Jurisdiction Guides / Asia-Pacific
Sri Lanka Privacy & Data Protection Laws
Every regime below can apply to a business handling Sri Lanka residents' data, depending on whether you have an established presence there, actively offer goods or services to residents, or monitor their behavior. This is a general reference, not a determination for your specific business — run the full questionnaire to see which of these actually apply to you.
Comprehensive Privacy Law · 1
Section 2 gives it GDPR-style extraterritorial reach: it applies to controllers and processors established in Sri Lanka, and to those outside Sri Lanka that offer goods or services to data subjects in Sri Lanka or monitor their behavior there. It carries a familiar apparatus — lawful bases, data-subject rights, DPO appointment for specified controllers, breach notification, and cross-border transfer controls — enforced by the Data Protection Authority of Sri Lanka, which was established ahead of the substantive provisions. Read the date line carefully, because an earlier commencement was reversed and the obligations are NOT yet in force. An Order appointing March 18, 2025 for Parts I, II, III and VII was repealed by Gazette Extraordinary No. 2427/34 of March 14, 2025, four days before it would have taken effect, so those Parts never commenced. The Personal Data Protection (Amendment) Act, No. 22 of 2025 (certified October 30, 2025) then removed the Act's fixed grace-period timetable altogether, leaving commencement wholly to an Order of the Minister published in the Gazette. Gazette Extraordinary No. 2498/16 of July 22, 2026 supplies that Order for the core of the regime: Part I (processing of personal data) and Part III (controllers and processors) come into operation January 1, 2027. Part II (rights of data subjects) and Part VII (offences and penalties) await a further Order, and Part IV (unsolicited messages) remains unappointed — so from January 1, 2027 Sri Lanka runs an unusual interim regime in which controller obligations bind before the data-subject rights and penalty provisions that would ordinarily enforce them. Marked 'check': the gazettes are not available in machine-readable form and the Authority's own 'dates of operation' page still displays the repealed March 18, 2025 notice, so this timeline was triangulated across independent legal-reference sources and Sri Lankan press reporting — confirm the current Orders with the Authority before relying on any single date.
Cross-Border Data Transfer · 1
s. 26 splits the regime in two, and the 2025 Amendment Act changed the mechanism available to the private half. Public authorities face a localisation default: personal data is to be processed only in Sri Lanka and not in a third country, save as permitted, and the Minister may restrict the categories of personal data a public authority may send abroad. Every other controller and processor may effect cross-border data flows — defined as moving personal data out of Sri Lanka for processing in a third country — where they ensure continued compliance with the Act's obligations and adopt the safeguard instruments specified by directive of the Authority. The material change is that the Amendment Act removed the ministerial adequacy route the original s. 26 carried, so there is no country whitelist to rely on: the only route is accountability plus an instrument the Authority has specified, which makes the Authority's directives the operative document rather than the statute. Data in transit is reported to be outside the section. Marked 'check': the amending text is not available in machine-readable form here, so the substituted s. 26 was triangulated across independent Sri Lankan and international legal-reference sources; and confirm whether the Authority has yet specified any instrument, because until it does the compliant route is undefined. Commencement is January 1, 2027 for Part III, in which s. 26 sits.
Data Security & Breach Notification · 1
The breach duty is not yet live, and the date it goes live has moved twice. s. 23 requires notification following a personal data breach; the Data Protection Authority has consulted on Personal Data Breach Notification Rules made under s. 23 read with s. 52, which set 72 hours from becoming aware for notifying the Authority and specify the content and manner of notice to the Authority and to data subjects, including where processors and sub-processors are involved. On commencement: an Order appointing March 18, 2025 was repealed days beforehand, the Amendment Act No. 22 of 2025 then stripped the Act of its fixed timetable, and Gazette Extraordinary No. 2498/16 of July 22, 2026 has now appointed January 1, 2027 for Part III — the controllers-and-processors Part in which s. 23 sits. Note what does NOT commence with it: Part VII (offences and penalties) awaits a further Order, so the duty will bind before its penalty backing does. Marked 'check' on two points. The gazette text could not be retrieved in machine-readable form, so the Part-level scope of the January 1, 2027 Order was triangulated from independent reporting rather than read directly; and the breach Rules were last seen in draft, so confirm they have been finalised before treating 72 hours as a live deadline.
Other Asia-Pacific jurisdictions