Every FSP should develop a data privacy policy that states the purpose of collecting or processing personal data and the legal basis for each personal data processing activity, and publish it on its website and on every customer-facing IT application through which it processes personal data, including internet banking and mobile banking applications.
The graph holds this control, the 0 it maps to, and the evidence behind each claim, over MCP and REST.