GuideData protection1 min read
A practical roadmap for Sri Lanka's Personal Data Protection Act
Where to start, what to prioritise and how to show progress to your board — a phased approach to the PDPA for organisations that can't do everything at once.
By ENKAYT Privacy Practice
The Personal Data Protection Act, No. 9 of 2022 gives organisations in Sri Lanka a comprehensive data protection regime for the first time. For most, the challenge isn't understanding the principles — lawfulness, purpose limitation, minimisation, security — but turning them into work that can be sequenced, resourced and evidenced.
Start with a map, not a policy
The most common mistake is to begin by drafting a privacy policy. A policy written before you know what data you hold will either promise too much or describe too little. Begin instead with a record of processing: what personal data each function collects, why, on what basis, where it is stored, who receives it and how long it is kept.
- Interview process owners, not only IT
- Follow data across vendors and group companies
- Flag special categories such as health and financial data early
- Note every transfer outside Sri Lanka
Prioritise by exposure
Once the map exists, rank processing activities by volume, sensitivity and visibility to data subjects. Customer-facing processing involving sensitive data usually comes first; internal administrative processing can follow. This gives you a defensible order of work if a regulator asks why something isn't finished.
Build the operating rhythm
Readiness is not a single deliverable. The Act expects ongoing duties: responding to data subject requests, assessing high-risk processing, managing processors and handling breaches. Assign owners, set internal timelines shorter than the statutory ones and keep records of every decision.
Show progress honestly
Boards respond better to a clear plan with visible gaps than to a green dashboard that collapses under scrutiny. Report what is complete, what is in progress and which risks are being accepted in the meantime.
Need this applied to your organisation?
Our team can turn this guidance into an action plan for your regulators, systems and timelines.
Book a consultationRelated reading
1 min read
Why compliance programmes fail at evidence, not intent
Most organisations do the right things. Far fewer can prove it on demand. The difference is designing controls around the evidence they produce.
1 min read
AI governance for regulated organisations: five first principles
Most AI risk in regulated firms comes from tools they buy, not models they build. A short set of principles to govern both.
1 min read
Third-party risk in 2026: the concentration problem
As more critical services run on a handful of cloud and software providers, vendor risk management has to look beyond individual questionnaires.
Regulatory notes, monthly
New rules, enforcement themes and practical guidance. One email a month, no promotions.