Deidentified data is data that cannot reasonably be linked to an identified or identifiable natural person or device. A controller that uses deidentified data must take reasonable measures to ensure the data cannot be associated with a natural person, publicly commit to maintain and use the data only in deidentified fashion and contractually obligate any recipients to comply with VCDPA.
The graph holds this control, the 0 it maps to, and the evidence behind each claim, over MCP and REST.