A data holder may refuse to seek an authorisation, to invite amendment, or to disclose required consumer data only where it considers this necessary to prevent physical, psychological or financial harm or abuse, where it has reasonable grounds to believe disclosure would adversely affect the security, integrity or stability of the Register of Accredited Persons or its own ICT systems, for a blocked or suspended account, in circumstances in the data standards, or where another rule forbids disclosure. It must inform the accredited person of the refusal under the data standards (civil penalty).
The graph holds this control, the 0 it maps to, and the evidence behind each claim, over MCP and REST.