Skip to content
As enacted
Contents

Part III · Controllers and Processors

24. Personal data protection impact assessments

Official English translation. Where it differs from the Sinhala or Tamil text, the Act itself says which text prevails.

(1)

Where a Controller intends to carry out any processing which involves–

(a)

a systematic and extensive evaluation of personal data or special categories of personal data including profiling;

(b)

a systematic monitoring of publicly accessible areas or telecommunication networks; or

(c)

a processing activity as may be determined by way of rules taking into consideration the scope and associated risks of that processing, such controller shall, prior to such processing, carry out a personal data protection impact assessment in a form and manner as may be prescribed, to ascertain the impact of the intended processing on the obligations imposed on the controller under Part I of this Act and the rights of data subjects under Part II of this Act.

(2)

The personal data protection impact assessment shall contain such information and particulars including any measures and safeguards taken by the controller to mitigate any risk of harm caused to the data subject by the processing referred to in subsection (1).

(3)

The controller shall seek the assistance of the Data

Protection Officer, where designated, when carrying out a personal data protection impact assessment under subsection (1).

(4)

The controller shall conduct a fresh personal data protection impact assessment in accordance with this section whenever there is any change in the methodology, technology or process adopted in the processing for which a personal data protection impact assessment has already been carried out.

(5)

The controller shall submit to the Authority, the personal data protection impact assessment required under this section and, on written request made by the Authority, provide any other information, for the purpose of making an assessment on the compliance of the processing and in respect of any risks of harm associated with the protection of personal data of the data subject and of the related safeguards recommended by the Authority.

Part IV

Use of Personal Data to Disseminate Solicited Messages

Part V

Data Protection Authority

Part VI

Director-General and the Staff of the Authority

Part VII

Penalties

Part VIII

Fund of the Authority

Part IX

Miscellaneous

Part X

Interpretation

Schedules