A primary data holder must use the secondary data holder's service only to request SR data it needs for an SR data request, must not use or disclose SR data it receives for any other purpose, and once it has responded must delete any SR data it holds under the CDR data deletion process.
The graph holds this control, the 0 it maps to, and the evidence behind each claim, over MCP and REST.