Data Protection in Transition: Understanding Sri Lanka’s New Legal Framework
INSIGHTS 05/09/26

Data Protection in Transition: Understanding Sri Lanka’s New Legal Framework

Sri Lanka’s data protection regime is entering a significant new phase with the commencement of key provisions of the Personal Data Protection Act on 1st January 2027. The new framework will impose substantive obligations on organisations that collect, use, store or otherwise process personal data, making effective governance, security, accountability and compliance measures increasingly important for businesses.

The Personal Data Protection Act, No. 9 of 2022 (PDPA) enacted on 19th March 2022 establishes a comprehensive legal framework governing the processing of personal data by public and private sector organisations and provides for the establishment of the Data Protection Authority (DPA) as the principal regulatory authority. 

The PDPA establishes rights for data subjects, obligations for data controllers and processors, and mechanisms for enforcement. The PDPA’s implementation has taken place on a staggered basis, with the PDPA (Amendment) Act, No. 22 of 2025 further amending section 1 to provide that the remaining provisions will come into operation on dates appointed by the Minister through Gazette Orders, thereby introducing a phased commencement framework.

Against this background, Extraordinary Gazette No. 2498/16 dated 22nd July 2026 is particularly significant. The Gazette  provides for 1st January 2027 as the date on which sections 2 and 3 and Parts I and III of the PDPA will come into operation. The commencement of these provisions represents an important development for organisations that determine the purposes and means of processing personal data, commonly referred to as controllers, and organisations that process personal data on behalf of controllers, referred to as processors.

Controllers and Processors

Under the PDPA, controllers are any natural or legal person, public authority, public corporation, NGO, agency or any other body or entity which alone or jointly determine the purposes and means of processing personal data. Processors, on the other hand, process personal data on behalf of and according to the instructions of a controller. 

From 1st January 2027, controllers and processors will be subject to substantive obligations under the provisions being brought into operation. These obligations include the following:

I. Lawful and Purpose-Limited Processing

Controllers must have a lawful basis for processing personal data and must process personal data only for specified, explicit and legitimate purposes. Organisations should therefore be able to demonstrate why personal data is being collected and the legal basis upon which the processing is undertaken.

This is particularly important where organisations routinely collect information that is unnecessary for the service being provided, retain personal data indefinitely, or subsequently use information for purposes that were not originally communicated to the data subject.

II. Data Minimisation, Accuracy and Retention

Personal data should be adequate, relevant and proportionate to the purpose for which it is processed. Organisations should therefore avoid collecting excessive information merely because it may be useful at some future point.

Controllers must also take appropriate steps to ensure that personal data is accurate and kept up to date where necessary. Personal data should not be retained for longer than is necessary for the purpose for which it is processed.

Organisations should consequently establish clear retention policies and determine when information should be securely deleted, anonymised or otherwise disposed of.

III. Security and Confidentiality

Controllers and processors must take appropriate measures to protect personal data against unauthorised or unlawful processing and against accidental loss, destruction, damage or other security risks.

Depending on the nature and sensitivity of the information and the risks involved, appropriate safeguards may include access controls, encryption, pseudonymisation, anonymisation and other technical and organisational measures.

Accordingly, organisations should understand what personal data they possess, why they possess it, who has access to it, where it is stored, how long it is retained and whether the purpose for which it was originally collected remains valid.

IV. Data Protection Management Programme

Controllers will also be required to establish internal controls and procedures constituting a Data Protection Management Programme (DPMP).

Such a programme is intended to provide an organisational framework for demonstrating compliance with data-protection obligations. It may include appropriate internal policies, records of processing activities, oversight mechanisms, complaint-handling procedures, processes for identifying and responding to personal-data breaches, periodic reviews of safeguards and mechanisms supporting compliance with data-subject rights when the relevant provisions become operational.

V. Data Protection Officers

The PDPA requires controllers and processors to appoint a Data Protection Officer (DPO) in specified circumstances, including where processing is carried out by government departments, involves large-scale monitoring, special categories of personal data, or poses a risk to data subjects’ rights.

The DPO must have relevant qualifications and expertise in data protection and must be accessible to the organization and the DPA and advises on compliance, training, impact assessments, and cooperation with the DPA. 

VI. Data Protection Impact Assessments

A Controller must conduct a Personal Data Protection Impact Assessment (DPIA) before undertaking high-risk processing of personal data. This includes profiling, systematic monitoring of public areas or telecommunication networks, and other processing activities identified by law. The assessment must identify risks to data subjects and measures to reduce or prevent harm.

The Controller should seek assistance from the DPO where one is designated. A fresh assessment is required when there is a change in the processing method, technology, or process. The assessment must be submitted to the DPA upon written request. If the assessment identifies a risk of harm, the Controller must take appropriate measures before processing begins and, where required, consult the DPA.

VII. Cross-Border Transfers

The PDPA also regulates circumstances in which personal data is transferred outside Sri Lanka.

Controllers and processors involved in cross-border processing must comply with the applicable requirements of the Act and, where required, adopt appropriate safeguards and legally binding and enforceable commitments for the protection of personal data transferred to recipients abroad.

The legislation also recognises limited circumstances in which certain transfers may be permitted without relying on the general safeguards framework, including circumstances involving explicit consent, contractual necessity, legal claims, public interest and emergencies, subject to the statutory requirements.

A Significant Transitional Position

The selective commencement of Parts I and III, without the simultaneous commencement of Part II and Part VII, creates a distinctive transitional environment.

Part II contains important statutory rights of data subjects, including rights relating to access, rectification, erasure and objection to certain processing activities. Since Part II is not included in the 1st January 2027 commencement order, those statutory rights under Part II will not yet be operational from that date. This should not, however, be understood as meaning that individuals have no other legal protections in relation to privacy or personal information under Sri Lankan law.

Similarly, Part VII contains the enforcement and penalty framework, including the DPA's power to impose penalties in specified circumstances. In particular, the Act provides for a penalty of up to Rs. 10 million for each non-compliance with a directive in the circumstances specified by the Act. As Part VII has not been brought into operation by the July 2026 commencement order, that administrative penalty regime will not be implemented from 1st January 2027.

What Organisations Should Do Now?

The commencement of the PDPA on 1st January 2027 will mark an important development in data protection compliance in Sri Lanka. Organisations should use the period before commencement to identify the personal data they hold, review processing purposes, retention periods, security measures, third-party processors, and data-processing agreements. They should also assess should also review how personal data is transferred across borders and whether appropriate safeguards are in place for such transfers. Although the PDPA will not be fully operational on this date, Parts I and III will impose substantive obligations on Controllers and Processors. 

For organisations, the practical message is clear, data protection compliance should not be treated as something that begins only when penalties become available. The systems, policies, contracts and governance structures required for compliance should be established before the relevant obligations take effect.