🔒 Data Protection Regulatory Intelligence
Data Protection Monitor · dataprotection.gi
LK v13-gdpri-1.0.0
content: ai_generated legal review: never_reviewed (informational) publication gate: 0 failing5 sources retrieved model claude-sonnet-5 · 2026-08-05

Sri Lanka

LK schema gdpri-v2 trajectory: not yet assessedin transitionoverlaps: FIM, WPM, AIC

Last updated · 10 categories · 36 claims · 17 sources in the cumulative register

10Categoriesbaseline.[]
57Sub-modulesbaseline..sub_modules{}
36Claimsbaseline..claims[]
3Tier-1 sourcesrun_metadata.t1_source_count
Traffic-light mix (sums to 10 rendered categories; click to filter)
No red categories; 28 sub-modules are flagged red.

Jurisdiction brief

Standing brief, as of 25 August 2026.

Lead Signal

Sri Lanka's Personal Data Protection Act regime enters a distinctive in-transition state this cycle. The Data Protection Authority of Sri Lanka, established under the PDPA in August 2023, appointed its first permanent Director General in March 2026, a concrete institutional capacity-building milestone. At the same time, the Personal Data Protection (Amendment) Act, No. 22 of 2025 -- certified 30 October 2025 -- removed the original grace-period provisions for operationalisation, meaning the PDPA's remaining substantive Parts now commence only upon a future Ministerial Gazette Order rather than on a fixed schedule. As of June 2026, no such Ministerial Gazette Order commencing the PDPA's substantive Parts had been published. The result is a regulator that is institutionally live and building capacity, sitting atop a substantive legal framework with no fixed commencement date -- an open-ended regulatory uncertainty for market participants that is the central development of this cycle.

10 of 10 categories
Signal
Density

Selections OR within a group, AND across groups. Press / to search.

#

Comprehensive omnibus statute enacted and regulator operational, but core substantive Parts (I, II, III, VII) have had commencement dates repeatedly postponed and several implementing regulations remain in draft/consultation.

Primary frameworkPersonal Data Protection Act, No. 9 of 2022 (PDPA)
Supervisory authorityData Protection Authority of Sri Lanka
Traffic-light rationale — AmberComprehensive omnibus statute enacted and regulator operational, but core substantive Parts (I, II, III, VII) have had commencement dates repeatedly postponed and several implementing regulations remain in draft/consultation.

Sub-modules (5)

Regulator And AuthorityGreen

The Authority was established under Part V of the PDPA, which entered into force on 17 July 2023.

Claims (1):

  • Part V of the PDPA entered into force on 17 July 2023, thereby establishing the Data Protection Authority of Sri Lanka.

Act And InstrumentsAmber

PDPA No. 9 of 2022 was enacted/endorsed on 19 March 2022 and commences in phases via ministerial Order, with an October 2025 amendment further adjusting timelines and substantive provisions.

Claims (3):

  • The Personal Data Protection Act, No. 9 of 2022 was passed by the Parliament of Sri Lanka and endorsed on 19 March 2022.
  • Parts VI, VIII, IX and X of the PDPA entered into effect on 1 December 2023, with Parts I, II, III and VII scheduled to enter into effect on 18 March 2025 per a January 2024 commencement Order.
  • Sri Lanka's Parliament adopted amendments to the PDPA on 21 October 2025, which postponed operational dates, clarified automated-decision-making rights, limited DPO requirements, and introduced more flexible cross-border data transfer mechanisms.

Material ScopeGreen

The PDPA applies to processing of personal data generally but excludes purely personal/domestic/household processing.

Claims (1):

  • The PDPA does not apply to personal data processed purely for personal, domestic, or household purposes by an individual, or to data other than personal data (Section 2(3)).

Territorial ScopeGreen

The PDPA has extraterritorial reach, applying to controllers/processors outside Sri Lanka who offer goods/services to, or monitor the behaviour of, data subjects in Sri Lanka.

Claims (1):

  • The PDPA applies extraterritorially to processing that offers goods or services to data subjects in Sri Lanka (including targeted offerings) or that monitors the behaviour of data subjects in Sri Lanka, including profiling (Section 2(2)).

Regulator Registration And FilingRed

No general controller/processor registration or filing regime with the Authority was identified in available sources; the closest analogue is the DPO-communication duty and the data-protection-management-programme obligation, which are treated under controller_processor_duties.

Absence provenance: unavailable. Searched: Sri Lanka PDPA controller registration filing requirement, Sri Lanka Data Protection Authority registration regulations.

Category narrative65 words

Sri Lanka's Personal Data Protection Act, No. 9 of 2022 (PDPA) is the first comprehensive data-protection statute in the jurisdiction, establishing the Data Protection Authority of Sri Lanka. Commencement has been staggered by ministerial Order across 2023-2025, and a further October 2025 amendment postponed several operational dates and adjusted DPO/ADM/cross-border provisions, so the regime is best characterised as in transition rather than fully in force.

No new data since the standing brief. 1 periodic run re-emitted it unchanged.

Sources and claims (6)
  1. ConfirmedDataGuidance — Part V of the PDPA entered into force on 17 July 2023, thereby establishing the Data Protection Authority of Sri Lanka.observed
  2. ConfirmedDataGuidance — The Personal Data Protection Act, No. 9 of 2022 was passed by the Parliament of Sri Lanka and endorsed on 19 March 2022.observed
  3. ConfirmedDataGuidance — Parts VI, VIII, IX and X of the PDPA entered into effect on 1 December 2023, with Parts I, II, III and VII scheduled to enter into effect on 18 March 2025 per a January 2024 commencement Order.observed
  4. ProbableDataGuidance — Sri Lanka's Parliament adopted amendments to the PDPA on 21 October 2025, which postponed operational dates, clarified automated-decision-making rights, limited DPO requirements, and introduced more flexible cross-border data transfer mechanisms.observed
  5. ConfirmedDataGuidance — The PDPA does not apply to personal data processed purely for personal, domestic, or household purposes by an individual, or to data other than personal data (Section 2(3)).observed
  6. ConfirmedDataGuidance — The PDPA applies extraterritorially to processing that offers goods or services to data subjects in Sri Lanka (including targeted offerings) or that monitors the behaviour of data subjects in Sri Lanka, including profiling (Section 2(2)).observed

#

Core lawful-basis and special-category provisions exist in the Act text, but they sit in Parts (I-III) whose commencement date has been repeatedly postponed, and pseudonymisation/anonymisation rules were not located.

Primary frameworkPersonal Data Protection Act, No. 9 of 2022 (PDPA) — Schedules I, II, III
Supervisory authorityData Protection Authority of Sri Lanka
Traffic-light rationale — AmberCore lawful-basis and special-category provisions exist in the Act text, but they sit in Parts (I-III) whose commencement date has been repeatedly postponed, and pseudonymisation/anonymisation rules were not located.

Sub-modules (4)

Lawful BasesAmber

Schedule I (given effect via Section 5) enumerates lawful bases including consent, vital-interest emergencies, public-interest/statutory tasks, and legitimate interests.

Claims (2):

  • Under the PDPA, personal data may only be processed pursuant to the legal bases set out in Schedule I (Section 5), including responding to emergencies threatening life, health or safety, performance of a public-interest task or statutory power, and legitimate interests of the controller or a third party.
  • Schedule I further clarifies 'legitimate interests' to include processing where the data subject is a client or in the service of the controller, where processing is reasonably expected, and where strictly necessary for preventing fraud.

Special CategoriesAmber

Schedule II imposes additional conditions limiting the circumstances in which special/sensitive categories of personal data may be processed.

Claims (1):

  • The PDPA affords additional protection to special categories of personal data (sensitive data) by limiting the circumstances in which such data may be processed, per the conditions in Schedule II.

Pseudonymisation And AnonymisationRed

No PDPA provision or DPA guidance specifically defining pseudonymisation/anonymisation safe-harbours was located in available sources.

Absence provenance: unavailable. Searched: Sri Lanka PDPA pseudonymisation anonymisation definition, Sri Lanka Data Protection Authority anonymisation guidance.

Category narrative42 words

The PDPA sets out an enumerated set of lawful bases in Schedule I (Section 5), a defined consent standard elaborated in Schedule III, and enhanced conditions for special/sensitive categories in Schedule II. No specific statutory pseudonymisation/anonymisation safe-harbour was identified in available sources.

Sources and claims (4)
  1. ConfirmedDataGuidance — Under the PDPA, personal data may only be processed pursuant to the legal bases set out in Schedule I (Section 5), including responding to emergencies threatening life, health or safety, performance of a public-interest task or statutory power, and legitimate interests of the controller or a third party.observed
  2. ProbableDataGuidance — Schedule I further clarifies 'legitimate interests' to include processing where the data subject is a client or in the service of the controller, where processing is reasonably expected, and where strictly necessary for preventing fraud.observed
  3. ConfirmedDataGuidance — Consent under the PDPA is defined as a freely given, specific, informed, and unambiguous indication by written declaration or affirmative action signifying the data subject's agreement, with further conditions elaborated in Schedule III.observed
  4. ConfirmedDataGuidance — The PDPA affords additional protection to special categories of personal data (sensitive data) by limiting the circumstances in which such data may be processed, per the conditions in Schedule II.observed

#

Rights exist in principle under the Act, but implementing regulations governing procedure/deadlines were still in public-consultation draft form as of late 2024, and core Parts covering these rights had postponed commencement.

Primary frameworkPersonal Data Protection Act, No. 9 of 2022 (PDPA)
Supervisory authorityData Protection Authority of Sri Lanka
Traffic-light rationale — AmberRights exist in principle under the Act, but implementing regulations governing procedure/deadlines were still in public-consultation draft form as of late 2024, and core Parts covering these rights had postponed commencement.

Sub-modules (5)

Access RightAmber

The Authority sought public input on draft fee regulations for data-subject-rights requests, implying an access/rights-request mechanism is being operationalised, but the underlying statutory access-request procedure text was not retrieved.

Claims (1):

  • The Data Protection Authority of Sri Lanka sought public input on draft fee regulations for data-subject-rights requests under the PDPA.

Rectification And ErasureRed

General strengthening of data-subject rights is stated as a Section 1/PDPA objective; specific rectification/erasure mechanics were not located.

Absence provenance: unavailable. Searched: Sri Lanka PDPA rectification erasure right to be forgotten section.

Restriction And ObjectionRed

No specific restriction-of-processing or objection-right provision text was retrieved in available sources.

Absence provenance: unavailable. Searched: Sri Lanka PDPA right to object restriction of processing.

Data PortabilityRed

No specific data-portability provision was identified in available sources.

Absence provenance: unavailable. Searched: Sri Lanka PDPA data portability right.

Deadlines And Response WindowsAmber

The Authority ran a 2024 consultation on draft regulations for data-subject rights and appeals, and separately on fee regulations for rights requests, indicating response-window mechanics were still being finalised via secondary legislation as of the survey window.

Claims (1):

  • The Authority sought public input on draft regulations for data subjects' rights and appeals under the PDPA, extending the feedback deadline to 15 November 2024.
Category narrative58 words

The PDPA is described as strengthening data-subject rights, and the Authority has run consultations on draft regulations for DSAR rights and appeals and fee schedules for rights requests, but concrete statutory deadlines and detailed mechanics for access, rectification, erasure, restriction, objection and portability were not located in available secondary sources — much of this remains in draft-regulation form.

Sources and claims (2)
  1. ProbableDataGuidance — The Data Protection Authority of Sri Lanka sought public input on draft fee regulations for data-subject-rights requests under the PDPA.observed
  2. ProbableDataGuidance — The Authority sought public input on draft regulations for data subjects' rights and appeals under the PDPA, extending the feedback deadline to 15 November 2024.observed

#

Substantive duties are set out in the Act, but a cluster of implementing regulations were still in draft/consultation stage as of the last confirmed update, and the DPO obligation itself was narrowed by the pending 2025 amendment.

Primary frameworkPersonal Data Protection Act, No. 9 of 2022 (PDPA)
Supervisory authorityData Protection Authority of Sri Lanka
Traffic-light rationale — AmberSubstantive duties are set out in the Act, but a cluster of implementing regulations were still in draft/consultation stage as of the last confirmed update, and the DPO obligation itself was narrowed by the pending 2025 amendment.

Sub-modules (7)

Accountability And DpiaAmber

Controllers must implement a Data Protection Management Programme and conduct Data Protection Impact Assessments (DPIAs) where applicable; the Authority ran a 2024 public consultation on draft PDPIA regulations.

Claims (2):

  • Controllers under the PDPA must implement a Data Protection Management Programme.
  • Controllers under the PDPA must conduct Data Protection Impact Assessments (DPIAs) where applicable, and the Authority launched a public consultation on draft PDPIA regulations.

Dpo RequirementsAmber

The PDPA requires appointment of a Data Protection Officer; the Authority consulted on draft DPO-appointment regulations in 2024, and the October 2025 amendment is reported to have introduced 'limited DPO requirements', narrowing the original obligation.

Claims (2):

  • The PDPA requires the appointment of a Data Protection Officer (DPO), and the Authority sought public input on draft DPO-appointment regulations under the Act.
  • The October 2025 amendments to the PDPA are reported to include 'limited DPO requirements', narrowing the scope of the original DPO-appointment obligation.

Ropa RequirementsAmber

The Data Protection Management Programme obligation functions as the PDPA's closest analogue to records-of-processing requirements; a dedicated ROPA provision distinct from the DPMP was not separately confirmed.

Claims (1):

  • Controllers under the PDPA must implement a Data Protection Management Programme.

Joint Controller ArrangementsAmber

Processors must comply with the controller's written instructions and confidentiality measures; specific joint-controller apportionment-of-liability provisions were not separately located.

Claims (1):

  • Processors under the PDPA must comply with the controller's written instructions and confidentiality measures.

Security MeasuresGreen

Section 10 of the PDPA requires controllers to ensure integrity and confidentiality of personal data using appropriate technical and organisational measures.

Claims (1):

  • Section 10 of the PDPA requires controllers to ensure integrity and confidentiality of personal data by using appropriate technical and organisational measures.

Breach NotificationAmber

The PDPA mandates notification of personal data breaches; the Authority launched a public consultation on draft breach-notification rules under the PDPA, indicating implementing detail was still being finalised.

Claims (2):

  • The PDPA mandates notification of data breaches and imposes conditions on processing personal data outside Sri Lanka, requiring adequacy decisions or appropriate safeguards.
  • The Data Protection Authority of Sri Lanka launched a public consultation on draft rules for data breach notifications under the PDPA.

Retention And DisposalRed

No specific statutory retention-period or disposal-duty provision was located in available sources.

Absence provenance: unavailable. Searched: Sri Lanka PDPA data retention disposal period.

Category narrative61 words

The PDPA imposes an accountability framework requiring a Data Protection Management Programme, DPIAs for higher-risk processing, DPO appointment (narrowed by the October 2025 amendment), processor obligations to act on written instructions with confidentiality safeguards, security-of-processing duties (Section 10), and mandatory breach notification — though several implementing regulations (DPO appointment, PDPIA, breach notification, DPMP guidelines) remained in public-consultation draft form through 2024.

Sources and claims (8)
  1. ConfirmedDataGuidance — Controllers under the PDPA must implement a Data Protection Management Programme.observed
  2. ConfirmedDataGuidance — Controllers under the PDPA must conduct Data Protection Impact Assessments (DPIAs) where applicable, and the Authority launched a public consultation on draft PDPIA regulations.observed
  3. ConfirmedDataGuidance — The PDPA requires the appointment of a Data Protection Officer (DPO), and the Authority sought public input on draft DPO-appointment regulations under the Act.observed
  4. UncertainDataGuidance — The October 2025 amendments to the PDPA are reported to include 'limited DPO requirements', narrowing the scope of the original DPO-appointment obligation.observed
  5. ConfirmedDataGuidance — Processors under the PDPA must comply with the controller's written instructions and confidentiality measures.observed
  6. ConfirmedDataGuidance — Section 10 of the PDPA requires controllers to ensure integrity and confidentiality of personal data by using appropriate technical and organisational measures.observed
  7. ConfirmedDataGuidance — The PDPA mandates notification of data breaches and imposes conditions on processing personal data outside Sri Lanka, requiring adequacy decisions or appropriate safeguards.observed
  8. ProbableDataGuidance — The Data Protection Authority of Sri Lanka launched a public consultation on draft rules for data breach notifications under the PDPA.observed

#

A transfer-mechanism framework exists in the Act, but implementing directives were in draft/consultation form and no adequacy decisions to or from Sri Lanka were identified.

Primary frameworkPersonal Data Protection Act, No. 9 of 2022 (PDPA)
Supervisory authorityData Protection Authority of Sri Lanka
Traffic-light rationale — AmberA transfer-mechanism framework exists in the Act, but implementing directives were in draft/consultation form and no adequacy decisions to or from Sri Lanka were identified.

Sub-modules (6)

Transfer MechanismsAmber

Cross-border transfers require either an adequacy-type decision or appropriate safeguards, including a legally binding enforceable instrument with the overseas recipient or another Authority-approved mechanism.

Claims (2):

  • The PDPA outlines conditions for processing personal data outside Sri Lanka, requiring adequacy decisions or appropriate safeguards.
  • To ensure compliance for overseas processing, a controller must enter into a legally binding and enforceable instrument with the recipient located outside Sri Lanka, or adopt another instrument determined by the Authority.

Adequacy ReceivedRed

No adequacy decision received by Sri Lanka from another regime (e.g. EU/UK) was identified in available sources.

Absence provenance: unavailable. Searched: Sri Lanka EU adequacy decision, Sri Lanka UK adequacy PDPA.

Adequacy GrantedAmber

No formal Sri Lankan adequacy determinations regarding third countries were identified; the Authority is instead developing a directive to classify personal-data categories for cross-border processing.

Claims (1):

  • The Data Protection Authority sought public input on a draft directive for classifying personal-data categories for processing abroad.

Sccs And BcrsAmber

No finalised standard-contractual-clause or binding-corporate-rules template issued by the Authority was located; the Act contemplates a 'legally binding and enforceable instrument' as one safeguard mechanism.

Claims (1):

  • To ensure compliance for overseas processing, a controller must enter into a legally binding and enforceable instrument with the recipient located outside Sri Lanka, or adopt another instrument determined by the Authority.

Transfer Impact AssessmentRed

No standalone transfer-impact-assessment requirement distinct from the general safeguard/adequacy mechanism was identified.

Absence provenance: unavailable. Searched: Sri Lanka PDPA transfer impact assessment requirement.

Data LocalisationAmber

The PDPA provisions governing cross-border data transfers carry data-localisation implications, generally requiring processing to remain within Sri Lanka unless permitted to be processed in a third country under the safeguard regime.

Claims (1):

  • The PDPA's cross-border data transfer provisions have data-localisation implications applicable to all controllers and processors intending to process personal data outside of Sri Lanka.
Category narrative74 words

The PDPA restricts cross-border transfers unless the destination benefits from an adequacy-type decision or the controller puts in place appropriate safeguards (including a legally binding enforceable instrument with the overseas recipient), and these provisions carry data-localisation implications for controllers/processors processing outside Sri Lanka. The Authority has run consultations on directives for processing personal data abroad and for classifying personal-data categories for overseas processing, and the October 2025 amendment reportedly introduced more flexible transfer mechanisms.

No new data since the standing brief. 1 periodic run re-emitted it unchanged.

Sources and claims (4)
  1. ConfirmedDataGuidance — The PDPA outlines conditions for processing personal data outside Sri Lanka, requiring adequacy decisions or appropriate safeguards.observed
  2. ProbableParliament of Sri Lanka (hosted via DataGuidance) — To ensure compliance for overseas processing, a controller must enter into a legally binding and enforceable instrument with the recipient located outside Sri Lanka, or adopt another instrument determined by the Authority.observed
  3. ProbableDataGuidance — The Data Protection Authority sought public input on a draft directive for classifying personal-data categories for processing abroad.observed
  4. ConfirmedDataGuidance — The PDPA's cross-border data transfer provisions have data-localisation implications applicable to all controllers and processors intending to process personal data outside of Sri Lanka.observed

#

General cross-sector coordination is committed to in policy statements, but dedicated sectoral overlay statutes/regulations for financial services, health, employment, credit, education, or insurance were not located.

Primary frameworkPersonal Data Protection Act, No. 9 of 2022 (PDPA)
Supervisory authorityData Protection Authority of Sri Lanka
Traffic-light rationale — AmberGeneral cross-sector coordination is committed to in policy statements, but dedicated sectoral overlay statutes/regulations for financial services, health, employment, credit, education, or insurance were not located.

Sub-modules (7)

Financial Sector OverlayAmber

The Authority is intended to engage with the Central Bank of Sri Lanka and the Securities and Exchange Commission to ensure proper governance of personal data in the financial sector.

Claims (1):

  • Sri Lanka's 2023 budget speech confirmed the Authority will be independent and engaged with the Central Bank of Sri Lanka and Securities and Exchange Commission to ensure proper governance of personal data.

Health Sector OverlayRed

No dedicated health-sector data-protection overlay statute was identified.

Absence provenance: unavailable. Searched: Sri Lanka health data protection law overlay.

Telecoms And EprivacyAmber

The Authority is intended to engage with the Telecommunications Regulatory Commission of Sri Lanka (TRCSL) for governance of personal data in the telecoms sector; no separate ePrivacy-style statute was identified.

Claims (1):

  • The 2023 budget speech confirmed the Authority will engage with the Telecommunications Regulatory Commission of Sri Lanka and other relevant sectoral regulators to ensure proper governance of personal data.

Employment DataRed

No dedicated employment-data overlay was identified beyond general PDPA coverage.

Absence provenance: unavailable. Searched: Sri Lanka employment data protection code.

Credit And ScoringRed

No dedicated credit-scoring data-protection overlay was identified.

Absence provenance: unavailable. Searched: Sri Lanka credit scoring data protection regulation.

EducationRed

No dedicated education-sector data-protection overlay was identified.

Absence provenance: unavailable. Searched: Sri Lanka education sector data protection rules.

InsuranceRed

No dedicated insurance-sector data-protection overlay was identified.

Absence provenance: unavailable. Searched: Sri Lanka insurance sector data protection regulation.

Category narrative63 words

Sri Lanka does not appear to have distinct sector-specific data-protection statutes (health, credit, education, insurance) separate from the PDPA; instead, the 2023 budget speech committed the incoming Authority to independent operation while engaging with the Central Bank of Sri Lanka, the Securities and Exchange Commission, and the Telecommunications Regulatory Commission of Sri Lanka (TRCSL) to ensure coordinated governance of personal data across sectors.

Sources and claims (2)
  1. ProbableDataGuidance — Sri Lanka's 2023 budget speech confirmed the Authority will be independent and engaged with the Central Bank of Sri Lanka and Securities and Exchange Commission to ensure proper governance of personal data.observed
  2. ProbableDataGuidance — The 2023 budget speech confirmed the Authority will engage with the Telecommunications Regulatory Commission of Sri Lanka and other relevant sectoral regulators to ensure proper governance of personal data.observed

#

Direct marketing is explicitly addressed by statute; other adtech-adjacent sub-modules (cookies, dark patterns, opt-out signals, clean rooms, cross-context advertising) have no located statutory or DPA-guidance basis.

Primary frameworkPersonal Data Protection Act, No. 9 of 2022 (PDPA), Part IV
Supervisory authorityData Protection Authority of Sri Lanka
Traffic-light rationale — AmberDirect marketing is explicitly addressed by statute; other adtech-adjacent sub-modules (cookies, dark patterns, opt-out signals, clean rooms, cross-context advertising) have no located statutory or DPA-guidance basis.

Sub-modules (6)

Cookies And TrackersRed

No cookie/tracker-specific consent regime was identified in the PDPA or Authority guidance.

Absence provenance: unavailable. Searched: Sri Lanka PDPA cookies consent regulation.

Dark PatternsRed

No dark-pattern prohibition was identified in available sources.

Absence provenance: unavailable. Searched: Sri Lanka PDPA dark patterns prohibition.

Opt Out SignalsRed

No recognised technical opt-out signal (e.g. Global Privacy Control analogue) was identified.

Absence provenance: unavailable. Searched: Sri Lanka PDPA opt-out signal Global Privacy Control.

Clean Rooms And DcrRed

No clean-room/data-collaboration-room framework was identified.

Absence provenance: unavailable. Searched: Sri Lanka data clean room regulation.

Cross Context AdvertisingRed

No 'sale'/'share'-style cross-context advertising provision analogous to US state law was identified.

Absence provenance: unavailable. Searched: Sri Lanka PDPA cross-context advertising sale of data.

Direct MarketingAmber

Part IV of the PDPA (Section 27) prohibits a controller from disseminating unsolicited messages to an identified or identifiable data subject, subject to specified exceptions.

Claims (1):

  • Section 27 of the PDPA provides that a controller shall not disseminate unsolicited messages to any identified or identifiable data subject, subject to conditions in the Act.
Category narrative31 words

The PDPA's Part IV restricts the use of personal data for unsolicited direct-marketing messages; no cookie/tracker-specific consent regime, dark-pattern prohibition, recognised opt-out signal, or clean-room framework was identified in available sources.

Sources and claims (1)
  1. ProbableParliament of Sri Lanka (hosted via DataGuidance) — Section 27 of the PDPA provides that a controller shall not disseminate unsolicited messages to any identified or identifiable data subject, subject to conditions in the Act.observed

#

ADM and profiling are addressed at a scope/definitional level and via a reported 2025 amendment, but dedicated biometric, genetic-data, and AI-risk-assessment regimes were not confirmed as enacted.

Primary frameworkPersonal Data Protection Act, No. 9 of 2022 (PDPA)
Supervisory authorityData Protection Authority of Sri Lanka
Traffic-light rationale — AmberADM and profiling are addressed at a scope/definitional level and via a reported 2025 amendment, but dedicated biometric, genetic-data, and AI-risk-assessment regimes were not confirmed as enacted.

Sub-modules (6)

Profiling RestrictionsAmber

The PDPA's territorial-scope provision captures profiling of data subjects in Sri Lanka undertaken with the intention of making decisions about their behaviour.

Claims (1):

  • The PDPA applies to processing that specifically monitors the behaviour of data subjects in Sri Lanka, including profiling with the intention of making decisions about such behaviour, insofar as it takes place in Sri Lanka.

Automated Decision Making TransparencyAmber

The October 2025 PDPA amendments are reported to have clarified automated-decision-making rights.

Claims (1):

  • Sri Lanka's October 2025 PDPA amendments clarified automated decision-making rights for data subjects.

Ai Risk AssessmentsRed

A Gazette reportedly repealed prior PDPA enforcement dates pending amendments tied to AI and technology adoption, signalling anticipated but not-yet-enacted AI-specific regulatory activity.

Claims (1):

  • A Sri Lankan Gazette reportedly repealed prior PDPA enforcement dates pending further amendments related to AI and technology adoption.

Biometric RegimeRed

No dedicated biometric-data regime (facial recognition, fingerprint, gait) distinct from the general personal-data definition was identified.

Absence provenance: unavailable. Searched: Sri Lanka PDPA biometric data facial recognition regulation.

Genetic DataAmber

Genetic factors are referenced within the PDPA's general 'personal data' definition as one of the identifying attributes, but no dedicated genetic-data regime was found.

Claims (1):

  • The PDPA's definition of personal data includes factors specific to the physical, physiological, genetic, psychological, economic, cultural, or social identity of a natural person.

State Surveillance CarveoutsAmber

Section 40 of the PDPA outlines exemptions, restrictions and derogations primarily relating to national security and public interest.

Claims (1):

  • Section 40 of the PDPA outlines several exemptions, restrictions, and derogations, primarily in relation to national security and public interest.
Category narrative65 words

The PDPA's extraterritorial-scope trigger expressly captures profiling used to make decisions about data subjects' behaviour in Sri Lanka, and the October 2025 amendment reportedly clarified automated-decision-making rights. National-security/public-interest carve-outs are set out in Section 40. No dedicated biometric- or genetic-data regime, or AI-specific risk-assessment obligation, was confirmed beyond genetic/physiological factors being folded into the general 'personal data' definition and a Gazette signalling pending AI-related amendments.

Sources and claims (5)
  1. ConfirmedDataGuidance — The PDPA applies to processing that specifically monitors the behaviour of data subjects in Sri Lanka, including profiling with the intention of making decisions about such behaviour, insofar as it takes place in Sri Lanka.observed
  2. UncertainDataGuidance — Sri Lanka's October 2025 PDPA amendments clarified automated decision-making rights for data subjects.observed
  3. SpeculativeDataGuidance — A Sri Lankan Gazette reportedly repealed prior PDPA enforcement dates pending further amendments related to AI and technology adoption.observed
  4. ConfirmedDataGuidance — The PDPA's definition of personal data includes factors specific to the physical, physiological, genetic, psychological, economic, cultural, or social identity of a natural person.observed
  5. ConfirmedDataGuidance — Section 40 of the PDPA outlines several exemptions, restrictions, and derogations, primarily in relation to national security and public interest.observed

#

Targeted searches for children/minors provisions in the PDPA and DPA guidance returned no relevant results.

Supervisory authorityData Protection Authority of Sri Lanka
Traffic-light rationale — Not assessedTargeted searches for children/minors provisions in the PDPA and DPA guidance returned no relevant results.

Sub-modules (5)

Age VerificationRed

No age-of-consent or age-verification provision was identified.

Absence provenance: unavailable. Searched: Sri Lanka PDPA age of consent minors.

Minor Profiling BansRed

No minor-specific profiling ban was identified.

Absence provenance: unavailable. Searched: Sri Lanka PDPA minor profiling ban.

Education SettingsRed

No education-setting-specific data-protection rule was identified.

Absence provenance: unavailable. Searched: Sri Lanka PDPA education sector children data.

Dependent AdultsRed

No dependent-adult-specific protection was identified.

Absence provenance: unavailable. Searched: Sri Lanka PDPA dependent adults incapacitated persons data protection.

Category narrative24 words

No PDPA provision or Authority guidance addressing age of consent, parental-consent mechanisms, minor-profiling bans, education-setting-specific rules, or dependent-adult protections was located in available sources.

#

Enforcement powers exist on the statute's face, but no confirmed enforcement decisions/fines were located, and the underlying substantive obligations remain subject to a shifting commencement timetable.

Primary frameworkPersonal Data Protection Act, No. 9 of 2022 (PDPA)
Supervisory authorityData Protection Authority of Sri Lanka
Traffic-light rationale — AmberEnforcement powers exist on the statute's face, but no confirmed enforcement decisions/fines were located, and the underlying substantive obligations remain subject to a shifting commencement timetable.

Sub-modules (6)

Regulator Powers And PenaltiesAmber

The Authority may impose fines payable into the Consolidated Fund; non-payment is enforceable via application to the Magistrate Court of Colombo, and penalty imposition does not preclude other regulatory measures such as suspension or licence cancellation.

Claims (2):

  • A person liable to a fine under the PDPA who fails to pay may have the Authority apply to the Magistrate Court of Colombo for an order requiring payment, recoverable in like manner as a court-imposed fine even if it exceeds the court's ordinary fining jurisdiction.
  • Imposition of a penalty under the PDPA does not preclude a supervisory or regulatory authority from taking other regulatory measures, including suspension of a business/profession or cancellation of a licence.

Enforcement Activity IndexRed

No published enforcement decisions or fines were located; Authority activity to date has centred on consultations, circulars and draft directives.

Absence provenance: unavailable. Searched: Sri Lanka Data Protection Authority fine enforcement decision.

Claims (1):

  • The Data Protection Authority's public activity to date includes issuing a compliance circular for public-sector authorities and multiple public consultations on draft directives/regulations, rather than published enforcement decisions.

Regulator Funding And CapacityAmber

The 2023 budget speech committed to an independent Authority, but no headcount or budget figures were located.

Absence provenance: unavailable. Searched: Sri Lanka Data Protection Authority budget staffing headcount.

Claims (1):

  • Sri Lanka's 2023 budget speech confirmed government commitment to establishing an independent Data Protection Authority.

Collective Redress And Class ActionsRed

No collective-redress or class-action mechanism specific to the PDPA was identified.

Absence provenance: unavailable. Searched: Sri Lanka PDPA class action collective redress.

Private Right Of ActionRed

No private right of direct court action distinct from Authority-mediated enforcement was identified.

Absence provenance: unavailable. Searched: Sri Lanka PDPA private right of action civil suit.

Recent Developments 180DAmber

Sri Lanka's Parliament adopted amendments to the PDPA on 21 October 2025, and a Gazette reportedly repealed prior PDPA enforcement dates pending amendments tied to AI and technology adoption.

Claims (2):

  • Sri Lanka's Parliament adopted amendments to the PDPA on 21 October 2025, which postponed operational dates, clarified automated-decision-making rights, limited DPO requirements, and introduced more flexible cross-border data transfer mechanisms.
  • A Sri Lankan Gazette reportedly repealed prior PDPA enforcement dates pending further amendments related to AI and technology adoption.
Category narrative91 words

The PDPA gives the Authority power to impose financial penalties (payable into the Consolidated Fund) enforceable through the Magistrate Court of Colombo for non-payment, and other regulatory measures including suspension of business/profession or cancellation of licences, without precluding sectoral regulators' own powers. As of the last confirmed update the Authority's public activity has been dominated by consultations, draft directives and circulars rather than published enforcement decisions, consistent with the still-staggered commencement of the Act's substantive Parts. The most recent material development is the 21 October 2025 Parliamentary adoption of PDPA amendments.

No new data since the standing brief. 1 periodic run re-emitted it unchanged.

Sources and claims (4)
  1. ProbableParliament of Sri Lanka (hosted via DataGuidance) — A person liable to a fine under the PDPA who fails to pay may have the Authority apply to the Magistrate Court of Colombo for an order requiring payment, recoverable in like manner as a court-imposed fine even if it exceeds the court's ordinary fining jurisdiction.observed
  2. ProbableParliament of Sri Lanka (hosted via DataGuidance) — Imposition of a penalty under the PDPA does not preclude a supervisory or regulatory authority from taking other regulatory measures, including suspension of a business/profession or cancellation of a licence.observed
  3. ProbableDataGuidance — The Data Protection Authority's public activity to date includes issuing a compliance circular for public-sector authorities and multiple public consultations on draft directives/regulations, rather than published enforcement decisions.observed
  4. ProbableDataGuidance — Sri Lanka's 2023 budget speech confirmed government commitment to establishing an independent Data Protection Authority.observed
No categories match.

Filters combine as OR inside a group and AND across groups.

Publication gate

No failing checks.

schema_validpass
min_t1_per_instrument_metn/a — no subject in this jurisdiction
min_quoted_text_presentwaived — floor 0%
translation_provenance_recordedn/a — no subject in this jurisdiction
egress_verifiedpass
source_tier_integrity_okpass
jurisdiction_source_floor_metpass
tier_a_b_national_primary_pct20.0
aggregator_only_jurisdiction_count0
manual_override

Editorial metadata

Provenance only. Nothing below gates publication or affects the render.

Editorial metadata for Sri Lanka
FieldValue
trust.lawyer_review.statusnever_reviewed
trust.lawyer_review.reviewerno reviewer on record
trust.content_sourceai_generated

Provenance and declared absence

Disclosure model: category cards load OPEN; narratives render in full; standing narratives load as a clamped teaser with an explicit “read full” control carrying the true word count. No text is hidden without disclosing how much of it there is.

Sub-modules are DP-specific nested subsections with their own real per-sub-module traffic light, rendered under each category (BRIEF section 2b.5). Neither WPM nor the crypto monitor carries this field.

Traffic-light dots are REAL data (baseline.<category>.traffic_light), not renderer-invented taxonomy, and are never suppressed -- unlike WPM, where a RAG dot would be forbidden as invented severity.

Family/accent taxonomy is renderer-level presentation config, not a JID field; it decorates the RAG dot, it does not replace it. Colour is always duplicated in text and is never the sole carrier of meaning.

Suppressed by doctrine: derived risk score; derived_scores = {}.

Band honesty: uncertainty bands are computed against a frozen build clock of 2026-10-02. A year-precision row is never promoted into a tighter band.

Envelope: baseline resolved at jurisdiction_json.baseline; 10 categories, 57 sub-module(s), 36 claim(s) (36 category placement(s)), 17 source(s) in the cumulative register.

Think something on this page is wrong? Report an error.

GDPR article map

Cross-reference: which category/sub-module covers each UK GDPR article (35 mapped).

Show article map
GDPR article to category mapping
ArticleCategorySub-module
Art. 5Controller/Processor Dutiesaccountability and dpia
Art. 6Lawful Processing & Special Datalawful bases
Art. 7Lawful Processing & Special Dataconsent thresholds
Art. 9Lawful Processing & Special Dataspecial categories
Art. 13Data Subject Rightsaccess right
Art. 14Data Subject Rightsaccess right
Art. 15Data Subject Rightsaccess right
Art. 16Data Subject Rightsrectification and erasure
Art. 17Data Subject Rightsrectification and erasure
Art. 18Data Subject Rightsrestriction and objection
Art. 19Data Subject Rightsrectification and erasure
Art. 20Data Subject Rightsdata portability
Art. 21Data Subject Rightsrestriction and objection
Art. 22Algorithmic, Biometric & Surveillance Governanceautomated decision making transparency
Art. 25Controller/Processor Dutiesaccountability and dpia
Art. 28Controller/Processor Dutiesjoint controller arrangements
Art. 30Controller/Processor Dutiesropa requirements
Art. 32Controller/Processor Dutiessecurity measures
Art. 33Controller/Processor Dutiesbreach notification
Art. 34Controller/Processor Dutiesbreach notification
Art. 35Controller/Processor Dutiesaccountability and dpia
Art. 37Controller/Processor Dutiesdpo requirements
Art. 38Controller/Processor Dutiesdpo requirements
Art. 39Controller/Processor Dutiesdpo requirements
Art. 44Cross-Border & Adequacytransfer mechanisms
Art. 45Cross-Border & Adequacyadequacy received
Art. 46Cross-Border & Adequacysccs and bcrs
Art. 47Cross-Border & Adequacysccs and bcrs
Art. 49Cross-Border & Adequacytransfer mechanisms
Art. 77Enforcement & Redresscollective redress and class actions
Art. 78Enforcement & Redressprivate right of action
Art. 79Enforcement & Redressprivate right of action
Art. 82Enforcement & Redresscollective redress and class actions
Art. 83Enforcement & Redressregulator powers and penalties
Art. 84Enforcement & Redressregulator powers and penalties

Self-audit

Regulator_and_framework, lawful_processing_and_special_data, controller_processor_duties, cross_border_and_adequacy, algorithmic_biometric_and_surveillance_governance and enforcement_and_redress drew on the PDPA's own text (T1) plus consistent T3 commercial secondary analysis (DataGuidance) corroborating section numbers and commencement Orders. data_subject_rights, sectoral_watch and adtech_and_commercial_privacy relied primarily on T3 secondary sources and DPA consultation-notice headlines, with several sub-modules (rectification/erasure, restriction/objection, portability, cookies, dark patterns, opt-out signals, clean rooms, cross-context advertising, most sectoral overlays) carrying explicit absent_field_provenance because no statutory text or DPA guidance was retrieved. children_and_vulnerable_groups returned no findings across all five sub-modules despite targeted searches and is emitted red with full absent_field_provenance. No T1 access to the official Authority website or the final consolidated post-amendment Act text was obtained in this run; all PDPA section-level claims derive from a 2021 draft-bill PDF and T3 secondary commentary, which is a material limitation given the confirmed October 2025 amendments.

Unresolved questions (6):

  • What is the final consolidated text of the PDPA as amended by the 21 October 2025 amendment, and which specific sections were changed (beyond the headline description of postponed dates, ADM clarification, limited DPO scope, and flexible transfer mechanisms)?
  • What are the revised commencement dates for PDPA Parts I, II, III and VII following the reported Gazette repeal of prior enforcement dates?
  • Does the PDPA or subsidiary regulation set any age of consent or parental-consent mechanism for minors' personal data?
  • What are the finalised (non-draft) breach-notification timelines and DSAR response-window regulations, given several were still in public consultation as of late 2024?
  • Has the Authority issued any published enforcement decisions, fines, or corrective orders to date?
  • What is the official URL/domain of the Data Protection Authority of Sri Lanka for future T1 anchoring?

Escalate to primary-source review: yes