Data Protection
Know what data exists, why it is used and who is responsible.
A credible privacy program needs inventories, ownership, contracts, retention and operational request/incident workflows.
01Program components
- Processing inventory
- Purpose/lawful-basis review
- Privacy notices
- Consent/preference controls where used
- Retention schedule
- Controller/processor contracts
- Supplier/privacy due diligence
- DPIA process where required
- Breach process
- Rights/request handling as applicable
- Cross-border review
- Training and awareness
02Sri Lanka PDPA readiness
- Target Date
- 2027-01-01
- Status
- readiness-required
- Workstreams
- Confirm controller/processor roles, Map processing activities, Review notices and purposes, Update processor/subprocessor contracts, Define breach escalation, Define DPIA process, Review cross-border arrangements, Assess DPO requirement, Document technical and organizational measures
- Rule
- Revalidate against the latest DPA guidance and Gazette notices before 1 January 2027.
This document is a draft framework provided for review. It is not legal advice, and it must be confirmed against actual Fuchsius operations and applicable law before publication.