For privacy safeguard 12, de-identification of redundant data applies only where the recipient's consent statement said it would de-identify (or decide at the time, and it now thinks de-identification appropriate) and the consumer has not elected deletion. The steps are to apply the CDR data de-identification process and to direct any direct OSP or CDR representative given a copy to delete it and anything derived from it, notify the recipient, and pass the same direction down to its own OSPs. A representative's failure to do the same for service data is the principal's failure.
The graph holds this control, the 0 it maps to, and the evidence behind each claim, over MCP and REST.