Law note · Sri Lanka

Personal Data Protection Act, cross-border transfer of personal data

cite Personal Data Protection Act, No. 9 of 2022, as amended by Act No. 22 of 2025, s.26 stage IN FORCE in force since 2025-03-18 kind Cross border transfer binds public and private bodies reviewed 2026-08-29

What it requires

  • An app transferring the personal data of a person in Sri Lanka abroad, including a voiceprint or other biometric identifier, must rely on an adequacy decision, Authority-specified appropriate safeguards, or one of section 26(5)'s derogations, such as explicit informed consent after risk disclosure. A public authority defaults to processing data only within Sri Lanka unless the Authority has affirmatively classified the category for third-country processing.

When LexLint raises it

  • crawls_web
  • trains_models
  • processes_biometrics
  • processes_voice

What we found

For a public authority, personal data shall be processed only in Sri Lanka and not in a third country, unless the Authority classifies categories permitted for third-country processing pursuant to a Ministerial adequacy decision, reviewed at least every two years (s.26(1)-(2)), a default-localization rule.

For a private controller or processor, transfer is permitted to a country covered by an adequacy decision, or elsewhere only with appropriate safeguards specified by the Authority (s.26(4)), or, absent both, only under listed derogations: explicit informed consent after risk disclosure, contract necessity, legal-claims necessity, public interest, or a life-or-safety emergency (s.26(5)).

← Back to the example  ·  Lint your app →