FOR ORGANIZATIONS
◫Build a defensible compliance programme.
Assess your readiness, identify material gaps, and move from policy to operational controls with a clear implementation plan.
Clear, Sri Lanka-focused resources for organizations, institutions, and citizens preparing for the Personal Data Protection Act.
ENFORCEMENT READINESS
Use the time ahead to establish governance, map data, close control gaps, and make privacy part of how your organization operates.
00
Days
00
Hours
00
Minutes
00
Seconds
A CLEARER PATH TO COMPLIANCE
PDPA.COM.LK turns complex data-protection obligations into useful decisions, practical actions, and credible evidence of progress.
WHO WE HELP
FOR ORGANIZATIONS
◫Assess your readiness, identify material gaps, and move from policy to operational controls with a clear implementation plan.
FOR CITIZENS
◎Find plain-language guidance on access, correction, deletion, objections, and responsible handling of your personal information.
FOR INSTITUTIONS
▦Use structured guidance for governance, data sharing, retention, transparency, and institutional accountability.
THE PDPA, IN CONTEXT
Strong compliance connects legal obligations with people, processes, technology, and accountability. Start with what data you hold, why you use it, and who is responsible.
Read the playbook01
Clear accountability, leadership sponsorship, and a responsible privacy owner.
02
A reliable view of data assets, flows, purposes, and third-party handling.
03
Security, retention, consent, and rights processes that work in practice.
04
Training, testing, audits, and continuous improvement to sustain progress.
FOR CITIZENS
The PDPA gives you powerful rights over your personal information. Here's what you need to know.
Ask organizations what data they hold about you and get a copy
Request correction of inaccurate or incomplete data
Request deletion of your data in certain circumstances
Object to processing of your data for specific purposes
WHY USE PDPA.COM.LK?
Everything you need to navigate PDPA compliance effectively.
Comprehensive 30-question assessment with Big 4-quality executive report
Templates, checklists, and guides you can actually use
Access to experienced cybersecurity and privacy professionals
Tailored to Sri Lankan context, regulations, and business environment
Compare your maturity against reference standards
Aligned with ISO 27001/27701 for integrated compliance
START HERE
IMPLEMENTATION GUIDE
01A practical seven-phase route from governance and data mapping through controls, training, and assurance.
INTERACTIVE TOOL
02Use a structured obligation tracker to monitor readiness and focus your remediation effort.
READY-TO-USE TEMPLATES
03Start with essential resources for privacy notices, data inventories, vendor agreements, and breach response.
COMPLIANCE JOURNEY
May 2022
2024-2027
January 2027
YOUR NEXT STEP
Take a structured assessment and receive a clear starting point for your PDPA compliance journey.