Sri Lanka · Personal Data Protection Act
PDPA Compliance Navigator
Understand. Assess. Prepare. A guided journey through Sri Lanka's Personal Data Protection Act — whether you are in scope, what role you play, what you owe, what evidence proves it, and how your existing GDPR, ISO 27001 or NIST work carries over.
Built from the Act itself: Personal Data Protection Act, No. 9 of 2022, as amended by the Personal Data Protection (Amendment) Act, No. 22 of 2025. Every legal statement on this page carries its section reference.
Before you start
Four everyday situations.
The most common misunderstanding in Sri Lanka is that the PDPA is about big companies and big databases. It is not. It turns on who is processing, why, and where the people are — not on how large you are or how the records are kept. A paper register in a pharmacy is in scope. A contact list on your own phone is not.
Your own phone's contact list
“You save your friends' and family's numbers, birthdays and photos on your personal phone.”
Section 2(3)(a) excludes personal data processed purely for personal, domestic or household purposes by an individual. This is exactly that.
The part people missBut if you start using that same phone list to send promotional messages for your shop, the purpose is no longer domestic — and the exclusion falls away.
A neighbourhood pharmacy's paper register
“A small pharmacy writes each customer's name, NIC number and the medicine dispensed into a notebook kept behind the counter.”
Processing takes place in Sri Lanka, so section 2(1)(a) applies. The Act has no minimum size threshold — three staff is as much in scope as three thousand. Medicine records are data concerning health, which is a special category, so Schedule II conditions apply on top of Schedule I.
The part people missPaper is not a loophole. “Processing” covers collection, storage and retrieval by any means, and the notebook behind the counter is an access-control question under section 10.
An overseas app with Sri Lankan users
“A company registered in Singapore, with no office or staff in Sri Lanka, runs a delivery app advertised in Sinhala and Tamil and priced in rupees.”
No Sri Lankan establishment is needed. Section 2(1)(b)(iii) reaches anyone offering goods or services to data subjects in Sri Lanka, including offerings that specifically target them. Local language and local currency are the kind of factors that evidence targeting.
The part people missThe Authority may make rules determining when specific targeting occurs, so the precise line here is expected to be drawn in rules rather than in the Act.
A three-person company's staff file
“A small design studio keeps a folder with each employee's NIC copy, bank details, salary and medical certificates.”
Employees are data subjects. The studio decides why the records are held, so it is a controller and carries the full Part I obligations — lawful basis, purpose, retention limits, security and transparency.
The part people missThe medical certificates are health data — a special category. Most small employers hold special-category data without ever having noticed.
Step 2 · Parties and responsibilities
Who decides why?
That single question decides whether you are a controller or a processor — and almost every obligation that follows hangs off the answer. The role is determined per processing activity, not per organisation: the same company is routinely a controller for its employee data and a processor for its clients'.
You are the controller
You decide that salaries will be processed and why. The payroll bureau runs it on your instructions and is your processor — which triggers your section 21 contracting duty.
It depends on the activity
Your customer is the controller for the data they put in your product; you are their processor. But you are the controller for your own account-holder and billing data. Both are true at once.
Watch for drift
An HR provider starts as a processor. The moment it decides to reuse the data for its own benchmarking product, it has determined a purpose — and becomes a controller for that activity.
Step 3 · Follow the data
One record, seven stages.
At each stage: who is responsible, what the Act requires, and what evidence would demonstrate it.
In practice
What the conversation actually sounds like.
Five situations that come up in almost every engagement. The questions are the ones we would ask you.
Timeline
Where the law actually stands.
The single most misreported thing about the PDPA is its commencement. The original Act set outer deadlines of 18–36 months for most provisions and 24–48 months for Part IV. The 2025 Amendment repealed all of them.
PDPA No. 9 of 2022 certified
Sri Lanka's first comprehensive personal data protection statute is certified by the Speaker.
Institutional Parts brought into force
Parts V, VI, VIII, IX and X — which establish and empower the Data Protection Authority — were brought into operation ahead of the substantive obligations. The 2025 Amendment expressly preserves anything done under those Parts as valid and continuing in force.
Amendment Act No. 22 of 2025 certified
Published as a supplement to the Gazette of 31 October 2025.
The fixed commencement windows were repealed
Section 2 of the Amendment repealed section 1(3) of the principal Act and substituted: all other provisions come into operation “on such date or dates as the Minister may appoint, by Order published in the Gazette.” Subsections 1(4) and 1(5) — which had set outer limits of 24–48 months for Part IV and a deadline for Part V — were repealed outright.
Substantive obligations — Parts I to IV
The controller and processor duties, data subject rights, and the enforcement provisions come into operation on the date or dates appointed by the Minister. Confirm the current position against the Gazette before treating any of these as presently enforceable.
Authority to make rules
Section 52(2) required the Authority to make rules within twenty-four months; the 2025 Amendment substituted thirty-six months. Much of the operational detail — breach notification form and timing, DPIA form, prescribed scale thresholds for DPO designation — sits in those rules and guidelines rather than in the Act.
Statuses reflect the Act as amended. Because commencement now depends on Ministerial Orders published in the Gazette, confirm the current position before treating any provision as presently enforceable. s.1(3) as substituted
If you already have GDPR
PDPA is not Sri Lankan GDPR.
It is strongly influenced by the same international principles, and a mature GDPR programme transfers a great deal. But several provisions diverge in ways that change what you must actually do — filter to the material differences and read those first.
If you already have ISO 27001
How much of PDPA does it cover?
A great deal of the security half, and none of the privacy half. This is the distinction that costs organisations the most time when they assume otherwise.
If you already have NIST CSF
Function by function.
NIST CSF 2.0 supports the cybersecurity risk-management side of PDPA readiness. It is not a privacy law and does not pretend to be one.
Step 4 · Self-assessment
Ten dimensions, not one percentage.
A single compliance score hides exactly the information you need. Rate each dimension honestly — the gap between “documented” and “documented and evidenced” is where most programmes actually sit.
This is a self-assessment of readiness. It is not a compliance determination, a legal opinion or a certification.
Evidence
What would actually prove it?
Section 12 requires duly catalogued records demonstrating how the obligations in sections 5 to 11 are carried out. Not that they exist — how they are carried out. This is that list.
- Record of processing activities
- Data inventory with categories and systems
- Data flow diagrams
- Controller / processor role determination per activity
- Lawful basis register mapped to Schedule I
- Schedule II assessment for special categories
- Consent records demonstrating Schedule III conditions
- Legitimate interest assessments
- Privacy notices carrying the Schedule V information
- Evidence of when and how notices are presented
- Layered notice versions and change history
- Retention schedule with per-category justification
- Deletion and erasure logs
- Accuracy and rectification procedure
- Minimisation review records
- Access control records
- Encryption and pseudonymisation configuration
- Risk assessments
- Security monitoring evidence
- Penetration test and remediation records
- Data subject request log with dates received and answered
- Extension notifications issued before the one-month expiry
- Refusal reasons and appeal-route notifications
- Automated decision review records
- Processor inventory
- Processor agreements meeting the s.21(1)(b) content requirements
- Processor due diligence
- Sub-processor authorisations
- Transfer inventory by destination
- The instrument adopted under s.26(2)
- Records of any s.26(3) condition relied on
- Data Protection Management Programme documentation
- DPO appointment and published contact details
- Training and awareness records
- Internal audit reports
- Management review minutes
- Personal data protection impact assessments
- Breach register
- Breach assessment records
- Notifications made to the Authority
- Post-incident improvement actions
Myths
Six things we hear every month.
“We have ISO 27001, so we are PDPA compliant.”
ISO 27001 gives you a strong answer to section 10 — integrity and confidentiality through technical and organisational measures. It says nothing about whether you have a lawful basis under Schedule I, whether your purpose is specified and explicit under section 6, whether your privacy notice carries the Schedule V information, or whether you can respond to a section 13 access request within one month. Those are legal and governance requirements, not security controls.
“PDPA is just Sri Lankan GDPR.”
It draws on the same principles, and much GDPR work transfers. But the differences are real and some of them bite: “data subject” expressly covers deceased persons; the response deadline structure differs; cross-border transfer runs on an Authority-directed instrument regime rather than adequacy decisions; and penalties attach to non-compliance with a directive rather than directly to a breach. Assess the Sri Lankan text independently.
“Only large companies need to worry about it.”
The Act contains no general size threshold for applicability — unlike NIS2, which does. Section 2(1) turns on where processing happens and who you are dealing with. Size affects some things: the DPO designation duty in section 20 turns on the scale and magnitude of monitoring or special-category processing, and the Data Protection Management Programme under section 12 is expressly designed around structure, scale and volume.
“We have a privacy policy, so we are covered.”
Section 11 requires that you give data subjects the Schedule V information in a concise, transparent, intelligible and easily accessible form. That is one obligation out of many. Section 12 requires a Data Protection Management Programme with catalogued records demonstrating how sections 5 to 11 are actually carried out. A policy is an input to that; it is not the evidence.
“We use a cloud provider, so it is their responsibility.”
Section 21 makes it the controller's duty to use only processors providing appropriate measures, and to bind them contractually on specified terms. Engaging a processor creates an obligation for you; it does not transfer one away. The processor carries its own duties under section 22 in addition, not instead.
“Nothing is in force yet, so there is nothing to do.”
The institutional Parts establishing the Authority are already operational, and the Amendment preserved everything done under them. More practically: a data inventory, a lawful-basis register and a retention schedule take months to build and are the prerequisites for everything else. Organisations that wait for the commencement Order will be starting from zero on the day it lands.
Building your programme?
Talk to DATADEFENZ about your PDPA readiness.
Thirty minutes, no charge. We will tell you whether you are in scope, what your role is, and what the first ninety days should contain.
