Set out as documented information how learner data are protected and handled transparently: which data are gathered and where and how they are processed and stored, who may access them, the conditions for sharing with third parties, and how long they are kept. Collect and share learner data only with the learner's explicit consent; let learners and other parties see, correct and update their own data; take effective measures so only authorized people can access learner data, and verify that technical protections work.
This control maps to 1 controls across 1 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.
Every mapping shown was judged rather than inferred from wording similarity, and the ones that failed review are published too. See the coverage reports and what was rejected.
The graph holds this control, the 1 it maps to, and the evidence behind each claim, over MCP and REST.