When de-identifying CDR data (under a de-identification consent or for redundant data under rule 7.12), the accredited data recipient must first consider, having regard to the De-Identification Decision-Making Framework published by the OAIC and Data61, the available techniques, whether re-identification is technically possible and how likely it is, whether the data can be de-identified so no one is identifiable or reasonably identifiable from it together with other information anyone will hold after the process. If so, it must choose the appropriate technique, apply it, delete under the CDR data deletion process any CDR data that must go to reach that extent, and as soon as practicable record its assessment, that the data was de-identified to that extent, how (including the technique) and any persons the de-identified data is disclosed to. If not, it must delete the data and anything derived from it under the deletion process.
The graph holds this control, the 0 it maps to, and the evidence behind each claim, over MCP and REST.