Skip to content
As enacted
Contents

Part III · Controllers and Processors

25. Measures to mitigate risks of harm and the requirement for prior consultation

Official English translation. Where it differs from the Sinhala or Tamil text, the Act itself says which text prevails.

(1)

Where a personal data protection impact assessment carried out under section 24 indicates that the processing is likely to result in a risk of harm to the rights of the data subjects guaranteed under this Act or any written law, a controller shall take such measures to mitigate such risk of harm, prior to any processing of personal data.

(2)

Where a Controller, despite having taken measures under subsection (1), is not able to mitigate such risks of harm to the data subject, such controller may consult the

Authority prior to such processing.

(3)

Upon such consultation, the Authority may issue written instructions to the controller requiring him to take additional measures to mitigate any risk of harm to the data subject or to cease such processing.

(4)

Where the controller consults the Authority under subsection (2), the controller shall provide additional information as may be requested by the Authority.

(5)

Where the controller fails to comply with the instructions of the Authority without any reasonable cause, such controller shall contravene the provisions of this Act.

(6)

For the avoidance of doubt it is declared that when processing of personal data referred to in items (b), (f), (g)

and (h) of Schedule II, such processing shall be considered to have provided such measures and appropriate safeguards to protect the rights of the data subjects required under

Schedule II.

(7)

Notwithstanding anything to the contrary in any other written law, whenever the controller engages in processing of personal data referred to in section 24(1) and where such processing is carried out by a controller in relation to national security, public order and public health, the controller shall consult the Authority.

Part IV

Use of Personal Data to Disseminate Solicited Messages

Part V

Data Protection Authority

Part VI

Director-General and the Staff of the Authority

Part VII

Penalties

Part VIII

Fund of the Authority

Part IX

Miscellaneous

Part X

Interpretation

Schedules