Users are given functionality to erase all their user data from the device simply, covering personal data, settings the user made, and secrets such as the user's passwords or keys created by the user or generated through their use, but not data present before first use. Status in Table B.1: M (mandatory, a shall provision).
This control maps to 2 controls across 2 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.
Every mapping shown was judged rather than inferred from wording similarity, and the ones that failed review are published too. See the coverage reports and what was rejected.
The graph holds this control, the 2 it maps to, and the evidence behind each claim, over MCP and REST.