PDPA Readiness Checklist for Sri Lankan Organisations
A practical starting point for leadership, privacy, IT, HR, legal, and operations teams preparing for personal-data protection responsibilities.
PDPA readiness starts with knowing where you stand
For most organisations, the first challenge is not understanding every legal provision. It is knowing where personal data exists, who is responsible for it, which risks matter most, and what must be done first. Use this checklist to establish a working baseline and a focused improvement plan.
01
Assign accountable ownership
Name an executive sponsor and a day-to-day privacy owner. Document who approves policy, risk decisions, resources, and management reporting.
02
Build a personal-data inventory
Record what personal data you collect, whose data it is, why it is used, where it is stored, who accesses it, and how long it is retained.
03
Map data flows
Trace personal data from collection through use, sharing, storage, retention, and deletion across systems, files, cloud services, paper records, and suppliers.
04
Review processing purposes and notices
Document the purpose and processing conditions for important activities. Review privacy notices used for customers, employees, job applicants, suppliers, and website visitors.
05
Prepare rights-request workflows
Define request intake, identity verification, case logging, ownership, escalation, secure response, and record retention before a real request arrives.
06
Strengthen security controls
Review access controls, multi-factor authentication, encryption, backup, logging, vulnerability management, secure development, and incident response.
07
Assess suppliers and cloud services
Identify vendors that process or access personal data and review contracts, security posture, privacy obligations, sub-processors, and deletion commitments.
08
Define retention and disposal
Set retention periods and make sure information can be deleted, anonymised, or securely disposed of across systems, archives, backups, paper records, and vendors.
A practical 90-day starting plan
| Period | Priority actions |
|---|---|
| First 30 days | Assign ownership, identify critical data, and create a privacy risk register. |
| Days 31–60 | Build an inventory, map data flows, and review notices and key suppliers. |
| Days 61–90 | Implement rights workflows, strengthen priority controls, and begin management reporting. |
Start with a baseline
Find your priority gaps.
Use the free PDPA readiness assessment to identify practical improvement priorities across governance, data, rights, security, suppliers, and operations.
Start free assessment →