Law note · Sri Lanka
Personal Data Protection Act, Data Protection Authority and penalties
What it requires
- An app processing the personal data of a person in Sri Lanka, including a biometric identifier, answers to the Data Protection Authority, which may investigate on complaint or its own initiative and direct corrective action, cessation of non-compliant processing, or compensation to an aggrieved person; Sri Lanka gives a data subject no standalone civil right of action of their own, only this regulator-administered compensation route.
When LexLint raises it
crawls_webtrains_modelsgenerates_contentdeploys_chatbotautomated_outreachhigh_risk_decisionsprocesses_voiceprocesses_biometrics
- Private right of action
- No
What we found
The Data Protection Authority (Part V, operative since July 2023, with the Chairman and Board appointed October 2023) is a body corporate that may sue and be sued. Under section 35, on complaint or its own initiative, the Authority may investigate a controller or processor and, after a hearing, direct it to cease non-compliant processing, take corrective action, or pay compensation to an aggrieved person who has suffered harm, loss, or damage.
Failure to comply with a directive triggers a monetary penalty under section 38 of up to Rs 10,000,000 per non-compliance, doubling for each subsequent one, collected by the Authority (net of any compensation payable) and credited to the Consolidated Fund; unpaid penalties are recoverable via the Magistrate Court of Colombo.
No standalone civil right of action was found; the Authority's directive-and-compensation mechanism under section 35(2)(c) is the only individual remedy, and it is regulator-administered rather than a court claim the data subject brings directly. Sections 35 and 38 themselves entered into force 18 March 2025, alongside the rest of Parts I-III and VII.