Employee Data Privacy Checklist: Protecting HR Records Under Sri Lankan Law

Employee Data Privacy Checklist: Protecting HR Records Under Sri Lankan Law

HR teams handle some of the most sensitive information in any organization — and protecting it requires more than a locked filing cabinet. This 10-step checklist helps Sri Lankan HR teams review how employee data is collected, stored, accessed, shared, and disposed of, with reference to the Personal Data Protection Act No. 9 of 2022.


A checklist for HR teams · data privacy & compliance

Protecting HR records under Sri Lankan law

HR holds some of the most sensitive information in any organization. Under the Personal Data Protection Act, protecting it takes more than a locked cabinet — here's the checklist for getting it right, end to end.

10 sections 10-point summary checklist ~9 min read

This is a practical checklist, not legal advice. PDPA requirements continue to evolve — confirm specifics against the current Act, amendments, and Data Protection Authority guidance.

The short version

0 of 10 checked

Employee Data Privacy Infographic01

Identify the employee data your HR team holds

You can't protect data you haven't mapped. Employee information is often scattered across HR platforms, payroll systems, email, spreadsheets, physical files, and external vendors — including data on applicants and former employees, not just current staff.

Mapping these data flows is what surfaces privacy risk in the first place. Document how information is collected, stored, processed, and deleted at every stage of the employee lifecycle.

02

Collect only what you actually need

More data isn't better HR — it's more risk. Every field on a form should have a clear business or legal justification. "It might be useful someday" is not a reason to collect something.

This principle — data minimization — matters most during recruitment, where background checks and application forms tend to accumulate more personal information than the role actually requires.

03

Tell employees how their data is used

Employees shouldn't have to guess what happens to their information. A clear privacy notice should cover what's collected, why, how it's used, where it's stored, who might receive it, and how long it's kept.

For Sri Lankan organizations, these notices should be checked against current PDPA requirements and any applicable DPA guidance.

04

Control access to HR records

Not everyone needs access to every HR record. Role-based access and least-privilege principles limit exposure to the people who genuinely need it for their job — nobody else.

Access reviews shouldn't be a one-time setup. Role changes, department moves, and offboarding all create opportunities for someone to keep access they no longer need.

05

Protect digital and physical records

Access control is one layer. HR also needs to think about how data is protected at rest and in transit — encryption, access controls, audit trails, and monitoring, scaled to how sensitive the information is.

Physical records need the same discipline: employee documents shouldn't sit on desks or in unlocked cabinets where the wrong person can see them.

06

Review third-party HR providers

Payroll providers, recruitment platforms, background-check services, benefits administrators, and cloud vendors all process employee data on your behalf — which means every one of them is a privacy risk you inherit.

Vendor contracts should spell out data-protection requirements explicitly, not assume they're implied. For Sri Lankan organizations, third-party processing and any cross-border transfers should be assessed against applicable PDPA requirements.

07

Establish data retention and disposal rules

Keeping employee data forever isn't caution — it's risk with no upside. HR needs defined retention periods, aligned with legal requirements, company policy, and actual business need, plus a secure way to dispose of data once it's no longer needed.

08

Prepare for a data privacy incident

Even strong controls don't prevent every incident — a lost device, a compromised account, an accidental disclosure. What separates a manageable incident from a damaging one is usually how prepared the response was, not whether the incident happened at all.

Sri Lanka's DPA is the relevant regulator here — consult the current PDPA, amendments, and DPA guidance when determining specific obligations after an incident.

09

Train HR teams and managers

Technology can't compensate for a team that doesn't understand how to handle sensitive information. Every person who touches personnel data — not just HR specialists — needs training, covering document handling, access permissions, phishing awareness, appropriate data sharing, and what to do when something looks wrong.

10

Audit your HR data practices regularly

A privacy policy that's published and forgotten stops protecting anyone. Regular audits catch what documentation alone misses: outdated records, excess access permissions, unsecured data, weak vendor controls, and the gap between what's written down and what actually happens.

Understanding the Sri Lankan data-protection framework

The Personal Data Protection Act, No. 9 of 2022 sets the rules for how personal data is processed in Sri Lanka, the rights of the people whose data is processed, and the role of the Data Protection Authority in overseeing compliance.

The framework has continued to evolve — the Personal Data Protection (Amendment) Act, No. 22 of 2025 changed provisions around when parts of the law take effect, and the DPA continues to issue guidance as implementation develops. That means an old privacy checklist can quietly go out of date. Compliance reviews should always check against the current version of the law and the latest DPA guidance, not assumptions from when a policy was first written.

Frequently asked questions

What employee information should HR protect?

Any personal or sensitive information collected or managed about employees and applicants — identification and contact details, payroll and financial records, health information, performance and disciplinary records, background-check results, and other employment-related data.

Does the Sri Lankan PDPA apply to employee data?

Employee information can fall within the scope of the PDPA when it qualifies as personal data and is processed within the Act's applicable scope. Organizations should assess their specific processing activities against the current Act, amendments, and DPA guidance rather than assuming all HR information is treated the same way.

How often should an organization review its HR data privacy practices?

There's no universal schedule. A practical approach is periodic review, plus a reassessment whenever there's a significant change — new systems, new vendors, changed business operations, or updated legal requirements.

Keeping HR data organized

Protecting employee data takes a mix of policy, process, people, and tooling. Centralizing HR information in a single system — rather than spreading it across spreadsheets and separate records — gives HR teams clearer visibility and more consistent handling. The goal isn't just storing information; it's building a system where employee data can be found when needed, handled consistently, and kept secure for the entire time someone is with the company.

Employee data privacy isn't a policy you publish once — it's a habit HR keeps for the life of every record.

Know what you hold, collect less of it, control access, vet vendors, set retention rules, prepare for incidents, and train the people who touch the data. For Sri Lankan companies, pair all of it with ongoing attention to the PDPA as it continues to evolve.

 

هل أنت مستعد لتحويل الموارد البشرية الخاصة بك؟

احجز عرضًا توضيحيًا مخصصًا واكتشف كيف يمكن لبرنامج Gallery HR تبسيط عمليات الموارد البشرية لديك.

احجز عرضًا توضيحيًا الوصول إلى قوائم مراجعة الموارد البشرية
انظر جميع المقالات في مدونة أفضل ممارسات الموارد البشرية - نصائح الخبراء من جاليري إتش آر

0 تعليقات

اترك تعليقا

يرجى ملاحظة أنه يجب الموافقة على التعليقات قبل نشرها.

Why 250+ teams chose Gallery HR

Built for the way SL teams actually work.

Modern HR. Local support. Live in 14 days — the platform 250+ growing teams already trust.

10+h Saved weekly
80% Less time on payroll
14d To go fully live
Clindata
E-Channelling
Access Engineering
Gestetner
LSC
zmessenger
Lanka AAC
Headmasters
JP
Connect BPO
Aweera
iPhonik
AIT
Plexus
Collective
Lihini Group
CIC
Lumizo
ODIRIS
Customer
Customer
Customer
Customer
Customer

“Gallery HR significantly streamlines our employee records, payroll, and benefits administration — freeing the HR team to focus on people, not paperwork.”

Dhananjaya De Silva · HR & Admin, E-Channelling PLC ★★★★★

★ Free demo

See Gallery HR running on your team's data — in 30 minutes.

A specialist will configure a demo around your team's structure, payroll setup, and policies. Honest answers, no sales theater — you decide if Gallery HR is the right fit.

No credit card. No commitment. 30 minutes.
  • Sri Lankan-based team
  • EPF / ETF / PAYE compliant
  • Live in 14 days
  • 4.9★ from 130+ reviews