Access, correction, deletion and portability rights do not apply to pseudonymous data where the controller can show identifying information is kept separately under effective controls preventing its access; a controller disclosing pseudonymous or deidentified data must exercise reasonable oversight of the contractual commitments attached and address breaches.
The graph holds this control, the 0 it maps to, and the evidence behind each claim, over MCP and REST.