Subject to the Act, a service provider may not disclose information about a customer without the customer's written consent unless the Regulator or law requires or permits it (48(1)); customers may inspect records about their service and have demonstrably incorrect information corrected or removed (48(2)); customer-specific information, especially billing data, is retained only for billing or another lawful purpose and only as long as the Regulator's rules or the law permit (48(3)); other uses, such as marketing additional services, need the Regulator's written approval (48(4)).
The graph holds this control, the 0 it maps to, and the evidence behind each claim, over MCP and REST.