A checklist for HR teams · data privacy & compliance
Protecting HR records under Sri Lankan law
HR holds some of the most sensitive information in any organization. Under the Personal Data Protection Act, protecting it takes more than a locked cabinet — here's the checklist for getting it right, end to end.
10 sections 10-point summary checklist ~9 min read
*
This is a practical checklist, not legal advice. PDPA requirements continue to evolve — confirm specifics against the current Act, amendments, and Data Protection Authority guidance.
The short version
0 of 10 checked
01
Identify the employee data your HR team holds
You can't protect data you haven't mapped. Employee information is often scattered across HR platforms, payroll systems, email, spreadsheets, physical files, and external vendors — including data on applicants and former employees, not just current staff.
Mapping these data flows is what surfaces privacy risk in the first place. Document how information is collected, stored, processed, and deleted at every stage of the employee lifecycle.
02
Collect only what you actually need
More data isn't better HR — it's more risk. Every field on a form should have a clear business or legal justification. "It might be useful someday" is not a reason to collect something.
This principle — data minimization — matters most during recruitment, where background checks and application forms tend to accumulate more personal information than the role actually requires.
03
Tell employees how their data is used
Employees shouldn't have to guess what happens to their information. A clear privacy notice should cover what's collected, why, how it's used, where it's stored, who might receive it, and how long it's kept.
For Sri Lankan organizations, these notices should be checked against current PDPA requirements and any applicable DPA guidance.
04
Control access to HR records
Not everyone needs access to every HR record. Role-based access and least-privilege principles limit exposure to the people who genuinely need it for their job — nobody else.
Access reviews shouldn't be a one-time setup. Role changes, department moves, and offboarding all create opportunities for someone to keep access they no longer need.
05
Protect digital and physical records
Access control is one layer. HR also needs to think about how data is protected at rest and in transit — encryption, access controls, audit trails, and monitoring, scaled to how sensitive the information is.
Physical records need the same discipline: employee documents shouldn't sit on desks or in unlocked cabinets where the wrong person can see them.
06
Review third-party HR providers
Payroll providers, recruitment platforms, background-check services, benefits administrators, and cloud vendors all process employee data on your behalf — which means every one of them is a privacy risk you inherit.
Vendor contracts should spell out data-protection requirements explicitly, not assume they're implied. For Sri Lankan organizations, third-party processing and any cross-border transfers should be assessed against applicable PDPA requirements.
07
Establish data retention and disposal rules
Keeping employee data forever isn't caution — it's risk with no upside. HR needs defined retention periods, aligned with legal requirements, company policy, and actual business need, plus a secure way to dispose of data once it's no longer needed.
08
Prepare for a data privacy incident
Even strong controls don't prevent every incident — a lost device, a compromised account, an accidental disclosure. What separates a manageable incident from a damaging one is usually how prepared the response was, not whether the incident happened at all.
Sri Lanka's DPA is the relevant regulator here — consult the current PDPA, amendments, and DPA guidance when determining specific obligations after an incident.
09
Train HR teams and managers
Technology can't compensate for a team that doesn't understand how to handle sensitive information. Every person who touches personnel data — not just HR specialists — needs training, covering document handling, access permissions, phishing awareness, appropriate data sharing, and what to do when something looks wrong.
10
Audit your HR data practices regularly
A privacy policy that's published and forgotten stops protecting anyone. Regular audits catch what documentation alone misses: outdated records, excess access permissions, unsecured data, weak vendor controls, and the gap between what's written down and what actually happens.
Understanding the Sri Lankan data-protection framework
The Personal Data Protection Act, No. 9 of 2022 sets the rules for how personal data is processed in Sri Lanka, the rights of the people whose data is processed, and the role of the Data Protection Authority in overseeing compliance.
The framework has continued to evolve — the Personal Data Protection (Amendment) Act, No. 22 of 2025 changed provisions around when parts of the law take effect, and the DPA continues to issue guidance as implementation develops. That means an old privacy checklist can quietly go out of date. Compliance reviews should always check against the current version of the law and the latest DPA guidance, not assumptions from when a policy was first written.
Frequently asked questions
What employee information should HR protect?
Any personal or sensitive information collected or managed about employees and applicants — identification and contact details, payroll and financial records, health information, performance and disciplinary records, background-check results, and other employment-related data.
Does the Sri Lankan PDPA apply to employee data?
Employee information can fall within the scope of the PDPA when it qualifies as personal data and is processed within the Act's applicable scope. Organizations should assess their specific processing activities against the current Act, amendments, and DPA guidance rather than assuming all HR information is treated the same way.
How often should an organization review its HR data privacy practices?
There's no universal schedule. A practical approach is periodic review, plus a reassessment whenever there's a significant change — new systems, new vendors, changed business operations, or updated legal requirements.
Keeping HR data organized
Protecting employee data takes a mix of policy, process, people, and tooling. Centralizing HR information in a single system — rather than spreading it across spreadsheets and separate records — gives HR teams clearer visibility and more consistent handling. The goal isn't just storing information; it's building a system where employee data can be found when needed, handled consistently, and kept secure for the entire time someone is with the company.
Employee data privacy isn't a policy you publish once — it's a habit HR keeps for the life of every record.
Know what you hold, collect less of it, control access, vet vendors, set retention rules, prepare for incidents, and train the people who touch the data. For Sri Lankan companies, pair all of it with ongoing attention to the PDPA as it continues to evolve.
0 comments