Personal information may not be kept (by the controller or its processors) longer than needed for its purpose; when no longer needed it must within a reasonable time be returned, destroyed, permanently de-identified or made permanently inaccessible, including all copies. Historical, archival, statistical or research collection and retention required or authorised by law are excepted, and regulations may set longer periods.
The graph holds this control, the 0 it maps to, and the evidence behind each claim, over MCP and REST.