Industry leaders sound alarm on data subject requests under PDPA

Monday, 31 August 2026 00:02 -     - {{hitsCtrl.values.hits}}

Digital Economy Ministry Secretary Waruna Sri Dhanapala 

Nestle Lanka Assistant Director and Head of Legal and Regulatory Keerthi Pathiraja

Consultant and Research Fellow, Technology, Media and Telecommunications Law and Policy Ashwini Natesan (centre) speaks at the panel discussion along with BDO Partners Deputy Managing Partner Ashen Jayasekera. It was moderated by Moderated by Colombo Stock Exchange Head of Enterprise Risk Management and Data Protection Officer Dinushan Godewitharana (right) 


 

 

  • Digital Economy Ministry Secretary Waruna Sri Dhanapala  announces 1 January 2027 as the operational date for key provisions of the PDPA
  • Identifies five critical challenges organisations must urgently address
  • Daily FT-CICRA 2nd Data Privacy and Protection Summit 2026 concludes with record participation

 

The 2nd Data Privacy and Protection Summit 2026, organised by the Daily FT and CICRA, concluded recently at the Oak Room, Cinnamon Grand Colombo, drawing over 380 senior professionals from data protection, governance, compliance, and cybersecurity sectors.

The landmark event, supported by Mastercard as Title Partner, Concentric AI as Strategic Partner (in partnership with Orin Corporation), People’s Bank as Exclusive Banking Partner, and LankaPay as Silver Partner, provided a critical platform for understanding how AI enablement is transforming both the threat landscape and defensive capabilities.

The Session Three : titled “Fulfilling Data Subject Requests – A Company’s Legal Obligation and Operational Challenges Under PDPA” featured powerful addresses from Digital Economy Ministry Secretary Waruna Sri Dhanapala, and Nestle Lanka Assistant Director and Head of Legal and Regulatory Keerthi Pathiraja, followed by a dynamic panel discussion that brought together legal, regulatory, and industry perspectives.

Delivering the keynote address, Waruna Sri Dhanapala laid out the core legal and operational challenges organisations face in fulfilling Data Subject Requests (DSRs) under Sri Lanka’s Personal Data Protection Act (PDPA), No. 9 of 2022.

“The PDPA gives citizens five withdrawal slips – and organisations one clock,” Waruna stated, referring to the statutory rights enshrined in Sections 13 to 18 of the Act: the Right of Access, Right to Withdraw Consent and Right to Object to Processing, Right to Rectification, Right to Erasure (the “Right to be Forgotten”), and Right to Review of Automated Decisions. “One month to grant the request – or refuse it in writing, with reasons. Extendable to two months for complex requests, on valid grounds.”

Dhanapala identified five critical challenges that organisations must urgently address:

1. Data silos and decentralised storage – Customer, employee, and vendor data is often scattered across fragmented departmental systems. “Locating all of an individual’s data across decentralised spreadsheets, shadow IT applications, and third-party tools within the statutory 30-day window is virtually impossible without automated discovery tools,” he warned.

2. Lack of centralised request protocols – Requests are often sent to generic email addresses or general customer service channels, lacking established identity verification processes. “Teams scramble to manually track these requests, struggle to authenticate the requester securely, and risk violating the law by missing the deadline – or, conversely, unlawfully disclosing data to the wrong person.”

3. The “IT-Only” misconception – Many organisations push PDPA compliance entirely onto IT or cybersecurity departments. “Because data is created and used across all business units, a lack of comprehensive organisation-wide training and policy enforcement leaves departments like Sales, Marketing, and HR highly vulnerable to processing breaches.”

4. Fragmented retention and deletion controls – Companies frequently hold onto inactive records indefinitely. “Fulfilling a data subject’s right to erasure requires identifying and completely destroying unstructured data – difficult if files are unorganised or duplicated across physical and digital formats.”

5. Consent management – The PDPA strictly mandates informed, voluntary, and unambiguous consent. “Organisations relying on outdated or implied consent models must completely restructure their privacy policies and consent forms, while also building a seamless system to handle data subject withdrawals.”

Dhanapala outlined key strategies for bridging the gap: implementing automated request channels with standardised intake forms, conducting comprehensive data mapping and inventory, establishing strict identity verification policies, and ensuring third-party vendor contracts include provisions to fulfil deletion and correction requests downstream.

In a significant announcement during his address, Waruna confirmed that the Government has decided to make 1 January 2027 as the operational date for key provisions of the PDPA, following Extraordinary Gazette No. 2498/16 issued by President Anura Kumara Dissanayake on 22 July 2026. From that date, Section 2 (Scope of application of the Act), Section 3 (Effect of the Act in relation to other written law), Part I (Processing of Personal Data – core requirements for lawful and transparent processing), and Part III (Controllers and Processors – including designation of Data Protection Officers, personal data breach notifications, Data Protection Impact Assessments, controller-processor obligations, and cross-border processing) will come into operation. These provisions collectively form the core compliance framework under the Act for in-scope controllers and processors.

Waruna noted that while the enforcement of data subject rights under Part II and administrative penalties under Part VII have been deferred, organisations now have a legally binding obligation to establish their privacy compliance frameworks without delay. “The Data Protection Authority will still wield considerable influence, including conducting compliance evaluations, issuing course corrections, and executing compensation directives,” he cautioned, urging organisations to utilise the remaining transition period to review their governance, policies, operational processes, contracts, and technical measures.

Urgency of PDPA compliance

Keerthi Pathiraja delivered a compelling presentation titled “The Withdrawals Are About to Begin,” drawing powerful analogies to drive home the urgency of PDPA compliance.

“Every deposit carries a silent promise,” Pathiraja began, comparing data collection to a bank deposit. “For years, these were deposits with no counter to return to. Data protection law has changed that every citizen now holds a withdrawal slip: ‘Show me.’ ‘Correct it.’ ‘Delete it.’ ‘I withdraw my consent.’ One month to honour it, or refuse it with valid reasons. Not a courtesy window, a statutory one.”

Keerthi warned organisations to honestly answer three uncomfortable questions:

“If a withdrawal slip landed in your organisation this morning an email saying ‘show me everything’ how do you handle it?”

“Could you locate every copy of one person’s data, the HR file, the CRM, the email archive, the spreadsheet on a manager’s laptop, the CCTV server, your payroll vendor’s cloud within one month?”

“If the Data Protection Authority asked you, two years from now, to prove exactly how you handled that withdrawal, how do you show it?”

Drawing on international case studies, Pathiraja referenced the Facebook/Max Schrems case, where a law student’s simple data request yielded 1,220 pages of personal data including deleted messages and withdrawn requests that Facebook itself had never properly counted. He also cited the Imran Rajah/Uber case, where a driver was “robo-fired” by an algorithm and had to fight through the courts to access the data and logic that dismissed him.

“A data subject request is not correspondence. It is the exercise of a statutory right,”  Pathiraja emphasised. “The law gives them a right. It gives you a clock.”

R.E.A.D.Y. Playbook, five actionable moves for organisations

Pathiraja introduced the R.E.A.D.Y. Playbook, five actionable moves for organisations:

R – Rails before requests: Build a single intake point, define what constitutes a request, start the clock immediately. “A request is a request whether it arrives by email or by letter. The clock starts when the request lands, not when Legal or the DPO finds out.”

E – Empower the DPO: Give the Data Protection Officer real cross-functional authority. “A deadline without an owner is a breach with a start date.”

A – Audit and map your data: Create a Record of Processing Activities (RoPA). “You can only honour what you can find.”

D – Deputise your processors: Ensure every data processor contract includes DSR assistance provisions. “Your statutory clock does not stop at your vendor’s door.”

Y – Your people, your proof: Train every employee – from receptionists to branch clerks – to recognise a withdrawal slip. Record everything. “A right you can’t prove you honoured is a right you never honoured.”

Pathiraja concluded with a stark warning: “The deposits have already been made of years of customer records, CVs, loyalty signups, and CCTV frames, from people who trusted you to hold a piece of themselves. The counter is built. The slips are printed. The clock is wound and waiting. And when it rings, your organisation will not rise to the level of its good intentions, it will fall to the level of its plumbing.”

Following the addresses, a dynamic panel discussion brought together legal and industry experts. Moderated by Colombo Stock Exchange Head of Enterprise Risk Management and Data Protection Officer Dinushan Godewitharana, the panel featured: Waruna Sri Dhanapala, Keerthi Pathiraja, Consultant and Research Fellow, Technology, Media and Telecommunications Law and Policy Ashwini Natesan and BDO Partners Deputy Managing Partner Ashen Jayasekera.

Legal and policy perspectives 

Ashwini Natesan brought a legal and policy perspective, translating regulatory frameworks into real-world organisational applications. She emphasised the importance of grounding AI development in strong data governance, noting that the legal and governance challenges emerging alongside AI deployment require careful attention, particularly around the use of personal data.

Ashen Jayasekera drew on his extensive experience in internal audit, cybersecurity, fraud investigations, corporate governance, and risk management. He stressed the need for organisations to build defensible data action frameworks – translating privacy obligations into practical, verifiable compliance measures.

The panel explored the practical challenges of implementing DSR processes ahead of the 1 January 2027 PDPA enforcement date. Key discussion points included:

Data mapping and discovery: The panel agreed that automated discovery tools are essential for locating personal data across siloed systems. Without a comprehensive data inventory, organisations cannot hope to meet the one-month statutory deadline.

Identity verification: Panellists emphasised that secure identity verification is critical to prevent unauthorised data disclosure, a risk that carries severe regulatory penalties.

Third-party vendor management: The panel highlighted that organisations must ensure their data processors are contractually obligated to assist with DSRs within the statutory timeframe. “Your statutory clock does not stop at your vendor’s door,” Pathiraja reiterated.

Audit trails and proof of compliance: The Data Protection Authority requires verifiable proof of compliance. Manual tracking of requests leads to missed deadlines and a higher risk of regulatory penalties.

Board-level accountability: The panel stressed that data protection must be treated as a strategic priority, not just an IT function. The tone must be set from the top – by Boards of Directors, Chairpersons, and CEOs.

Consent withdrawal cascades: When a user withdraws consent, organisations often lack automated protocols to push that “opt-out” status to third-party processors, affiliate systems, and marketing lists a gap that must be urgently addressed.

The session concluded with a powerful consensus: fulfilling Data Subject Requests is not merely a compliance exercise; it is a fundamental obligation that speaks to the trust citizens place in organisations holding their personal data.

“The withdrawals are about to begin,” Pathiraja warned. “Build your counter now, while nobody is standing at it.”

With the PDPA enforcement date fast approaching, the message from the summit was clear: organisations must move beyond good intentions and build the operational plumbing necessary to honour data subject rights or face the consequences of regulatory penalties, reputational damage, and eroded public trust.

Cinnamon Grand was the Hospitality Partner of the 2nd Data Privacy and Protection Summit 2026 and MullenLowe Sri Lanka was the Brand Communications Partner.

- Pix by Upul Abyasekara and Ruwan Walpola

COMMENTS