A controller must conduct and document a data protection assessment for each processing activity presenting a heightened risk of harm: targeted advertising, sale, profiling with a reasonably foreseeable risk of unfair or deceptive treatment or unlawful disparate impact, financial, physical or reputational injury, offensive intrusion on seclusion, or other substantial injury, and processing of sensitive data; each must weigh direct and indirect benefits against risks to consumers' rights as mitigated by safeguards, factoring in deidentified data, reasonable expectations, context and the relationship. One assessment may cover comparable operations, one made under another law counts if reasonably similar, and the duty applies to processing activities created or generated after 1 January 2028.
The graph holds this control, the 0 it maps to, and the evidence behind each claim, over MCP and REST.