A controller must not process sensitive data without consent and unless reasonably necessary for the purposes of collection, must not sell sensitive data without consent, and, where it knows or wilfully disregards that a consumer is a child, must process the child's sensitive data under COPPA and, where applicable, 9 V.S.A. § 2449f. Sensitive data includes health data, sex life, transgender or nonbinary status, genetic, biometric and neural data, precise geolocation, financial account credentials and government identification numbers.
The graph holds this control, the 0 it maps to, and the evidence behind each claim, over MCP and REST.