World Watch/Sri Lanka/Data & Privacy

Data & Privacy · Sri Lanka

Data protection & privacy laws in Sri Lanka (2026)

Comprehensive lawPersonal Data Protection Act, No. 9 of 2022 (as amended by Act No. 22 of 2025); supervised by the Data Protection Authority of Sri Lanka (dpa.gov.lk)Country index 69 · B

Sri Lanka shaded by its data & privacy status

Sri Lanka enacted a comprehensive data protection law in March 2022 — the first in South Asia — modelled broadly on GDPR principles. Implementation has been phased: the Data Protection Authority (DPA) was established in mid-2023 and institutional provisions are active, but the core substantive obligations on data controllers and processors (Parts I–III and VII) were delayed from March 2025 by gazette and are now subject to ministerial commencement order following the Personal Data Protection (Amendment) Act No. 22 of 2025, with full enforcement expected in 2026.

Key points

Enactment & scope

The Personal Data Protection Act, No. 9 of 2022 was passed by Parliament on 19 March 2022 and certified by the Speaker. It applies to any person or entity that processes personal data of Sri Lankan data subjects, regardless of where the controller is located.

Supervisory authority

The Data Protection Authority of Sri Lanka (DPA) was constituted under Part V of the PDPA, which came into operation on 17 July 2023. Board members and Chairman are appointed by the President; the DPA is tasked with enforcement, guidelines, and promoting data protection. As of late 2025, recruitment of a Director General and senior management team was underway.

Phased commencement

Parts VI, VIII, IX, and X (DPA staffing, offences, miscellaneous) came into force on 1 December 2023 per Gazette No. 2366/08. Parts I–III (definitions, data subject rights, controller obligations) and Part VII (enforcement/penalties) were originally scheduled for 18 March 2025 but that date was revoked by Gazette No. 2427/34 on 14 March 2025. The 2025 Amendment Act now gives the Minister discretion to bring all remaining provisions into force by gazette order.

Core data subject rights

Once fully in force, the PDPA confers rights to access, rectification, erasure, restriction of processing, data portability, and objection to automated decision-making. Data subjects may seek remedies through the DPA or courts, and the 2025 Amendment strengthened procedures against algorithmic bias and discrimination.

Controller & processor obligations

The Act requires lawful basis for processing (including consent), purpose limitation, data minimisation, privacy notices, appointment of Data Protection Officers in prescribed circumstances, and data breach notification to the DPA. Sensitive personal data (health, biometrics, religion, etc.) attracts heightened obligations.

Cross-border data transfers

The PDPA restricts transfers of personal data to jurisdictions lacking adequate protection. The 2025 Amendment introduced flexibility by allowing organisations to choose between resident, sovereign, or public cloud infrastructure depending on the sensitivity and security classification of data, pending DPA regulations specifying adequate-protection criteria.

Sri Lanka - other topics

Last verified 5/24/2026 · Orientation, not legal advice - verify against the primary sources linked above. Explore the full world map →