Controllers in possession of de-identified data must take reasonable measures to prevent re-identification, publicly commit to maintaining de-identification, and contractually bind recipients; rights do not apply to de-identified/pseudonymous data.
The graph holds this control, the 0 it maps to, and the evidence behind each claim, over MCP and REST.