A controller that profiles to make decisions producing legal or similarly significant effects must conduct an impact assessment stating, as far as reasonably known, the purpose, intended use cases, deployment context and benefits; whether the profiling poses a known or reasonably foreseeable heightened risk of harm, its nature and the mitigation taken; the main categories of input data and the outputs; data used to customise the profiling; performance metrics and known limitations; transparency measures, including disclosure to consumers while profiling occurs; and post-deployment monitoring and user safeguards, including oversight, use and learning processes.
The graph holds this control, the 0 it maps to, and the evidence behind each claim, over MCP and REST.