Instruments
Each one links to its
LexLint note, which carries what it requires and what it flags on.
Breach notification
What it requires →
Section 23(1) requires a controller to notify the Authority of a personal data breach, in the form, manner, and within the time rules made under the Act determine. Section 23(2) requires the Authority to set, by rule, the circumstances triggering notice to the Authority, the circumstances triggering notice to the affected data subject, and the form and content of the notification.
The duty to notify the Authority is itself currently in force; the threshold, timeline, and whether the affected individual must be told are deferred entirely to rules made under section 52, which were not located this pass.
Comprehensive regime
What it requires →
Lawful basis, referenced by s.5 against Schedule I, follows a General Data Protection Regulation (GDPR) Article 6 shape: consent, contract necessity, legal obligation, vital interests, a public-interest task, or legitimate interest subject to a balancing test. Controller and processor duties are allocated at ss.20-25, with processors bound by written instructions and sub-processor flow-down duties.
Section 18(1) gives every data subject the right to request review of a decision based solely on automated processing that has created or is likely to create an irreversible and continuous impact on their rights and freedoms, subject to listed exceptions (authorized by law, authorized by the Authority, based on consent, or contract necessity). In force since 18 March 2025.
Cross border transfer
What it requires →
For a public authority, personal data shall be processed only in Sri Lanka and not in a third country, unless the Authority classifies categories permitted for third-country processing pursuant to a Ministerial adequacy decision, reviewed at least every two years (s.26(1)-(2)), a default-localization rule.
For a private controller or processor, transfer is permitted to a country covered by an adequacy decision, or elsewhere only with appropriate safeguards specified by the Authority (s.26(4)), or, absent both, only under listed derogations: explicit informed consent after risk disclosure, contract necessity, legal-claims necessity, public interest, or a life-or-safety emergency (s.26(5)).
Data subject rights
What it requires →
Data subjects have rights of access (s.13), withdrawal of consent and cessation of further processing (s.14), rectification and completion (s.15), erasure (s.16), and (s.18) review of a decision based solely on automated processing. Section 17, amended in 2025, requires the controller to respond in writing within one month of a written request under ss.13-16 or 18, extendable by up to two further months with notice given before the original month expires.
Section 19, also amended in 2025, gives a right of appeal to the Authority against a controller's refusal on any of these grounds, with the Authority empowered to determine lawfulness and to direct compensation under s.35(2)(c).
Enforcement supervision
What it requires →
The Data Protection Authority (Part V, operative since July 2023, with the Chairman and Board appointed October 2023) is a body corporate that may sue and be sued. Under section 35, on complaint or its own initiative, the Authority may investigate a controller or processor and, after a hearing, direct it to cease non-compliant processing, take corrective action, or pay compensation to an aggrieved person who has suffered harm, loss, or damage.
Failure to comply with a directive triggers a monetary penalty under section 38 of up to Rs 10,000,000 per non-compliance, doubling for each subsequent one, collected by the Authority (net of any compensation payable) and credited to the Consolidated Fund; unpaid penalties are recoverable via the Magistrate Court of Colombo.
No standalone civil right of action was found; the Authority's directive-and-compensation mechanism under section 35(2)(c) is the only individual remedy, and it is regulator-administered rather than a court claim the data subject brings directly. Sections 35 and 38 themselves entered into force 18 March 2025, alongside the rest of Parts I-III and VII.
Sensitive categories
What it requires →
Biometric data is defined at s.56 as personal data resulting from specific technical processing relating to the physical, physiological or behavioral characteristics of a natural person, which allow or confirm unique identification, including facial images, dactyloscopic (fingerprint) data, or iris-related data. Biometric data used for unique identification is one of the enumerated special categories of personal data.
Schedule II conditions processing of a special category on the data subject's consent (or a parent or guardian's for a child) unless another written law prohibits it regardless of consent, employment or social-security or defined public-health necessity, emergency necessity, data manifestly made public by the data subject, legal-claims necessity, or public interest under a written law with safeguards.
The operative definition's technology-neutral "physical, physiological or behavioral characteristics" language reaches a voice-derived identifier on its own terms, though the illustrative list names only facial images, fingerprint, and iris data, not voice specifically.