← Back to insights
GOVERNANCE

Data Protection Officer Responsibilities in Sri Lanka

What an effective privacy lead or DPO function needs to help an organisation turn privacy obligations into everyday practice.

Written by Lahiru Livera, Cybersecurity Advisor · Last reviewed: August 2026
Educational guidance only — not legal advice. Verify current requirements, appointment thresholds, and role expectations against official Data Protection Authority and Gazette publications.

A DPO is not just a job title

A Data Protection Officer, or equivalent privacy function, is most effective when it has a clear mandate, appropriate authority, access to decision-makers, independence in advice, and enough support to operate. Naming a person without time, resources, or management backing does not create a working privacy programme.

Core responsibilities

  • Advise leadership and teams on privacy obligations and practical decisions.
  • Coordinate PDPA readiness activities and improvement plans.
  • Support data inventories, processing registers, notices, and privacy workflows.
  • Help teams respond to individual rights requests and privacy concerns.
  • Review privacy risks in projects, systems, supplier relationships, and changes.
  • Support incident response, evidence gathering, escalation, and lessons learned.
  • Deliver privacy awareness and role-based training.
  • Report material privacy risks, progress, and improvement actions to management.

What the role needs to succeed

The organisation should provide a documented mandate, access to senior management, authority to challenge high-risk decisions, visibility over systems and projects, support from legal, IT, security, HR, procurement, and operations, a realistic workload, clear reporting lines, and evidence of management oversight.

Independence matters

The privacy role should be able to provide objective advice. Where the same person owns high-risk business decisions, approves technology deployment, and acts as the privacy reviewer, conflicts can arise. The operating model should allow the privacy function to advise, monitor, and escalate concerns appropriately.

Internal DPO or vDPO?

An internal privacy lead may work well where adequate in-house capacity and stable processes exist. A virtual DPO model can help organisations that need specialist expertise, independent advice, scalable support, rapid programme launch, assistance with complex supplier or security issues, and structured management reporting.

First 90 days for a new privacy lead

PeriodPriority
Days 1–30Understand governance, key data, systems, risks, policies, and stakeholders.
Days 31–60Build inventory, review notices, identify critical vendors, and establish reporting.
Days 61–90Implement priority controls, rights workflows, training plans, and incident processes.

Expert support

Build a practical privacy operating model.

Explore vDPO, privacy-governance, and PDPA implementation support for your organisation.

Explore advisory support →