Services

Personal Data Protection Act readiness

Sri Lanka’s Personal Data Protection Act No. 9 of 2022 brings its core obligations for controllers and processors into force on 1 January 2027. We assess where you stand, build the records, notices and procedures the Act requires, and align the work with ISO 27001 and ISO 27701 so the same evidence serves both.

What we do

  1. Applicability and gap assessment

    We map what personal data you hold, where it flows, who processes it for you, and where you stand against Parts I and III of the Act.

  2. Data inventory and records

    A register of processing activities with lawful bases, retention periods and cross-border transfers.

  3. Policies and notices

    Privacy notices, an internal data protection policy, a retention schedule, a data subject request procedure and a breach notification procedure with the Authority’s timelines built in.

  4. Data Protection Officer support

    Help deciding whether you must appoint a DPO, defining the role, and acting as an outsourced DPO adviser where that is appropriate.

  5. Processor and vendor contracts

    Clauses for your vendors, and for your own client contracts where you act as a processor.

  6. Alignment with ISO 27001 and ISO 27701

    Where you run or plan an ISMS, we map the PDPA requirements onto it so one set of controls and evidence covers both.

What you receive

  • PDPA gap report and remediation plan
  • Data inventory and processing register
  • Privacy notice set and internal data protection policies
  • Data subject request and breach procedures with templates
  • DPO role description or outsourced DPO arrangement
  • Processor and vendor contract clauses

Common questions

Does ISO 27001 make us PDPA compliant?
No, but it covers much of the security side. The Act also needs lawful bases, notices, handling of data subject rights, retention rules and a DPO where required. ISO 27701 adds those privacy controls on top of an ISMS, which is why we often run the two together.
Who enforces the Act?
The Data Protection Authority of Sri Lanka. We follow its guidance and the commencement orders, and we update your plan as rules are issued.

Related services

Business continuity and ISO 22301

Business impact analysis, continuity plans and exercises that prove the plans work. Certifiable to ISO 22301 if you need the certificate.

Not sure where you stand? Start with a scoping call.

Forty-five minutes, no charge. We ask about your organisation, what is driving the project and what you already have in place, then send a written proposal with a fixed scope and fee.