Personal Data Protection Act 2022 · As enacted · Part III · Controllers and Processors
24. Personal data protection impact assessments
Official English translation. Where it differs from the Sinhala or Tamil text, the Act itself says which text prevails.
Official translationFrom Department of Government Printing, unchanged
Where a Controller intends to carry out any processing which involves–
a systematic and extensive evaluation of personal data or special categories of personal data including profiling;
a systematic monitoring of publicly accessible areas or telecommunication networks; or
a processing activity as may be determined by way of rules taking into consideration the scope and associated risks of that processing, such controller shall, prior to such processing, carry out a personal data protection impact assessment in a form and manner as may be prescribed, to ascertain the impact of the intended processing on the obligations imposed on the controller under Part I of this Act and the rights of data subjects under Part II of this Act.
The personal data protection impact assessment shall contain such information and particulars including any measures and safeguards taken by the controller to mitigate any risk of harm caused to the data subject by the processing referred to in subsection (1).
The controller shall seek the assistance of the Data
Protection Officer, where designated, when carrying out a personal data protection impact assessment under subsection (1).
The controller shall conduct a fresh personal data protection impact assessment in accordance with this section whenever there is any change in the methodology, technology or process adopted in the processing for which a personal data protection impact assessment has already been carried out.
The controller shall submit to the Authority, the personal data protection impact assessment required under this section and, on written request made by the Authority, provide any other information, for the purpose of making an assessment on the compliance of the processing and in respect of any risks of harm associated with the protection of personal data of the data subject and of the related safeguards recommended by the Authority.
Part IV
Use of Personal Data to Disseminate Solicited Messages
Part V
Data Protection Authority
Part VI
Director-General and the Staff of the Authority
Part VII
Penalties
Part VIII
Fund of the Authority
Part IX
Miscellaneous
Part X