Service providers must keep an inventory of personal data breaches recording the facts of each breach, its effects and the remedial action taken, sufficient for the Commissioner to verify compliance with the notification rules, and containing only the information needed for that purpose.
The graph holds this control, the 0 it maps to, and the evidence behind each claim, over MCP and REST.