← Back to insights
PDPA GUIDE

PDPA Readiness Checklist for Sri Lankan Organisations

A practical starting point for leadership, privacy, IT, HR, legal, and operations teams preparing for personal-data protection responsibilities.

Written by Lahiru Livera, Cybersecurity Advisor · Last reviewed: August 2026
Educational guidance only — not legal advice. Verify current requirements against official Data Protection Authority and Gazette publications before relying on this material.

PDPA readiness starts with knowing where you stand

For most organisations, the first challenge is not understanding every legal provision. It is knowing where personal data exists, who is responsible for it, which risks matter most, and what must be done first. Use this checklist to establish a working baseline and a focused improvement plan.

01

Assign accountable ownership

Name an executive sponsor and a day-to-day privacy owner. Document who approves policy, risk decisions, resources, and management reporting.

02

Build a personal-data inventory

Record what personal data you collect, whose data it is, why it is used, where it is stored, who accesses it, and how long it is retained.

03

Map data flows

Trace personal data from collection through use, sharing, storage, retention, and deletion across systems, files, cloud services, paper records, and suppliers.

04

Review processing purposes and notices

Document the purpose and processing conditions for important activities. Review privacy notices used for customers, employees, job applicants, suppliers, and website visitors.

05

Prepare rights-request workflows

Define request intake, identity verification, case logging, ownership, escalation, secure response, and record retention before a real request arrives.

06

Strengthen security controls

Review access controls, multi-factor authentication, encryption, backup, logging, vulnerability management, secure development, and incident response.

07

Assess suppliers and cloud services

Identify vendors that process or access personal data and review contracts, security posture, privacy obligations, sub-processors, and deletion commitments.

08

Define retention and disposal

Set retention periods and make sure information can be deleted, anonymised, or securely disposed of across systems, archives, backups, paper records, and vendors.

A practical 90-day starting plan

PeriodPriority actions
First 30 daysAssign ownership, identify critical data, and create a privacy risk register.
Days 31–60Build an inventory, map data flows, and review notices and key suppliers.
Days 61–90Implement rights workflows, strengthen priority controls, and begin management reporting.

Start with a baseline

Find your priority gaps.

Use the free PDPA readiness assessment to identify practical improvement priorities across governance, data, rights, security, suppliers, and operations.

Start free assessment →