Honor consumer privacy rights + consent + marketing + loyalty data obligations per applicable jurisdiction privacy law + sectoral marketing law. Privacy rights must (a) honor data subject access + deletion + correction + portability + opt-out of sale or sharing + opt-out of targeted advertising + limit use of sensitive personal information + non-discrimination per CCPA + CPRA + similar state laws, (b) provide privacy notice at collection with content per applicable law, (c) honor Global Privacy Control signal + Universal Opt-Out Mechanism where applicable, (d) age-gate children data per COPPA + state child privacy laws + sensitive flag transgender/non-binary data per state-specific provisions. Consent must (a) obtain opt-in consent where required (sensitive data + marketing email/SMS per CAN-SPAM/TCPA + cross-border transfers per GDPR + EU consumer products per ePrivacy), (b) distinguish opt-in vs opt-out per data type + per jurisdiction + per processing purpose, (c) maintain consent receipts + revocation processes + audit trail. Marketing and loyalty data must (a) bind loyalty data uses to disclosed purposes + obtain explicit consent for novel uses (third-party sharing + behavioral advertising + cross-context advertising), (b) implement marketing preference centers + suppression lists + CAN-SPAM unsubscribe + TCPA prior express written consent for autodialed/prerecorded calls + texts + DNC compliance, (c) maintain transparency around personalisation + recommendation + price discrimination (where used + watch the regulatory trajectory).
This control maps to 28 controls across 21 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.
Every mapping shown was judged rather than inferred from wording similarity, and the ones that failed review are published too. See the coverage reports and what was rejected.
The graph holds this control, the 28 it maps to, and the evidence behind each claim, over MCP and REST.