Cross-Border Data Transfer
Personal Data Protection Act, No. 9 of 2022 — cross border data flows
Sri Lanka · January 1, 2027, being the date appointed by Gazette Extraordinary No. 2498/16 of July 22, 2026 for Part III, in which s. 26 sits
Verify detailss. 26 splits the regime in two, and the 2025 Amendment Act changed the mechanism available to the private half. Public authorities face a localisation default: personal data is to be processed only in Sri Lanka and not in a third country, save as permitted, and the Minister may restrict the categories of personal data a public authority may send abroad. Every other controller and processor may effect cross-border data flows — defined as moving personal data out of Sri Lanka for processing in a third country — where they ensure continued compliance with the Act's obligations and adopt the safeguard instruments specified by directive of the Authority. The material change is that the Amendment Act removed the ministerial adequacy route the original s. 26 carried, so there is no country whitelist to rely on: the only route is accountability plus an instrument the Authority has specified, which makes the Authority's directives the operative document rather than the statute. Data in transit is reported to be outside the section. Marked 'check': the amending text is not available in machine-readable form here, so the substituted s. 26 was triangulated across independent Sri Lankan and international legal-reference sources; and confirm whether the Authority has yet specified any instrument, because until it does the compliant route is undefined. Commencement is January 1, 2027 for Part III, in which s. 26 sits.
This is a general reference, not legal advice or a determination that this law applies to your specific business. Run the full questionnaire to check against your actual presence, activities, and data types.