Where a request to exercise access, correction, deletion or portability cannot be authenticated with commercially reasonable efforts, the controller need not act but must tell the consumer it cannot authenticate until more information is provided; opt-out requests need no authentication, and may be denied only on a good faith, reasonable and documented belief of fraud, with a notice to the requester saying so and why.
The graph holds this control, the 0 it maps to, and the evidence behind each claim, over MCP and REST.