A data holder must keep records that record and explain authorisations and their amendment or withdrawal, notices of consent withdrawal, SR data requests and responses (and a secondary data holder's refusal reasons), disclosures, any white-label disclosure agreement under subrule 2.4(5) and any Schedule 3 clause 7.1A election, refusals and the rule or standard relied on, CDR complaint data and complaints, and its authorisation and amendment processes including a video of each. An accredited data recipient must record all consents and uses consented to, amendments and withdrawals, authorisation withdrawal notices received, CDR complaint data and complaints, collections, disclosures to accredited persons, trusted advisers (with verification steps), of insights (with a copy of each) and under business consumer disclosure consents (with business consumer statements counted and verification steps), deletion elections, its use of CDR data, its consent and amendment processes with videos, sponsorship and outsourcing arrangements and how OSPs are overseen, de-identification under consent and under privacy safeguard 12, Schedule 2 records, and the terms and conditions of CDR-enabled services. A CDR representative principal must keep the equivalent records for each representative, including the arrangement and oversight steps. Every record must carry the date and time made and of the event, an English translation must be available on request to anyone entitled to inspect, and records must be kept for 6 years from creation (each a civil penalty).
The graph holds this control, the 0 it maps to, and the evidence behind each claim, over MCP and REST.