By The Pulseline News Desk
Sri Lanka’s public sector has been directed to step up protection of citizens’ personal information, with the Data Protection Authority (DPA) instructing ministries, departments and other public institutions to appoint dedicated data protection officers and establish formal programmes to manage personal data.
The directive reportedly comes through a new “Personal Data Protection Circular” issued by the DPA this month, setting out the legal framework and practical steps public institutions must take to comply with the Personal Data Protection Act (PDPA).
Ministry Secretaries and other administrative heads have been instructed to notify institutions under their purview and ensure immediate action is taken to meet the requirements of the law.
DPOs to become key privacy officials
Under the latest circular, every ministry and government department that processes personal data is required to appoint a Data Protection Officer (DPO).
The requirement has broad implications because the Act defines “processing” in expansive terms. It has covered virtually any activity involving personal information, from collecting and recording names, NIC numbers, addresses and salaries to storing, retrieving, analysing, using, sharing or disclosing such information.
It has also included transmitting data to another organisation, combining databases, correcting or changing information, restricting access, and ultimately deleting or destroying personal data.
This means that personal data protection is not limited to specialised databases or sensitive government records. Routine administrative activities across the public sector can fall within the scope of the law.
Other public bodies, including corporations and state-owned enterprises that are not automatically required to appoint a DPO, have also been told to assess whether the nature and volume of personal data they handle makes such an appointment necessary.
The DPA has further directed institutions to publish their DPO’s contact details on their official websites and provide the information to the Authority.
Institutions are also encouraged to give DPOs sufficient resources, authority and access to information to carry out their responsibilities effectively.
From data collection to data protection
A major component of the circular is the establishment of a Data Protection Management Programme (DPMP) within public institutions.
The programme is intended to create a structured system for identifying, managing and protecting personal information rather than treating data protection as an isolated administrative responsibility.
Public-sector “controllers” — the organisations that determine why and how personal information is collected and processed — are reportedly required to ensure that their activities comply with the fundamental principles of the PDPA.
These include lawfulness, purpose specification, purpose limitation, data accuracy, retention limitation, integrity, confidentiality and transparency.
In practical terms, institutions must be able to demonstrate why they are collecting personal information, how it is being used, whether it remains accurate, how long it is retained and who has access to it.
Cloud services also under scrutiny
The new requirements extend beyond information held directly on government computers and servers.
Where a public institution uses a foreign cloud service to store or process personal information, it must ensure that the data receives adequate protection when transferred outside Sri Lanka.
The requirement could become increasingly important as government institutions expand their use of cloud computing and external digital platforms.
The DPA has also placed responsibility on public institutions when selecting third-party “processors” — external organisations that handle personal data on behalf of a public-sector data controller.
Institutions must ensure that such processors have the necessary technical and organisational capacity to comply with the PDPA.
Six steps for public institutions
The circular has set out six initial areas of action for public institutions seeking to bring their operations into line with the data protection framework.
First, staff must be educated on the PDPA and their responsibilities relating to compliance.
Second, institutions must establish an internal structure for data protection. This could include appointing a DPO, identifying “privacy champions” or establishing a dedicated steering committee.
Third, institutions must document the personal data they hold, where it comes from, why it is retained, who it is shared with and the workflows through which it is processed.
The fourth step is to identify gaps between existing data practices and the requirements of the PDPA and develop a remediation plan to address those shortcomings.
Fifth, institutions are expected to formulate and implement policies covering areas such as data-subject rights, data retention, privacy notices, consent and staff training.
Finally, the circular calls for continuous maintenance of technical skills and awareness among staff to ensure compliance does not become a one-time exercise.
A major shift for the public sector
The new circular represents a significant shift in how public institutions are expected to handle information about citizens.
Government agencies routinely collect vast quantities of personal data, ranging from identification and contact details to employment, financial, health and social information. Much of this information is shared between institutions or processed through digital systems and third-party services.
The challenge now is to ensure that such data is not only collected for legitimate purposes but is also securely stored, accurately maintained, appropriately shared and eventually disposed of when it is no longer required.
The appointment of DPOs and introduction of formal management programmes are intended to place responsibility for these issues within the institutional structure.
For citizens, the effectiveness of the new framework will ultimately depend not merely on whether public institutions appoint officers, but on whether those officers are given sufficient authority and resources to monitor compliance and address weaknesses.
As Sri Lanka’s public services become increasingly digital, the protection of personal information is likely to become a central part of public-sector governance. The DPA’s latest circular signals that institutions will now be expected to treat personal data not simply as an administrative resource, but as information requiring clear legal and organisational safeguards.
Leave a comment