Model 1 rests on preserving consumers' anonymity: with very limited exceptions a CSP performs tax calculation, remittance and reporting without retaining consumers' personally identifiable information. The Governing Board may certify a CSP only if the CSP certifies that its system is designed and tested to respect that precept; that it uses and keeps personal information only as needed to administer Model 1 for exempt purchasers and to identify taxing jurisdictions; that it gives consumers clear and conspicuous notice of what it collects, how, how it uses it, how long it keeps it and whether it discloses it to states, by a public written privacy policy on its website; that its collection, use and retention are limited to what states need to validate status- or use-based exemptions and document jurisdiction assignment; and that it has adequate technical, physical and administrative safeguards. Member states publicly notify consumers of their own practices, stop retaining personal information once no longer needed for those purposes, give individuals reasonable access to and correction of their own information, and make reasonable, timely efforts to tell an individual when an unauthorised party seeks it. Attorneys general enforce the policy; state confidentiality law still applies in full.
The graph holds this control, the 0 it maps to, and the evidence behind each claim, over MCP and REST.