Under the Personal Data Protection Act No. 9 of 2022, businesses must be ready to identify a lawful basis for their processing, answer data-subject requests within twenty-one working days, and satisfy the rules on sending data abroad. Penalties can reach LKR 10 million for each non-compliance.
Sri Lanka now has a law telling organisations how they may collect and use personal data. The Act was the first comprehensive data protection statute in South Asia, and it borrows heavily from the European Union's General Data Protection Regulation, or GDPR. If your organisation handles personal data, whether it is based in Sri Lanka or simply deals with people who are, the Act applies to you.
What the Act does and when it applies
Parliament passed the Act on 19 March 2022, but it does not all switch on at once. It comes into force in stages. The Data Protection Authority of Sri Lanka, the regulator that runs the system, was set up in 2023. The parts that actually bite, meaning the rules on processing personal data, the rights of data subjects, the duties of controllers and processors, and the penalties, take effect on a date the Minister appoints by Gazette. A later amendment, the Personal Data Protection (Amendment) Act No. 22 of 2025, adjusted the scheme again. As things stand, those core obligations are not yet fully in force. The framework is settled even so, and organisations are expected to get ready while they wait.
Who the Act covers
The Act reaches well beyond Sri Lankan companies. It applies:
- Within Sri Lanka: where the processing of personal data takes place wholly or partly in Sri Lanka, or is carried out by a person or entity in Sri Lanka.
- Outside Sri Lanka: to entities abroad that offer goods or services to individuals in Sri Lanka, or that monitor the behaviour of individuals in Sri Lanka.
This extraterritorial reach mirrors the GDPR, and it means an overseas business with Sri Lankan customers or users can fall within the Act even without a local office.
What counts as personal data
Personal data is any information by which an individual can be identified, directly or indirectly, such as a name, an identification number, financial or location data, or an online identifier.
The Act gives extra protection to special categories of personal data, which include information revealing racial or ethnic origin, political opinions, religious beliefs, genetic and biometric data, health data, sex life or sexual orientation, information about criminal offences, and data relating to children.
The rights of individuals
The Act gives data subjects a set of enforceable rights over their personal data:
- Access: to confirm whether their data is being processed and obtain a copy.
- Withdraw consent: where the processing is based on consent.
- Object: to processing carried out on legitimate-interest or public-interest grounds.
- Rectification: to have inaccurate or incomplete data corrected or completed.
- Restriction: to limit processing in defined circumstances.
- Review of automated decisions: where a decision taken solely by automated means has a significant and irreversible effect.
- Erasure: to have their data deleted under specified conditions.
Section 17(1) gives the controller twenty-one working days from the date of the request to inform the data subject in writing whether the request has been granted, refused, or whether it has refrained from further processing, and to inform the data subject of the right of appeal against a refusal. There is no extension mechanism: the Act carries nothing equivalent to the further two months the GDPR allows for complex requests. Section 17(2) sets out the grounds on which a controller may refuse, including national security, public order, an investigation under any written law, and the technical and operational feasibility of acting on the request, and section 17(3) requires the reasons for any refusal to be recorded and produced to the Authority on request.
Sending data overseas
The Act restricts transfers of personal data out of Sri Lanka. A controller may transfer data abroad only where it continues to meet the Act's obligations and either puts in place a recognised safeguard, such as binding corporate rules, an appropriate contract, an approved code of conduct or certification scheme, or a transfer impact assessment, or can rely on a specific exception such as the individual's explicit consent or the performance of a contract.
Penalties
Enforcement sits with the Data Protection Authority. The Authority can impose a penalty of up to LKR 10 million for non-compliance, and for a repeat non-compliance it may impose an additional penalty of twice the amount imposed for the previous one.
What businesses should be doing now
Even though the substantive obligations are still being brought into force, preparing early is far easier than reacting to enforcement once it begins. Sensible first steps include:
- mapping what personal data the business holds, where it comes from, and where it flows;
- identifying a lawful basis for each type of processing;
- reviewing privacy notices, consent mechanisms and data-sharing arrangements;
- putting a process in place to handle data-subject requests within the time limits;
- checking any transfers of data outside Sri Lanka against the Act's transfer rules.
The PDPA moves Sri Lanka into line with the data protection standards already used across much of the world. For anyone holding personal data, wherever they are based, compliance will be a continuing duty rather than a box ticked once.







