The organization must establish a clear and consistent process to inform individuals about how their personal data is collected and used. Before or at the time of collection, individuals should be provided with all essential details, the controller's detail, the purpose and legal basis of processing, how long the data will be retained, and how they can exercise or withdraw consent for processing. The organization must also clarify whether providing data is optional or mandatory.
The procedure must also specify how individuals are informed of their ability to withdraw consent and the implications of doing so. In cases where the data subject already possesses this information or disclosure would breach legal restrictions, the organization may justifiably withhold notification while maintaining a record of that decision for accountability.