Personal Data Protection Act 2022 · As enacted · Part III · Controllers and Processors
20. Designation or appointment of the Data Protection Officer
Official English translation. Where it differs from the Sinhala or Tamil text, the Act itself says which text prevails.
Official translationFrom Department of Government Printing, unchanged
Every controller and processor shall designate or appoint a Data Protection Officer, to ensure compliance with the provisions of this Act, in the following circumstances:–
where the processing is carried out by a ministry, government department or public corporation, except for judiciary acting in their judicial capacity;
or
where the core activities of processing carried out by the controller or processor consist of the following:–
operations which, by virtue of their nature, their scope or their purposes, require regular and systematic monitoring of data subjects on a scale and magnitude as may be prescribed; or
processing of special categories of personal data on a scale and magnitude as may be prescribed; or
processing which results in a risk of harm affecting the rights of the data subjects protected under this Act based on the nature of processing and its impact on data subjects.
A Data Protection Officer shall possess relevant academic and professional qualifications as may be prescribed which may include academic background, knowledge and technical skills in matters relating to data protection having competency and capacity to implement strategies and mechanisms to respond to inquiries and incidents related to processing of personal data.
Where the controller is a group of entities, such controller may appoint a single Data Protection Officer who is easily accessible by each entity. Where a controller or a processor is a Public Authority, a single Data Protection
Officer may be designated for several such public authorities, taking into account their organizational structures.
A controller or processor shall publish the contact details of the Data Protection Officer and communicate such details to the Authority.
The responsibility of the Data Protection Officer shall be to–
advise the controller or processor and their employees on data processing requirements provided under this Act or any other written law;
ensure on behalf of the controller or processor that the provisions of this Act are complied with;
facilitate capacity building of staff involved in data processing operations;
provide advice on personal data protection impact assessments; and
co-operate and comply with all directives and instructions issued by the Authority on matters relating to data protection.
Part IV
Use of Personal Data to Disseminate Solicited Messages
Part V
Data Protection Authority
Part VI
Director-General and the Staff of the Authority
Part VII
Penalties
Part VIII
Fund of the Authority
Part IX
Miscellaneous
Part X