| Sec. 8(3) | Ensure completeness, accuracy and consistency of personal data where it is used to make a decision affecting the Principal or is disclosed to another Data Fiduciary. | Discovery maps every copy of an attribute across the estate and flags divergence between them, so accuracy is measured against all copies rather than the system of record alone. |
|---|
| Sec. 8(7) | Erase personal data on withdrawal of consent or when the purpose is no longer being served, unless retention is legally required. | The catalogue returns every store holding a given Principal's data, so erasure runs against a complete list — and the completeness itself is evidenced rather than assumed. |
|---|
| Sec. 5 | Notice must itemise the personal data being collected — which requires knowing what is actually collected. | Discovery reconciles the data declared in notice against the data actually present, surfacing collection that no notice covers. |
|---|
| Sec. 11–12 | The Principal may obtain a summary of personal data held and processing activities, and may request correction, completion, updating and erasure. | Access and correction resolve against a live, identity-resolved catalogue instead of a manual hunt across systems and owners. |
|---|
| Sec. 8(6) | Breach intimation must reach every affected Data Principal. | When an incident is scoped to systems, the catalogue converts that into the exact list of affected Principals — turning notification from an investigation into a query. |
|---|