Skip to content
As enacted
Contents

Part III · Controllers and Processors

20. Designation or appointment of the Data Protection Officer

Official English translation. Where it differs from the Sinhala or Tamil text, the Act itself says which text prevails.

(1)

Every controller and processor shall designate or appoint a Data Protection Officer, to ensure compliance with the provisions of this Act, in the following circumstances:–

(a)

where the processing is carried out by a ministry, government department or public corporation, except for judiciary acting in their judicial capacity;

or

(b)

where the core activities of processing carried out by the controller or processor consist of the following:–

(i)

operations which, by virtue of their nature, their scope or their purposes, require regular and systematic monitoring of data subjects on a scale and magnitude as may be prescribed; or

(ii)

processing of special categories of personal data on a scale and magnitude as may be prescribed; or

(iii)

processing which results in a risk of harm affecting the rights of the data subjects protected under this Act based on the nature of processing and its impact on data subjects.

(2)

A Data Protection Officer shall possess relevant academic and professional qualifications as may be prescribed which may include academic background, knowledge and technical skills in matters relating to data protection having competency and capacity to implement strategies and mechanisms to respond to inquiries and incidents related to processing of personal data.

(3)

Where the controller is a group of entities, such controller may appoint a single Data Protection Officer who is easily accessible by each entity. Where a controller or a processor is a Public Authority, a single Data Protection

Officer may be designated for several such public authorities, taking into account their organizational structures.

(4)

A controller or processor shall publish the contact details of the Data Protection Officer and communicate such details to the Authority.

(5)

The responsibility of the Data Protection Officer shall be to–

(a)

advise the controller or processor and their employees on data processing requirements provided under this Act or any other written law;

(b)

ensure on behalf of the controller or processor that the provisions of this Act are complied with;

(c)

facilitate capacity building of staff involved in data processing operations;

(d)

provide advice on personal data protection impact assessments; and

(e)

co-operate and comply with all directives and instructions issued by the Authority on matters relating to data protection.

Part IV

Use of Personal Data to Disseminate Solicited Messages

Part V

Data Protection Authority

Part VI

Director-General and the Staff of the Authority

Part VII

Penalties

Part VIII

Fund of the Authority

Part IX

Miscellaneous

Part X

Interpretation

Schedules