← Back to insights
TRANSPARENCY

How to Write a Privacy Notice for a Sri Lankan Website

A practical, people-first approach to explaining how a website or digital service collects, uses, protects, and shares personal data.

Written by Lahiru Livera, Cybersecurity Advisor · Last reviewed: August 2026
Educational guidance only — not legal advice. Verify the notice and applicable obligations against current official requirements and obtain professional advice where appropriate.

A privacy notice is a trust document

A privacy notice should not be hidden, vague, or written only for lawyers. It should help visitors understand what happens to their information and give them a clear route to ask questions. A useful notice makes the organisation more transparent while helping internal teams document what they actually do with personal data.

SECTION 1

Start with a plain-language summary

Use a short opening that explains what the notice covers and why it matters. Avoid using legal language as a substitute for clarity.

SECTION 2

Identify who is responsible

State the organisation name, relevant contact details, and the privacy contact route that visitors can use for questions or rights-related requests.

SECTION 3

Explain what data you collect

List relevant categories such as names, contact details, account information, form submissions, device details, cookies, analytics data, and communications.

SECTION 4

Explain why data is used

Connect each important category of data to a clear business purpose, such as responding to enquiries, delivering a service, improving a website, or meeting legitimate operational obligations.

SECTION 5

Describe sharing and service providers

Explain when data may be shared with suppliers, hosting providers, analytics tools, payment partners, professional advisers, or authorities where applicable.

SECTION 6

Set out retention and security

Describe how long information is retained at a high level and explain that technical and organisational safeguards are used to protect it.

SECTION 7

Explain individual rights and contact routes

Tell people how to contact the organisation, ask questions, update information, or make a request relating to their personal data.

SECTION 8

Keep it current

Review the notice whenever your website, forms, marketing tools, suppliers, analytics, or processing activities change.

Common mistakes to avoid

  • • Copying a generic notice that does not match the organisation’s real practices.
  • • Listing purposes that are too broad or unclear.
  • • Forgetting forms, cookies, analytics, marketing tools, and third-party services.
  • • Providing no clear privacy contact route.
  • • Failing to update the notice after changing systems or suppliers.

Practical readiness

Make privacy visible from the first interaction.

Use the free assessment to identify gaps in transparency, data governance, supplier management, and privacy operations.

Start free assessment →