If a personal data breach occurs, the service provider must notify the Information Commissioner without undue delay and, where feasible, no later than 72 hours after becoming aware of it; a notification made after 72 hours must give reasons for the delay. The notification must at least describe the nature and consequences of the breach and the measures taken or proposed to address it. A personal data breach is a breach of security leading to accidental or unlawful destruction, loss, alteration, unauthorised disclosure of, or access to, personal data processed in connection with providing a public electronic communications service. Under Article 2 of Commission Regulation (EU) No 611/2013 as amended by the same section, Annex 1 information not yet available may follow in phases without undue further delay.
The graph holds this control, the 0 it maps to, and the evidence behind each claim, over MCP and REST.