Notice given by Data Fiduciary to Data Principal
3. The notice given by the Data Fiduciary to the Data Principal shallΓÇö
(a) be presented and be understandable independently of any other information that has been, is or may be made available by such Data Fiduciary;
(b) give, in clear and plain language, a fair account of the details necessary to enable the Data Principal to give specific and informed consent for the processing of her personal data, which shall include, at the minimum, ΓÇö
(i) an itemised description of such personal data; and
(ii) the specified purpose or purposes of, and specific description of the goods or services to be provided or uses to be enabled by, such processing; and
(c) give, the particular communication link for accessing the website or app, or both, of such Data Fiduciary, and a description of other means, if any, using which such Data Principal mayΓÇö
(i) withdraw her consent, with the ease of doing so being comparable to that with which such consent was given;
(ii) exercise her rights under the Act; and
(iii) make a complaint to the Board.
What this means: The era of hiding data collection in 50-page Terms of Service documents is over.
Privacy notices must now be independent, readable, and contain an itemized description of every single piece of data being collected (e.g., Location, Contacts, Email). It must also contain direct links to withdraw consent or complain.
Key Practical Takeaways for Compliance Teams
-
•
Delegated Specificity: This rule provides concrete operational criteria that must be reflected in technical architectures and compliance records.
-
•
Audit Readiness: Ensure written SOPs, consent logs, and security controls correspond directly to the statutory wording of Rule 3.
-
•
Statutory Traceability: In any legal interpretation, the exact Gazette text above takes precedence over internal summaries.