A controller in possession of de-identified data must take measures to prevent re-identification, publicly commit to maintaining de-identification, and contractually obligate recipients to comply; rights do not apply to de-identified data.
The graph holds this control, the 0 it maps to, and the evidence behind each claim, over MCP and REST.