← NDPA 2023 · Transparency

s.27 — Information to be provided to data subjects

high privacy-notice

Requirement

A data controller shall, at the point of collection, provide the data subject with the identity and contact details of the controller, the purposes and lawful basis of processing, recipients, transfer arrangements, retention period, the data subject's rights and the right to lodge a complaint with the Commission.

What the engine looks for

Every group below must be satisfied — by an affirmative statement, not a plan, a hedge or a denial — for the control to count as covered. A term ending in … matches any word it begins. Supporting terms do not change the verdict — they raise confidence and distinguish a policy that names a mechanism from one that gestures at a category.

Required element 1 — any one of
privacy noticeprivacy policyinformat the point of collection
Required element 2 — any one of
purposeidentityrecipientretentionrightsretain
Supporting terms — specificity signals
section 27complaintndpccontactplain languagetransfer
Contradiction markers

Finding any of these outranks coverage — a policy that admits the gap is worse than silence.

no privacy notice

Equivalent controls elsewhere

Matched on shared topics. Satisfying this control usually moves these too.

FrameworkControlTitleShared topics
GDPR Art.13 Information when data is collected from the data subject privacy-notice
CCPA/CPRA 1798.130(a)(5) Privacy policy content and annual update privacy-notice
GLBA Reg P 1016.4-1016.6 Initial and annual privacy notices privacy-notice
GDPR Art.5(1)(a) Lawfulness, fairness and transparency privacy-notice
GDPR Art.12 Transparent communication and handling of rights requests privacy-notice
GDPR Art.14 Information when data is not obtained from the data subject privacy-notice
CCPA/CPRA 1798.100(a)-(b) Notice at collection privacy-notice
CCPA/CPRA 1798.135 "Do Not Sell or Share" and "Limit the Use" links privacy-notice