Advanced implementation checklist

A practical PDPA checklist for implementation.

A GDPR-style control framework adapted for Sri Lankan PDPA readiness—covering ownership, data operations, rights, security, vendors, evidence, and continuous improvement.

How to use it

1

Assign an owner

Make each control somebody’s accountable action.

2

Record the evidence

Capture proof as you implement, test, and review.

3

Track the gaps

Use the checklist to prioritise open risks and remediation.

Checklist discipline

Work control by control. Evidence as you go.

A mature privacy programme does more than state good intentions. It assigns owners, establishes repeatable practices, tests whether they work, and retains evidence that the organisation can demonstrate accountability.

Foundation: establish firstHigh priority: address earlyOperational: embed and sustain
01

Governance and accountability

Set accountable ownership and make privacy a managed organisational capability.

4 controls

Appoint a privacy lead or Data Protection Officer

Define authority, responsibilities, reporting line, independence where appropriate, and access to senior management.

Foundation
Suggested evidence: Appointment letter, role description, reporting structure, annual plan.

Create a privacy governance model

Assign decision rights across leadership, legal, IT, security, HR, procurement, marketing, and operational teams.

Foundation
Suggested evidence: RACI matrix, steering committee terms of reference, meeting minutes.

Approve core privacy policies

Establish policy requirements for personal-data handling, acceptable use, retention, rights, incidents, vendors, and security.

High priority
Suggested evidence: Approved policies, version control, review schedule, staff acknowledgement.

Deliver role-based awareness training

Provide baseline training for all staff and deeper modules for high-risk roles such as HR, customer service, IT, security, and marketing.

Operational
Suggested evidence: Training content, attendance records, completion metrics, assessment results.
02

Data inventory and processing records

Know what personal data you process, why you process it, where it flows, and who handles it.

3 controls

Build a personal-data inventory

Identify data categories, sources, systems, business owners, recipients, storage locations, transfers, and retention periods.

Foundation
Suggested evidence: Data inventory, system register, data-flow diagrams, asset ownership records.

Maintain a Record of Processing Activities

Document processing purposes, lawful basis, data subjects, categories, recipients, safeguards, retention, and risk considerations.

High priority
Suggested evidence: ROPA register, processing-owner approvals, periodic review record.

Classify personal and sensitive data

Define categories, handling expectations, access restrictions, and protective requirements based on data sensitivity and risk.

Operational
Suggested evidence: Data-classification policy, tagging standards, system configuration evidence.
03

Lawful processing and transparency

Ensure each processing activity has a legitimate purpose, an appropriate basis, and clear communication to people.

3 controls

Identify and document lawful bases

For each material processing activity, document the lawful basis and ensure the operational practice matches the stated basis.

Foundation
Suggested evidence: Lawful-basis register, ROPA entries, legal review notes.

Publish clear privacy notices

Explain what data is collected, why, how it is used, how long it is kept, who receives it, and how rights can be exercised.

High priority
Suggested evidence: Website, employee, customer, vendor, and application privacy notices.

Manage consent where it is required

Make consent specific, informed, demonstrable, and easy to withdraw. Avoid relying on consent where it is not appropriate.

Operational
Suggested evidence: Consent language, consent logs, withdrawal workflow, system screenshots.
04

Data-subject rights

Create a repeatable, secure process for receiving, verifying, tracking, and fulfilling personal-data requests.

3 controls

Create a rights-request workflow

Define intake channels, identity verification, request triage, ownership, response timelines, escalation, and closure criteria.

High priority
Suggested evidence: Standard operating procedure, request form, workflow diagram, response templates.

Maintain a request register

Track requests, verification steps, decisions, disclosures, exceptions, response dates, and any remediation actions.

Operational
Suggested evidence: Data-subject request log, response records, quality-review notes.

Test retrieval and deletion capability

Validate that teams can locate, export, correct, restrict, or delete relevant personal data across key systems.

Operational
Suggested evidence: Test reports, technical procedures, exception records, remediation plan.
05

Security and incident readiness

Apply technical and organisational safeguards proportionate to the confidentiality, integrity, and availability risks involved.

3 controls

Apply access-control and authentication safeguards

Use least privilege, role-based access, multi-factor authentication where appropriate, privileged-access controls, and periodic reviews.

High priority
Suggested evidence: Access-control standard, access-review reports, MFA configuration, audit logs.

Protect data in storage and transit

Use appropriate encryption, key management, secure configuration, backup, and resilience controls for sensitive and high-risk data.

High priority
Suggested evidence: Security architecture, encryption configuration, backup test records, vulnerability reports.

Operate a personal-data breach process

Define detection, containment, investigation, impact assessment, notification decision-making, communications, and lessons learned.

Foundation
Suggested evidence: Incident-response plan, playbooks, contact list, tabletop exercise results, incident register.
06

Retention and disposal

Keep personal data only for as long as necessary and dispose of it securely when the purpose ends.

2 controls

Define retention periods

Set defensible periods for data categories based on purpose, legal requirements, contractual needs, risk, and operational necessity.

High priority
Suggested evidence: Retention schedule, legal review notes, data-owner approvals.

Implement deletion and archival controls

Build practical deletion, anonymisation, archival, disposal, and exception-management processes into priority systems.

Operational
Suggested evidence: System rules, deletion certificates, archival procedure, exception register.
07

Third parties and data sharing

Maintain control over processors, vendors, partners, and transfers that handle personal data on your behalf.

3 controls

Identify third parties handling personal data

Maintain a complete inventory of processors, vendors, cloud services, partners, and recipients with access to personal data.

Foundation
Suggested evidence: Vendor register, procurement records, data-flow maps, system integrations list.

Use appropriate contractual safeguards

Include privacy, security, confidentiality, incident, audit, retention, subcontracting, and return/deletion terms where relevant.

High priority
Suggested evidence: Data Processing Agreements, contract clauses, contract review checklist.

Perform risk-based vendor assurance

Assess suppliers before onboarding and periodically thereafter, focusing on the sensitivity and scale of processing.

Operational
Suggested evidence: Due-diligence questionnaire, assurance reports, risk ratings, remediation tracking.
08

Privacy risk and continuous improvement

Assess high-risk activity before it begins and maintain a repeatable cycle of monitoring, assurance, and improvement.

3 controls

Embed privacy risk assessment and DPIA processes

Identify triggers for high-risk processing, assess impacts, document mitigations, obtain approvals, and review residual risk.

High priority
Suggested evidence: DPIA procedure, completed assessments, risk register, approval records.

Integrate privacy into project and procurement lifecycles

Make privacy review a standard gate for new systems, products, vendors, data-sharing arrangements, and material changes.

Operational
Suggested evidence: Project checklist, procurement gate, design-review minutes, issue tracker.

Monitor, audit, and report progress

Track implementation metrics, control effectiveness, incidents, requests, vendor findings, training, and open risks for leadership review.

Operational
Suggested evidence: KPI dashboard, audit reports, steering committee packs, remediation register.

Need a tailored implementation plan?

Turn checklist findings into an accountable roadmap.

Use the readiness assessment to establish a baseline, then speak with an adviser about privacy governance, vDPO support, risk, security alignment, supplier assurance, evidence, and implementation leadership.