Per OWASP MASVS v2 MASVS-PRIVACY: protect privacy + personal data in mobile apps. Requirements include (a) implement data minimisation collecting only data necessary for the function + (b) provide clear + accessible privacy notices + consent mechanisms + (c) implement data subject rights (access + rectification + erasure + portability) per applicable regulation + (d) implement secure handling of third-party SDK data sharing including privacy review + contractual controls + (e) maintain logging + monitoring for privacy-sensitive operations + (f) implement appropriate permission justifications + just-in-time prompts + (g) align to applicable privacy regulation (GDPR + CCPA + APPI + LGPD + similar) including breach notification + cross-border transfer controls.
The graph holds this control, the 0 it maps to, and the evidence behind each claim, over MCP and REST.