Who and what the Act covers
The Act applies to the processing of personal data, meaning information relating to an identified or identifiable natural person, by a controller or processor that is established in Sri Lanka, or that is outside Sri Lanka but offers goods or services to, or monitors the behaviour of, data subjects in Sri Lanka. It covers public authorities as well as companies. Processing by an individual for purely personal or household purposes is excluded.
The Act draws heavily on the European General Data Protection Regulation, so GDPR guidance is a useful starting point, but the Sri Lankan text differs in detail, especially on consent, legitimate interests and the role of the regulator.
The obligations on controllers
Part II sets out the principles a controller must follow. Processing must be lawful, resting on one of the grounds in Schedule I such as consent, contract, legal obligation or legitimate interests, with stricter grounds in Schedule II for special categories such as health, biometric, genetic and criminal data and data about children. Data must be collected for a specified purpose and not used incompatibly, kept accurate, limited to what is necessary, retained no longer than needed and protected by appropriate security measures.
Controllers must be able to demonstrate compliance through a data protection management programme, carry out data protection impact assessments for high-risk processing, notify the Authority of personal data breaches and, where the Act or the Authority requires, appoint a data protection officer. Processors must act only on the controller's documented instructions and under a written contract.
Rights of data subjects
Part III gives individuals the right to be told how their data is used, to access it, to have it rectified or erased, to withdraw consent, to object to processing, and to request a review of automated decisions that significantly affect them. A controller must respond within the period set by the Act, normally twenty-one working days, and may refuse only on the grounds the Act allows. A data subject who is dissatisfied may complain to the Data Protection Authority.
Cross-border transfers
Personal data may be transferred outside Sri Lanka only where the destination has been designated as providing adequate protection, where the transfer is covered by an instrument approved by the Authority, or where another condition in the Act, such as the data subject's explicit consent or performance of a contract, is met. Public authorities face additional restrictions. The practical effect is that cloud services and offshore processors need contractual safeguards that satisfy the Act.
The Data Protection Authority and penalties
The Act establishes the Data Protection Authority of Sri Lanka, which issues rules and guidelines, receives complaints and breach notifications, conducts inquiries and issues directives. Failure to comply with a directive can lead to an administrative penalty of up to ten million rupees, with higher amounts for repeated non-compliance. Decisions can be appealed to the Court of Appeal. The Authority also maintains the register of designated adequate jurisdictions and the framework for data protection officers.
Commencement and what to do now
The Act was certified in March 2022. The provisions establishing the Authority came into operation first, and the obligations of controllers and processors in Parts I to IV were brought into force on 18 March 2025, after the transition period. Rules and guidelines from the Authority continue to be issued, so compliance programmes should be reviewed against the latest Gazette notifications.
A practical starting point is a data inventory: what personal data the organisation holds, where it came from, the lawful basis, who it is shared with and where it is stored. From there follow the privacy notice, the processor contracts, the retention schedule, the breach procedure and the impact assessments.
Researching data protection with Lex
Because the Act is new, the Authority's rules and determinations will shape its meaning over the next few years. Ask Lex "what is the time limit to respond to a data subject access request in Sri Lanka" or "which transfers are permitted under the PDPA" and open the section and any Gazette notifications cited. For how new Acts fit into the wider system, see our guide to the Sri Lankan legal system.
Questions and answers
What is the Personal Data Protection Act of Sri Lanka?
The Personal Data Protection Act No. 9 of 2022 is Sri Lanka's comprehensive data protection law. It regulates how organisations collect, use, store, share and transfer personal data, gives individuals rights over their data and creates the Data Protection Authority to enforce it. Its main obligations on controllers and processors came into force on 18 March 2025.
Who does the Personal Data Protection Act apply to?
It applies to any controller or processor established in Sri Lanka, including public authorities, and to organisations outside Sri Lanka that offer goods or services to, or monitor the behaviour of, data subjects in Sri Lanka. Purely personal or household processing by an individual is excluded.
What are the penalties under Sri Lanka's data protection law?
The Data Protection Authority can impose an administrative penalty of up to ten million rupees for failure to comply with a directive, and higher amounts for repeated failures. Decisions of the Authority can be appealed to the Court of Appeal.
Does Sri Lanka's PDPA require a data protection officer?
Yes, in the circumstances set out in the Act and the Authority's rules, which focus on public authorities and on organisations whose core activities involve large-scale or high-risk processing. Every controller must in any case maintain a data protection management programme and be able to demonstrate compliance.
This guide is general information, not legal advice. Last updated 6 October 2026.