Where a breach is likely to adversely affect the personal data or privacy of a subscriber or user, the service provider must also notify that person without undue delay, describing the nature of the breach, giving contact points in the provider from which more information can be obtained and recommending measures to mitigate possible adverse effects. The notice is not needed if the provider has shown the Commissioner, to the Commissioner's satisfaction, that it applied technological protection measures rendering the data unintelligible to anyone not authorised to access it; if the provider has not notified, the Commissioner may require it to do so after considering the likely adverse effects.
The graph holds this control, the 0 it maps to, and the evidence behind each claim, over MCP and REST.