Personal Data Protection Act 2022 · As enacted · Part V · Data Protection Authority
33. Duties and functions of the Authority
Official English translation. Where it differs from the Sinhala or Tamil text, the Act itself says which text prevails.
Official translationFrom Department of Government Printing, unchanged
For the purpose of carrying out its objects, the
Authority shall, perform and discharge all or any of the following duties and functions:–
direct controllers to comply with the provisions of sections 11 and 13 in accordance with the information set out in Schedule V hereto;
monitor and examine all data processing operations to ensure the due compliance by controllers or processors, of the obligations imposed on such controllers or processors under this Act, either of its own motion or at the request of a data subject;
issue directives to any specific controller or processor regarding any processing activity performed by such controller or processor;
facilitate or undertake training, based on international best practices, for controllers and processors to ensure the effective implementation of the provisions of this Act;
issue directives to ensure effective implementation of data protection management programmes by the controllers;
promote transparency and self-regulation among controllers and processors;
ensure domestic compliance of data protection obligations under international conventions;
recommend to the Government on all matters relating to data protection;
represent the Government internationally on matters relating to data protection with the approval of the Minister;
promote studies and educational activities relating to data protection, including organising and conducting seminars, workshops and symposia relating thereto, and supporting other organisations conducting such activities;
manage technical co-operation and exchange in the area of data protection with other organisations, including foreign data protection authorities and international or inter-governmental organisations, on its own behalf or on behalf of the government;
carry out functions conferred on the Authority under any other written law;
undertake research into the use and impact of new technologies on processing of personal data;
make rules governing the sharing of personal data between controllers which are public authorities, in accordance with the provisions of this Act, where such data can be shared between the controllers via a secure interoperability platform, including setting in place criteria mandating the sharing of personal data between controllers thereby restricting the duplication of collection and storage of data already available with another controller;
appoint advisory committees to formulate sectoral guidelines, rules and to identify criteria and define categories of processing by controllers or processors requiring a licence for the purpose of regulating identity management and related services provided to data subjects under any written law;
make rules in relation to the use of special categories of personal data, the use of personal data for the dissemination of solicited messages, in complience with section 27, the use of personal data for profiling of individuals, the use of personal data for automated decision making; and
perform such other acts not inconsistent with the provisions of this Act or any other written law, as are necessary for the promotion of the objects of the Authority under this Act.
Part VI
Director-General and the Staff of the Authority
Part VII
Penalties
Part VIII
Fund of the Authority
Part IX
Miscellaneous
Part X