Taking new engagements — Q4 hello@datadefenz.com
ServicesAll servicesGRC & Compliance7Security Culture1Risk Management3Technical Security5Leadership Advisory1Fast-Turnaround1
ProductsResourcesPracticeAboutBook a 30-minute callContact
Services / PDPA Compliance Navigator

Sri Lanka · Personal Data Protection Act

PDPA Compliance Navigator

Understand. Assess. Prepare. A guided journey through Sri Lanka's Personal Data Protection Act — whether you are in scope, what role you play, what you owe, what evidence proves it, and how your existing GDPR, ISO 27001 or NIST work carries over.

Built from the Act itself: Personal Data Protection Act, No. 9 of 2022, as amended by the Personal Data Protection (Amendment) Act, No. 22 of 2025. Every legal statement on this page carries its section reference.

Before you start

Four everyday situations.

The most common misunderstanding in Sri Lanka is that the PDPA is about big companies and big databases. It is not. It turns on who is processing, why, and where the people are — not on how large you are or how the records are kept. A paper register in a pharmacy is in scope. A contact list on your own phone is not.

Not in scopes.2(3)(a)

Your own phone's contact list

“You save your friends' and family's numbers, birthdays and photos on your personal phone.”

Section 2(3)(a) excludes personal data processed purely for personal, domestic or household purposes by an individual. This is exactly that.

The part people missBut if you start using that same phone list to send promotional messages for your shop, the purpose is no longer domestic — and the exclusion falls away.

In scopes.2(1)(a) · s.56

A neighbourhood pharmacy's paper register

“A small pharmacy writes each customer's name, NIC number and the medicine dispensed into a notebook kept behind the counter.”

Processing takes place in Sri Lanka, so section 2(1)(a) applies. The Act has no minimum size threshold — three staff is as much in scope as three thousand. Medicine records are data concerning health, which is a special category, so Schedule II conditions apply on top of Schedule I.

The part people missPaper is not a loophole. “Processing” covers collection, storage and retrieval by any means, and the notebook behind the counter is an access-control question under section 10.

In scopes.2(1)(b)(iii)

An overseas app with Sri Lankan users

“A company registered in Singapore, with no office or staff in Sri Lanka, runs a delivery app advertised in Sinhala and Tamil and priced in rupees.”

No Sri Lankan establishment is needed. Section 2(1)(b)(iii) reaches anyone offering goods or services to data subjects in Sri Lanka, including offerings that specifically target them. Local language and local currency are the kind of factors that evidence targeting.

The part people missThe Authority may make rules determining when specific targeting occurs, so the precise line here is expected to be drawn in rules rather than in the Act.

In scopes.2(1)(a) · s.56

A three-person company's staff file

“A small design studio keeps a folder with each employee's NIC copy, bank details, salary and medical certificates.”

Employees are data subjects. The studio decides why the records are held, so it is a controller and carries the full Part I obligations — lawful basis, purpose, retention limits, security and transparency.

The part people missThe medical certificates are health data — a special category. Most small employers hold special-category data without ever having noticed.

Step 1 · Are you in scope?Six questions · nothing leaves your browser
DATADEFENZ provides an educational and preliminary readiness assessment. It does not constitute legal advice, regulatory approval or certification.

Step 2 · Parties and responsibilities

Who decides why?

That single question decides whether you are a controller or a processor — and almost every obligation that follows hangs off the answer. The role is determined per processing activity, not per organisation: the same company is routinely a controller for its employee data and a processor for its clients'.

Data subject Personal data Controller — decides why Processor — acts on instructions Sub-processor
Example · Payroll

You are the controller

You decide that salaries will be processed and why. The payroll bureau runs it on your instructions and is your processor — which triggers your section 21 contracting duty.

Example · Cloud SaaS

It depends on the activity

Your customer is the controller for the data they put in your product; you are their processor. But you are the controller for your own account-holder and billing data. Both are true at once.

Example · Outsourced HR

Watch for drift

An HR provider starts as a processor. The moment it decides to reuse the data for its own benchmarking product, it has determined a purpose — and becomes a controller for that activity.

Step 3 · Follow the data

One record, seven stages.

At each stage: who is responsible, what the Act requires, and what evidence would demonstrate it.

In practice

What the conversation actually sounds like.

Five situations that come up in almost every engagement. The questions are the ones we would ask you.

Timeline

Where the law actually stands.

The single most misreported thing about the PDPA is its commencement. The original Act set outer deadlines of 18–36 months for most provisions and 24–48 months for Part IV. The 2025 Amendment repealed all of them.

19 March 2022
historical

PDPA No. 9 of 2022 certified

Sri Lanka's first comprehensive personal data protection statute is certified by the Speaker.

As appointed
operational

Institutional Parts brought into force

Parts V, VI, VIII, IX and X — which establish and empower the Data Protection Authority — were brought into operation ahead of the substantive obligations. The 2025 Amendment expressly preserves anything done under those Parts as valid and continuing in force.

30 October 2025
historical

Amendment Act No. 22 of 2025 certified

Published as a supplement to the Gazette of 31 October 2025.

On certification of the Amendment
current

The fixed commencement windows were repealed

Section 2 of the Amendment repealed section 1(3) of the principal Act and substituted: all other provisions come into operation “on such date or dates as the Minister may appoint, by Order published in the Gazette.” Subsections 1(4) and 1(5) — which had set outer limits of 24–48 months for Part IV and a deadline for Part V — were repealed outright.

This is the single most important thing to understand about the current timeline. The original Act contained statutory outer deadlines. They no longer exist. Commencement of the remaining provisions is now entirely at the Minister's discretion by Gazette Order.
Not yet appointed
pending

Substantive obligations — Parts I to IV

The controller and processor duties, data subject rights, and the enforcement provisions come into operation on the date or dates appointed by the Minister. Confirm the current position against the Gazette before treating any of these as presently enforceable.

Within 36 months
pending

Authority to make rules

Section 52(2) required the Authority to make rules within twenty-four months; the 2025 Amendment substituted thirty-six months. Much of the operational detail — breach notification form and timing, DPIA form, prescribed scale thresholds for DPO designation — sits in those rules and guidelines rather than in the Act.

Statuses reflect the Act as amended. Because commencement now depends on Ministerial Orders published in the Gazette, confirm the current position before treating any provision as presently enforceable. s.1(3) as substituted

If you already have GDPR

PDPA is not Sri Lankan GDPR.

It is strongly influenced by the same international principles, and a mature GDPR programme transfers a great deal. But several provisions diverge in ways that change what you must actually do — filter to the material differences and read those first.

If you already have ISO 27001

How much of PDPA does it cover?

A great deal of the security half, and none of the privacy half. This is the distinction that costs organisations the most time when they assume otherwise.

ISO 27001+ NIST CSF= Security foundation+ PDPA privacy & legal requirements= PDPA readiness
ISO 27001 helps hereExisting Annex A controls and management-system clauses carry real weight
s.10 Integrity and confidentialityA.5.15 Access control, A.8.5 Secure authentication, A.8.24 Cryptography, A.8.3 Information access restrictionStrong
s.12(e) Internal oversightClause 9.2 Internal audit, Clause 9.3 Management reviewStrong
s.12(f) Breach identification mechanismA.5.24–5.28 Incident management planning, assessment, response and evidence collectionStrong
s.21 Processor selection and contractsA.5.19–5.22 Supplier relationships, agreements, ICT supply chain, monitoringStrong
s.23 Breach notificationA.5.24 Incident management planning, A.5.5 Contact with authoritiesPartial — ISO gives you the process, not the legal trigger or deadline
s.9 Retention limitsA.5.33 Protection of records, A.8.10 Information deletionPartial — ISO handles the mechanism, not the justification
s.24 Impact assessmentsClause 6.1 Risk assessment, A.5.8 Security in project managementPartial — different risk lens: harm to the data subject, not to the organisation
s.12(g) Periodic monitoringClause 9.1 Monitoring and measurement, Clause 10 ImprovementStrong
ISO 27001 does not reach hereLegal and governance requirements with no Annex A equivalent
Lawful basis under Schedule IThere is no Annex A control that establishes a legal ground for processing. This is a legal determination per processing activity.
Purpose specification under s.6ISO 27001 protects information; it does not ask why you hold it or whether a new use is compatible with the original purpose.
Transparency under s.11 and Schedule VPrivacy notices carrying the prescribed information have no ISO 27001 equivalent.
Data subject rights under ss.13–19Access, rectification, erasure, automated-decision review and the appeal route are legal processes with statutory deadlines. No Annex A control delivers them.
Controller or processor role determinationA legal characterisation of each processing activity, and the foundation for everything else. Outside the ISMS entirely.
Data Protection Management Programme under s.12Overlaps an ISMS structurally, but its content is privacy-specific and it must demonstrate how ss.5–11 are carried out.
Cross-border instruments under s.26The Authority-directed instrument regime is a legal mechanism, not a security control.
Consent conditions under Schedule IIIDemonstrability, distinguishability, freely-given assessment and withdrawal notice are all outside ISO 27001's scope.

If you already have NIST CSF

Function by function.

NIST CSF 2.0 supports the cybersecurity risk-management side of PDPA readiness. It is not a privacy law and does not pretend to be one.

GOVERN
s.12 Data Protection Management Programme; s.20 DPO designation and responsibilities
The closest structural match in the whole framework. CSF 2.0's Govern function and the section 12 programme are asking for the same organisational shape — accountability, oversight, integration into governance.
IDENTIFY
s.6 purpose; s.7 minimisation; s.24 impact assessments
CSF asset inventory gets you part of the way to a data inventory, but a privacy inventory needs purpose, lawful basis and retention against each item — fields CSF has no reason to ask for.
PROTECT
s.10 integrity and confidentiality; s.22 processor security
Direct overlap. This is the part of PDPA that an existing CSF programme genuinely does cover.
DETECT
s.12(f) mechanism to identify personal data breaches
CSF detection tells you a security event occurred. It does not tell you whether personal data was affected — which is the question that starts the section 23 clock.
RESPOND
s.23 breach notification to the Authority
CSF response covers containment and communication generally. The regulatory notification form, manner and period come from rules made under the Act.
RECOVER
s.8 accuracy; s.12(g) updating based on monitoring
Restoration is a security concern; ensuring restored data is still accurate and lawfully held is a privacy one.

Step 4 · Self-assessment

Ten dimensions, not one percentage.

A single compliance score hides exactly the information you need. Rate each dimension honestly — the gap between “documented” and “documented and evidenced” is where most programmes actually sit.

This is a self-assessment of readiness. It is not a compliance determination, a legal opinion or a certification.

Evidence

What would actually prove it?

Section 12 requires duly catalogued records demonstrating how the obligations in sections 5 to 11 are carried out. Not that they exist — how they are carried out. This is that list.

Scope and inventory
  • Record of processing activities
  • Data inventory with categories and systems
  • Data flow diagrams
  • Controller / processor role determination per activity
Lawfulness
  • Lawful basis register mapped to Schedule I
  • Schedule II assessment for special categories
  • Consent records demonstrating Schedule III conditions
  • Legitimate interest assessments
Transparency
  • Privacy notices carrying the Schedule V information
  • Evidence of when and how notices are presented
  • Layered notice versions and change history
Data governance
  • Retention schedule with per-category justification
  • Deletion and erasure logs
  • Accuracy and rectification procedure
  • Minimisation review records
Security
  • Access control records
  • Encryption and pseudonymisation configuration
  • Risk assessments
  • Security monitoring evidence
  • Penetration test and remediation records
Rights
  • Data subject request log with dates received and answered
  • Extension notifications issued before the one-month expiry
  • Refusal reasons and appeal-route notifications
  • Automated decision review records
Third parties
  • Processor inventory
  • Processor agreements meeting the s.21(1)(b) content requirements
  • Processor due diligence
  • Sub-processor authorisations
Cross-border
  • Transfer inventory by destination
  • The instrument adopted under s.26(2)
  • Records of any s.26(3) condition relied on
Governance and assurance
  • Data Protection Management Programme documentation
  • DPO appointment and published contact details
  • Training and awareness records
  • Internal audit reports
  • Management review minutes
  • Personal data protection impact assessments
Incidents
  • Breach register
  • Breach assessment records
  • Notifications made to the Authority
  • Post-incident improvement actions

Myths

Six things we hear every month.

Myth

“We have ISO 27001, so we are PDPA compliant.”

Reality

ISO 27001 gives you a strong answer to section 10 — integrity and confidentiality through technical and organisational measures. It says nothing about whether you have a lawful basis under Schedule I, whether your purpose is specified and explicit under section 6, whether your privacy notice carries the Schedule V information, or whether you can respond to a section 13 access request within one month. Those are legal and governance requirements, not security controls.

Myth

“PDPA is just Sri Lankan GDPR.”

Reality

It draws on the same principles, and much GDPR work transfers. But the differences are real and some of them bite: “data subject” expressly covers deceased persons; the response deadline structure differs; cross-border transfer runs on an Authority-directed instrument regime rather than adequacy decisions; and penalties attach to non-compliance with a directive rather than directly to a breach. Assess the Sri Lankan text independently.

Myth

“Only large companies need to worry about it.”

Reality

The Act contains no general size threshold for applicability — unlike NIS2, which does. Section 2(1) turns on where processing happens and who you are dealing with. Size affects some things: the DPO designation duty in section 20 turns on the scale and magnitude of monitoring or special-category processing, and the Data Protection Management Programme under section 12 is expressly designed around structure, scale and volume.

Myth

“We have a privacy policy, so we are covered.”

Reality

Section 11 requires that you give data subjects the Schedule V information in a concise, transparent, intelligible and easily accessible form. That is one obligation out of many. Section 12 requires a Data Protection Management Programme with catalogued records demonstrating how sections 5 to 11 are actually carried out. A policy is an input to that; it is not the evidence.

Myth

“We use a cloud provider, so it is their responsibility.”

Reality

Section 21 makes it the controller's duty to use only processors providing appropriate measures, and to bind them contractually on specified terms. Engaging a processor creates an obligation for you; it does not transfer one away. The processor carries its own duties under section 22 in addition, not instead.

Myth

“Nothing is in force yet, so there is nothing to do.”

Reality

The institutional Parts establishing the Authority are already operational, and the Amendment preserved everything done under them. More practically: a data inventory, a lawful-basis register and a retention schedule take months to build and are the prerequisites for everything else. Organisations that wait for the commencement Order will be starting from zero on the day it lands.

Building your programme?

Talk to DATADEFENZ about your PDPA readiness.

Thirty minutes, no charge. We will tell you whether you are in scope, what your role is, and what the first ninety days should contain.