A CDR representative's request to give or amend a consent must comply with the relevant data standards, be reasonably easy to understand having regard to the consumer experience guidelines (plain concise language, visual aids where appropriate), not include or refer to the principal's CDR policy or other documents in a way that reduces understandability, and not be combined with other requests except other consents under the rules (never direct marketing or de-identification consents). A failure makes the principal liable (rule 1.16A).
The graph holds this control, the 0 it maps to, and the evidence behind each claim, over MCP and REST.