Data Security & Breach Notification
Personal Data Protection Act, No. 9 of 2022 — personal data breach notification
Sri Lanka · January 1, 2027, being the date appointed by Gazette Extraordinary No. 2498/16 of July 22, 2026 for Part III, in which s. 23 sits; an earlier appointment of March 18, 2025 was repealed before it took effect
Verify detailsThe breach duty is not yet live, and the date it goes live has moved twice. s. 23 requires notification following a personal data breach; the Data Protection Authority has consulted on Personal Data Breach Notification Rules made under s. 23 read with s. 52, which set 72 hours from becoming aware for notifying the Authority and specify the content and manner of notice to the Authority and to data subjects, including where processors and sub-processors are involved. On commencement: an Order appointing March 18, 2025 was repealed days beforehand, the Amendment Act No. 22 of 2025 then stripped the Act of its fixed timetable, and Gazette Extraordinary No. 2498/16 of July 22, 2026 has now appointed January 1, 2027 for Part III — the controllers-and-processors Part in which s. 23 sits. Note what does NOT commence with it: Part VII (offences and penalties) awaits a further Order, so the duty will bind before its penalty backing does. Marked 'check' on two points. The gazette text could not be retrieved in machine-readable form, so the Part-level scope of the January 1, 2027 Order was triangulated from independent reporting rather than read directly; and the breach Rules were last seen in draft, so confirm they have been finalised before treating 72 hours as a live deadline.
This is a general reference, not legal advice or a determination that this law applies to your specific business. Run the full questionnaire to check against your actual presence, activities, and data types.