Where personal data is processed by consumer IoT devices and services, the manufacturer/operator shall: provide transparent and accessible information about the processing of personal data, the purposes and lawful bases; obtain consent where required and provide a mechanism to withdraw consent; provide a means to opt out of telemetry/usage data where not strictly necessary; minimise the data collected and retained; and maintain a privacy-by-design design approach throughout the device lifecycle.
The graph holds this control, the 0 it maps to, and the evidence behind each claim, over MCP and REST.