The best answer is B. To establish the organization’s accountability for the use and protection of personal information.
ISACA privacy guidance emphasizes accountability as a core privacy principle and describes privacy notices as documents that explain how personal information is collected, used, shared, retained, and protected. A privacy notice is fundamentally about transparency and accountability to data subjects regarding the organization’s handling of personal information.
Option A is incorrect because a privacy notice is not primarily a liability shield. Option C is incorrect because a privacy notice may disclose sharing practices, but it is not primarily to obtain blanket approval for sale of personal information. Option D is also incorrect because compliance of controls is a broader privacy governance objective; the notice itself is mainly for transparent disclosure and accountability.
References (Official ISACA):
ISACA, Privacy Notice.
ISACA Privacy Resource Center.
ISACA Journal, Creating a Compliant and Accountable Data Culture.
ISACA, Using ISACA Privacy Principles for GDPR Compliance.