When a data holder receives a consumer data request from an accredited person on a consumer's behalf, it must, in the circumstances the sector Schedule specifies, give the consumer an online dashboard to manage authorisations, showing for each authorisation the data authorised, when given, the period, scheduled or actual expiry, disclosures made (rule 7.9), any disclosure of corrected data under subsection 56EN(4) of the Act, and each amendment, plus any information the data standards or the Register specify; allowing withdrawal at any time with a data-standards consequence message; no more complicated than giving the authorisation; and prominently displayed and readily accessible (civil penalty). For non-individuals and partnership accounts only nominated representatives may manage authorisations. Where the consumer is a secondary user, the data holder must also give the account holder a service showing the secondary user's authorisations and letting the account holder withdraw the secondary user instruction, with a consequence message, no more complicated than giving it, included in the account holder's dashboard where one exists (civil penalty).
The graph holds this control, the 0 it maps to, and the evidence behind each claim, over MCP and REST.