📚 SRI LANKA PRIVACY & CYBERSECURITY INSIGHTS

Practical PDPA guidance for Sri Lankan organisations

Expert-led articles on PDPA readiness, privacy governance, individual rights, information security, and practical implementation.

PDPA Guide8 min read

PDPA Readiness Checklist for Sri Lankan Organisations

A practical starting checklist covering governance, data mapping, individual rights, security, vendors, retention, and implementation priorities.

Leadership6 min read

What the 2027 PDPA Milestone Means for Organisations

The leadership priorities, operating-model decisions, and low-regret actions organisations can begin now.

Implementation9 min read

How to Build a Personal-Data Inventory and Processing Register

A step-by-step guide to mapping personal data, systems, owners, vendors, purposes, retention, and data flows.

Governance7 min read

Data Protection Officer Responsibilities in Sri Lanka

What an effective DPO or privacy function needs: mandate, independence, management access, operating support, and clear accountability.

Privacy & Security8 min read

PDPA, ISO 27001 and ISO 27701: A Practical Operating Model

How to connect privacy governance with security controls, risk management, supplier assurance, audits, and continual improvement.

Data Rights7 min read

How to Respond to a Data-Subject Access Request

A practical workflow for request intake, identity verification, data discovery, secure disclosure, documentation, and improvement.

Transparency6 min read

How to Write a Privacy Notice for a Sri Lankan Website

A practical, people-first approach to explaining how a website or digital service collects, uses, protects, and shares personal data.

Incident Response8 min read

PDPA Data Breach Response Plan: What Organisations Should Prepare

A practical operating model for detecting, containing, assessing, communicating, and learning from personal-data incidents.

Third Parties7 min read

PDPA Supplier and Processor Due Diligence Checklist

A practical checklist for procurement, legal, security, IT, and business teams that rely on third parties to process or access personal data.

Privacy Risk7 min read

When Should You Conduct a Data Protection Impact Assessment?

A practical screening approach for identifying high-risk processing and building privacy into projects before they go live.

HR & People Data8 min read

PDPA Compliance for HR and Employee Data

A practical guide for HR leaders, management teams, security professionals, and people managers handling employee and applicant information.

Public Sector9 min read

Public Sector PDPA Readiness: A Practical Implementation Pathway

A practical roadmap for ministries, departments, authorities, and public institutions to build accountable privacy and data-protection capabilities.

Start with a baseline

Understand your organisation's PDPA readiness.

Take the free assessment to identify priority gaps across governance, data, rights, security, suppliers, and operational readiness.

Start free assessment

Educational guidance only — not legal advice. Verify current requirements against official Data Protection Authority and Gazette publications. Articles are reviewed periodically.