Skip to content
As enacted
Contents

Part I · Processing of Personal Data

12. Accountability in the processing of personal data

Official English translation. Where it differs from the Sinhala or Tamil text, the Act itself says which text prevails.

(1)

It shall be the duty of every controller to implement internal controls and procedures, (hereinafter referred to as the “Data Protection Management Programme”)

that—

(a)

establishes and maintains duly catalogued records to demonstrate the manner in which the implementation of the data protection obligations referred to in sections 5, 6, 7, 8, 9, 10 and 11 are carried out by the controller;

(b)

is designed on the basis of structure, scale, volume and sensitivity of processing activities of the controller;

(c)

provides for appropriate safeguards based on data protection impact assessments specified in section 24;

(d)

is integrated into the governance structure of the controller;

(e)

establishes internal oversight mechanisms;

(f)

has a mechanism to receive complaints, conduct of inquiries and to identify personal data breaches;

(g)

is updated based on periodic monitoring and assessments; and

(h)

facilitates the exercise of rights of data subjects under sections 13, 14, 15, 16 and 18, for the purpose of complying with the obligations referred to in sections 5, 6, 7, 8, 9, 10 and 11.

(2)

The Authority shall from time to time issue such guidelines in respect of the Data Protection Management

Programme.

Part II

Rights of Data Subjects

Part III

Controllers and Processors

Part IV

Use of Personal Data to Disseminate Solicited Messages

Part V

Data Protection Authority

Part VI

Director-General and the Staff of the Authority

Part VII

Penalties

Part VIII

Fund of the Authority

Part IX

Miscellaneous

Part X

Interpretation

Schedules