The accredited person must state whether its general policy when collected data becomes redundant is to delete it, to de-identify it, or to decide at the time. If it may de-identify, it must also state that it would apply the CDR data de-identification process and could then use or disclose (including by sale) the de-identified data without further consent, what de-identification under that process means, and, where applicable, examples of how it could use de-identified redundant data.
The graph holds this control, the 0 it maps to, and the evidence behind each claim, over MCP and REST.