Section 5 is short, and it is the provision most consent implementations fail. It requires a notice given with, or before, a request for consent — not a link to a policy, and not a paragraph in terms of service that a person accepted at signup two years earlier.
What it has to say
The notice must set out the personal data to be collected and the purpose it will be processed for. Both are itemised, not summarised: "we collect data to improve our services" describes nothing a person can consent to. It must also tell the Data Principal three procedural things — how to withdraw consent, how to exercise their rights under the Act, and how to complain to the Data Protection Board.
Purpose is the unit
The Act ties consent to purpose, and it is per purpose rather than per organisation. A single consent covering "marketing, analytics and product improvement" is one consent doing three jobs, and withdrawing from one of them leaves the record ambiguous. Splitting purposes at the point of notice is what makes selective withdrawal expressible later.
The language right sits with the reader
A Data Principal may ask for the notice in English or in any of the 22 languages of the Eighth Schedule. This is a right of the reader, not an option the Data Fiduciary exercises when convenient, and translating only the interface while leaving the notice in English does not satisfy it. Machine translation of a statutory notice carries its own risk: the notice is the document the consent rests on, and a mistranslated purpose is a defective purpose.
Why this is an evidence problem
At the moment a complaint is filed, the question will not be whether you had a notice. It will be which version of the notice a specific person saw, in which language, on which date, before giving a consent you are now relying on. That is a record-keeping requirement disguised as a drafting requirement, and it is far cheaper to build at the start than to reconstruct.