
The graph holds this control, the 0 it maps to, and the evidence behind each claim, over MCP and REST.