An accredited ADI or relevant non-bank lender (to which the rules already apply as a data holder) may hold CDR data collected under a collection consent as a data holder, rather than an accredited data recipient, only if it reasonably believes the data is relevant to supplying a product to the consumer and either it is supplying, or has an application or knows of a proposed application for, that product and notified the consumer before the first collection that it would hold the data under its usual data holding practices, or it is supplying the product and the consumer has consented to the change after being told that data holder privacy safeguards would then apply instead, how the data will be treated, why it may ask, and the consequences of refusing. Related authorisations then expire.
The graph holds this control, the 0 it maps to, and the evidence behind each claim, over MCP and REST.