Law / Sri Lanka

Sri Lanka

privacy

Sri Lanka's Personal Data Protection Act, No. 9 of 2022 (PDPA) was certified by the Speaker 19 March 2022 and amended by the Personal Data Protection (Amendment) Act, No. 22 of 2025, certified 30 October 2025.

Commencement is phased by Part: Part V (the Data Protection Authority itself) began operation in July 2023; Parts VI, VIII, IX and X on 1 December 2023; and Parts I, II, III and VII, the entire substantive core (processing of personal data, data-subject rights, controller/processor duties, and penalties), on 18 March 2025.

Only Part IV (unsolicited-message provisions) remains unstarted, and the 2025 Amendment Act removed the fixed outer deadline for it entirely, leaving its commencement open-ended and Minister-discretionary. So every lawful-basis, special-category, data-subject-rights, cross-border-transfer, breach-notification, and enforcement duty this document describes has been in force since 18 March 2025.

Biometric data is an express special category, defined technology-neutrally to reach a voice-derived identifier by its own terms even though its illustrative list names only facial images, fingerprint, and iris data.

10 instruments named 6 researched in detail As of 2026-08-29

Instruments

Each one links to its LexLint note, which carries what it requires and what it flags on.

Breach notification

Personal Data Protection Act, breach notification duties

cite Personal Data Protection Act, No. 9 of 2022, as amended by Act No. 22 of 2025, s.23 stage IN FORCE in force since 2025-03-18 binds public and private bodies source official statute text, Parliament of Sri Lanka
What it requires

Section 23(1) requires a controller to notify the Authority of a personal data breach, in the form, manner, and within the time rules made under the Act determine. Section 23(2) requires the Authority to set, by rule, the circumstances triggering notice to the Authority, the circumstances triggering notice to the affected data subject, and the form and content of the notification.

The duty to notify the Authority is itself currently in force; the threshold, timeline, and whether the affected individual must be told are deferred entirely to rules made under section 52, which were not located this pass.

Comprehensive regime

Personal Data Protection Act, comprehensive regime and lawful basis

cite Personal Data Protection Act, No. 9 of 2022, as amended by Act No. 22 of 2025, Schedule I, ss.5, 18(1), 20-25 stage IN FORCE in force since 2025-03-18 binds public and private bodies source official statute text, Parliament of Sri Lanka
What it requires

Lawful basis, referenced by s.5 against Schedule I, follows a General Data Protection Regulation (GDPR) Article 6 shape: consent, contract necessity, legal obligation, vital interests, a public-interest task, or legitimate interest subject to a balancing test. Controller and processor duties are allocated at ss.20-25, with processors bound by written instructions and sub-processor flow-down duties.

Section 18(1) gives every data subject the right to request review of a decision based solely on automated processing that has created or is likely to create an irreversible and continuous impact on their rights and freedoms, subject to listed exceptions (authorized by law, authorized by the Authority, based on consent, or contract necessity). In force since 18 March 2025.

Cross border transfer

Personal Data Protection Act, cross-border transfer of personal data

cite Personal Data Protection Act, No. 9 of 2022, as amended by Act No. 22 of 2025, s.26 stage IN FORCE in force since 2025-03-18 binds public and private bodies source official statute text, Parliament of Sri Lanka
What it requires

For a public authority, personal data shall be processed only in Sri Lanka and not in a third country, unless the Authority classifies categories permitted for third-country processing pursuant to a Ministerial adequacy decision, reviewed at least every two years (s.26(1)-(2)), a default-localization rule.

For a private controller or processor, transfer is permitted to a country covered by an adequacy decision, or elsewhere only with appropriate safeguards specified by the Authority (s.26(4)), or, absent both, only under listed derogations: explicit informed consent after risk disclosure, contract necessity, legal-claims necessity, public interest, or a life-or-safety emergency (s.26(5)).

Data subject rights

Personal Data Protection Act, data subject rights

cite Personal Data Protection Act, No. 9 of 2022, as amended by Act No. 22 of 2025, ss.13-19 stage IN FORCE in force since 2025-03-18 binds public and private bodies source official statute text, Parliament of Sri Lanka, as amended
What it requires

Data subjects have rights of access (s.13), withdrawal of consent and cessation of further processing (s.14), rectification and completion (s.15), erasure (s.16), and (s.18) review of a decision based solely on automated processing. Section 17, amended in 2025, requires the controller to respond in writing within one month of a written request under ss.13-16 or 18, extendable by up to two further months with notice given before the original month expires.

Section 19, also amended in 2025, gives a right of appeal to the Authority against a controller's refusal on any of these grounds, with the Authority empowered to determine lawfulness and to direct compensation under s.35(2)(c).

Enforcement supervision

Personal Data Protection Act, Data Protection Authority and penalties

cite Personal Data Protection Act, No. 9 of 2022, as amended by Act No. 22 of 2025, ss.35, 38 stage IN FORCE in force since 2025-03-18 binds public and private bodies source official statute text, Parliament of Sri Lanka
What it requires

The Data Protection Authority (Part V, operative since July 2023, with the Chairman and Board appointed October 2023) is a body corporate that may sue and be sued. Under section 35, on complaint or its own initiative, the Authority may investigate a controller or processor and, after a hearing, direct it to cease non-compliant processing, take corrective action, or pay compensation to an aggrieved person who has suffered harm, loss, or damage.

Failure to comply with a directive triggers a monetary penalty under section 38 of up to Rs 10,000,000 per non-compliance, doubling for each subsequent one, collected by the Authority (net of any compensation payable) and credited to the Consolidated Fund; unpaid penalties are recoverable via the Magistrate Court of Colombo.

No standalone civil right of action was found; the Authority's directive-and-compensation mechanism under section 35(2)(c) is the only individual remedy, and it is regulator-administered rather than a court claim the data subject brings directly. Sections 35 and 38 themselves entered into force 18 March 2025, alongside the rest of Parts I-III and VII.

Sensitive categories

Personal Data Protection Act, special categories and biometric data

cite Personal Data Protection Act, No. 9 of 2022, as amended by Act No. 22 of 2025, s.56, Schedule II stage IN FORCE in force since 2025-03-18 binds public and private bodies source official statute text, Parliament of Sri Lanka
What it requires

Biometric data is defined at s.56 as personal data resulting from specific technical processing relating to the physical, physiological or behavioral characteristics of a natural person, which allow or confirm unique identification, including facial images, dactyloscopic (fingerprint) data, or iris-related data. Biometric data used for unique identification is one of the enumerated special categories of personal data.

Schedule II conditions processing of a special category on the data subject's consent (or a parent or guardian's for a child) unless another written law prohibits it regardless of consent, employment or social-security or defined public-health necessity, emergency necessity, data manifestly made public by the data subject, legal-claims necessity, or public interest under a written law with safeguards.

The operative definition's technology-neutral "physical, physiological or behavioral characteristics" language reaches a voice-derived identifier on its own terms, though the illustrative list names only facial images, fingerprint, and iris data, not voice specifically.

This summary covers the instruments LexLint has researched to a stage. Instruments named in the corpus but not yet researched are counted above and are not listed here. Every entry carries its own primary source on its note page. This is a research index, not legal advice.