නිල පරිවර්තනයවෙනස් නොකළ පාඨය, Department of Government Printing වෙතින්
(1)
Where a personal data protection impact assessment carried out under section 24 indicates that the processing is likely to result in a risk of harm to the rights of the data subjects guaranteed under this Act or any written law, a controller shall take such measures to mitigate such risk of harm, prior to any processing of personal data.
(2)
Where a Controller, despite having taken measures under subsection (1), is not able to mitigate such risks of harm to the data subject, such controller may consult the
Authority prior to such processing.
(3)
Upon such consultation, the Authority may issue written instructions to the controller requiring him to take additional measures to mitigate any risk of harm to the data subject or to cease such processing.
(4)
Where the controller consults the Authority under subsection (2), the controller shall provide additional information as may be requested by the Authority.
(5)
Where the controller fails to comply with the instructions of the Authority without any reasonable cause, such controller shall contravene the provisions of this Act.
(6)
For the avoidance of doubt it is declared that when processing of personal data referred to in items (b), (f), (g)
and (h) of Schedule II, such processing shall be considered to have provided such measures and appropriate safeguards to protect the rights of the data subjects required under
Schedule II.
(7)
Notwithstanding anything to the contrary in any other written law, whenever the controller engages in processing of personal data referred to in section 24(1) and where such processing is carried out by a controller in relation to national security, public order and public health, the controller shall consult the Authority.