Controllers must limit the collection of personal data to what is adequate, relevant and reasonably necessary in relation to the disclosed purposes. Controllers may not process personal data for purposes that are neither reasonably necessary to nor compatible with the disclosed purposes unless the consumer's consent is obtained.
The graph holds this control, the 0 it maps to, and the evidence behind each claim, over MCP and REST.