Sri Lanka PDPA
Personal Data Protection Act, No. 9 of 2022 (as amended by Act No. 22 of 2025)
- Regulator
- Data Protection Authority of Sri Lanka
- Who it applies to
- Controllers and processors processing personal data in Sri Lanka, and those abroad offering goods or services to people in Sri Lanka or monitoring them.
- If you fall short
- Administrative penalties of up to LKR 10 million for each non-compliance, doubled for repeat violations.
- What it asks of you
- Lawful, fair and transparent processing for a specified purpose, with data minimisation, accuracy and storage limits
- Data subject rights of access, correction, erasure and objection
- A Data Protection Officer for the controllers and processors the Act specifies, and impact assessments for high-risk processing
- Notify the Data Protection Authority of personal data breaches
- Conditions on cross-border transfers
The Act's obligations come into operation in stages on dates set by the Minister; the 2025 amendment revised several provisions.