A controller holding de-identified data must take reasonable measures to stop it being linked to an individual, publicly commit not to reidentify it and contractually bind recipients to the chapter; one disclosing pseudonymous or de-identified data must monitor recipients' contractual compliance and act on breaches. Pseudonymous data escapes the access, correction, deletion and portability rights and s 541.101 duties only where identifying information is kept separately under effective controls.
The graph holds this control, the 0 it maps to, and the evidence behind each claim, over MCP and REST.