Appoint a privacy lead or Data Protection Officer
Define authority, responsibilities, reporting line, independence where appropriate, and access to senior management.
Advanced implementation checklist
A GDPR-style control framework adapted for Sri Lankan PDPA readiness—covering ownership, data operations, rights, security, vendors, evidence, and continuous improvement.
How to use it
Assign an owner
Make each control somebody’s accountable action.
Record the evidence
Capture proof as you implement, test, and review.
Track the gaps
Use the checklist to prioritise open risks and remediation.
Checklist discipline
A mature privacy programme does more than state good intentions. It assigns owners, establishes repeatable practices, tests whether they work, and retains evidence that the organisation can demonstrate accountability.
Set accountable ownership and make privacy a managed organisational capability.
Define authority, responsibilities, reporting line, independence where appropriate, and access to senior management.
Assign decision rights across leadership, legal, IT, security, HR, procurement, marketing, and operational teams.
Establish policy requirements for personal-data handling, acceptable use, retention, rights, incidents, vendors, and security.
Provide baseline training for all staff and deeper modules for high-risk roles such as HR, customer service, IT, security, and marketing.
Know what personal data you process, why you process it, where it flows, and who handles it.
Identify data categories, sources, systems, business owners, recipients, storage locations, transfers, and retention periods.
Document processing purposes, lawful basis, data subjects, categories, recipients, safeguards, retention, and risk considerations.
Define categories, handling expectations, access restrictions, and protective requirements based on data sensitivity and risk.
Ensure each processing activity has a legitimate purpose, an appropriate basis, and clear communication to people.
For each material processing activity, document the lawful basis and ensure the operational practice matches the stated basis.
Explain what data is collected, why, how it is used, how long it is kept, who receives it, and how rights can be exercised.
Make consent specific, informed, demonstrable, and easy to withdraw. Avoid relying on consent where it is not appropriate.
Create a repeatable, secure process for receiving, verifying, tracking, and fulfilling personal-data requests.
Define intake channels, identity verification, request triage, ownership, response timelines, escalation, and closure criteria.
Track requests, verification steps, decisions, disclosures, exceptions, response dates, and any remediation actions.
Validate that teams can locate, export, correct, restrict, or delete relevant personal data across key systems.
Apply technical and organisational safeguards proportionate to the confidentiality, integrity, and availability risks involved.
Use least privilege, role-based access, multi-factor authentication where appropriate, privileged-access controls, and periodic reviews.
Use appropriate encryption, key management, secure configuration, backup, and resilience controls for sensitive and high-risk data.
Define detection, containment, investigation, impact assessment, notification decision-making, communications, and lessons learned.
Keep personal data only for as long as necessary and dispose of it securely when the purpose ends.
Set defensible periods for data categories based on purpose, legal requirements, contractual needs, risk, and operational necessity.
Build practical deletion, anonymisation, archival, disposal, and exception-management processes into priority systems.
Maintain control over processors, vendors, partners, and transfers that handle personal data on your behalf.
Maintain a complete inventory of processors, vendors, cloud services, partners, and recipients with access to personal data.
Include privacy, security, confidentiality, incident, audit, retention, subcontracting, and return/deletion terms where relevant.
Assess suppliers before onboarding and periodically thereafter, focusing on the sensitivity and scale of processing.
Assess high-risk activity before it begins and maintain a repeatable cycle of monitoring, assurance, and improvement.
Identify triggers for high-risk processing, assess impacts, document mitigations, obtain approvals, and review residual risk.
Make privacy review a standard gate for new systems, products, vendors, data-sharing arrangements, and material changes.
Track implementation metrics, control effectiveness, incidents, requests, vendor findings, training, and open risks for leadership review.
Need a tailored implementation plan?
Use the readiness assessment to establish a baseline, then speak with an adviser about privacy governance, vDPO support, risk, security alignment, supplier assurance, evidence, and implementation leadership.