Data Protection

Know what data exists, why it is used and who is responsible.

A credible privacy program needs inventories, ownership, contracts, retention and operational request/incident workflows.

01Program components

  • Processing inventory
  • Purpose/lawful-basis review
  • Privacy notices
  • Consent/preference controls where used
  • Retention schedule
  • Controller/processor contracts
  • Supplier/privacy due diligence
  • DPIA process where required
  • Breach process
  • Rights/request handling as applicable
  • Cross-border review
  • Training and awareness

02Sri Lanka PDPA readiness

Target Date
2027-01-01
Status
readiness-required
Workstreams
Confirm controller/processor roles, Map processing activities, Review notices and purposes, Update processor/subprocessor contracts, Define breach escalation, Define DPIA process, Review cross-border arrangements, Assess DPO requirement, Document technical and organizational measures
Rule
Revalidate against the latest DPA guidance and Gazette notices before 1 January 2027.

This document is a draft framework provided for review. It is not legal advice, and it must be confirmed against actual Fuchsius operations and applicable law before publication.