A CDR outsourcing arrangement is a written contract between an OSP principal and a provider under which the provider collects CDR data on behalf of an OSP chain principal with unrestricted accreditation, or uses or discloses service data to provide specified goods or services to the principal (for the purpose of enabling the chain principal to serve the consumers under their consents, or the principal to provide the goods and services specified in its own arrangement). The contract must require the provider, for service data: to comply as if it were the OSP principal with the principal's CDR policy on deletion, de-identification and treatment of redundant or de-identified data and with privacy safeguards 4, 6, 7, 8 and 9 (sections 56EG, 56EI, 56EJ, 56EK and 56EL of the Act); to take the Schedule 2 steps as if it were an accredited data recipient; to disclose service data only to another direct or indirect OSP of the chain principal, to the chain principal, or where the chain principal's own disclosure would be permitted; to use or disclose it only as the contract with the OSP principal allows; to give access to, delete under the CDR data deletion process with records, and hand over records of, service data, and to direct its own sub-providers to do the same, when directed by the OSP principal, the chain principal or (for a representative's chain) the CDR representative principal; and, where it is itself a principal in a further arrangement, to ensure its provider complies. Direct OSPs, indirect OSPs down any chain, the OSP chain principal and service data are defined in subrules (1), (2), (6) and (7).
The graph holds this control, the 0 it maps to, and the evidence behind each claim, over MCP and REST.