Law note · Sri Lanka
Personal Data Protection Act, cross-border transfer of personal data
What it requires
- An app transferring the personal data of a person in Sri Lanka abroad, including a voiceprint or other biometric identifier, must rely on an adequacy decision, Authority-specified appropriate safeguards, or one of section 26(5)'s derogations, such as explicit informed consent after risk disclosure. A public authority defaults to processing data only within Sri Lanka unless the Authority has affirmatively classified the category for third-country processing.
When LexLint raises it
crawls_webtrains_modelsprocesses_biometricsprocesses_voice
What we found
For a public authority, personal data shall be processed only in Sri Lanka and not in a third country, unless the Authority classifies categories permitted for third-country processing pursuant to a Ministerial adequacy decision, reviewed at least every two years (s.26(1)-(2)), a default-localization rule.
For a private controller or processor, transfer is permitted to a country covered by an adequacy decision, or elsewhere only with appropriate safeguards specified by the Authority (s.26(4)), or, absent both, only under listed derogations: explicit informed consent after risk disclosure, contract necessity, legal-claims necessity, public interest, or a life-or-safety emergency (s.26(5)).