Recipients must protect CDR data from misuse, interference, loss and unauthorised access per the information-security requirements (Schedule 2), and destroy or de-identify redundant CDR data.
The graph holds this control, the 0 it maps to, and the evidence behind each claim, over MCP and REST.