Personal Data Protection Act 2022 · As enacted · Part III · Controllers and Processors
22. Additional obligations of the processors
Official English translation. Where it differs from the Sinhala or Tamil text, the Act itself says which text prevails.
Official translationFrom Department of Government Printing, unchanged
Where a processor is engaged in processing activities on behalf of the controller, the processor shall–
ensure that processing activities are carried out only on the written instructions of the controller;
ensure that its personnel are bound by contractual obligations on confidentiality and secrecy by the implementation of appropriate technical and organizational measures;
facilitate the controller to carry out compliance audits, including inspections upon the written request of the controller, taking into account the nature of processing and the information available to the processor; and
upon the written instructions of the controller, erase existing copies of personal data or return all personal data to the controller after the completion of the provisions of services relating to processing.
Where a processor fails to comply with the provisions of paragraph (a) of subsection (1) or determines the purposes and means of processing by itself, such processor shall, for the purposes of this Act be deemed to be a controller, in respect of such processing.
Where a processor engages another processor
(hereinafter referred to as the “sub processor”) for carrying out specific processing activities, the provisions of this section shall apply to and in relation to such sub processor.
Where a sub processor fails to fulfil its obligations under subsection (3), the processor shall be liable to the controller for the performance or carrying out of the obligations of such sub processor.
For the purposes of this section “personnel” means any employee, consultant, agent, affiliate or any person who is contracted by the processor to process personal data.
Part IV
Use of Personal Data to Disseminate Solicited Messages
Part V
Data Protection Authority
Part VI
Director-General and the Staff of the Authority
Part VII
Penalties
Part VIII
Fund of the Authority
Part IX
Miscellaneous
Part X