Compliance software · Sri Lanka

PDPA and GRC compliance software built for Sri Lankan businesses

Sri Lanka's Personal Data Protection Act brings GDPR-style duties to every organisation that processes personal data here, and banks answer to CBSL's technology risk rules too. AI Pazz Govnex is built in Sri Lanka, with the PDPA as a ready-made control set and a free readiness check to start.

In short

Organisations that process personal data in Sri Lanka must get ready for the Personal Data Protection Act, No. 9 of 2022, as amended in 2025: lawful processing, a Data Protection Officer for many controllers, impact assessments, breach notification and rights for data subjects, supervised by the Data Protection Authority. Govnex holds the PDPA as a ready-made control set, with a free public readiness check.

Reviewed . A plain-language guide, not legal advice — check the regulator's site for the current position.

The laws and rules that apply in Sri Lanka

What each asks of a business, who it applies to, what happens if you fall short — and whether Govnex holds it as a ready-made control set.

Sri Lanka PDPA

Personal Data Protection Act, No. 9 of 2022 (as amended by Act No. 22 of 2025)

Ready-made in the Govnex Library
Regulator
Data Protection Authority of Sri Lanka
Who it applies to
Controllers and processors processing personal data in Sri Lanka, and those abroad offering goods or services to people in Sri Lanka or monitoring them.
If you fall short
Administrative penalties of up to LKR 10 million for each non-compliance, doubled for repeat violations.
What it asks of you
  • Lawful, fair and transparent processing for a specified purpose, with data minimisation, accuracy and storage limits
  • Data subject rights of access, correction, erasure and objection
  • A Data Protection Officer for the controllers and processors the Act specifies, and impact assessments for high-risk processing
  • Notify the Data Protection Authority of personal data breaches
  • Conditions on cross-border transfers

The Act's obligations come into operation in stages on dates set by the Minister; the 2025 amendment revised several provisions.

Source: Parliament of Sri Lanka

Sri Lanka ETA

Electronic Transactions Act, No. 19 of 2006 (as amended in 2017)

Ready-made in the Govnex Library
Regulator
Information and Communication Technology Agency (ICTA)
Who it applies to
Electronic records, signatures and transactions in Sri Lanka.
If you fall short
None specific — it sets the rules electronic evidence relies on.
What it asks of you
  • Legal recognition of electronic records and signatures, and the conditions for their reliability

Source: icta.lk

CBSL TRM

CBSL technology risk management and resilience directions

Track it with your own controls
Regulator
Central Bank of Sri Lanka (CBSL)
Who it applies to
Licensed banks and other financial institutions the Central Bank regulates.
If you fall short
Supervisory action by the Central Bank.
What it asks of you
  • Technology risk governance, cyber security controls and resilience
  • Incident reporting and third-party risk management

Source: cbsl.gov.lk

Standards Sri Lanka buyers ask for

How AI Pazz Govnex helps in Sri Lanka

What you needHow Govnex does itModule
PDPA readinessAdopt the ready-made PDPA control set, assign owners and collect evidence cycle by cycle — after a free readiness check.
A consultant-led gap assessmentThe AI Pazz team scores your data protection maturity and gives you a roadmap.
Personal data inventoryA register of personal data, purposes, owners and cross-border transfers.
Breach notificationEach breach an issue with an owner, notification and corrective actions.
Policies and staff awarenessData protection policies with tracked acknowledgement.

Your first 90 days

  1. 1Take the free PDPA readiness check to see where you stand.
  2. 2Adopt the PDPA control set and assign owners, starting with your DPO.
  3. 3Map the personal data you hold and where it goes.
  4. 4Put a breach notification process in place and publish the policies staff acknowledge.
  5. 5Close gaps cycle by cycle and report readiness to your board.

Free readiness check

No account needed. Answer the questions and get an executive summary of where you stand.

Compliance in Sri Lanka: questions and answers

When does Sri Lanka's PDPA come into force?
The Act was passed in 2022 and amended in 2025. Its obligations come into operation in stages on dates set by the Minister — check the latest operative dates, and use the time to get ready.
Who does the Sri Lanka PDPA apply to?
Controllers and processors processing personal data in Sri Lanka, and organisations abroad that offer goods or services to people in Sri Lanka or monitor them.
Do we need a Data Protection Officer?
Many controllers and processors must designate a DPO — for example public authorities and those processing personal data at scale or sensitive data. Govnex gives your DPO one place to run the program.
What are the penalties under the PDPA?
The Data Protection Authority can impose penalties of up to LKR 10 million for each non-compliance, doubled for repeated violations.
Is the PDPA in the Govnex Library?
Yes — the Personal Data Protection Act, No. 9 of 2022 (consolidated with the 2025 amendment) is a ready-made control set, and there is a free public readiness check.
Is Govnex a Sri Lankan product?
Yes. AI Pazz Govnex is built by RedBlocks Technologies, with the AI Pazz consultancy team in Sri Lanka.