Sri Lanka
ModeratePersonal Data Protection Act No. 9 of 2022
Authority: Data Protection Authority of Sri Lanka | Enforcement: Pending | Enacted: March 2024
Overview
Sri Lanka enacted its Personal Data Protection Act in 2022, with a phased implementation. The law is GDPR-inspired and covers consent, data subject rights, cross-border transfers, and breach notification. The Data Protection Authority is being established.
14-Topic Coverage
Data Protection Authority
Pending EnforcementData Protection Authority established by law. Operational capacity being built.
Consent Requirements
Fully AddressedConsent required. Must be freely given, specific, informed, and unambiguous.
Data Subject Rights
Fully AddressedRights to access, rectification, erasure, restriction, portability, and objection.
Cross-Border Transfer
Fully AddressedTransfers to countries with adequate protection or with appropriate safeguards.
Breach Notification
Fully AddressedMust notify the Authority within 72 hours. Must notify data subjects if high risk.
DPO Requirements
Fully AddressedDPO required for certain categories of controllers and processors.
Children's Data
Fully AddressedParental consent required for children under 16.
Penalties & Enforcement
Fully AddressedFines up to LKR 10 million for organisations. Personal liability for responsible officers.
Sector-Specific Rules
Partially AddressedCBSL financial data rules, health data regulations.
Cookie/Tracking
Partially AddressedGeneral consent requirements apply.
AI & Automated Decisions
Partially AddressedRight to not be subject to automated decisions.
Data Localisation
Partially AddressedSome sector-specific localisation requirements.
Significant Data Fiduciary
Not AddressedNo equivalent concept.
Government Data
Partially AddressedAct applies to government processing with national security exemptions.
Coverage Summary
Quick Navigation
Need Compliance Help?
Our data privacy team can help you navigate Sri Lanka's regulations.
Book a Consultation