A controller that sells sensitive data must post the statutory notice that it may sell the consumer's sensitive personal data, and one that sells biometric data must post the equivalent biometric notice, each in the same place and manner as the privacy notice.
The graph holds this control, the 0 it maps to, and the evidence behind each claim, over MCP and REST.