← Back to insights
LEADERSHIP

What the 2027 PDPA Milestone Means for Sri Lankan Organisations

A leadership-focused view of the practical governance, operational, and risk-management work organisations can begin now.

Written by Lahiru Livera, Cybersecurity Advisor · Last reviewed: August 2026
Educational guidance only — not legal advice. Operational dates, implementation status, and legal obligations must be verified against the latest official Gazette and Data Protection Authority publications.

The question is no longer whether privacy matters

The practical question is whether an organisation is operationally ready. A working privacy programme is broader than a policy document or a job title. It requires accountability, visibility over data and systems, security controls, supplier oversight, clear communications, and management reporting.

Why boards and leadership teams matter

Privacy cannot be delegated entirely to IT or legal. Leadership teams set risk appetite, approve resources, oversee high-risk initiatives, assign accountability, and ensure privacy is integrated into digital transformation and business operations.

PRIORITY 1

Establish ownership

Assign a senior sponsor and clearly accountable privacy lead. Define responsibilities across legal, IT, security, HR, compliance, procurement, and operations.

PRIORITY 2

Establish visibility

Create a personal-data inventory and data-flow map. These are the foundation for understanding processing, risk, systems, suppliers, and ownership.

PRIORITY 3

Address high-risk processing

Prioritise sensitive data, large-scale data sets, children’s information, biometric data, financial data, health information, surveillance systems, and cross-border cloud services.

PRIORITY 4

Improve transparency

Review privacy notices, forms, marketing practices, consent arrangements, cookie notices, and rights-request channels.

PRIORITY 5

Strengthen supplier governance

Review vendor due diligence, processing arrangements, contract obligations, security controls, and escalation processes.

PRIORITY 6

Prepare incident response

Establish a response process, decision framework, evidence log, escalation path, and communications plan for privacy incidents.

A practical roadmap

TimeframeFocus
NowGovernance, ownership, risk assessment, and a baseline data inventory.
Next phaseData flows, notices, supplier review, and rights workflows.
OngoingTraining, control testing, incident exercises, audit, reporting, and improvement.

Do not wait for perfect certainty

Regulatory frameworks develop through legislation, guidance, regulations, and operational practice. That is not a reason to wait. Accountability, visibility, security, transparency, supplier oversight, and incident readiness are low-regret actions that strengthen organisational trust today.

Build readiness

Understand your current position.

Start with a baseline assessment and create a focused roadmap for your organisation.

Start free assessment →