Where regulations 28 (national security) and 29 (legal requirements and law enforcement) apply, communications providers must establish and maintain internal procedures for responding to requests for access to users' personal data, and on demand give the Commissioner information about those procedures, the number of requests received, the legal justification for each request and the provider's response.
The graph holds this control, the 0 it maps to, and the evidence behind each claim, over MCP and REST.