A private entity in possession of biometric identifiers or biometric information must develop a written policy, made available to the public, establishing a retention schedule and guidelines for permanently destroying biometric data when the initial purpose has been satisfied or within 3 years of the individual's last interaction with the private entity, whichever occurs first (Section 15(d)).
The graph holds this control, the 0 it maps to, and the evidence behind each claim, over MCP and REST.