{
 "jurisdiction_id": "LK",
 "jurisdiction": "Sri Lanka",
 "url": "https://dataprotection.gi/jurisdictions/sri-lanka/",
 "generator": "render_jid v13-gdpri-1.0.0",
 "date_modified": "2026-08-05",
 "schema_version": "gdpri-v2",
 "counts": {
  "categories": 10,
  "claims": 36,
  "sub_modules": 57,
  "source_register": 15
 },
 "categories": [
  {
   "code": "regulator_and_framework",
   "name": "Regulator & Framework",
   "traffic_light": "amber",
   "sub_modules": [
    "act_and_instruments",
    "material_scope",
    "regulator_and_authority",
    "regulator_registration_and_filing",
    "territorial_scope"
   ],
   "url": "https://dataprotection.gi/jurisdictions/sri-lanka/#regulator-and-framework-regulator-framework",
   "traffic_light_rationale": "Comprehensive omnibus statute enacted and regulator operational, but core substantive Parts (I, II, III, VII) have had commencement dates repeatedly postponed and several implementing regulations remain in draft/consultation.",
   "claims": [
    {
     "statement": "Part V of the PDPA entered into force on 17 July 2023, thereby establishing the Data Protection Authority of Sri Lanka.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "DataGuidance",
     "source_url": "https://www.dataguidance.com/jurisdiction/sri-lanka",
     "source_tier": null,
     "observed_at": "2026-08-05"
    },
    {
     "statement": "The Personal Data Protection Act, No. 9 of 2022 was passed by the Parliament of Sri Lanka and endorsed on 19 March 2022.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "DataGuidance",
     "source_url": "https://www.dataguidance.com/jurisdiction/sri-lanka",
     "source_tier": null,
     "observed_at": "2026-08-05"
    },
    {
     "statement": "Parts VI, VIII, IX and X of the PDPA entered into effect on 1 December 2023, with Parts I, II, III and VII scheduled to enter into effect on 18 March 2025 per a January 2024 commencement Order.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "DataGuidance",
     "source_url": "https://www.dataguidance.com/jurisdiction/sri-lanka",
     "source_tier": null,
     "observed_at": "2026-08-05"
    },
    {
     "statement": "Sri Lanka's Parliament adopted amendments to the PDPA on 21 October 2025, which postponed operational dates, clarified automated-decision-making rights, limited DPO requirements, and introduced more flexible cross-border data transfer mechanisms.",
     "regulatory_stage": "enacted_not_yet_effective",
     "is_binding": true,
     "confidence": "Probable",
     "source_publisher": "DataGuidance",
     "source_url": "https://www.dataguidance.com/jurisdiction/sri-lanka",
     "source_tier": null,
     "observed_at": "2026-08-05"
    },
    {
     "statement": "The PDPA does not apply to personal data processed purely for personal, domestic, or household purposes by an individual, or to data other than personal data (Section 2(3)).",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "DataGuidance",
     "source_url": "https://www.dataguidance.com/opinion/sri-lanka-personal-data-protection-act-overview-part",
     "source_tier": null,
     "observed_at": "2026-08-05"
    },
    {
     "statement": "The PDPA applies extraterritorially to processing that offers goods or services to data subjects in Sri Lanka (including targeted offerings) or that monitors the behaviour of data subjects in Sri Lanka, including profiling (Section 2(2)).",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "DataGuidance",
     "source_url": "https://www.dataguidance.com/opinion/sri-lanka-personal-data-protection-act-overview-part",
     "source_tier": null,
     "observed_at": "2026-08-05"
    }
   ]
  },
  {
   "code": "lawful_processing_and_special_data",
   "name": "Lawful Processing & Special Data",
   "traffic_light": "amber",
   "sub_modules": [
    "consent_thresholds",
    "lawful_bases",
    "pseudonymisation_and_anonymisation",
    "special_categories"
   ],
   "url": "https://dataprotection.gi/jurisdictions/sri-lanka/#lawful-processing-and-special-data-lawful-processing-special-data",
   "traffic_light_rationale": "Core lawful-basis and special-category provisions exist in the Act text, but they sit in Parts (I-III) whose commencement date has been repeatedly postponed, and pseudonymisation/anonymisation rules were not located.",
   "claims": [
    {
     "statement": "Under the PDPA, personal data may only be processed pursuant to the legal bases set out in Schedule I (Section 5), including responding to emergencies threatening life, health or safety, performance of a public-interest task or statutory power, and legitimate interests of the controller or a third party.",
     "regulatory_stage": "enacted_not_yet_effective",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "DataGuidance",
     "source_url": "https://www.dataguidance.com/opinion/sri-lanka-personal-data-protection-act-overview-part",
     "source_tier": null,
     "observed_at": "2026-08-05"
    },
    {
     "statement": "Schedule I further clarifies 'legitimate interests' to include processing where the data subject is a client or in the service of the controller, where processing is reasonably expected, and where strictly necessary for preventing fraud.",
     "regulatory_stage": "enacted_not_yet_effective",
     "is_binding": true,
     "confidence": "Probable",
     "source_publisher": "DataGuidance",
     "source_url": "https://www.dataguidance.com/opinion/sri-lanka-personal-data-protection-act-overview-part",
     "source_tier": null,
     "observed_at": "2026-08-05"
    },
    {
     "statement": "Consent under the PDPA is defined as a freely given, specific, informed, and unambiguous indication by written declaration or affirmative action signifying the data subject's agreement, with further conditions elaborated in Schedule III.",
     "regulatory_stage": "enacted_not_yet_effective",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "DataGuidance",
     "source_url": "https://www.dataguidance.com/opinion/sri-lanka-personal-data-protection-act-overview-part",
     "source_tier": null,
     "observed_at": "2026-08-05"
    },
    {
     "statement": "The PDPA affords additional protection to special categories of personal data (sensitive data) by limiting the circumstances in which such data may be processed, per the conditions in Schedule II.",
     "regulatory_stage": "enacted_not_yet_effective",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "DataGuidance",
     "source_url": "https://www.dataguidance.com/opinion/sri-lanka-personal-data-protection-act-overview-part",
     "source_tier": null,
     "observed_at": "2026-08-05"
    }
   ]
  },
  {
   "code": "data_subject_rights",
   "name": "Data Subject Rights",
   "traffic_light": "amber",
   "sub_modules": [
    "access_right",
    "data_portability",
    "deadlines_and_response_windows",
    "rectification_and_erasure",
    "restriction_and_objection"
   ],
   "url": "https://dataprotection.gi/jurisdictions/sri-lanka/#data-subject-rights-data-subject-rights",
   "traffic_light_rationale": "Rights exist in principle under the Act, but implementing regulations governing procedure/deadlines were still in public-consultation draft form as of late 2024, and core Parts covering these rights had postponed commencement.",
   "claims": [
    {
     "statement": "The Data Protection Authority of Sri Lanka sought public input on draft fee regulations for data-subject-rights requests under the PDPA.",
     "regulatory_stage": null,
     "is_binding": false,
     "confidence": "Probable",
     "source_publisher": "DataGuidance",
     "source_url": "https://www.dataguidance.com/jurisdiction/sri-lanka",
     "source_tier": null,
     "observed_at": "2026-08-05"
    },
    {
     "statement": "The Authority sought public input on draft regulations for data subjects' rights and appeals under the PDPA, extending the feedback deadline to 15 November 2024.",
     "regulatory_stage": null,
     "is_binding": false,
     "confidence": "Probable",
     "source_publisher": "DataGuidance",
     "source_url": "https://www.dataguidance.com/jurisdiction/sri-lanka",
     "source_tier": null,
     "observed_at": "2026-08-05"
    }
   ]
  },
  {
   "code": "controller_processor_duties",
   "name": "Controller/Processor Duties",
   "traffic_light": "amber",
   "sub_modules": [
    "accountability_and_dpia",
    "breach_notification",
    "dpo_requirements",
    "joint_controller_arrangements",
    "retention_and_disposal",
    "ropa_requirements",
    "security_measures"
   ],
   "url": "https://dataprotection.gi/jurisdictions/sri-lanka/#controller-processor-duties-controller-processor-duties",
   "traffic_light_rationale": "Substantive duties are set out in the Act, but a cluster of implementing regulations were still in draft/consultation stage as of the last confirmed update, and the DPO obligation itself was narrowed by the pending 2025 amendment.",
   "claims": [
    {
     "statement": "Controllers under the PDPA must implement a Data Protection Management Programme.",
     "regulatory_stage": "enacted_not_yet_effective",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "DataGuidance",
     "source_url": "https://www.dataguidance.com/opinion/sri-lanka-personal-data-protection-act-overview-0",
     "source_tier": null,
     "observed_at": "2026-08-05"
    },
    {
     "statement": "Controllers under the PDPA must conduct Data Protection Impact Assessments (DPIAs) where applicable, and the Authority launched a public consultation on draft PDPIA regulations.",
     "regulatory_stage": "enacted_not_yet_effective",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "DataGuidance",
     "source_url": "https://www.dataguidance.com/opinion/sri-lanka-personal-data-protection-act-overview-0",
     "source_tier": null,
     "observed_at": "2026-08-05"
    },
    {
     "statement": "The PDPA requires the appointment of a Data Protection Officer (DPO), and the Authority sought public input on draft DPO-appointment regulations under the Act.",
     "regulatory_stage": "enacted_not_yet_effective",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "DataGuidance",
     "source_url": "https://www.dataguidance.com/opinion/sri-lanka-personal-data-protection-act-overview-0",
     "source_tier": null,
     "observed_at": "2026-08-05"
    },
    {
     "statement": "The October 2025 amendments to the PDPA are reported to include 'limited DPO requirements', narrowing the scope of the original DPO-appointment obligation.",
     "regulatory_stage": "enacted_not_yet_effective",
     "is_binding": true,
     "confidence": "Uncertain",
     "source_publisher": "DataGuidance",
     "source_url": "https://www.dataguidance.com/jurisdiction/sri-lanka",
     "source_tier": null,
     "observed_at": "2026-08-05"
    },
    {
     "statement": "Processors under the PDPA must comply with the controller's written instructions and confidentiality measures.",
     "regulatory_stage": "enacted_not_yet_effective",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "DataGuidance",
     "source_url": "https://www.dataguidance.com/opinion/sri-lanka-personal-data-protection-act-overview-0",
     "source_tier": null,
     "observed_at": "2026-08-05"
    },
    {
     "statement": "Section 10 of the PDPA requires controllers to ensure integrity and confidentiality of personal data by using appropriate technical and organisational measures.",
     "regulatory_stage": "enacted_not_yet_effective",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "DataGuidance",
     "source_url": "https://www.dataguidance.com/opinion/sri-lanka-personal-data-protection-act-overview-part",
     "source_tier": null,
     "observed_at": "2026-08-05"
    },
    {
     "statement": "The PDPA mandates notification of data breaches and imposes conditions on processing personal data outside Sri Lanka, requiring adequacy decisions or appropriate safeguards.",
     "regulatory_stage": "enacted_not_yet_effective",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "DataGuidance",
     "source_url": "https://www.dataguidance.com/opinion/sri-lanka-personal-data-protection-act-overview-0",
     "source_tier": null,
     "observed_at": "2026-08-05"
    },
    {
     "statement": "The Data Protection Authority of Sri Lanka launched a public consultation on draft rules for data breach notifications under the PDPA.",
     "regulatory_stage": null,
     "is_binding": false,
     "confidence": "Probable",
     "source_publisher": "DataGuidance",
     "source_url": "https://www.dataguidance.com/jurisdiction/sri-lanka",
     "source_tier": null,
     "observed_at": "2026-08-05"
    }
   ]
  },
  {
   "code": "cross_border_and_adequacy",
   "name": "Cross-Border & Adequacy",
   "traffic_light": "amber",
   "sub_modules": [
    "adequacy_granted",
    "adequacy_received",
    "data_localisation",
    "sccs_and_bcrs",
    "transfer_impact_assessment",
    "transfer_mechanisms"
   ],
   "url": "https://dataprotection.gi/jurisdictions/sri-lanka/#cross-border-and-adequacy-cross-border-adequacy",
   "traffic_light_rationale": "A transfer-mechanism framework exists in the Act, but implementing directives were in draft/consultation form and no adequacy decisions to or from Sri Lanka were identified.",
   "claims": [
    {
     "statement": "The PDPA outlines conditions for processing personal data outside Sri Lanka, requiring adequacy decisions or appropriate safeguards.",
     "regulatory_stage": "enacted_not_yet_effective",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "DataGuidance",
     "source_url": "https://www.dataguidance.com/opinion/sri-lanka-personal-data-protection-act-overview-0",
     "source_tier": null,
     "observed_at": "2026-08-05"
    },
    {
     "statement": "To ensure compliance for overseas processing, a controller must enter into a legally binding and enforceable instrument with the recipient located outside Sri Lanka, or adopt another instrument determined by the Authority.",
     "regulatory_stage": "enacted_not_yet_effective",
     "is_binding": true,
     "confidence": "Probable",
     "source_publisher": "Parliament of Sri Lanka (hosted via DataGuidance)",
     "source_url": "https://www.dataguidance.com/sites/default/files/sri_lanka_draft_data_protection_bill_2021.pdf",
     "source_tier": null,
     "observed_at": "2026-08-05"
    },
    {
     "statement": "The Data Protection Authority sought public input on a draft directive for classifying personal-data categories for processing abroad.",
     "regulatory_stage": null,
     "is_binding": false,
     "confidence": "Probable",
     "source_publisher": "DataGuidance",
     "source_url": "https://www.dataguidance.com/jurisdiction/sri-lanka",
     "source_tier": null,
     "observed_at": "2026-08-05"
    },
    {
     "statement": "The PDPA's cross-border data transfer provisions have data-localisation implications applicable to all controllers and processors intending to process personal data outside of Sri Lanka.",
     "regulatory_stage": "enacted_not_yet_effective",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "DataGuidance",
     "source_url": "https://www.dataguidance.com/jurisdiction/sri-lanka",
     "source_tier": null,
     "observed_at": "2026-08-05"
    }
   ]
  },
  {
   "code": "sectoral_watch",
   "name": "Sectoral Watch",
   "traffic_light": "amber",
   "sub_modules": [
    "credit_and_scoring",
    "education",
    "employment_data",
    "financial_sector_overlay",
    "health_sector_overlay",
    "insurance",
    "telecoms_and_eprivacy"
   ],
   "url": "https://dataprotection.gi/jurisdictions/sri-lanka/#sectoral-watch-sectoral-watch",
   "traffic_light_rationale": "General cross-sector coordination is committed to in policy statements, but dedicated sectoral overlay statutes/regulations for financial services, health, employment, credit, education, or insurance were not located.",
   "claims": [
    {
     "statement": "Sri Lanka's 2023 budget speech confirmed the Authority will be independent and engaged with the Central Bank of Sri Lanka and Securities and Exchange Commission to ensure proper governance of personal data.",
     "regulatory_stage": null,
     "is_binding": false,
     "confidence": "Probable",
     "source_publisher": "DataGuidance",
     "source_url": "https://www.dataguidance.com/news/sri-lanka-government-commits-establishing-data",
     "source_tier": null,
     "observed_at": "2026-08-05"
    },
    {
     "statement": "The 2023 budget speech confirmed the Authority will engage with the Telecommunications Regulatory Commission of Sri Lanka and other relevant sectoral regulators to ensure proper governance of personal data.",
     "regulatory_stage": null,
     "is_binding": false,
     "confidence": "Probable",
     "source_publisher": "DataGuidance",
     "source_url": "https://www.dataguidance.com/news/sri-lanka-government-commits-establishing-data",
     "source_tier": null,
     "observed_at": "2026-08-05"
    }
   ]
  },
  {
   "code": "adtech_and_commercial_privacy",
   "name": "AdTech & Commercial Privacy",
   "traffic_light": "amber",
   "sub_modules": [
    "clean_rooms_and_dcr",
    "cookies_and_trackers",
    "cross_context_advertising",
    "dark_patterns",
    "direct_marketing",
    "opt_out_signals"
   ],
   "url": "https://dataprotection.gi/jurisdictions/sri-lanka/#adtech-and-commercial-privacy-adtech-commercial-privacy",
   "traffic_light_rationale": "Direct marketing is explicitly addressed by statute; other adtech-adjacent sub-modules (cookies, dark patterns, opt-out signals, clean rooms, cross-context advertising) have no located statutory or DPA-guidance basis.",
   "claims": [
    {
     "statement": "Section 27 of the PDPA provides that a controller shall not disseminate unsolicited messages to any identified or identifiable data subject, subject to conditions in the Act.",
     "regulatory_stage": "enacted_not_yet_effective",
     "is_binding": true,
     "confidence": "Probable",
     "source_publisher": "Parliament of Sri Lanka (hosted via DataGuidance)",
     "source_url": "https://www.dataguidance.com/sites/default/files/sri_lanka_draft_data_protection_bill_2021.pdf",
     "source_tier": null,
     "observed_at": "2026-08-05"
    }
   ]
  },
  {
   "code": "algorithmic_biometric_and_surveillance_governance",
   "name": "Algorithmic, Biometric & Surveillance Governance",
   "traffic_light": "amber",
   "sub_modules": [
    "ai_risk_assessments",
    "automated_decision_making_transparency",
    "biometric_regime",
    "genetic_data",
    "profiling_restrictions",
    "state_surveillance_carveouts"
   ],
   "url": "https://dataprotection.gi/jurisdictions/sri-lanka/#algorithmic-biometric-and-surveillance-governance-algorithmic-biometric-surveill",
   "traffic_light_rationale": "ADM and profiling are addressed at a scope/definitional level and via a reported 2025 amendment, but dedicated biometric, genetic-data, and AI-risk-assessment regimes were not confirmed as enacted.",
   "claims": [
    {
     "statement": "The PDPA applies to processing that specifically monitors the behaviour of data subjects in Sri Lanka, including profiling with the intention of making decisions about such behaviour, insofar as it takes place in Sri Lanka.",
     "regulatory_stage": "enacted_not_yet_effective",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "DataGuidance",
     "source_url": "https://www.dataguidance.com/opinion/sri-lanka-personal-data-protection-act-overview-part",
     "source_tier": null,
     "observed_at": "2026-08-05"
    },
    {
     "statement": "Sri Lanka's October 2025 PDPA amendments clarified automated decision-making rights for data subjects.",
     "regulatory_stage": "enacted_not_yet_effective",
     "is_binding": true,
     "confidence": "Uncertain",
     "source_publisher": "DataGuidance",
     "source_url": "https://www.dataguidance.com/jurisdiction/sri-lanka",
     "source_tier": null,
     "observed_at": "2026-08-05"
    },
    {
     "statement": "A Sri Lankan Gazette reportedly repealed prior PDPA enforcement dates pending further amendments related to AI and technology adoption.",
     "regulatory_stage": null,
     "is_binding": false,
     "confidence": "Speculative",
     "source_publisher": "DataGuidance",
     "source_url": "https://www.dataguidance.com/jurisdiction/sri-lanka",
     "source_tier": null,
     "observed_at": "2026-08-05"
    },
    {
     "statement": "The PDPA's definition of personal data includes factors specific to the physical, physiological, genetic, psychological, economic, cultural, or social identity of a natural person.",
     "regulatory_stage": "enacted_not_yet_effective",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "DataGuidance",
     "source_url": "https://www.dataguidance.com/opinion/sri-lanka-personal-data-protection-act-overview-part",
     "source_tier": null,
     "observed_at": "2026-08-05"
    },
    {
     "statement": "Section 40 of the PDPA outlines several exemptions, restrictions, and derogations, primarily in relation to national security and public interest.",
     "regulatory_stage": "enacted_not_yet_effective",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "DataGuidance",
     "source_url": "https://www.dataguidance.com/opinion/sri-lanka-personal-data-protection-act-overview-part",
     "source_tier": null,
     "observed_at": "2026-08-05"
    }
   ]
  },
  {
   "code": "children_and_vulnerable_groups",
   "name": "Children & Vulnerable Groups",
   "traffic_light": "red",
   "sub_modules": [
    "age_verification",
    "dependent_adults",
    "education_settings",
    "minor_profiling_bans",
    "parental_consent"
   ],
   "url": "https://dataprotection.gi/jurisdictions/sri-lanka/#children-and-vulnerable-groups-children-vulnerable-groups",
   "traffic_light_rationale": "Targeted searches for children/minors provisions in the PDPA and DPA guidance returned no relevant results.",
   "claims": []
  },
  {
   "code": "enforcement_and_redress",
   "name": "Enforcement & Redress",
   "traffic_light": "amber",
   "sub_modules": [
    "collective_redress_and_class_actions",
    "enforcement_activity_index",
    "private_right_of_action",
    "recent_developments_180d",
    "regulator_funding_and_capacity",
    "regulator_powers_and_penalties"
   ],
   "url": "https://dataprotection.gi/jurisdictions/sri-lanka/#enforcement-and-redress-enforcement-redress",
   "traffic_light_rationale": "Enforcement powers exist on the statute's face, but no confirmed enforcement decisions/fines were located, and the underlying substantive obligations remain subject to a shifting commencement timetable.",
   "claims": [
    {
     "statement": "A person liable to a fine under the PDPA who fails to pay may have the Authority apply to the Magistrate Court of Colombo for an order requiring payment, recoverable in like manner as a court-imposed fine even if it exceeds the court's ordinary fining jurisdiction.",
     "regulatory_stage": "enacted_not_yet_effective",
     "is_binding": true,
     "confidence": "Probable",
     "source_publisher": "Parliament of Sri Lanka (hosted via DataGuidance)",
     "source_url": "https://www.dataguidance.com/sites/default/files/sri_lanka_draft_data_protection_bill_2021.pdf",
     "source_tier": null,
     "observed_at": "2026-08-05"
    },
    {
     "statement": "Imposition of a penalty under the PDPA does not preclude a supervisory or regulatory authority from taking other regulatory measures, including suspension of a business/profession or cancellation of a licence.",
     "regulatory_stage": "enacted_not_yet_effective",
     "is_binding": true,
     "confidence": "Probable",
     "source_publisher": "Parliament of Sri Lanka (hosted via DataGuidance)",
     "source_url": "https://www.dataguidance.com/sites/default/files/sri_lanka_draft_data_protection_bill_2021.pdf",
     "source_tier": null,
     "observed_at": "2026-08-05"
    },
    {
     "statement": "The Data Protection Authority's public activity to date includes issuing a compliance circular for public-sector authorities and multiple public consultations on draft directives/regulations, rather than published enforcement decisions.",
     "regulatory_stage": null,
     "is_binding": false,
     "confidence": "Probable",
     "source_publisher": "DataGuidance",
     "source_url": "https://www.dataguidance.com/jurisdiction/sri-lanka",
     "source_tier": null,
     "observed_at": "2026-08-05"
    },
    {
     "statement": "Sri Lanka's 2023 budget speech confirmed government commitment to establishing an independent Data Protection Authority.",
     "regulatory_stage": null,
     "is_binding": false,
     "confidence": "Probable",
     "source_publisher": "DataGuidance",
     "source_url": "https://www.dataguidance.com/news/sri-lanka-government-commits-establishing-data",
     "source_tier": null,
     "observed_at": "2026-08-05"
    }
   ]
  }
 ]
}