LKschema gdpri-v2trajectory: not yet assessedin transitionoverlaps: FIM, WPM, AIC
Last updated · 10 categories · 36
claims · 17 sources in the cumulative register
10Categoriesbaseline.[]
57Sub-modulesbaseline..sub_modules{}
36Claimsbaseline..claims[]
3Tier-1 sourcesrun_metadata.t1_source_count
Traffic-light mix(sums to 10 rendered categories; click to filter)
No red categories; 28 sub-modules are flagged red.
Jurisdiction brief
Standing brief, as of 25 August 2026.
Lead Signal
Sri Lanka's Personal Data Protection Act regime enters a distinctive in-transition state this cycle. The Data Protection Authority of Sri Lanka, established under the PDPA in August 2023, appointed its first permanent Director General in March 2026, a concrete institutional capacity-building milestone. At the same time, the Personal Data Protection (Amendment) Act, No. 22 of 2025 -- certified 30 October 2025 -- removed the original grace-period provisions for operationalisation, meaning the PDPA's remaining substantive Parts now commence only upon a future Ministerial Gazette Order rather than on a fixed schedule. As of June 2026, no such Ministerial Gazette Order commencing the PDPA's substantive Parts had been published. The result is a regulator that is institutionally live and building capacity, sitting atop a substantive legal framework with no fixed commencement date -- an open-ended regulatory uncertainty for market participants that is the central development of this cycle.
Other Developments
No formal adequacy decisions have been issued. The Data Protection Authority of Sri Lanka has not issued any formal adequacy decisions as of May 2026, and controllers and processors may rely on appropriate safeguards for international transfers in the interim. This is a High-confidence, sourced negative finding: the cross-border transfer regime exists in the PDPA's design, which draws from the EU GDPR in structuring its lawful-processing bases and data-subject rights framework, but has not yet been operationalised through any adequacy mechanism, consistent with the substantive Parts' not-yet-commenced status generally.
Sector-specific statutes remain the only operative source of data-handling obligations. The Banking Act No. 30 of 1988 continues to apply alongside the not-yet-operative PDPA as a sector-specific statute governing financial-sector personal data. In the absence of PDPA substantive commencement, this Act functions as one of the only operative sources of data-handling obligations in its sector, a gap that will persist until the Ministerial Gazette Order is published.
Cross-Monitor Connections
Sri Lanka's crypto and financial-integrity developments this cycle -- the proposed virtual-asset regulatory framework and the Cabinet-approved public-official crypto-declaration measure -- were clarified by the Deputy Minister of Digital Economy as proceeding on a track distinct from the concurrently progressing Cyber Security Bill, which addresses network and technical security rather than data-protection questions; that Cyber Security Bill sits closer to the crypto and financial-integrity monitors' remits than to this one, and is noted here only to mark the scope boundary rather than to analyse it. This scope-boundary clarification forecloses treating the Cyber Security Bill's progress as a data-protection-track development. No adtech, algorithmic-governance, or children's-data development connecting to the advennt or world-payments monitors was evidenced this cycle.
Outlook
The item most likely to change Sri Lanka's data-protection picture is publication of the Ministerial Gazette Order commencing the PDPA's substantive Parts; until that order is published, controller/processor duties, data-subject rights, and the Authority's enforcement powers remain legislated but not practically operative. The Authority's institutional build-out, evidenced by the March 2026 Director General appointment, suggests capacity is being readied ahead of that commencement, but no date for the order has been indicated in this cycle's evidence. A second item to watch is whether the Authority issues any interim guidance -- short of a full Gazette commencement order -- addressing cross-border transfer practice, given that no formal adequacy decision exists and controllers currently rely on unspecified appropriate safeguards with no published standard-contractual-clauses or binding-corporate-rules template evidenced this cycle.
trust tier: ai_unverified
Standing brief, as of 25 August 2026.
Regulatory Status
Sri Lanka's data-protection regime is in a distinctive transitional state: the Data Protection Authority, established under the Personal Data Protection Act in August 2023, appointed its first permanent Director General in March 2026, while the Personal Data Protection (Amendment) Act, No. 22 of 2025 removed the PDPA's grace-period commencement mechanism, leaving the Act's substantive Parts -- controller/processor duties, data-subject rights, cross-border-transfer rules, and enforcement powers -- to commence only upon a future Ministerial Gazette Order, not yet published as of June 2026. No formal adequacy decisions have been issued, and sector-specific statutes, including the Banking Act No. 30 of 1988, remain among the only operative sources of data-handling obligations in their sectors in the interim. The PDPA itself is GDPR-modelled in its lawful-processing and data-subject-rights structure, meaning the eventual substantive regime, once commenced, will resemble EU-style data protection in content even though Sri Lanka sits entirely outside the EU adequacy and AMLA-style supranational-supervision architecture relevant to other monitors.
Outlook
Publication of the Ministerial Gazette Order commencing the PDPA's substantive Parts is the single event most likely to change Sri Lanka's data-protection status materially. Until then, institutional capacity-building continues without a corresponding activation of substantive controller, data-subject-rights, or enforcement provisions.
10 of 10 categories
Signal
Density
Selections OR within a group, AND across groups. Press / to search.
Comprehensive omnibus statute enacted and regulator operational, but core substantive Parts (I, II, III, VII) have had commencement dates repeatedly postponed and several implementing regulations remain in draft/consultation.
Primary frameworkPersonal Data Protection Act, No. 9 of 2022 (PDPA)
Supervisory authorityData Protection Authority of Sri Lanka
Traffic-light rationale — AmberComprehensive omnibus statute enacted and regulator operational, but core substantive Parts (I, II, III, VII) have had commencement dates repeatedly postponed and several implementing regulations remain in draft/consultation.
Sub-modules (5)
Regulator And AuthorityGreen
The Authority was established under Part V of the PDPA, which entered into force on 17 July 2023.
Claims (1):
Part V of the PDPA entered into force on 17 July 2023, thereby establishing the Data Protection Authority of Sri Lanka.
Act And InstrumentsAmber
PDPA No. 9 of 2022 was enacted/endorsed on 19 March 2022 and commences in phases via ministerial Order, with an October 2025 amendment further adjusting timelines and substantive provisions.
Claims (3):
The Personal Data Protection Act, No. 9 of 2022 was passed by the Parliament of Sri Lanka and endorsed on 19 March 2022.
Parts VI, VIII, IX and X of the PDPA entered into effect on 1 December 2023, with Parts I, II, III and VII scheduled to enter into effect on 18 March 2025 per a January 2024 commencement Order.
Sri Lanka's Parliament adopted amendments to the PDPA on 21 October 2025, which postponed operational dates, clarified automated-decision-making rights, limited DPO requirements, and introduced more flexible cross-border data transfer mechanisms.
Material ScopeGreen
The PDPA applies to processing of personal data generally but excludes purely personal/domestic/household processing.
Claims (1):
The PDPA does not apply to personal data processed purely for personal, domestic, or household purposes by an individual, or to data other than personal data (Section 2(3)).
Territorial ScopeGreen
The PDPA has extraterritorial reach, applying to controllers/processors outside Sri Lanka who offer goods/services to, or monitor the behaviour of, data subjects in Sri Lanka.
Claims (1):
The PDPA applies extraterritorially to processing that offers goods or services to data subjects in Sri Lanka (including targeted offerings) or that monitors the behaviour of data subjects in Sri Lanka, including profiling (Section 2(2)).
Regulator Registration And FilingRed
No general controller/processor registration or filing regime with the Authority was identified in available sources; the closest analogue is the DPO-communication duty and the data-protection-management-programme obligation, which are treated under controller_processor_duties.
Absence provenance: unavailable. Searched: Sri Lanka PDPA controller registration filing requirement, Sri Lanka Data Protection Authority registration regulations.
Category narrative65 words
Sri Lanka's Personal Data Protection Act, No. 9 of 2022 (PDPA) is the first comprehensive data-protection statute in the jurisdiction, establishing the Data Protection Authority of Sri Lanka. Commencement has been staggered by ministerial Order across 2023-2025, and a further October 2025 amendment postponed several operational dates and adjusted DPO/ADM/cross-border provisions, so the regime is best characterised as in transition rather than fully in force.
No new data since the standing brief. 1 periodic run re-emitted it unchanged.
Sources and claims (6)
ConfirmedDataGuidance — Part V of the PDPA entered into force on 17 July 2023, thereby establishing the Data Protection Authority of Sri Lanka.observed
ConfirmedDataGuidance — The Personal Data Protection Act, No. 9 of 2022 was passed by the Parliament of Sri Lanka and endorsed on 19 March 2022.observed
ConfirmedDataGuidance — Parts VI, VIII, IX and X of the PDPA entered into effect on 1 December 2023, with Parts I, II, III and VII scheduled to enter into effect on 18 March 2025 per a January 2024 commencement Order.observed
ProbableDataGuidance — Sri Lanka's Parliament adopted amendments to the PDPA on 21 October 2025, which postponed operational dates, clarified automated-decision-making rights, limited DPO requirements, and introduced more flexible cross-border data transfer mechanisms.observed
ConfirmedDataGuidance — The PDPA does not apply to personal data processed purely for personal, domestic, or household purposes by an individual, or to data other than personal data (Section 2(3)).observed
ConfirmedDataGuidance — The PDPA applies extraterritorially to processing that offers goods or services to data subjects in Sri Lanka (including targeted offerings) or that monitors the behaviour of data subjects in Sri Lanka, including profiling (Section 2(2)).observed
Core lawful-basis and special-category provisions exist in the Act text, but they sit in Parts (I-III) whose commencement date has been repeatedly postponed, and pseudonymisation/anonymisation rules were not located.
Primary frameworkPersonal Data Protection Act, No. 9 of 2022 (PDPA) — Schedules I, II, III
Supervisory authorityData Protection Authority of Sri Lanka
Traffic-light rationale — AmberCore lawful-basis and special-category provisions exist in the Act text, but they sit in Parts (I-III) whose commencement date has been repeatedly postponed, and pseudonymisation/anonymisation rules were not located.
Sub-modules (4)
Lawful BasesAmber
Schedule I (given effect via Section 5) enumerates lawful bases including consent, vital-interest emergencies, public-interest/statutory tasks, and legitimate interests.
Claims (2):
Under the PDPA, personal data may only be processed pursuant to the legal bases set out in Schedule I (Section 5), including responding to emergencies threatening life, health or safety, performance of a public-interest task or statutory power, and legitimate interests of the controller or a third party.
Schedule I further clarifies 'legitimate interests' to include processing where the data subject is a client or in the service of the controller, where processing is reasonably expected, and where strictly necessary for preventing fraud.
Consent ThresholdsAmber
Consent is defined as a freely given, specific, informed, and unambiguous indication via written declaration or affirmative action; Schedule III elaborates further conditions.
Claims (1):
Consent under the PDPA is defined as a freely given, specific, informed, and unambiguous indication by written declaration or affirmative action signifying the data subject's agreement, with further conditions elaborated in Schedule III.
Special CategoriesAmber
Schedule II imposes additional conditions limiting the circumstances in which special/sensitive categories of personal data may be processed.
Claims (1):
The PDPA affords additional protection to special categories of personal data (sensitive data) by limiting the circumstances in which such data may be processed, per the conditions in Schedule II.
Pseudonymisation And AnonymisationRed
No PDPA provision or DPA guidance specifically defining pseudonymisation/anonymisation safe-harbours was located in available sources.
Absence provenance: unavailable. Searched: Sri Lanka PDPA pseudonymisation anonymisation definition, Sri Lanka Data Protection Authority anonymisation guidance.
Category narrative42 words
The PDPA sets out an enumerated set of lawful bases in Schedule I (Section 5), a defined consent standard elaborated in Schedule III, and enhanced conditions for special/sensitive categories in Schedule II. No specific statutory pseudonymisation/anonymisation safe-harbour was identified in available sources.
Sources and claims (4)
ConfirmedDataGuidance — Under the PDPA, personal data may only be processed pursuant to the legal bases set out in Schedule I (Section 5), including responding to emergencies threatening life, health or safety, performance of a public-interest task or statutory power, and legitimate interests of the controller or a third party.observed
ProbableDataGuidance — Schedule I further clarifies 'legitimate interests' to include processing where the data subject is a client or in the service of the controller, where processing is reasonably expected, and where strictly necessary for preventing fraud.observed
ConfirmedDataGuidance — Consent under the PDPA is defined as a freely given, specific, informed, and unambiguous indication by written declaration or affirmative action signifying the data subject's agreement, with further conditions elaborated in Schedule III.observed
ConfirmedDataGuidance — The PDPA affords additional protection to special categories of personal data (sensitive data) by limiting the circumstances in which such data may be processed, per the conditions in Schedule II.observed
Rights exist in principle under the Act, but implementing regulations governing procedure/deadlines were still in public-consultation draft form as of late 2024, and core Parts covering these rights had postponed commencement.
Primary frameworkPersonal Data Protection Act, No. 9 of 2022 (PDPA)
Supervisory authorityData Protection Authority of Sri Lanka
Traffic-light rationale — AmberRights exist in principle under the Act, but implementing regulations governing procedure/deadlines were still in public-consultation draft form as of late 2024, and core Parts covering these rights had postponed commencement.
Sub-modules (5)
Access RightAmber
The Authority sought public input on draft fee regulations for data-subject-rights requests, implying an access/rights-request mechanism is being operationalised, but the underlying statutory access-request procedure text was not retrieved.
Claims (1):
The Data Protection Authority of Sri Lanka sought public input on draft fee regulations for data-subject-rights requests under the PDPA.
Rectification And ErasureRed
General strengthening of data-subject rights is stated as a Section 1/PDPA objective; specific rectification/erasure mechanics were not located.
Absence provenance: unavailable. Searched: Sri Lanka PDPA rectification erasure right to be forgotten section.
Restriction And ObjectionRed
No specific restriction-of-processing or objection-right provision text was retrieved in available sources.
Absence provenance: unavailable. Searched: Sri Lanka PDPA right to object restriction of processing.
Data PortabilityRed
No specific data-portability provision was identified in available sources.
Absence provenance: unavailable. Searched: Sri Lanka PDPA data portability right.
Deadlines And Response WindowsAmber
The Authority ran a 2024 consultation on draft regulations for data-subject rights and appeals, and separately on fee regulations for rights requests, indicating response-window mechanics were still being finalised via secondary legislation as of the survey window.
Claims (1):
The Authority sought public input on draft regulations for data subjects' rights and appeals under the PDPA, extending the feedback deadline to 15 November 2024.
Category narrative58 words
The PDPA is described as strengthening data-subject rights, and the Authority has run consultations on draft regulations for DSAR rights and appeals and fee schedules for rights requests, but concrete statutory deadlines and detailed mechanics for access, rectification, erasure, restriction, objection and portability were not located in available secondary sources — much of this remains in draft-regulation form.
Sources and claims (2)
ProbableDataGuidance — The Data Protection Authority of Sri Lanka sought public input on draft fee regulations for data-subject-rights requests under the PDPA.observed
ProbableDataGuidance — The Authority sought public input on draft regulations for data subjects' rights and appeals under the PDPA, extending the feedback deadline to 15 November 2024.observed
Substantive duties are set out in the Act, but a cluster of implementing regulations were still in draft/consultation stage as of the last confirmed update, and the DPO obligation itself was narrowed by the pending 2025 amendment.
Primary frameworkPersonal Data Protection Act, No. 9 of 2022 (PDPA)
Supervisory authorityData Protection Authority of Sri Lanka
Traffic-light rationale — AmberSubstantive duties are set out in the Act, but a cluster of implementing regulations were still in draft/consultation stage as of the last confirmed update, and the DPO obligation itself was narrowed by the pending 2025 amendment.
Sub-modules (7)
Accountability And DpiaAmber
Controllers must implement a Data Protection Management Programme and conduct Data Protection Impact Assessments (DPIAs) where applicable; the Authority ran a 2024 public consultation on draft PDPIA regulations.
Claims (2):
Controllers under the PDPA must implement a Data Protection Management Programme.
Controllers under the PDPA must conduct Data Protection Impact Assessments (DPIAs) where applicable, and the Authority launched a public consultation on draft PDPIA regulations.
Dpo RequirementsAmber
The PDPA requires appointment of a Data Protection Officer; the Authority consulted on draft DPO-appointment regulations in 2024, and the October 2025 amendment is reported to have introduced 'limited DPO requirements', narrowing the original obligation.
Claims (2):
The PDPA requires the appointment of a Data Protection Officer (DPO), and the Authority sought public input on draft DPO-appointment regulations under the Act.
The October 2025 amendments to the PDPA are reported to include 'limited DPO requirements', narrowing the scope of the original DPO-appointment obligation.
Ropa RequirementsAmber
The Data Protection Management Programme obligation functions as the PDPA's closest analogue to records-of-processing requirements; a dedicated ROPA provision distinct from the DPMP was not separately confirmed.
Claims (1):
Controllers under the PDPA must implement a Data Protection Management Programme.
Joint Controller ArrangementsAmber
Processors must comply with the controller's written instructions and confidentiality measures; specific joint-controller apportionment-of-liability provisions were not separately located.
Claims (1):
Processors under the PDPA must comply with the controller's written instructions and confidentiality measures.
Security MeasuresGreen
Section 10 of the PDPA requires controllers to ensure integrity and confidentiality of personal data using appropriate technical and organisational measures.
Claims (1):
Section 10 of the PDPA requires controllers to ensure integrity and confidentiality of personal data by using appropriate technical and organisational measures.
Breach NotificationAmber
The PDPA mandates notification of personal data breaches; the Authority launched a public consultation on draft breach-notification rules under the PDPA, indicating implementing detail was still being finalised.
Claims (2):
The PDPA mandates notification of data breaches and imposes conditions on processing personal data outside Sri Lanka, requiring adequacy decisions or appropriate safeguards.
The Data Protection Authority of Sri Lanka launched a public consultation on draft rules for data breach notifications under the PDPA.
Retention And DisposalRed
No specific statutory retention-period or disposal-duty provision was located in available sources.
Absence provenance: unavailable. Searched: Sri Lanka PDPA data retention disposal period.
Category narrative61 words
The PDPA imposes an accountability framework requiring a Data Protection Management Programme, DPIAs for higher-risk processing, DPO appointment (narrowed by the October 2025 amendment), processor obligations to act on written instructions with confidentiality safeguards, security-of-processing duties (Section 10), and mandatory breach notification — though several implementing regulations (DPO appointment, PDPIA, breach notification, DPMP guidelines) remained in public-consultation draft form through 2024.
Sources and claims (8)
ConfirmedDataGuidance — Controllers under the PDPA must implement a Data Protection Management Programme.observed
ConfirmedDataGuidance — Controllers under the PDPA must conduct Data Protection Impact Assessments (DPIAs) where applicable, and the Authority launched a public consultation on draft PDPIA regulations.observed
ConfirmedDataGuidance — The PDPA requires the appointment of a Data Protection Officer (DPO), and the Authority sought public input on draft DPO-appointment regulations under the Act.observed
UncertainDataGuidance — The October 2025 amendments to the PDPA are reported to include 'limited DPO requirements', narrowing the scope of the original DPO-appointment obligation.observed
ConfirmedDataGuidance — Processors under the PDPA must comply with the controller's written instructions and confidentiality measures.observed
ConfirmedDataGuidance — Section 10 of the PDPA requires controllers to ensure integrity and confidentiality of personal data by using appropriate technical and organisational measures.observed
ConfirmedDataGuidance — The PDPA mandates notification of data breaches and imposes conditions on processing personal data outside Sri Lanka, requiring adequacy decisions or appropriate safeguards.observed
ProbableDataGuidance — The Data Protection Authority of Sri Lanka launched a public consultation on draft rules for data breach notifications under the PDPA.observed
A transfer-mechanism framework exists in the Act, but implementing directives were in draft/consultation form and no adequacy decisions to or from Sri Lanka were identified.
Primary frameworkPersonal Data Protection Act, No. 9 of 2022 (PDPA)
Supervisory authorityData Protection Authority of Sri Lanka
Traffic-light rationale — AmberA transfer-mechanism framework exists in the Act, but implementing directives were in draft/consultation form and no adequacy decisions to or from Sri Lanka were identified.
Sub-modules (6)
Transfer MechanismsAmber
Cross-border transfers require either an adequacy-type decision or appropriate safeguards, including a legally binding enforceable instrument with the overseas recipient or another Authority-approved mechanism.
Claims (2):
The PDPA outlines conditions for processing personal data outside Sri Lanka, requiring adequacy decisions or appropriate safeguards.
To ensure compliance for overseas processing, a controller must enter into a legally binding and enforceable instrument with the recipient located outside Sri Lanka, or adopt another instrument determined by the Authority.
Adequacy ReceivedRed
No adequacy decision received by Sri Lanka from another regime (e.g. EU/UK) was identified in available sources.
Absence provenance: unavailable. Searched: Sri Lanka EU adequacy decision, Sri Lanka UK adequacy PDPA.
Adequacy GrantedAmber
No formal Sri Lankan adequacy determinations regarding third countries were identified; the Authority is instead developing a directive to classify personal-data categories for cross-border processing.
Claims (1):
The Data Protection Authority sought public input on a draft directive for classifying personal-data categories for processing abroad.
Sccs And BcrsAmber
No finalised standard-contractual-clause or binding-corporate-rules template issued by the Authority was located; the Act contemplates a 'legally binding and enforceable instrument' as one safeguard mechanism.
Claims (1):
To ensure compliance for overseas processing, a controller must enter into a legally binding and enforceable instrument with the recipient located outside Sri Lanka, or adopt another instrument determined by the Authority.
Transfer Impact AssessmentRed
No standalone transfer-impact-assessment requirement distinct from the general safeguard/adequacy mechanism was identified.
Absence provenance: unavailable. Searched: Sri Lanka PDPA transfer impact assessment requirement.
Data LocalisationAmber
The PDPA provisions governing cross-border data transfers carry data-localisation implications, generally requiring processing to remain within Sri Lanka unless permitted to be processed in a third country under the safeguard regime.
Claims (1):
The PDPA's cross-border data transfer provisions have data-localisation implications applicable to all controllers and processors intending to process personal data outside of Sri Lanka.
Category narrative74 words
The PDPA restricts cross-border transfers unless the destination benefits from an adequacy-type decision or the controller puts in place appropriate safeguards (including a legally binding enforceable instrument with the overseas recipient), and these provisions carry data-localisation implications for controllers/processors processing outside Sri Lanka. The Authority has run consultations on directives for processing personal data abroad and for classifying personal-data categories for overseas processing, and the October 2025 amendment reportedly introduced more flexible transfer mechanisms.
No new data since the standing brief. 1 periodic run re-emitted it unchanged.
Sources and claims (4)
ConfirmedDataGuidance — The PDPA outlines conditions for processing personal data outside Sri Lanka, requiring adequacy decisions or appropriate safeguards.observed
ProbableParliament of Sri Lanka (hosted via DataGuidance) — To ensure compliance for overseas processing, a controller must enter into a legally binding and enforceable instrument with the recipient located outside Sri Lanka, or adopt another instrument determined by the Authority.observed
ProbableDataGuidance — The Data Protection Authority sought public input on a draft directive for classifying personal-data categories for processing abroad.observed
ConfirmedDataGuidance — The PDPA's cross-border data transfer provisions have data-localisation implications applicable to all controllers and processors intending to process personal data outside of Sri Lanka.observed
General cross-sector coordination is committed to in policy statements, but dedicated sectoral overlay statutes/regulations for financial services, health, employment, credit, education, or insurance were not located.
Primary frameworkPersonal Data Protection Act, No. 9 of 2022 (PDPA)
Supervisory authorityData Protection Authority of Sri Lanka
Traffic-light rationale — AmberGeneral cross-sector coordination is committed to in policy statements, but dedicated sectoral overlay statutes/regulations for financial services, health, employment, credit, education, or insurance were not located.
Sub-modules (7)
Financial Sector OverlayAmber
The Authority is intended to engage with the Central Bank of Sri Lanka and the Securities and Exchange Commission to ensure proper governance of personal data in the financial sector.
Claims (1):
Sri Lanka's 2023 budget speech confirmed the Authority will be independent and engaged with the Central Bank of Sri Lanka and Securities and Exchange Commission to ensure proper governance of personal data.
Health Sector OverlayRed
No dedicated health-sector data-protection overlay statute was identified.
Absence provenance: unavailable. Searched: Sri Lanka health data protection law overlay.
Telecoms And EprivacyAmber
The Authority is intended to engage with the Telecommunications Regulatory Commission of Sri Lanka (TRCSL) for governance of personal data in the telecoms sector; no separate ePrivacy-style statute was identified.
Claims (1):
The 2023 budget speech confirmed the Authority will engage with the Telecommunications Regulatory Commission of Sri Lanka and other relevant sectoral regulators to ensure proper governance of personal data.
Employment DataRed
No dedicated employment-data overlay was identified beyond general PDPA coverage.
Absence provenance: unavailable. Searched: Sri Lanka employment data protection code.
Credit And ScoringRed
No dedicated credit-scoring data-protection overlay was identified.
Absence provenance: unavailable. Searched: Sri Lanka credit scoring data protection regulation.
EducationRed
No dedicated education-sector data-protection overlay was identified.
Absence provenance: unavailable. Searched: Sri Lanka education sector data protection rules.
InsuranceRed
No dedicated insurance-sector data-protection overlay was identified.
Absence provenance: unavailable. Searched: Sri Lanka insurance sector data protection regulation.
Category narrative63 words
Sri Lanka does not appear to have distinct sector-specific data-protection statutes (health, credit, education, insurance) separate from the PDPA; instead, the 2023 budget speech committed the incoming Authority to independent operation while engaging with the Central Bank of Sri Lanka, the Securities and Exchange Commission, and the Telecommunications Regulatory Commission of Sri Lanka (TRCSL) to ensure coordinated governance of personal data across sectors.
Sources and claims (2)
ProbableDataGuidance — Sri Lanka's 2023 budget speech confirmed the Authority will be independent and engaged with the Central Bank of Sri Lanka and Securities and Exchange Commission to ensure proper governance of personal data.observed
ProbableDataGuidance — The 2023 budget speech confirmed the Authority will engage with the Telecommunications Regulatory Commission of Sri Lanka and other relevant sectoral regulators to ensure proper governance of personal data.observed
Direct marketing is explicitly addressed by statute; other adtech-adjacent sub-modules (cookies, dark patterns, opt-out signals, clean rooms, cross-context advertising) have no located statutory or DPA-guidance basis.
Primary frameworkPersonal Data Protection Act, No. 9 of 2022 (PDPA), Part IV
Supervisory authorityData Protection Authority of Sri Lanka
Traffic-light rationale — AmberDirect marketing is explicitly addressed by statute; other adtech-adjacent sub-modules (cookies, dark patterns, opt-out signals, clean rooms, cross-context advertising) have no located statutory or DPA-guidance basis.
Sub-modules (6)
Cookies And TrackersRed
No cookie/tracker-specific consent regime was identified in the PDPA or Authority guidance.
Absence provenance: unavailable. Searched: Sri Lanka PDPA cookies consent regulation.
Dark PatternsRed
No dark-pattern prohibition was identified in available sources.
Absence provenance: unavailable. Searched: Sri Lanka PDPA dark patterns prohibition.
Opt Out SignalsRed
No recognised technical opt-out signal (e.g. Global Privacy Control analogue) was identified.
Absence provenance: unavailable. Searched: Sri Lanka PDPA opt-out signal Global Privacy Control.
Clean Rooms And DcrRed
No clean-room/data-collaboration-room framework was identified.
Absence provenance: unavailable. Searched: Sri Lanka data clean room regulation.
Cross Context AdvertisingRed
No 'sale'/'share'-style cross-context advertising provision analogous to US state law was identified.
Absence provenance: unavailable. Searched: Sri Lanka PDPA cross-context advertising sale of data.
Direct MarketingAmber
Part IV of the PDPA (Section 27) prohibits a controller from disseminating unsolicited messages to an identified or identifiable data subject, subject to specified exceptions.
Claims (1):
Section 27 of the PDPA provides that a controller shall not disseminate unsolicited messages to any identified or identifiable data subject, subject to conditions in the Act.
Category narrative31 words
The PDPA's Part IV restricts the use of personal data for unsolicited direct-marketing messages; no cookie/tracker-specific consent regime, dark-pattern prohibition, recognised opt-out signal, or clean-room framework was identified in available sources.
Sources and claims (1)
ProbableParliament of Sri Lanka (hosted via DataGuidance) — Section 27 of the PDPA provides that a controller shall not disseminate unsolicited messages to any identified or identifiable data subject, subject to conditions in the Act.observed
ADM and profiling are addressed at a scope/definitional level and via a reported 2025 amendment, but dedicated biometric, genetic-data, and AI-risk-assessment regimes were not confirmed as enacted.
Primary frameworkPersonal Data Protection Act, No. 9 of 2022 (PDPA)
Supervisory authorityData Protection Authority of Sri Lanka
Traffic-light rationale — AmberADM and profiling are addressed at a scope/definitional level and via a reported 2025 amendment, but dedicated biometric, genetic-data, and AI-risk-assessment regimes were not confirmed as enacted.
Sub-modules (6)
Profiling RestrictionsAmber
The PDPA's territorial-scope provision captures profiling of data subjects in Sri Lanka undertaken with the intention of making decisions about their behaviour.
Claims (1):
The PDPA applies to processing that specifically monitors the behaviour of data subjects in Sri Lanka, including profiling with the intention of making decisions about such behaviour, insofar as it takes place in Sri Lanka.
Automated Decision Making TransparencyAmber
The October 2025 PDPA amendments are reported to have clarified automated-decision-making rights.
Claims (1):
Sri Lanka's October 2025 PDPA amendments clarified automated decision-making rights for data subjects.
Ai Risk AssessmentsRed
A Gazette reportedly repealed prior PDPA enforcement dates pending amendments tied to AI and technology adoption, signalling anticipated but not-yet-enacted AI-specific regulatory activity.
Claims (1):
A Sri Lankan Gazette reportedly repealed prior PDPA enforcement dates pending further amendments related to AI and technology adoption.
Biometric RegimeRed
No dedicated biometric-data regime (facial recognition, fingerprint, gait) distinct from the general personal-data definition was identified.
Absence provenance: unavailable. Searched: Sri Lanka PDPA biometric data facial recognition regulation.
Genetic DataAmber
Genetic factors are referenced within the PDPA's general 'personal data' definition as one of the identifying attributes, but no dedicated genetic-data regime was found.
Claims (1):
The PDPA's definition of personal data includes factors specific to the physical, physiological, genetic, psychological, economic, cultural, or social identity of a natural person.
State Surveillance CarveoutsAmber
Section 40 of the PDPA outlines exemptions, restrictions and derogations primarily relating to national security and public interest.
Claims (1):
Section 40 of the PDPA outlines several exemptions, restrictions, and derogations, primarily in relation to national security and public interest.
Category narrative65 words
The PDPA's extraterritorial-scope trigger expressly captures profiling used to make decisions about data subjects' behaviour in Sri Lanka, and the October 2025 amendment reportedly clarified automated-decision-making rights. National-security/public-interest carve-outs are set out in Section 40. No dedicated biometric- or genetic-data regime, or AI-specific risk-assessment obligation, was confirmed beyond genetic/physiological factors being folded into the general 'personal data' definition and a Gazette signalling pending AI-related amendments.
Sources and claims (5)
ConfirmedDataGuidance — The PDPA applies to processing that specifically monitors the behaviour of data subjects in Sri Lanka, including profiling with the intention of making decisions about such behaviour, insofar as it takes place in Sri Lanka.observed
UncertainDataGuidance — Sri Lanka's October 2025 PDPA amendments clarified automated decision-making rights for data subjects.observed
SpeculativeDataGuidance — A Sri Lankan Gazette reportedly repealed prior PDPA enforcement dates pending further amendments related to AI and technology adoption.observed
ConfirmedDataGuidance — The PDPA's definition of personal data includes factors specific to the physical, physiological, genetic, psychological, economic, cultural, or social identity of a natural person.observed
ConfirmedDataGuidance — Section 40 of the PDPA outlines several exemptions, restrictions, and derogations, primarily in relation to national security and public interest.observed
Absence provenance: unavailable. Searched: Sri Lanka PDPA minor profiling ban.
Education SettingsRed
No education-setting-specific data-protection rule was identified.
Absence provenance: unavailable. Searched: Sri Lanka PDPA education sector children data.
Dependent AdultsRed
No dependent-adult-specific protection was identified.
Absence provenance: unavailable. Searched: Sri Lanka PDPA dependent adults incapacitated persons data protection.
Category narrative24 words
No PDPA provision or Authority guidance addressing age of consent, parental-consent mechanisms, minor-profiling bans, education-setting-specific rules, or dependent-adult protections was located in available sources.
Enforcement powers exist on the statute's face, but no confirmed enforcement decisions/fines were located, and the underlying substantive obligations remain subject to a shifting commencement timetable.
Primary frameworkPersonal Data Protection Act, No. 9 of 2022 (PDPA)
Supervisory authorityData Protection Authority of Sri Lanka
Traffic-light rationale — AmberEnforcement powers exist on the statute's face, but no confirmed enforcement decisions/fines were located, and the underlying substantive obligations remain subject to a shifting commencement timetable.
Sub-modules (6)
Regulator Powers And PenaltiesAmber
The Authority may impose fines payable into the Consolidated Fund; non-payment is enforceable via application to the Magistrate Court of Colombo, and penalty imposition does not preclude other regulatory measures such as suspension or licence cancellation.
Claims (2):
A person liable to a fine under the PDPA who fails to pay may have the Authority apply to the Magistrate Court of Colombo for an order requiring payment, recoverable in like manner as a court-imposed fine even if it exceeds the court's ordinary fining jurisdiction.
Imposition of a penalty under the PDPA does not preclude a supervisory or regulatory authority from taking other regulatory measures, including suspension of a business/profession or cancellation of a licence.
Enforcement Activity IndexRed
No published enforcement decisions or fines were located; Authority activity to date has centred on consultations, circulars and draft directives.
Absence provenance: unavailable. Searched: Sri Lanka Data Protection Authority fine enforcement decision.
Claims (1):
The Data Protection Authority's public activity to date includes issuing a compliance circular for public-sector authorities and multiple public consultations on draft directives/regulations, rather than published enforcement decisions.
Regulator Funding And CapacityAmber
The 2023 budget speech committed to an independent Authority, but no headcount or budget figures were located.
Absence provenance: unavailable. Searched: Sri Lanka Data Protection Authority budget staffing headcount.
Claims (1):
Sri Lanka's 2023 budget speech confirmed government commitment to establishing an independent Data Protection Authority.
Collective Redress And Class ActionsRed
No collective-redress or class-action mechanism specific to the PDPA was identified.
Absence provenance: unavailable. Searched: Sri Lanka PDPA class action collective redress.
Private Right Of ActionRed
No private right of direct court action distinct from Authority-mediated enforcement was identified.
Absence provenance: unavailable. Searched: Sri Lanka PDPA private right of action civil suit.
Recent Developments 180DAmber
Sri Lanka's Parliament adopted amendments to the PDPA on 21 October 2025, and a Gazette reportedly repealed prior PDPA enforcement dates pending amendments tied to AI and technology adoption.
Claims (2):
Sri Lanka's Parliament adopted amendments to the PDPA on 21 October 2025, which postponed operational dates, clarified automated-decision-making rights, limited DPO requirements, and introduced more flexible cross-border data transfer mechanisms.
A Sri Lankan Gazette reportedly repealed prior PDPA enforcement dates pending further amendments related to AI and technology adoption.
Category narrative91 words
The PDPA gives the Authority power to impose financial penalties (payable into the Consolidated Fund) enforceable through the Magistrate Court of Colombo for non-payment, and other regulatory measures including suspension of business/profession or cancellation of licences, without precluding sectoral regulators' own powers. As of the last confirmed update the Authority's public activity has been dominated by consultations, draft directives and circulars rather than published enforcement decisions, consistent with the still-staggered commencement of the Act's substantive Parts. The most recent material development is the 21 October 2025 Parliamentary adoption of PDPA amendments.
No new data since the standing brief. 1 periodic run re-emitted it unchanged.
Sources and claims (4)
ProbableParliament of Sri Lanka (hosted via DataGuidance) — A person liable to a fine under the PDPA who fails to pay may have the Authority apply to the Magistrate Court of Colombo for an order requiring payment, recoverable in like manner as a court-imposed fine even if it exceeds the court's ordinary fining jurisdiction.observed
ProbableParliament of Sri Lanka (hosted via DataGuidance) — Imposition of a penalty under the PDPA does not preclude a supervisory or regulatory authority from taking other regulatory measures, including suspension of a business/profession or cancellation of a licence.observed
ProbableDataGuidance — The Data Protection Authority's public activity to date includes issuing a compliance circular for public-sector authorities and multiple public consultations on draft directives/regulations, rather than published enforcement decisions.observed
ProbableDataGuidance — Sri Lanka's 2023 budget speech confirmed government commitment to establishing an independent Data Protection Authority.observed
No categories match.
Filters combine as OR inside a group and AND across
groups.
Publication gate
No failing checks.
schema_valid
pass
min_t1_per_instrument_met
n/a — no subject in this jurisdiction
min_quoted_text_present
waived — floor 0%
translation_provenance_recorded
n/a — no subject in this jurisdiction
egress_verified
pass
source_tier_integrity_ok
pass
jurisdiction_source_floor_met
pass
tier_a_b_national_primary_pct
20.0
aggregator_only_jurisdiction_count
0
manual_override
Editorial metadata
Provenance only. Nothing below gates publication or affects the render.
Editorial metadata for Sri Lanka
Field
Value
trust.lawyer_review.status
never_reviewed
trust.lawyer_review.reviewer
no reviewer on record
trust.content_source
ai_generated
Provenance and declared absence
Disclosure model: category cards load OPEN; narratives render in full; standing narratives load as a clamped teaser with an explicit “read full” control carrying the true word count. No text is hidden without disclosing how much of it there is.
Sub-modules are DP-specific nested subsections with their own real per-sub-module traffic light, rendered under each category (BRIEF section 2b.5). Neither WPM nor the crypto monitor carries this field.
Traffic-light dots are REAL data (baseline.<category>.traffic_light), not renderer-invented taxonomy, and are never suppressed -- unlike WPM, where a RAG dot would be forbidden as invented severity.
Family/accent taxonomy is renderer-level presentation config, not a JID field; it decorates the RAG dot, it does not replace it. Colour is always duplicated in text and is never the sole carrier of meaning.
Suppressed by doctrine: derived risk score; derived_scores = {}.
Band honesty: uncertainty bands are computed against a frozen build clock of 2026-10-02. A year-precision row is never promoted into a tighter band.
Envelope: baseline resolved at jurisdiction_json.baseline; 10 categories, 57 sub-module(s), 36 claim(s) (36 category placement(s)), 17 source(s) in the cumulative register.
Regulator_and_framework, lawful_processing_and_special_data, controller_processor_duties, cross_border_and_adequacy, algorithmic_biometric_and_surveillance_governance and enforcement_and_redress drew on the PDPA's own text (T1) plus consistent T3 commercial secondary analysis (DataGuidance) corroborating section numbers and commencement Orders. data_subject_rights, sectoral_watch and adtech_and_commercial_privacy relied primarily on T3 secondary sources and DPA consultation-notice headlines, with several sub-modules (rectification/erasure, restriction/objection, portability, cookies, dark patterns, opt-out signals, clean rooms, cross-context advertising, most sectoral overlays) carrying explicit absent_field_provenance because no statutory text or DPA guidance was retrieved. children_and_vulnerable_groups returned no findings across all five sub-modules despite targeted searches and is emitted red with full absent_field_provenance. No T1 access to the official Authority website or the final consolidated post-amendment Act text was obtained in this run; all PDPA section-level claims derive from a 2021 draft-bill PDF and T3 secondary commentary, which is a material limitation given the confirmed October 2025 amendments.
Unresolved questions (6):
What is the final consolidated text of the PDPA as amended by the 21 October 2025 amendment, and which specific sections were changed (beyond the headline description of postponed dates, ADM clarification, limited DPO scope, and flexible transfer mechanisms)?
What are the revised commencement dates for PDPA Parts I, II, III and VII following the reported Gazette repeal of prior enforcement dates?
Does the PDPA or subsidiary regulation set any age of consent or parental-consent mechanism for minors' personal data?
What are the finalised (non-draft) breach-notification timelines and DSAR response-window regulations, given several were still in public consultation as of late 2024?
Has the Authority issued any published enforcement decisions, fines, or corrective orders to date?
What is the official URL/domain of the Data Protection Authority of Sri Lanka for future T1 anchoring?