Per Cavoukian PbD Principle 2: Privacy as the Default Setting. Requirements include (a) implement privacy-protective defaults in products + services + processes + (b) require explicit action to reduce privacy + (c) implement data minimisation by default + (d) implement granular consent + (e) align with GDPR Article 25 + Privacy by Default + (f) document default configurations + (g) maintain change management for default updates.
The graph holds this control, the 0 it maps to, and the evidence behind each claim, over MCP and REST.