Thursday Sep 03, 2026
Thursday, 3 September 2026 00:00 - - {{hitsCtrl.values.hits}}

Brandix Apparel Director Oshada Senanayake

D. L. & F. De Saram Consultant Counsel Shenuka Jayalath


The 2nd Data Privacy and Protection Summit 2026, organised by CICRA and the Daily FT, concluded recently at the Oak Room, Cinnamon Grand Colombo, drawing over 380 senior professionals from data protection, governance, compliance, and cybersecurity sectors. The landmark event, supported by Mastercard as Title Partner, Concentric AI as Strategic Partner (in partnership with Orin Corporation), People's Bank as Exclusive Banking Partner, and LankaPay as Silver Partner, provided a critical platform for understanding how AI enablement is transforming both the threat landscape and defensive capabilities.
The final session of the day, titled “Before the Breach: Why a Data Protection Impact Assessment (DPIA) Saves You from Disaster,” featured powerful addresses from Brandix Apparel Ltd., Director Oshada Senanayake, and D. L. & F. De Saram Consultant Counsel Shenuka Jayalath, followed by a dynamic panel discussion that brought together regulatory, legal, and industry perspectives.
Delivering the keynote address, Oshada Senanayake presented a practitioner's perspective on why DPIAs are not merely a regulatory checkbox but a strategic defence mechanism. “Before the breach is the only moment you get to choose your risks. After it, they choose you,” he warned the packed audience.
Senanayake began by underscoring the urgency of the moment. With the Personal Data Protection Act (PDPA), No. 9 of 2022 enacted in 2022, the Data Protection Authority established in 2023, and the Amendment Act No. 22 of 2025 restructuring the grace-period regime, “organisational runway is ending,” he stated. “Substantive obligations – controller duties, data subject rights, penalties – are becoming fully operational.”
He reminded the audience that the maximum administrative penalty per non-compliance stands at Rs. 10 million and it can double for repeat offences. “But the real cost of a breach, trust, remediation, litigation, dwarfs the fine. The law requires the assessment before processing begins, not after the breach.”
Oshada outlined the statutory triggers for a DPIA under Section 24 of the PDPA: systematic and extensive evaluation of personal data or special categories including profiling; systematic monitoring of publicly accessible areas or telecommunication networks; and further processing activities to be prescribed by rules. He noted that the draft DPIA Regulations add a risk matrix: probability × impact ≥ 10 makes a DPIA mandatory.
The draft Regulations prescribe a formal process: a prescribed form (Schedule I) covering purposes, data categories, volumes, recipients, cross-border transfers, retention, and safeguards; impact mapped against every controller obligation (Sections 5–12) and every data subject right (Sections 13–19); DPO assistance in conducting the assessment; and consultation with the Authority where residual risk cannot be mitigated.
Oshada then shared five practical realities drawn from his boardroom experience:
Reality 1: You cannot assess what you have not inventorised. He advocated for a tiered approach, Tier 1 systems (HR, payroll, customer, and claims) requiring DPIA first; Tier 2 requiring monitoring and scheduling; Tier 3 screening at next change; and Tier 4 requiring only registration. “Inventory every solution touching personal data – in-house, vendor, and the spreadsheets nobody admits to,” he urged. “Most failed programs trace back to inventories that were out of date before the ink dried.”
Reality 2: Don't wait for perfect guidance – borrow proven scaffolding. With the Data Protection Authority newly established and the DPIA Regulations still in draft, Senanayake advised organisations to design to the draft Schedule I form now. “Waiting is a decision and it is the wrong one, because processing is happening today,” he cautioned. He recommended leveraging global frameworks: the EDPB/WP248 nine criteria for judging “high risk,” the UK ICO’s practical DPIA template, CNIL’s free open-source PIA software, and ISO/IEC 29134.
Reality 3: Assemble the right room – a DPIA is a team sport. Oshada stressed that a DPIA requires the product/process owner, technical and data teams, cyber security, risk and control, legal/compliance, and the DPO from day one, not at the end. “If the DPIA is one officer filling a form alone, it is already a rubber stamp.”
Reality 4: In-house vs vendor-driven two different playbooks. For built-in-house systems, embed the DPIA into design and build gates (privacy by design). For vendor-driven systems, assess through due-diligence questionnaires, certifications, and audits and negotiate mitigations into contracts. “A DPIA is not just a defence document; it is negotiating leverage,” he said, citing the Dutch government’s DPIAs on Microsoft 365 that resulted in legal, technical, and product changes from one of the world’s largest vendors.
Reality 5: The bandwidth problem design around it. Oshada acknowledged that the best people are already consumed by BAU and digital transformation. His solution: screen first with a 15 minute threshold questionnaire at project intake; embed the DPIA as a stage-gate inside existing project and procurement workflows; reuse DPIAs ruthlessly rather than assessing the same cloud platform multiple times; and protect the DPO “the DPO orchestrates and challenges he business owns and writes.”
Oshada concluded with a seven-point playbook: inventorise and tier every system touching personal data; adopt one methodology now mapped to the draft Schedule I form; screen at every gate with a threshold questionnaire; assemble the right room; split the tracks for in-house and vendor-driven systems; keep the DPIA alive with reviews on material change; and escalate honestly , “Residual risk still high? Consult the Authority before processing, not after the breach.”
“A DPIA done on paper is a document. A DPIA done in practice is a defence,” he concluded.
Real-world case studies
Shenuka Jayalath delivered a compelling presentation titled “Assess, Don’t Guess,” reinforcing the proactive power of DPIAs through real-world case studies.
Shenuka defined a DPIA as a risk management procedure used by organisations to identify, evaluate, and mitigate privacy risks before launching new products, technologies, or projects that process personal data. “DPIAs help organisations avoid compliance issues and prevent harm to individuals by proactively addressing risks,” she explained. “They also demonstrate accountability to the Data Protection Authority and build trust with customers.”
She provided practical examples of when a DPIA is triggered: using AI to track customer behaviour and profile them for targeted ads; rolling out facial recognition; and hospitals handling thousands of patient health records. “If unsure whether a project requires a DPIA, err on the side of caution – perform at least a preliminary risk assessment,” she advised.
Shenuka then walked the audience through four cautionary tales from around the world:
Mercadona Supermarkets (Spain) The supermarket chain deployed facial recognition in 48 stores to identify individuals with restraining orders. The DPIA failed to assess proportionality to catch 10 banned people, they unlawfully captured the biometric data of hundreds of thousands of innocent shoppers, including children. Result: €2.5 million fine and forced dismantling of the entire system. “A proper DPIA would have caught this at the design stage, saving them millions.”
Clearview AI (Global) The company scraped billions of facial images from public platforms to create a massive biometric database, falsely assuming that because the original photos were “publicly available,” they did not need a DPIA. The UK ICO explicitly cited the failure to conduct a DPIA as a core statutory breach. Result: £7.5 million fine (UK ICO) and enforcement notices from French, Italian, and Dutch authorities. “Applying AI to extract biometric profiles creates entirely new, high-risk data processing that legally mandates an impact assessment.”
Deliveroo (Italy), The food delivery platform used an AI-driven algorithm to manage its workforce, systematically monitoring rider performance and assigning shifts. The Italian regulator fined Deliveroo €2.5 million, explicitly citing the complete failure to conduct a DPIA. The AI penalised riders for legitimate absences such as illness, indirectly processing health-related data without human oversight. “Without a DPIA, Deliveroo could not explain the logic of the AI system to its workers, violating transparency and fairness.”
The Meta Pixel Crisis, Major hospital networks in the US and UK installed Meta Pixel tracking code on patient portals without DPIAs. The code scraped patients' private medical conditions, appointment types, and doctors' names, sending it all to Meta for targeted advertising. “Hospitals that conducted a DPIA mapped the data flow, saw health data was going to Meta, and blocked the pixel before it went live. Those that skipped the DPIA faced multi-million dollar class-action settlements.”
Shenuka also highlighted another examples where DPIAs averted catastrophe:
UK NHS COVID-19 App, The UK Government initially planned a centralised model for contact tracing, where location logs and health status would be uploaded to a single government database. The DPIA revealed that a centralised database holding health and location data of an entire country would become the prime target for hackers and failed the “data minimisation” test. Result: The government scrapped the centralised approach entirely and pivoted to a decentralised model, saving the UK from what experts warned would have been the most dangerous health data vulnerability in British history.
Shenuka identified common mistakes: not collecting the information needed (business process details, technology, PII collected, data flows, security features, storage, retention, third-party access); failing to update the DPIA as a living document; and failure to consider all stakeholders, “Leaving the DPIA solely to the legal team or DPO ignores IT, cybersecurity, product, and data science teams who understand the technical reality.”
She outlined a 7-step DPIA process: Identify the need (does this trigger high-risk criteria?); Describe the processing (the data lifecycle); Consult stakeholders (DPO, IT, security, vendors); Assess necessity and proportionality (is there a less intrusive way?); Identify and assess risks (what if data is hacked, leaked, or altered?); Design mitigating measures (encryption, access controls, data minimisation); and Sign-off (document decisions, escalate if residual risk remains high).
“Proactive risk assessment prevents Rs. 10 million mistakes,” Shenuka concluded.
Following the addresses, a dynamic panel discussion brought together regulatory, legal, and industry experts. Moderated by Pyramid Wilmar Ltd., Group Head of Legal Thamali Tennakoon, the panel featured: Oshada Senanayake, Shenuka Jayalath; Former Securities and Exchange Commission Chairman and CA Sri Lanka Past President Ranel T. Wijesinha and Hatton National Bank PLC Data Protection Officer Shenalie Wijeyeratne.
Ranel T. Wijesinha brought a regulatory and governance perspective, drawing on his extensive experience at the SEC and CA Sri Lanka. He emphasised that data protection is fundamentally a governance issue that demands attention at the highest levels of corporate leadership. “Directors and boards cannot delegate data protection to IT alone – it is a strategic risk that requires board-level oversight,” he stressed. He noted that DPIAs serve as critical tools for directors to demonstrate they have exercised reasonable care in overseeing data processing activities, and that failure to conduct proper assessments could expose boards to liability under the PDPA’s penalty provisions.
Shenalie Wijeyeratne shared the practical realities of implementing DPIAs within a large financial institution. Drawing on her experience as DPO at HNB, she highlighted the challenges of identifying high-risk processing activities across a sprawling banking operation. “In a bank, personal data flows through countless systems, core banking, loan origination, credit scoring, fraud detection, and customer relationship management,” she explained. “The challenge is not just conducting the DPIA, but building the inventory and data mapping that makes it possible.” She emphasised that financial institutions must prioritise DPIAs for systems involving credit scoring and automated decision-making, as these carry heightened risks for customers.
Oshada Senanayake reinforced the importance of the tiered approach he had outlined in his keynote, noting that organisations must be realistic about their capacity to conduct DPIAs. “You cannot do everything at once. Tier your systems based on business criticality and personal-data exposure, and build a sequenced DPIA pipeline,” he advised. He also stressed that DPIAs must be embedded into existing project and procurement workflows rather than treated as standalone exercises.
Shenuka Jayalath addressed the legal dimensions, noting that the draft DPIA Regulations provide a useful framework but that organisations should not wait for finalisation. “The draft Schedule I form gives you a clear indication of what the Authority expects, purposes, data categories, volumes, recipients, cross-border transfers, retention, safeguards,” she said. “Design to that now, and you won’t have to rework when the Regulations are gazetted.”
The panel explored several key themes:
n Board accountability: Ranel stressed that DPIAs are not just operational tools but governance instruments. “When a breach occurs, the first question regulators ask is: ‘What did you know, and when did you know it?’ A properly conducted DPIA is the answer.”
The session concluded with a powerful consensus: DPIAs are not merely a regulatory requirement, they are a strategic defence that can save organisations from financial ruin, reputational damage, and regulatory penalties.
“Before the breach is the only moment you get to choose your risks. After it, they choose you,” Oshada reminded the audience.
With the PDPA enforcement date fast approaching, the message from the summit was clear: organisations must move beyond reactive compliance and embrace proactive risk assessment. “A DPIA done on paper is a document. A DPIA done in practice is a defence,” Oshada concluded.
Cinnamon Grand was the Hospitality Partner of The Data Protection and Privacy Summit and MullenLowe Sri Lanka was the Brand Communications Partner.