FB pixel

Sri Lanka building data minimization into digital ID to protect privacy

Sri Lanka building data minimization into digital ID to protect privacy
 

Purpose limitation and data minimization will be key safeguards for data protection in Sri Lanka as the island nation rolls out its first digital ID later this year. Officials highlight that the critical principles dictate that only the essential data necessary for specific services and lawful identity functions should be collected and utilized.

Controlled access and the principle of least privilege are implemented in the national digital ID (SL-UDI) through role-based access controls, separation of duties, and strong administrative measures to ensure that only authorized personnel can access sensitive information, Deputy Minister of Digital Economy Eranga Weeraratne told Biometric Update.

“Encryption and secure key management are vital, necessitating data to be encrypted both in transit and at rest, besides secure storage and strict life cycle control. Auditability and traceability are ensured through immutable audit logs maintenance that tracks access and transactions, with regular reviews to identify illegal access or unusual activities.”

He maintained that strong, integrated governance is crucial in this regard because it prevents external systems from gaining unrestricted access. “Instead, integrations are conducted via a secure Application Programming Interface (API) that compels scoped permissions, logging, and clear authorization rules for each service. Retention and disposal rules are formed to align data retention with legal obligations and operational needs, including secure deletion and archival policies.”

Weeraratne added that mechanisms for citizen rights and redress are in place, letting individuals seek corrections, file complaints, and obtain remedies In line with the Data Protection Act. “Periodic security testing provided by Independent assurance vulnerability assessments, and audits, which include independent evaluations of high-risk components and processes,” he added noting that incident preparedness is addressed with defined response procedures, breach containment and notification protocols, and ongoing monitoring to ensure readiness for potential incidents.

The country is also in the midst of setting up a Cybersecurity Regulatory Authority.

Sri Lanka is preparing a phased rollout of the SL-UDI, Weeraratne previously told Biometric Update.

Related Posts

Article Topics

 |   |   |   |   | 

Latest Biometrics News

 

ID4Africa vendors see Africa leapfrogging legacy digital identity systems

The annual ID4Africa AGM is a major world event in identity – a must-attend for many biometrics providers working on…

 

Gataca boosts age assurance pitch with certification to ISO standard by ACCS

Madrid-based Gataca is now certified as a provider of privacy-preserving age assurance following an independent assessment. The company successfully completed…

 

BixeLab testing activity highlights expansion of biometric assurance

As digital identity systems evolve, biometric testing labs are increasingly becoming central to trust, compliance and interoperability. BixeLab’s recent activity…

 

Apple removes Russian digital ID app Max from its stores citing sanctions

Apple has removed Russian state-backed messaging and digital ID platform Max from its official App Store, affecting more than 20…

 

G7 backs privacy-preserving age assurance as Japan proposes social media access limits

Japan is considering new restrictions on minors’ access to social media while stopping short of blanket age bans. While countries…

 

Digital company ID could save UK financial sector £1.7B: CFIT

A UK initiative to create a reusable digital identity credential for businesses could save financial institutions £1.7 billion (US$2.2 billion)…

Comments

Leave a Reply

This site uses Akismet to reduce spam. Learn how your comment data is processed.

Biometric Market Analysis and Buyer's Guides

DIGITAL ID for ALL NEWS

Featured Company

ID for ALL FEATURE REPORTS

BIOMETRICS WHITE PAPERS

BIOMETRICS EVENTS

EXPLAINING BIOMETRICS