A CDR representative principal breaches subrule (1) (civil penalty) if its representative fails to comply with section 56EK of the Act (privacy safeguard 8, overseas disclosure) for service data as if it were an accredited data recipient, and subrule (2) (civil penalty) if it fails to comply with section 56EL (privacy safeguard 9, government related identifiers).
The graph holds this control, the 0 it maps to, and the evidence behind each claim, over MCP and REST.