Controllers must conduct and document a data protection assessment of each of the following processing activities: processing for purposes of targeted advertising, sale of personal data, processing for profiling that presents a reasonably foreseeable risk of unfair or deceptive treatment or financial, physical or reputational injury, processing of sensitive data and any processing activities involving personal data that present a heightened risk of harm.
The graph holds this control, the 0 it maps to, and the evidence behind each claim, over MCP and REST.