Xapi, a governance platform focused on Data, API, and AI Governance, has introduced a new resource aimed at aiding Sri Lankan organisations in complying with the country’s Personal Data Protection Act (PDPA). The Xapi Personal Data Protection Compliance Playbook offers a practical guide designed to help businesses translate the legal requirements of the PDPA into structured, operational governance frameworks that are ready to demonstrate compliance.
The launch arrives as Sri Lankan entities prepare for the next critical stage of PDPA enforcement, with key provisions set to take effect in January 2027. The Playbook, which spans approximately 160 pages, is built around Xapi’s six-layer implementation framework and incorporates a four-level maturity model. This model enables organisations to evaluate their current compliance status, identify critical gaps, and prioritize remediation efforts.
Included in the Playbook are tools such as a case study focusing on a Sri Lankan enterprise, a leadership checklist, and a PDPA Gap and Readiness Audit, all designed to support practical implementation efforts. The aim is to move beyond theoretical understanding towards building robust, evidence-based governance practices.
Prabath Ariyarthana, CEO and Chief Architect of Xapi, emphasized the shift in challenges faced by organisations under the PDPA. He stated that while awareness of the law has increased, the greater difficulty lies in operationalising compliance. Ariyarthana noted that relying solely on policies or spreadsheets is insufficient, stressing the need for transparency over data handling and the controls applied.
“The Playbook helps make that transition from understanding the law to building evidence-ready governance in practice,” he said.
Shanaka Mendis, Head of Sales at Xapi, described the Playbook as a practical starting point for organisations aiming to navigate the complex requirements of the PDPA effectively. As the January 2027 deadline approaches, the resource is poised to become a key tool for Sri Lankan organisations seeking to align their data protection practices with statutory obligations.
