Collection and processing are lawful only where one of these applies: (1) the consent of the user who owns the data; (2) necessity to comply with a legal obligation on the service provider; (3) necessity to protect the user's data; (4) the provider's purposes require identifying the data owner; (5) written consent of the guardian where the user is a minor under 18. In every case the service provider must be able to demonstrate that the data owner consented to the processing. The 2021 text also gave a right to withdraw consent with destruction of the data processed before withdrawal, age-verification efforts and a CITRA mechanism for guardian consent; the 2024 text keeps withdrawal only through Article 4.12 and 4.13.
The graph holds this control, the 0 it maps to, and the evidence behind each claim, over MCP and REST.