Recipients must respond to eligible data breaches and comply with notifiable-data-breach obligations (OAIC) for CDR data.
The graph holds this control, the 0 it maps to, and the evidence behind each claim, over MCP and REST.