mcps.workTraining · The Personal Data Protection Act
Sri Lanka · Act No. 9 of 2022, as amended 2025

The Personal Data Protection Act

What it requires of your company, and what you have to decide before January.

Neither you nor I have to become a lawyer this morning.

Three outcomes for this morning
Understand
Your obligations
Decide
Your priorities
Act
Your next 30 days

You have to make 5 (five) decisions.

01The clock
04The plan

Four
Moves

02The law
03Your part in it
100+
days until this is law for your company

Join at kahoot.it

Enter the game PIN on screen. Any nickname. Nothing is recorded against your name.

Kahoot join screen with QR code and game PIN
01

The clock

01The clock
04The plan
Four
Moves
02The law
03Your part in it

This room thinks it has time.

Clock
01 · The clock
Calendar
What starts on

January 1, 2027

The processing obligations and the controller and processor obligations commence. There is no transition period in the Act.

Scope
Sections 2 & 3
Processing
Part I
Responsibilities
Part III
01 · The clock
Board of directors
2
board meetings left in most of your companies
01 · The clock

How the Act reached this date

Jul 17, 2023
The regulator exists. Part V commences, the Data Protection Authority is constituted and its board appointed.
Dec 1, 2023
Machinery follows. The parts covering staff, funding, miscellaneous provisions and interpretation come into force.
Mar 18, 2025
Full enforcement, cancelled. The appointed date is repealed four days before it would have bitten.
Oct 30, 2025
The Amendment lands. Response times, appeal grounds, the officer role and the entire cross border regime are rewritten.
Jan 1, 2027
The duties arrive. The processing obligations and the controller and processor obligations commence.
Not set
Still unappointed. Data subject rights, direct marketing and the penalty regime have no date yet.
01 · The clock

Your duties start before anyone can complain or fine you.

duties
build window
rights, penalties
bound already, and nobody can yet demand
today
Jan 1, 2027
date not set
01 · The clock

“It slipped once. Will it not slip again?”

Two ways this goes.

Two ways this goes

Wait, and the date holds
No records, no programme, no contracts, no officer. Every duty live and unmet, and the first thing the Authority asks for is the programme you do not have.
Build, and the date slips
You hold a data inventory, a retention schedule and clean vendor contracts. Every one of those is something a well run business should hold anyway.
01 · The clock
02

The law

01The clock
04The plan
Four
Moves
02The law
03Your part in it

Personal data is any information about a living person you can identify.

Customers
Names · IDs · contact details
Employees
Payroll · CVs · attendance
Visitors
CCTV · access records
02 · The law

Your employees are data subjects.

02 · The law

So are the candidates you did not hire.

02 · The law

The group is not the controller. Each company is.

A directive lands on a company. Its board answers for it. Group membership does not remove data-sharing obligations.

Shared group, activity-specific responsibilities
Company A
Company B
Assess roles, lawful basis and transparency. Document sharing or processing terms.
02 · The law

Duties attach to processing activities. Not to companies. Not to systems.

Company
Paying staff
Onboarding a customer
purpose · basis · retention · owner
The CCTV estate
Sending a promotion
02 · The law

Seven obligations govern every processing activity

s. 5
Lawful
Every activity stands on a named condition in Schedules I to IV. No basis, no processing.
s. 6
Purposeful
Specified, explicit, legitimate purposes, recorded before collection, no incompatible reuse.
s. 7
Minimised
Adequate, relevant, proportionate. Every field you collect has to earn its place.
s. 8
Accurate
Kept up to date, with inaccurate data rectified without undue delay. A review cycle and a log.
s. 9
Time limited
An approved retention schedule, and records proving disposal actually happened.
s. 10
Secure IT
Encryption, pseudonymisation, anonymisation, access control. The one your IT function can own.
s. 11
Transparent
The Schedule V information, in a concise, intelligible and accessible form.
02 · The law
IT head

Six of those seven are yours. One is your IT head's.

02 · The law

A notice is the receipt for work you have already done.

Retention schedule
Processor register
Lawful basis register
The notice
02 · The law

Retention is where this group will fail hardest.

02 · The law
Schedule I

Six lawful bases. You have to name one.

(a)
Consent
Freely given, specific, informed and provable. And withdrawable at any time.
(b)
Contract
(c)
Legal obligation
(d)
Emergency
(e)
Public interest
(f)
Legitimate interests
02 · The law
The Act, section 56

“consent” means any freely given, specific, informed and unambiguous indication by way of a written declaration or an affirmative action signifying a data subject’s agreement to the processing of his personal data.

Consent can be withdrawn. A contract cannot.

Checklist

Bundle marketing consent into your terms, and the consent fails.

02 · The law
Schedule coverage and supporting evidence map
QR code to the schedule map
02 · The law
Schedule II

Higher sensitivity, stronger safeguards

Health
Patients & employee medicals
Biometrics
Unique identification
Children
Data about a child
Stack of documents

Section 12. A data protection management programme.

Make the controls operate.
Records→Safeguards→Oversight→Review
02 · The law
Matters to consider when imposing a penalty

39. In making a determination to impose an administrative penalty, including the amount as provided in subsection (1) of section 38, the Authority shall have regard to the following matters:—

Every cloud service you run is a cross border transfer.

Know where the data goes. Map the actual flow before deciding whether it crosses a border, then assess the applicable section 26 route and safeguards.
Service→Destination→Recipient→Safeguard
02 · The law
03

Your part in it

01The clock
04The plan
Four
Moves
02The law
03Your part in it

The 49 duties in force on January 1, and what a technical control can prove

11
provable by a technical control
38
provable only by documents, decisions and dates
03 · Your part in it

Not one of the thirty eight is an IT deliverable.

servers · code · access control
03 · Your part in it

PDPA evidence comes in five shapes.

01
A document exists
A register, a notice, a contract, a policy, a schedule.
02
A decision was recorded
And by whom, on what date, with the reasoning behind it.
03
A person was appointed
To a named role, on a date, and still holding it today.
04
One date preceded another
The assessment was done before the processing began, not after.
05
A register is current
Reviewed since the last thing that changed it.
03 · Your part in it

What each shape looks like in practice

Item
Sample
Linked duty
Why required
Register
ROPA — internal log tracking data flows and tools
Accountability
Section 12. Mandates a structured programme to prove compliance.
Notice
Privacy notice on a website checkout page
Transparency
Section 11. Must inform individuals of purposes and bases before collecting data.
Contract
DPA with a cloud or IT vendor
Processor control
Section 21. Requires binding contracts to govern third-party processors.
Policy
Data rights policy for handling opt-outs
Rights facilitation
Section 12 & Part II. Clear internal paths for people to access or delete data.
Schedule
Retention schedule — e.g. delete CVs after 6 months
Storage limitation
Section 9. Personal data cannot be kept longer than its legal or business purpose.
03 · Your part in it

None of the five needs a software purchase.

Rs
03 · Your part in it

A vendor who claims to cover the whole Act has not read it.

03 · Your part in it

Five decisions only management can make.

01
Lawful basis
Contract, legal obligation, legitimate interests or consent, for each activity. A commercial choice.
02
Retention periods
How long you keep customer, employee, applicant, supplier and CCTV data.
03
The officer
Whether section 20 bites, at group or entity level, and crucially who they report to.
04
Risk appetite
Which processing you stop, which you change, and which you accept and document.
05
Budget and owner
A named accountable executive and a funded plan, approved at the December board.
03 · Your part in it
Data Protection Officer · definition, as amended 2025

“Data Protection Officer” means the person designated or appointed under section 20 and includes a third party who is not directly employed by a controller or processor, but fulfils the responsibilities under section 20(5).

The officer can be external
A shared or outsourced officer is lawful. The section 20(5) duties travel with the role, not with the payroll.
03 · Your part in it
Section 20(1)

When you must appoint a Data Protection Officer

The officer may be a third party not directly employed by the controller or processor, provided they fulfil the section 20(5) responsibilities. Changed by Amendment 2025.

(a)
Processing carried out by a ministry, government department or public corporation, except the judiciary acting in its judicial capacity; or
(b)
The core activities of the controller or processor consist of:
(i)
Operations which by their nature, scope or purposes require regular and systematic monitoring of data subjects on a prescribed scale; or
(ii)
Processing of special categories of personal data on a prescribed scale; or
(iii)
Processing which results in a risk of harm to the rights of data subjects, based on its nature and impact.
03 · Your part in it
Section 20(5)

What the officer is responsible for

(a)
Advise the controller or processor and their employees on data processing obligations under this Act or any other written law. Amended 2025.
(b)
Advise on how to comply with the provisions of this Act. Amended 2025.
(c)
Facilitate capacity building of staff involved in data processing operations.
(d)
Provide advice on personal data protection impact assessments.
(e)
Co-operate and comply with all directives and instructions issued by the Authority on matters relating to personal data protection.
03 · Your part in it
Who decides the lawful basis

Lawful basis is a business decision.

Hand it to your IT head, and you have asked a technologist how you may market.

IT head

Inside this group, some companies are processors.

Controller
Purpose and means
Processor
Acts on instructions
Written terms and instructions
Both roles carry applicable responsibilities
Return / erasure · confidentiality · audit support
03 · Your part in it

Two roles, two sets of duties

Controller decides why and how
Carries Part I in full, runs the section 12 programme, appoints an officer where required, answers the Authority. And remains liable for its processors: section 21 does not let you outsource the duty.
Processor acts on instructions
Processes only as instructed, binds personnel to confidentiality, facilitates audits, erases or returns data when the work ends, needs authority before appointing a sub processor.
03 · Your part in it

The machine behind it

Compliance is the output. Data governance is the machine.

The data lifecycle

01
Create and collect
Purpose, basis, notice, minimisation. Almost all compliance is won or lost here. ss. 5, 6, 7, 11.
02
Store
Classification, access, encryption, and whether it left the country. ss. 10, 26.
03
Use
Reuse for a new purpose needs a compatibility test. Automated decisions need a human path. ss. 6, 8, 18, 24.
04
Share
Every disclosure needs a contract or a basis, and appears in the notice. ss. 21, 22, 26.
05
Archive
Archiving is not disposal. Archived data carries every duty, and is most often forgotten in a breach.
06
Destroy
The stage nobody funds and the Act requires. Section 9 needs disposal records, including from backups.
The machine behind it
The five parties

How data, instructions and oversight move between the roles

Personal data
Instructions and notices
Oversight by the Authority
Provides personal data Personal data Gives notice · s. 11 Complains Audits, investigates, directs · s. 35 Personal data Written instructions · s. 21 Discloses Needs a basis and a line in the notice Data subject Data Protection Authority Other controllers Controller Processor
The machine behind it

“Does your shared services company have written instructions from each company it serves?”

Signed document
The machine behind it

Your sector

Your sector

One statute. A different first problem in each business.

Telecommunications
Section 24 names monitoring of telecommunication networks expressly, so impact assessments are not optional. Section 27 will govern all promotional messaging.
Insurance
Underwriting and claims files are Schedule II special categories. Automated underwriting engages section 18. Agents and brokers are an unpapered processor chain.
Plantations
Estate worker and family records, welfare and housing, clinic records, ethnicity, biometric attendance. Largely paper based, rarely inventoried.
Healthcare
Patient records are special categories at scale, which is the section 20 officer trigger. Breach notification needs a rehearsed procedure, not a policy.
Outsourcing and shared services
Section 22 applies directly: written instructions, confidentiality, audit facilitation, deletion on completion. Call recording needs a basis.
Common to every sector
Employee data, CCTV and cloud services. The same three activities, in every company in this room.
The machine behind it
04

The plan

01The clock
04The plan
Four
Moves
02The law
03Your part in it

Ready does not mean perfect. There is no certification under this Act.

but
ISO27001
ISO27701

Partly ready, honestly documented, is a legitimate position.

04 · The plan
The Authority's first question

“Show me your programme, your records, and the basis for this activity.”

Employee data is the holding every one of you has.

So start the inventory with HR. It is identical in every company.

PAYROLL · CVS · ATTENDANCE
04 · The plan

Your CCTV estate is a processing activity.

“Can your CCTV installer still see your cameras?”

04 · The plan

Sharing data with a sister company is a disclosure.

Cross selling a sister company's product is a new purpose.

One group, but not one controller
Company A
disclosure
Company B
Needs a basis, a contract, and a line in the notice.
04 · The plan

Nine artifacts. Count yours.

6 Six Nine
04 · The plan

The nine artifacts

01
Record of processing activities
Per activity: purpose, basis, categories, recipients, transfers, retention, security, owner. s. 12(1)(a).
02
Lawful basis register
The named Schedule condition per activity, plus the written balancing test wherever you rely on legitimate interests.
03
Privacy notices
All eight Schedule V items, per collection point: web, contracts, forms, CCTV signage, job applications, call recording.
04
Retention schedule
Approved periods per data category, and evidence disposal happened, including from backups and processors. s. 9.
05
Processor contract register
Every vendor holding personal data, the executed clauses and sub processor terms. Includes intra group shared services.
06
Breach procedure, and one rehearsal
Who is called, who decides, who notifies, within what time. A procedure never rehearsed is a document, not a capability.
07
The programme, and the appointment
The section 12 programme, board approved and dated. The officer appointed and notified to the Authority where s. 20 applies.
08
Impact assessment register
An entry per triggering activity, recording the officer's involvement, dated before the processing began. s. 24.
09
Cross border transfer register
Each destination, each service, the instrument relied on, the date. Built from the IT service list. s. 26.
04 · The plan

One activity.
Trace it end to end.

Purpose→People→Recipients→Retention→Controls
Data Protection Authority, Sri Lanka
Data Protection Authority
Sri Lanka
QR code
04 · The plan
!

What it costs to get wrong

Up to Rs 10m

per non-compliance with a section 35 directive. Repeat non-compliance can bring an additional penalty. Part VII commencement is tracked separately.

What it costs to get wrong

The penalty is not for the breach. It is for ignoring the instruction to fix it.

Breach Authorityinvestigates Directive Complyno penalty IgnoreRs 10m s. 38
What it costs to get wrong

An incident needs a response

Contain
Limit exposure
Assess
Facts & affected people
Escalate
Notify as required

The fine is not your biggest exposure.

Already available to a counterparty, today
Contractual
Multinational customers and principals already impose data protection terms with indemnities and audit rights. Failing an audit costs the contract this year.
Tenders
Lenders and investors
Sector regulators
Reputation
Operational
What it costs to get wrong

Four gates between here and January

Day 30
Mobilise
A named executive per company. The section 20 decision taken. The HR inventory started.
Day 60
Record
Records complete for HR, customers and CCTV. Basis named for each. The cross border service list. Contract triage.
Day 90
Approve
The programme approved by each board, with the retention schedule. The officer appointed. Notices rewritten. Assessments done.
Jan 1, 2027
Operate
Programme live. Breach procedure rehearsed once. Rights intake standing by. Evidence pack assembled.
04 · The plan

The first week

Mon
Name one person
In writing, copied to your board chair. Not a committee.
Tue
Book the agenda slot
The section 12 programme on the November agenda, today.
Wed
Ask IT two questions
Which services hold personal data abroad? Is production data used in test?
Thu
Start with HR
The processing record for one function. One owner, two weeks.
Fri
Publish a breach contact
One address, and one named decision maker.
04 · The plan

Before you leave this room

01
A named accountable executive, this week
MD or CEO decides
02
Whether section 20 requires an officer, by day 30
MD with the board
03
Lawful basis for your three largest activities, by day 60
Function heads with legal
04
Retention periods approved, by day 90
Entity board
05
Budget and the section 12 programme approved, by day 90
Entity board
04 · The plan

Thank you

The schedule map and supporting evidence are one scan away.

QR code to the schedule map
← → or click to move · F for full screen · Esc to exit