A private entity in possession of biometric identifiers or biometric information shall store, transmit and protect them from disclosure in a manner that is the same as or more protective than the manner in which it stores, transmits and protects its other confidential and sensitive information, such as account numbers, PINs, pass codes, driver's licence numbers and social security numbers. This is an internal parity test: whatever the entity does for its most sensitive personal data it must do at least for biometrics.
The graph holds this control, the 0 it maps to, and the evidence behind each claim, over MCP and REST.