Personal Data Protection Act 2022 · As enacted · Part I · Processing of Personal Data
12. Accountability in the processing of personal data
Official English translation. Where it differs from the Sinhala or Tamil text, the Act itself says which text prevails.
Official translationFrom Department of Government Printing, unchanged
It shall be the duty of every controller to implement internal controls and procedures, (hereinafter referred to as the “Data Protection Management Programme”)
that—
establishes and maintains duly catalogued records to demonstrate the manner in which the implementation of the data protection obligations referred to in sections 5, 6, 7, 8, 9, 10 and 11 are carried out by the controller;
is designed on the basis of structure, scale, volume and sensitivity of processing activities of the controller;
provides for appropriate safeguards based on data protection impact assessments specified in section 24;
is integrated into the governance structure of the controller;
establishes internal oversight mechanisms;
has a mechanism to receive complaints, conduct of inquiries and to identify personal data breaches;
is updated based on periodic monitoring and assessments; and
facilitates the exercise of rights of data subjects under sections 13, 14, 15, 16 and 18, for the purpose of complying with the obligations referred to in sections 5, 6, 7, 8, 9, 10 and 11.
The Authority shall from time to time issue such guidelines in respect of the Data Protection Management
Programme.
Part II
Rights of Data Subjects
Part III
Controllers and Processors
Part IV
Use of Personal Data to Disseminate Solicited Messages
Part V
Data Protection Authority
Part VI
Director-General and the Staff of the Authority
Part VII
Penalties
Part VIII
Fund of the Authority
Part IX
Miscellaneous
Part X