Law / Sri Lanka

Computer Crime Act, unauthorised access, modification and dealing with unlawfully obtained data

Computer Crime Act, No. 24 of 2007, ss. 3-7

A citation is an address, not a summary. The first part names the law; what follows narrows it to the exact section, article or paragraph.

Commencement not set.

A computer misuse rule binding public and private bodies.

As of 6 September 2026.

What it requires

  • Do not secure access to a computer or to information held in it without lawful authority; the test does not turn on defeating a technical control, so relying on a page being public and unauthenticated is not itself a defence and has not been tested by a Sri Lankan court.
  • Do not intentionally cause unauthorised modification or damage to a computer, computer system, or computer programme in the course of an automated collection process.
  • Do not buy, receive, retain, download, upload, or copy information known or believed to have been obtained from a computer without lawful authority by someone else.

If you get it wrong

Criminal exposureYes

Private right of actionNo

Criminal exposure note

Section 3 (unauthorised access): a fine up to LKR 100,000, or imprisonment up to five years, or both. Section 4 (unauthorised access with intent to commit a further offence): a fine up to LKR 200,000, or imprisonment up to five years, or both. Section 5 (unauthorised modification or damage): a fine up to LKR 300,000, or imprisonment up to five years, or both. Section 6 (danger to national security, the economy, or public order): imprisonment up to five years, with no fine option stated. Section 7 (dealing with unlawfully obtained data): a fine of not less than LKR 100,000 and not exceeding LKR 300,000, or imprisonment of not less than six months and not exceeding three years, or both.

What this law does

Drafted with AI from the cited sources under the direction of UnGovr staff. UnGovr holds editorial responsibility for this page.

Section 3 makes it an offence to intentionally secure access to a computer or to information held in it, knowing or having reason to believe there is no lawful authority for that access; section 4 raises the same conduct to a second offence where it is done with intent to commit a further offence.

Neither section requires infringing a security measure or defeating any technical control, so the provision's reach over a public, unauthenticated page turns entirely on whether the accessor had lawful authority, a question no reported Sri Lankan decision has tested against a scraping fact pattern. Section 5 separately criminalises causing a computer to perform a function that the person knows or has reason to believe will result in unauthorised modification or damage.

Section 6 criminalises intentionally causing danger or imminent danger to national security, the national economy, or public order. Section 7 criminalises buying, receiving, retaining, selling, downloading, uploading, copying or otherwise dealing with information known or believed to have been obtained from a computer without lawful authority by another person.

The Act's own section 1 defers its commencement to a date the Minister appoints by Gazette Order; no notice of that Order has been located, only the deferral mechanism itself.

When LexLint raises it

  • crawls_web
  • trains_models

Read the law

Official Act text, Parliament of Sri Lanka, Internet Archive capture of the National ICT Agency's copy

archived copyRead from a public archive copy, not the publisher directly. The publisher does not serve this page to automated readers, so a direct fetch was not an option here; how we access sources. Archived February 9, 2026. Publisher's page: https://www.icta.lk/icta-assets/uploads/2016/03/ComputerCrimesActNo24of2007.pdf

Back to the example  ·  Lint your app