A registered provider that is not an APP entity under the Privacy Act 1988, a State or Territory, or a State or Territory public body (Rules 155-85) must allow and facilitate an individual's access to the records and information, including personal information, it holds about them, complying with Australian Privacy Principle 12 as if it were an organisation under that Act; providers that are APP entities are already bound by APP 12.
The graph holds this control, the 0 it maps to, and the evidence behind each claim, over MCP and REST.