Data Protection in Sri Lanka

Security in Sri Lanka

The PDPA does not prescribe the specific technical measures or standards that ought to be implemented but requires the adoption of appropriate technical and organizational measures to ensure security that is commensurate to the risk of the processing activity.

Nonetheless, it provides insight into such technical and organizational measures by setting out that such measures include encryption, pseudonymization, anonymization or access controls. 

Moreover, the PDPA also requires processors of personal data to have in place such technical and organizational measures, and ensure that their personnel data are bound by contractual obligations of confidentiality and secrecy.

As regards to data security, the DPMP Guidelines, (which are in draft form as at date), have provided examples of measures that may be adopted in this regard including encrypting sensitive customer data such as payment information during online transactions, role-based access controls to limit data access based on job roles, using data centres with advanced security features like biometric access and surveillance, conducting regular security audits and vulnerability assessments, implementing regular data backup procedures to ensure data can be recovered in the event of a loss or disaster, providing ongoing training to employees on data security best practices and recognising phishing attempts or other cyber threats and developing and maintaining an incident response plan.

Continue reading

  • no results

Previous topic
Back to top