It is unlawful for a covered operator to collect personal information from a child in a manner that violates the Rule. Generally an operator must: provide notice of what it collects, how it uses it, and its disclosure practices; obtain verifiable parental consent before collection, use, or disclosure; provide a reasonable means for a parent to review and refuse further use of the child's information; not condition participation on disclosing more information than is reasonably necessary; and establish and maintain reasonable security procedures.
The graph holds this control, the 0 it maps to, and the evidence behind each claim, over MCP and REST.