A service provider is responsible for customer information and communications held by it or its agents (50(1)); it operates its network with due regard for customer privacy and, except as permitted or required by law or with consent, does not collect, use, maintain or disclose customer information or communications for undisclosed purposes (50(2)); collection purposes are identified at or before collection (50(3)); information is kept accurate, complete and current, and information and communications are protected by security safeguards appropriate to their sensitivity (50(4)).
The graph holds this control, the 0 it maps to, and the evidence behind each claim, over MCP and REST.