Personal data must be treated with care and processed under data protection law and their published privacy notice, and must protect confidential information, using or disclosing it only for its purpose, with consent or as the law requires or permits; firms must have appropriate cyber security to protect their own and clients' data.
The graph holds this control, the 0 it maps to, and the evidence behind each claim, over MCP and REST.