EnglishSI
Sri Lanka flag

Sri Lanka

Sri Lanka Data Privacy Laws: PDPA No. 9 of 2022 Complete Guide (2026)

By Recording Law Editorial TeamReviewed May 20, 202623 min read
Sri Lanka Data Privacy Laws: PDPA No. 9 of 2022 Complete Guide (2026)

Frequently Asked Questions

Is Sri Lanka's PDPA currently enforceable?

No, not in full. The parts of the PDPA that establish the Data Protection Authority and govern its administrative operations have been in force since 2023. The substantive provisions covering data subject rights, controller and processor obligations, and enforcement penalties are not yet in force. The Personal Data Protection (Amendment) Act No. 22 of 2025, enacted in October 2025, removed all fixed commencement dates and granted the Minister discretion to set the operative date by gazette order. No such order has been issued as of May 2026. Full enforcement is expected once the DPA completes its guideline development and rollout planning under newly appointed Director General Dimuth Atapattu.

Does Sri Lanka's constitution protect privacy?

Not explicitly. Sri Lanka's 1978 Constitution does not contain an express right to privacy in its fundamental rights chapter. The 2015 constitutional amendment introduced Article 14A, which protects the right of access to information held by public authorities. Article 14A acknowledges privacy only as a potential restriction on that access right, not as a standalone fundamental right. Sri Lankan courts have recognized limited privacy protections through common law, primarily in the context of residential privacy, using the actio iniuriarum doctrine. The PDPA provides the main statutory framework for personal data protection.

Does the Sri Lanka PDPA apply to companies outside Sri Lanka?

Yes. The PDPA has extraterritorial reach. It applies to any controller or processor outside Sri Lanka that offers goods or services to individuals located in Sri Lanka, or that monitors the behavior of data subjects in Sri Lanka. Foreign companies with Sri Lankan customers or users must comply with the PDPA regardless of where they are headquartered.

What are the penalties for violating the PDPA?

Once the enforcement provisions of Part VII come into force, organizations that fail to comply with directives issued by the Data Protection Authority face fines of up to 10 million Sri Lankan rupees (approximately USD 30,000) per instance of non-compliance. For repeat violations, the penalty doubles with each subsequent instance. The DPA can also issue binding compliance directives requiring changes to data processing practices or cessation of unlawful processing activities.

How does the Sri Lanka PDPA compare to the GDPR?

The PDPA is closely modeled on the GDPR and shares its core architecture: consent and other lawful bases for processing, data subject rights (access, rectification, erasure, object to processing, object to automated decision-making), breach notification within 72 hours, Data Protection Impact Assessments, and Data Protection Officer requirements. Key differences include the PDPA's fixed monetary penalty caps rather than revenue-based fines, the 21 working day response period for subject access requests versus the GDPR's one calendar month, and the ongoing phased implementation approach. The 2025 Amendment Act added cloud computing flexibility and AI governance provisions.

What changed under the Personal Data Protection (Amendment) Act No. 22 of 2025?

The 2025 Amendment Act, enacted on October 21, 2025, made several significant changes. Most importantly, it removed all fixed statutory commencement dates for the remaining parts of the PDPA and replaced them with ministerial discretion to set enforcement dates by gazette order. It also introduced cloud computing flexibility allowing organizations to choose between resident, sovereign, or public cloud options based on data sensitivity. It clarified AI and automated decision-making protections, expanded the DPA's authority to issue sector-specific guidelines, and amended Section 26 to require binding instruments for cross-border data transfers.

Who is required to appoint a Data Protection Officer under the PDPA?

The PDPA requires controllers and processors to appoint a DPO when their core activities consist of regular and systematic monitoring of data subjects on a large scale, or large-scale processing of sensitive personal data. Groups of related entities can appoint a shared DPO who is easily accessible to each entity, and multiple public authorities can designate a single DPO. The DPA has published draft regulatory guidance on DPO qualifications and appointment procedures. Organizations not legally required to appoint a DPO are encouraged to do so as a compliance best practice.

Updates

Comprehensive refresh: updated enforcement timeline to reflect Amendment Act No. 22 of 2025 (October 2025), which removed fixed commencement dates and granted the Minister discretion to set the operative date by gazette; noted Dimuth Atapattu appointed first permanent DG of the DPA effective March 2026; corrected constitutional privacy context; expanded coverage of sector-specific laws, cloud and AI provisions, and compliance steps.

Initial publication: overview of PDPA No. 9 of 2022, phased commencement, DPA establishment, data subject rights, controller obligations, breach notification, cross-border transfers, and penalties.

Sources and References

  1. Personal Data Protection Act, No. 9 of 2022 -- Full Text(parliament.lk).gov
  2. Data Protection Authority of Sri Lanka -- Official Website(dpa.gov.lk).gov
  3. Data Protection Authority -- Background and Phased Implementation Dates(dpa.gov.lk).gov
  4. DPA Draft Regulations on Data Protection Officer Appointment(dpa.gov.lk).gov
  5. Personal Data Protection (Amendment) Act No. 22 of 2025 -- Parliament of Sri Lanka(parliament.lk).gov
  6. Ministry of Digital Economy -- Data Protection Authority Profile(mode.gov.lk).gov
  7. ICTA -- Data Protection Legislation Overview(icta.lk).gov
  8. Financial Consumer Protection Regulations No. 1 of 2023 -- Central Bank of Sri Lanka(cbsl.gov.lk).gov
  9. Dimuth Atapattu Appointed Director General of Data Protection Authority(newswire.lk)
  10. New Enforcement Date for PDPA Expected by April 2026 -- The Morning(themorning.lk)
  11. Sri Lanka PDPA Amendments November 2025 -- Biometric Update(biometricupdate.com)
  12. DLA Piper -- Data Protection Laws in Sri Lanka(dlapiperdataprotection.com)
  13. Wikipedia -- Personal Data Protection Act (Sri Lanka)(en.wikipedia.org)
  14. Financial Consumer Protection Regulations No. 1 of 2023 -- Central Bank of Sri Lanka(cbsl.gov.lk).gov
Share: