A controller may use personal data internally to detect or correct bias in profiling for automated decisions with significant effects only to the extent necessary where bias cannot otherwise be detected or corrected, deleting the data afterwards, under appropriate safeguards for constitutional and statutory rights, technical reuse restrictions and industry-standard security and privacy measures including pseudonymisation, strict and documented access controls, and without transmission to or access by any third party.
The graph holds this control, the 0 it maps to, and the evidence behind each claim, over MCP and REST.