What the 2027 PDPA Milestone Means for Sri Lankan Organisations
A leadership-focused view of the practical governance, operational, and risk-management work organisations can begin now.
The question is no longer whether privacy matters
The practical question is whether an organisation is operationally ready. A working privacy programme is broader than a policy document or a job title. It requires accountability, visibility over data and systems, security controls, supplier oversight, clear communications, and management reporting.
Why boards and leadership teams matter
Privacy cannot be delegated entirely to IT or legal. Leadership teams set risk appetite, approve resources, oversee high-risk initiatives, assign accountability, and ensure privacy is integrated into digital transformation and business operations.
PRIORITY 1
Establish ownership
Assign a senior sponsor and clearly accountable privacy lead. Define responsibilities across legal, IT, security, HR, compliance, procurement, and operations.
PRIORITY 2
Establish visibility
Create a personal-data inventory and data-flow map. These are the foundation for understanding processing, risk, systems, suppliers, and ownership.
PRIORITY 3
Address high-risk processing
Prioritise sensitive data, large-scale data sets, children’s information, biometric data, financial data, health information, surveillance systems, and cross-border cloud services.
PRIORITY 4
Improve transparency
Review privacy notices, forms, marketing practices, consent arrangements, cookie notices, and rights-request channels.
PRIORITY 5
Strengthen supplier governance
Review vendor due diligence, processing arrangements, contract obligations, security controls, and escalation processes.
PRIORITY 6
Prepare incident response
Establish a response process, decision framework, evidence log, escalation path, and communications plan for privacy incidents.
A practical roadmap
| Timeframe | Focus |
|---|---|
| Now | Governance, ownership, risk assessment, and a baseline data inventory. |
| Next phase | Data flows, notices, supplier review, and rights workflows. |
| Ongoing | Training, control testing, incident exercises, audit, reporting, and improvement. |
Do not wait for perfect certainty
Regulatory frameworks develop through legislation, guidance, regulations, and operational practice. That is not a reason to wait. Accountability, visibility, security, transparency, supplier oversight, and incident readiness are low-regret actions that strengthen organisational trust today.
Build readiness
Understand your current position.
Start with a baseline assessment and create a focused roadmap for your organisation.
Start free assessment →