Skip to content
As enacted
Contents

Part III · Controllers and Processors

21. Additional obligations of a controller

Official English translation. Where it differs from the Sinhala or Tamil text, the Act itself says which text prevails.

(1)

Where processing is to be carried out by a processor on behalf of a controller, the controller shall–

(a)

use only processors who ensure the provision of appropriate technical and organizational measures to give effect to the provisions of this Act and ensure the protection of rights of the data subjects under this Act; and

(b)

ensure that such processor is bound by a contract or provisions of any written law which sets out the subject-matter and duration of the processing, the nature and purpose of the processing, the type of personal data and categories of the data subjects and the obligations of the controller.

(2)

Where two or more controllers jointly determine the purposes and means of processing, such controllers shall be referred to as “joint controllers” who shall be jointly responsible for discharging the obligations stipulated under this Act.

Part IV

Use of Personal Data to Disseminate Solicited Messages

Part V

Data Protection Authority

Part VI

Director-General and the Staff of the Authority

Part VII

Penalties

Part VIII

Fund of the Authority

Part IX

Miscellaneous

Part X

Interpretation

Schedules