Sri Lanka

Moderate

Personal Data Protection Act No. 9 of 2022

Authority: Data Protection Authority of Sri Lanka | Enforcement: Pending | Enacted: March 2024

Overview

Sri Lanka enacted its Personal Data Protection Act in 2022, with a phased implementation. The law is GDPR-inspired and covers consent, data subject rights, cross-border transfers, and breach notification. The Data Protection Authority is being established.

14-Topic Coverage

Data Protection Authority

Pending Enforcement

Data Protection Authority established by law. Operational capacity being built.

Data Subject Rights

Fully Addressed

Rights to access, rectification, erasure, restriction, portability, and objection.

Cross-Border Transfer

Fully Addressed

Transfers to countries with adequate protection or with appropriate safeguards.

Breach Notification

Fully Addressed

Must notify the Authority within 72 hours. Must notify data subjects if high risk.

DPO Requirements

Fully Addressed

DPO required for certain categories of controllers and processors.

Children's Data

Fully Addressed

Parental consent required for children under 16.

Penalties & Enforcement

Fully Addressed

Fines up to LKR 10 million for organisations. Personal liability for responsible officers.

Sector-Specific Rules

Partially Addressed

CBSL financial data rules, health data regulations.

AI & Automated Decisions

Partially Addressed

Right to not be subject to automated decisions.

Data Localisation

Partially Addressed

Some sector-specific localisation requirements.

Significant Data Fiduciary

Not Addressed

No equivalent concept.

Government Data

Partially Addressed

Act applies to government processing with national security exemptions.