Law note · Sri Lanka
Personal Data Protection Act, breach notification duties
cite Personal Data Protection Act, No. 9 of 2022, as amended by Act No. 22 of 2025, s.23
stage IN FORCE in force since 2025-03-18
kind Breach notification
binds public and private bodies
reviewed 2026-08-29
What it requires
- An app that suffers a personal data breach in Sri Lanka, including one involving a biometric identifier, must notify the Data Protection Authority in the form, manner, and time a rule made under the Act determines; whether and when the affected individual must also be told is set by a rule not yet located this pass.
When LexLint raises it
crawls_webtrains_modelsdeploys_chatbotprocesses_biometricsprocesses_voice
What we found
Section 23(1) requires a controller to notify the Authority of a personal data breach, in the form, manner, and within the time rules made under the Act determine. Section 23(2) requires the Authority to set, by rule, the circumstances triggering notice to the Authority, the circumstances triggering notice to the affected data subject, and the form and content of the notification.
The duty to notify the Authority is itself currently in force; the threshold, timeline, and whether the affected individual must be told are deferred entirely to rules made under section 52, which were not located this pass.