| Section 5 — Notice |
Plain-language notice before/at data collection |
A.7.3.2 (Privacy notices) |
Layered notice templates per data subject category — employees, customers, vendors, website visitors |
| Section 6 — Consent |
Freely given, specific, informed, unambiguous consent |
A.7.3.3 (Consent management) |
Consent capture framework, granular per-purpose records, withdrawal mechanism, withdrawal processing verification |
| Section 7 — Legitimate uses |
Document non-consent lawful bases for each processing activity |
A.7.2.3 (Lawful basis) |
RoPA with lawful basis per activity; Legitimate Interest Assessments (LIAs) where applicable |
| Section 8(3) — Accuracy |
Ensure personal data is accurate and up to date |
A.7.4.3 (Accuracy and quality) |
Data quality procedures, periodic accuracy review, self-service correction portal for data subjects |
| Section 8(5) — Security |
Appropriate technical and organisational security measures |
ISO 27001 + 27701 combined controls |
ISMS + PIMS combined — security safeguards evidenced through integrated audit |
| Section 8(7) — Breach notification |
Notify DPB and data principals of personal data breach |
ISO 27001 A.16 + 27701 extension |
Breach detection, classification, notification templates, 72-hour response SLA, DPB notification workflow |
| Section 12 — Right to access |
Data principal right to know what data is processed |
A.7.3.6 (Access to PII) |
DSAR procedure, identity verification, response within 30 days, complete data inventory extraction |
| Section 13 — Right to correction/erasure |
Correct inaccurate data; erase when no longer needed |
A.7.3.6 (Correction and erasure) |
Correction and erasure procedures, system-wide propagation, sub-processor notification, deletion certificate |
| Section 14 — Grievance redressal |
Grievance officer, complaint resolution within 30 days |
A.7.3.5 (Complaints and appeals) |
Grievance officer appointment, ticketing system, 30-day SLA tracking, escalation to DPB if unresolved |
| Section 16 — Significant Data Fiduciary |
DPO appointment, DPIA, periodic audit |
ISO 27701 Clauses 6.1.2, 7.4.1 |
DPO appointment support, DPIA methodology, audit framework — including DPB inspection preparation |