Personal Data Protection Act 2022 · As enacted · Part X · Interpretation
56. Interpretation
Official English translation. The Sinhala text prevails. Open the official Sinhala text, official PDF on documents.gov.lk
Official translationFrom Department of Government Printing, unchanged
In this Act, unless the context otherwise requires–
“anonymise” in relation to personal data means permanent removal of any personal identifiers from personal data to render any such personal data from being related to a identified or identifiable natural person;
“automated processing” means, processing that does not involve any manual processing;
“biometric data” means, personal data resulting from specific technical processing relating to the physical, physiological or behavioral characteristics of a natural person, which allow or confirm the unique identification of that natural person, including facial images, dactyloscopic data or iris related data;
“certifying bodies” means, the bodies local or foreign that provide certification services relating to the processing of personal data or qualifications of Data Protection Officers;
“child” means, a natural person who is below the age of sixteen years;
“consent” means, any freely given, specific, informed and unambiguous indication by way of a written declaration or an affirmative action signifying a data subject’s agreement to the processing of his personal data;
“controller” means, any natural or legal person, public authority, public corporation, non-governmental organization, agency or any other body or entity which alone or jointly with others determines the purposes and means of the processing of personal data;
“cross-border data flow ” means, the movement of personal data out of the territory of Sri Lanka for the purpose of processing personal data in a third country;
“dactyloscopic data” means, data relating to fingerprints;
“data concerning health” means, personal data related to the physical or psychological health of a natural person, which includes any information that indicates his health situation or status;
“Data Protection Authority” means, the Authority established under section 28 of this Act;
“Data Protection Officer” means, the person designated or appointed under section 20 of this Act;
“data subject” means, an identified or identifiable natural person, alive or deceased, to whom the personal data relates;
“identifiable natural person” is a natural person who can be identified, directly or indirectly, by reference to any personal data;
“encryption” means, the act of ciphering or altering data using mathematical algorithm to make such data unintelligible to unauthorized users;
“financial data” means, any alpha-numeric identifier or other personal data which can identify an account opened by a data subject, or card or payment instrument issued by a financial institution to a data subject or any personal data regarding the relationship between a financial institution and a data subject, financial status and credit history relating to such data subjects, including data relating to remuneration;
“genetic data” means, personal data relating to the genetic characteristics of a natural person which gives unique information about the physiology or the health of that natural person which results from an analysis of a biological sample or bodily fluid of that natural person;
“local authority” means, a Municipal Council,
Urban Council or a Pradeshiya Sabha and includes any authority created or established by or under any law to exercise, perform and discharge powers, duties and functions corresponding or similar to the powers, duties and functions exercised, performed or discharged by any such Council or Sabha;
“Minister” means, the Minister assigned the subject of data protection under Article 44 or 45 of the Constitution;
“personal data” means, any information that can identify a data subject directly or indirectly, by reference to–
an identifier such as a name, an identification number, financial data, location data or an online identifier; or
one or more factors specific to the physical, physiological, genetic, psychological, economic, cultural or social identity of that individual or natural person.
“personal data breach” means, any act or omission that results in accidental or unlawful destruction, loss, alteration, unauthorized disclosure of, or access to, personal data transmitted, stored or otherwise processed;
“personal data revealing racial or ethnic origin”
means, any personal data including photographs that may indicate or be related to the race or ethnicity of a natural person;
“prescribed” means, prescribed by regulations made under this Act;
“processing” means, any operation performed on personal data including but not limited to collection, storage, preservation, alteration, retrieval, disclosure, transmission, making available, erasure, destruction of, consultation, alignment, combination, or the carrying out of logical or arithmetical operations on personal data;
“processor” means, a natural or legal person, public authority or other entity established by or under any written law, which processes personal data on behalf of the controller;
for the avoidance of doubt, a processor shall be a separate entity or person from the controller and not a person subject to any hierarchical control of the controller and excludes processing that is done internally such as one department processing for another, or an employee processing data on behalf of their employer;
Illustration: Hospital A, employs a data scientist as an employee to manage its analysis of patient records. The Hospital has decided to store its patient records on a third-party local cloud platform hosted by
Company B. Hospital A is the controller, and the Company B is the processor where management of patient records are concerned.
The data scientist of the hospital is only an employee of the controller and not a processor.
“profiling” means, processing of personal data to evaluate, analyse or predict aspects concerning that data subject’s performance at work, economic situation, health, personal preferences, interests, credibility, behavior, habits, location or movements;
“pseudonymisation” means, the processing of personal data in such a manner that the personal data cannot be used to identify a data subject without the use of additional information and such additional information is kept separately and is subject to technical and organizational measures to ensure that the personal data is not attributed to a data subject;
“public authority” means, a Ministry, any
Department or Provincial Council, local authority, statutory body or any institution established by any written law, or a Ministry, any Department or other authority or institution established or created by a
Provincial Council;
“relevant regulatory or statutory body” means, the regulatory or statutory body established by or under any written law which regulates, authorizes or supervises the controller and includes a Ministry which carries out the supervisory functions for the purpose of sections 26, 27 and 38 of this Act;
“recipient” means, a natural or legal person to whom the personal data is disclosed, or a public Authority or any incorporated or unincorporated body to which the personal data is disclosed;
“special categories of personal data” means, the personal data revealing racial or ethnic origin, political opinions, religious or philosophical beliefs, the processing of genetic data, biometric data for the purpose of uniquely identifying a natural person, data concerning health or data concerning a natural person’s sex life or sexual orientation, personal data relating to offences, criminal proceedings and convictions, or personal data relating to a child;
“Sri Lanka” means, the territorial limits of Sri
Lanka as stipulated by Article 5 of the
Constitution and includes the territorial waters or air space of Sri Lanka, any ship or aircraft registered in Sri Lanka, any location within the premises of a Sri Lankan mission or the residence of the Head of such mission, diplomatic agent or any other member of such mission, situated outside Sri Lanka, or within any premises occupied on behalf of, or under the control of, the Government of Sri Lanka or any statutory body established in Sri Lanka and situated outside Sri Lanka;
“third country” means, a country prescribed under section 26 for the purpose of cross-border data flow;
“third party” means, a natural or legal person, public authority, agency or body other than the data subject, controller, processor and persons who are under the direct authority of the controller or processor, are authorized to process personal data;
“written” includes a document written manually or electronically.