Per APPs 2-5: anonymity + collection + notice. Requirements include (a) implement APP 2 - Anonymity and Pseudonymity - data subjects have option to deal with the entity not identifying themselves or using a pseudonym + (b) implement APP 3 - Collection of Solicited Personal Information only if reasonably necessary + lawful + (c) implement APP 4 - Dealing with Unsolicited Personal Information - destroy or de-identify if it would not have been lawful to collect + (d) implement APP 5 - Notification of the Collection of Personal Information at or before time of collection covering identity + purposes + recipients + access + correction + complaints + (e) maintain records of consent + notice + (f) integrate with broader privacy policy.
The graph holds this control, the 0 it maps to, and the evidence behind each claim, over MCP and REST.