🔒 Data Protection Regulatory Intelligence
GDPRI · dataprotection.gi
LK · run data-protection-2026-08-05 v13-gdpri-1.0.0
content: ai_generated 5 sources retrieved model claude-sonnet-5 ·

Sri Lanka

LK schema gdpri-v2 trajectory: not recorded

Last updated · 10 categories · 36 claims · 5 sources in the cumulative register

10Categoriesbaseline.[]
57Sub-modulesbaseline..sub_modules{}
36Claimsbaseline..claims[]
0Tier-1 sourcesrun_metadata.t1_source_count
Traffic-light mix (sums to 10 rendered categories; click to filter)

Jurisdiction brief

No content recorded at this JID path.

10 of 10 categories
Signal
Density

Selections OR within a group, AND across groups. Press / to search.

#

Comprehensive omnibus statute enacted and regulator operational, but core substantive Parts (I, II, III, VII) have had commencement dates repeatedly postponed and several implementing regulations remain in draft/consultation.

Primary frameworkPersonal Data Protection Act, No. 9 of 2022 (PDPA)
Supervisory authorityData Protection Authority of Sri Lanka
Traffic-light rationale — AmberComprehensive omnibus statute enacted and regulator operational, but core substantive Parts (I, II, III, VII) have had commencement dates repeatedly postponed and several implementing regulations remain in draft/consultation.

Sub-modules (5)

Regulator And AuthorityGreen

The Authority was established under Part V of the PDPA, which entered into force on 17 July 2023.

Claims: CLM-LK-a1b2c3d4

Act And InstrumentsAmber

PDPA No. 9 of 2022 was enacted/endorsed on 19 March 2022 and commences in phases via ministerial Order, with an October 2025 amendment further adjusting timelines and substantive provisions.

Claims: CLM-LK-b2c3d4e5, CLM-LK-c3d4e5f6, CLM-LK-d4e5f6a7

Material ScopeGreen

The PDPA applies to processing of personal data generally but excludes purely personal/domestic/household processing.

Claims: CLM-LK-e5f6a7b8

Territorial ScopeGreen

The PDPA has extraterritorial reach, applying to controllers/processors outside Sri Lanka who offer goods/services to, or monitor the behaviour of, data subjects in Sri Lanka.

Claims: CLM-LK-f6a7b8c9

Regulator Registration And FilingRed

No general controller/processor registration or filing regime with the Authority was identified in available sources; the closest analogue is the DPO-communication duty and the data-protection-management-programme obligation, which are treated under controller_processor_duties.

Absence provenance: not recorded. Searched: Sri Lanka PDPA controller registration filing requirement, Sri Lanka Data Protection Authority registration regulations.

Category narrative65 words

Sri Lanka's Personal Data Protection Act, No. 9 of 2022 (PDPA) is the first comprehensive data-protection statute in the jurisdiction, establishing the Data Protection Authority of Sri Lanka. Commencement has been staggered by ministerial Order across 2023-2025, and a further October 2025 amendment postponed several operational dates and adjusted DPO/ADM/cross-border provisions, so the regime is best characterised as in transition rather than fully in force.

Sources and claims (6)
  1. ConfirmedDataGuidancePart V of the PDPA entered into force on 17 July 2023, thereby establishing the Data Protection Authority of Sri Lanka.
  2. ConfirmedDataGuidanceThe Personal Data Protection Act, No. 9 of 2022 was passed by the Parliament of Sri Lanka and endorsed on 19 March 2022.
  3. ConfirmedDataGuidanceParts VI, VIII, IX and X of the PDPA entered into effect on 1 December 2023, with Parts I, II, III and VII scheduled to enter into effect on 18 March 2025 per a January 2024 commencement Order.
  4. ProbableDataGuidanceSri Lanka's Parliament adopted amendments to the PDPA on 21 October 2025, which postponed operational dates, clarified automated-decision-making rights, limited DPO requirements, and introduced more flexible cross-border data transfer mechanisms.
  5. ConfirmedDataGuidanceThe PDPA does not apply to personal data processed purely for personal, domestic, or household purposes by an individual, or to data other than personal data (Section 2(3)).
  6. ConfirmedDataGuidanceThe PDPA applies extraterritorially to processing that offers goods or services to data subjects in Sri Lanka (including targeted offerings) or that monitors the behaviour of data subjects in Sri Lanka, including profiling (Section 2(2)).

#

Core lawful-basis and special-category provisions exist in the Act text, but they sit in Parts (I-III) whose commencement date has been repeatedly postponed, and pseudonymisation/anonymisation rules were not located.

Primary frameworkPersonal Data Protection Act, No. 9 of 2022 (PDPA) — Schedules I, II, III
Supervisory authorityData Protection Authority of Sri Lanka
Traffic-light rationale — AmberCore lawful-basis and special-category provisions exist in the Act text, but they sit in Parts (I-III) whose commencement date has been repeatedly postponed, and pseudonymisation/anonymisation rules were not located.

Sub-modules (4)

Lawful BasesAmber

Schedule I (given effect via Section 5) enumerates lawful bases including consent, vital-interest emergencies, public-interest/statutory tasks, and legitimate interests.

Claims: CLM-LK-a7b8c9d0, CLM-LK-b8c9d0e1

Special CategoriesAmber

Schedule II imposes additional conditions limiting the circumstances in which special/sensitive categories of personal data may be processed.

Claims: CLM-LK-d0e1f2a3

Pseudonymisation And AnonymisationRed

No PDPA provision or DPA guidance specifically defining pseudonymisation/anonymisation safe-harbours was located in available sources.

Absence provenance: not recorded. Searched: Sri Lanka PDPA pseudonymisation anonymisation definition, Sri Lanka Data Protection Authority anonymisation guidance.

Category narrative42 words

The PDPA sets out an enumerated set of lawful bases in Schedule I (Section 5), a defined consent standard elaborated in Schedule III, and enhanced conditions for special/sensitive categories in Schedule II. No specific statutory pseudonymisation/anonymisation safe-harbour was identified in available sources.

Sources and claims (4)
  1. ConfirmedDataGuidanceUnder the PDPA, personal data may only be processed pursuant to the legal bases set out in Schedule I (Section 5), including responding to emergencies threatening life, health or safety, performance of a public-interest task or statutory power, and legitimate interests of the controller or a third party.
  2. ProbableDataGuidanceSchedule I further clarifies 'legitimate interests' to include processing where the data subject is a client or in the service of the controller, where processing is reasonably expected, and where strictly necessary for preventing fraud.
  3. ConfirmedDataGuidanceConsent under the PDPA is defined as a freely given, specific, informed, and unambiguous indication by written declaration or affirmative action signifying the data subject's agreement, with further conditions elaborated in Schedule III.
  4. ConfirmedDataGuidanceThe PDPA affords additional protection to special categories of personal data (sensitive data) by limiting the circumstances in which such data may be processed, per the conditions in Schedule II.

#

Rights exist in principle under the Act, but implementing regulations governing procedure/deadlines were still in public-consultation draft form as of late 2024, and core Parts covering these rights had postponed commencement.

Primary frameworkPersonal Data Protection Act, No. 9 of 2022 (PDPA)
Supervisory authorityData Protection Authority of Sri Lanka
Traffic-light rationale — AmberRights exist in principle under the Act, but implementing regulations governing procedure/deadlines were still in public-consultation draft form as of late 2024, and core Parts covering these rights had postponed commencement.

Sub-modules (5)

Access RightAmber

The Authority sought public input on draft fee regulations for data-subject-rights requests, implying an access/rights-request mechanism is being operationalised, but the underlying statutory access-request procedure text was not retrieved.

Claims: CLM-LK-e1f2a3b4

Rectification And ErasureRed

General strengthening of data-subject rights is stated as a Section 1/PDPA objective; specific rectification/erasure mechanics were not located.

Absence provenance: not recorded. Searched: Sri Lanka PDPA rectification erasure right to be forgotten section.

Restriction And ObjectionRed

No specific restriction-of-processing or objection-right provision text was retrieved in available sources.

Absence provenance: not recorded. Searched: Sri Lanka PDPA right to object restriction of processing.

Data PortabilityRed

No specific data-portability provision was identified in available sources.

Absence provenance: not recorded. Searched: Sri Lanka PDPA data portability right.

Deadlines And Response WindowsAmber

The Authority ran a 2024 consultation on draft regulations for data-subject rights and appeals, and separately on fee regulations for rights requests, indicating response-window mechanics were still being finalised via secondary legislation as of the survey window.

Claims: CLM-LK-f2a3b4c5

Category narrative58 words

The PDPA is described as strengthening data-subject rights, and the Authority has run consultations on draft regulations for DSAR rights and appeals and fee schedules for rights requests, but concrete statutory deadlines and detailed mechanics for access, rectification, erasure, restriction, objection and portability were not located in available secondary sources — much of this remains in draft-regulation form.

Sources and claims (2)
  1. ProbableDataGuidanceThe Data Protection Authority of Sri Lanka sought public input on draft fee regulations for data-subject-rights requests under the PDPA.
  2. ProbableDataGuidanceThe Authority sought public input on draft regulations for data subjects' rights and appeals under the PDPA, extending the feedback deadline to 15 November 2024.

#

Substantive duties are set out in the Act, but a cluster of implementing regulations were still in draft/consultation stage as of the last confirmed update, and the DPO obligation itself was narrowed by the pending 2025 amendment.

Primary frameworkPersonal Data Protection Act, No. 9 of 2022 (PDPA)
Supervisory authorityData Protection Authority of Sri Lanka
Traffic-light rationale — AmberSubstantive duties are set out in the Act, but a cluster of implementing regulations were still in draft/consultation stage as of the last confirmed update, and the DPO obligation itself was narrowed by the pending 2025 amendment.

Sub-modules (7)

Accountability And DpiaAmber

Controllers must implement a Data Protection Management Programme and conduct Data Protection Impact Assessments (DPIAs) where applicable; the Authority ran a 2024 public consultation on draft PDPIA regulations.

Claims: CLM-LK-a3b4c5d6, CLM-LK-b4c5d6e7

Dpo RequirementsAmber

The PDPA requires appointment of a Data Protection Officer; the Authority consulted on draft DPO-appointment regulations in 2024, and the October 2025 amendment is reported to have introduced 'limited DPO requirements', narrowing the original obligation.

Claims: CLM-LK-c5d6e7f8, CLM-LK-d6e7f8a9

Ropa RequirementsAmber

The Data Protection Management Programme obligation functions as the PDPA's closest analogue to records-of-processing requirements; a dedicated ROPA provision distinct from the DPMP was not separately confirmed.

Claims: CLM-LK-a3b4c5d6

Joint Controller ArrangementsAmber

Processors must comply with the controller's written instructions and confidentiality measures; specific joint-controller apportionment-of-liability provisions were not separately located.

Claims: CLM-LK-e7f8a9b0

Security MeasuresGreen

Section 10 of the PDPA requires controllers to ensure integrity and confidentiality of personal data using appropriate technical and organisational measures.

Claims: CLM-LK-f8a9b0c1

Breach NotificationAmber

The PDPA mandates notification of personal data breaches; the Authority launched a public consultation on draft breach-notification rules under the PDPA, indicating implementing detail was still being finalised.

Claims: CLM-LK-a9b0c1d2, CLM-LK-b0c1d2e3

Retention And DisposalRed

No specific statutory retention-period or disposal-duty provision was located in available sources.

Absence provenance: not recorded. Searched: Sri Lanka PDPA data retention disposal period.

Category narrative61 words

The PDPA imposes an accountability framework requiring a Data Protection Management Programme, DPIAs for higher-risk processing, DPO appointment (narrowed by the October 2025 amendment), processor obligations to act on written instructions with confidentiality safeguards, security-of-processing duties (Section 10), and mandatory breach notification — though several implementing regulations (DPO appointment, PDPIA, breach notification, DPMP guidelines) remained in public-consultation draft form through 2024.

Sources and claims (8)
  1. ConfirmedDataGuidanceControllers under the PDPA must implement a Data Protection Management Programme.
  2. ConfirmedDataGuidanceControllers under the PDPA must conduct Data Protection Impact Assessments (DPIAs) where applicable, and the Authority launched a public consultation on draft PDPIA regulations.
  3. ConfirmedDataGuidanceThe PDPA requires the appointment of a Data Protection Officer (DPO), and the Authority sought public input on draft DPO-appointment regulations under the Act.
  4. UncertainDataGuidanceThe October 2025 amendments to the PDPA are reported to include 'limited DPO requirements', narrowing the scope of the original DPO-appointment obligation.
  5. ConfirmedDataGuidanceProcessors under the PDPA must comply with the controller's written instructions and confidentiality measures.
  6. ConfirmedDataGuidanceSection 10 of the PDPA requires controllers to ensure integrity and confidentiality of personal data by using appropriate technical and organisational measures.
  7. ConfirmedDataGuidanceThe PDPA mandates notification of data breaches and imposes conditions on processing personal data outside Sri Lanka, requiring adequacy decisions or appropriate safeguards.
  8. ProbableDataGuidanceThe Data Protection Authority of Sri Lanka launched a public consultation on draft rules for data breach notifications under the PDPA.

#

A transfer-mechanism framework exists in the Act, but implementing directives were in draft/consultation form and no adequacy decisions to or from Sri Lanka were identified.

Primary frameworkPersonal Data Protection Act, No. 9 of 2022 (PDPA)
Supervisory authorityData Protection Authority of Sri Lanka
Traffic-light rationale — AmberA transfer-mechanism framework exists in the Act, but implementing directives were in draft/consultation form and no adequacy decisions to or from Sri Lanka were identified.

Sub-modules (6)

Transfer MechanismsAmber

Cross-border transfers require either an adequacy-type decision or appropriate safeguards, including a legally binding enforceable instrument with the overseas recipient or another Authority-approved mechanism.

Claims: CLM-LK-c1d2e3f4, CLM-LK-d2e3f4a5

Adequacy ReceivedRed

No adequacy decision received by Sri Lanka from another regime (e.g. EU/UK) was identified in available sources.

Absence provenance: not recorded. Searched: Sri Lanka EU adequacy decision, Sri Lanka UK adequacy PDPA.

Adequacy GrantedAmber

No formal Sri Lankan adequacy determinations regarding third countries were identified; the Authority is instead developing a directive to classify personal-data categories for cross-border processing.

Claims: CLM-LK-e3f4a5b6

Sccs And BcrsAmber

No finalised standard-contractual-clause or binding-corporate-rules template issued by the Authority was located; the Act contemplates a 'legally binding and enforceable instrument' as one safeguard mechanism.

Claims: CLM-LK-d2e3f4a5

Transfer Impact AssessmentRed

No standalone transfer-impact-assessment requirement distinct from the general safeguard/adequacy mechanism was identified.

Absence provenance: not recorded. Searched: Sri Lanka PDPA transfer impact assessment requirement.

Data LocalisationAmber

The PDPA provisions governing cross-border data transfers carry data-localisation implications, generally requiring processing to remain within Sri Lanka unless permitted to be processed in a third country under the safeguard regime.

Claims: CLM-LK-f4a5b6c7

Category narrative74 words

The PDPA restricts cross-border transfers unless the destination benefits from an adequacy-type decision or the controller puts in place appropriate safeguards (including a legally binding enforceable instrument with the overseas recipient), and these provisions carry data-localisation implications for controllers/processors processing outside Sri Lanka. The Authority has run consultations on directives for processing personal data abroad and for classifying personal-data categories for overseas processing, and the October 2025 amendment reportedly introduced more flexible transfer mechanisms.

Sources and claims (4)
  1. ConfirmedDataGuidanceThe PDPA outlines conditions for processing personal data outside Sri Lanka, requiring adequacy decisions or appropriate safeguards.
  2. ProbableParliament of Sri Lanka (hosted via DataGuidance)To ensure compliance for overseas processing, a controller must enter into a legally binding and enforceable instrument with the recipient located outside Sri Lanka, or adopt another instrument determined by the Authority.
  3. ProbableDataGuidanceThe Data Protection Authority sought public input on a draft directive for classifying personal-data categories for processing abroad.
  4. ConfirmedDataGuidanceThe PDPA's cross-border data transfer provisions have data-localisation implications applicable to all controllers and processors intending to process personal data outside of Sri Lanka.

#

General cross-sector coordination is committed to in policy statements, but dedicated sectoral overlay statutes/regulations for financial services, health, employment, credit, education, or insurance were not located.

Primary frameworkPersonal Data Protection Act, No. 9 of 2022 (PDPA)
Supervisory authorityData Protection Authority of Sri Lanka
Traffic-light rationale — AmberGeneral cross-sector coordination is committed to in policy statements, but dedicated sectoral overlay statutes/regulations for financial services, health, employment, credit, education, or insurance were not located.

Sub-modules (7)

Financial Sector OverlayAmber

The Authority is intended to engage with the Central Bank of Sri Lanka and the Securities and Exchange Commission to ensure proper governance of personal data in the financial sector.

Claims: CLM-LK-a5b6c7d8

Health Sector OverlayRed

No dedicated health-sector data-protection overlay statute was identified.

Absence provenance: not recorded. Searched: Sri Lanka health data protection law overlay.

Telecoms And EprivacyAmber

The Authority is intended to engage with the Telecommunications Regulatory Commission of Sri Lanka (TRCSL) for governance of personal data in the telecoms sector; no separate ePrivacy-style statute was identified.

Claims: CLM-LK-b6c7d8e9

Employment DataRed

No dedicated employment-data overlay was identified beyond general PDPA coverage.

Absence provenance: not recorded. Searched: Sri Lanka employment data protection code.

Credit And ScoringRed

No dedicated credit-scoring data-protection overlay was identified.

Absence provenance: not recorded. Searched: Sri Lanka credit scoring data protection regulation.

EducationRed

No dedicated education-sector data-protection overlay was identified.

Absence provenance: not recorded. Searched: Sri Lanka education sector data protection rules.

InsuranceRed

No dedicated insurance-sector data-protection overlay was identified.

Absence provenance: not recorded. Searched: Sri Lanka insurance sector data protection regulation.

Category narrative63 words

Sri Lanka does not appear to have distinct sector-specific data-protection statutes (health, credit, education, insurance) separate from the PDPA; instead, the 2023 budget speech committed the incoming Authority to independent operation while engaging with the Central Bank of Sri Lanka, the Securities and Exchange Commission, and the Telecommunications Regulatory Commission of Sri Lanka (TRCSL) to ensure coordinated governance of personal data across sectors.

Sources and claims (2)
  1. ProbableDataGuidanceSri Lanka's 2023 budget speech confirmed the Authority will be independent and engaged with the Central Bank of Sri Lanka and Securities and Exchange Commission to ensure proper governance of personal data.
  2. ProbableDataGuidanceThe 2023 budget speech confirmed the Authority will engage with the Telecommunications Regulatory Commission of Sri Lanka and other relevant sectoral regulators to ensure proper governance of personal data.

#

Direct marketing is explicitly addressed by statute; other adtech-adjacent sub-modules (cookies, dark patterns, opt-out signals, clean rooms, cross-context advertising) have no located statutory or DPA-guidance basis.

Primary frameworkPersonal Data Protection Act, No. 9 of 2022 (PDPA), Part IV
Supervisory authorityData Protection Authority of Sri Lanka
Traffic-light rationale — AmberDirect marketing is explicitly addressed by statute; other adtech-adjacent sub-modules (cookies, dark patterns, opt-out signals, clean rooms, cross-context advertising) have no located statutory or DPA-guidance basis.

Sub-modules (6)

Cookies And TrackersRed

No cookie/tracker-specific consent regime was identified in the PDPA or Authority guidance.

Absence provenance: not recorded. Searched: Sri Lanka PDPA cookies consent regulation.

Dark PatternsRed

No dark-pattern prohibition was identified in available sources.

Absence provenance: not recorded. Searched: Sri Lanka PDPA dark patterns prohibition.

Opt Out SignalsRed

No recognised technical opt-out signal (e.g. Global Privacy Control analogue) was identified.

Absence provenance: not recorded. Searched: Sri Lanka PDPA opt-out signal Global Privacy Control.

Clean Rooms And DcrRed

No clean-room/data-collaboration-room framework was identified.

Absence provenance: not recorded. Searched: Sri Lanka data clean room regulation.

Cross Context AdvertisingRed

No 'sale'/'share'-style cross-context advertising provision analogous to US state law was identified.

Absence provenance: not recorded. Searched: Sri Lanka PDPA cross-context advertising sale of data.

Direct MarketingAmber

Part IV of the PDPA (Section 27) prohibits a controller from disseminating unsolicited messages to an identified or identifiable data subject, subject to specified exceptions.

Claims: CLM-LK-c7d8e9f0

Category narrative31 words

The PDPA's Part IV restricts the use of personal data for unsolicited direct-marketing messages; no cookie/tracker-specific consent regime, dark-pattern prohibition, recognised opt-out signal, or clean-room framework was identified in available sources.

Sources and claims (1)
  1. ProbableParliament of Sri Lanka (hosted via DataGuidance)Section 27 of the PDPA provides that a controller shall not disseminate unsolicited messages to any identified or identifiable data subject, subject to conditions in the Act.

#

ADM and profiling are addressed at a scope/definitional level and via a reported 2025 amendment, but dedicated biometric, genetic-data, and AI-risk-assessment regimes were not confirmed as enacted.

Primary frameworkPersonal Data Protection Act, No. 9 of 2022 (PDPA)
Supervisory authorityData Protection Authority of Sri Lanka
Traffic-light rationale — AmberADM and profiling are addressed at a scope/definitional level and via a reported 2025 amendment, but dedicated biometric, genetic-data, and AI-risk-assessment regimes were not confirmed as enacted.

Sub-modules (6)

Profiling RestrictionsAmber

The PDPA's territorial-scope provision captures profiling of data subjects in Sri Lanka undertaken with the intention of making decisions about their behaviour.

Claims: CLM-LK-d8e9f0a1

Automated Decision Making TransparencyAmber

The October 2025 PDPA amendments are reported to have clarified automated-decision-making rights.

Claims: CLM-LK-e9f0a1b2

Ai Risk AssessmentsRed

A Gazette reportedly repealed prior PDPA enforcement dates pending amendments tied to AI and technology adoption, signalling anticipated but not-yet-enacted AI-specific regulatory activity.

Claims: CLM-LK-f0a1b2c3

Biometric RegimeRed

No dedicated biometric-data regime (facial recognition, fingerprint, gait) distinct from the general personal-data definition was identified.

Absence provenance: not recorded. Searched: Sri Lanka PDPA biometric data facial recognition regulation.

Genetic DataAmber

Genetic factors are referenced within the PDPA's general 'personal data' definition as one of the identifying attributes, but no dedicated genetic-data regime was found.

Claims: CLM-LK-a1b2c3e4

State Surveillance CarveoutsAmber

Section 40 of the PDPA outlines exemptions, restrictions and derogations primarily relating to national security and public interest.

Claims: CLM-LK-b2c3e4f5

Category narrative65 words

The PDPA's extraterritorial-scope trigger expressly captures profiling used to make decisions about data subjects' behaviour in Sri Lanka, and the October 2025 amendment reportedly clarified automated-decision-making rights. National-security/public-interest carve-outs are set out in Section 40. No dedicated biometric- or genetic-data regime, or AI-specific risk-assessment obligation, was confirmed beyond genetic/physiological factors being folded into the general 'personal data' definition and a Gazette signalling pending AI-related amendments.

Sources and claims (5)
  1. ConfirmedDataGuidanceThe PDPA applies to processing that specifically monitors the behaviour of data subjects in Sri Lanka, including profiling with the intention of making decisions about such behaviour, insofar as it takes place in Sri Lanka.
  2. UncertainDataGuidanceSri Lanka's October 2025 PDPA amendments clarified automated decision-making rights for data subjects.
  3. SpeculativeDataGuidanceA Sri Lankan Gazette reportedly repealed prior PDPA enforcement dates pending further amendments related to AI and technology adoption.
  4. ConfirmedDataGuidanceThe PDPA's definition of personal data includes factors specific to the physical, physiological, genetic, psychological, economic, cultural, or social identity of a natural person.
  5. ConfirmedDataGuidanceSection 40 of the PDPA outlines several exemptions, restrictions, and derogations, primarily in relation to national security and public interest.

#

Targeted searches for children/minors provisions in the PDPA and DPA guidance returned no relevant results.

Supervisory authorityData Protection Authority of Sri Lanka
Traffic-light rationale — RedTargeted searches for children/minors provisions in the PDPA and DPA guidance returned no relevant results.

Sub-modules (5)

Age VerificationRed

No age-of-consent or age-verification provision was identified.

Absence provenance: not recorded. Searched: Sri Lanka PDPA age of consent minors.

Minor Profiling BansRed

No minor-specific profiling ban was identified.

Absence provenance: not recorded. Searched: Sri Lanka PDPA minor profiling ban.

Education SettingsRed

No education-setting-specific data-protection rule was identified.

Absence provenance: not recorded. Searched: Sri Lanka PDPA education sector children data.

Dependent AdultsRed

No dependent-adult-specific protection was identified.

Absence provenance: not recorded. Searched: Sri Lanka PDPA dependent adults incapacitated persons data protection.

Category narrative24 words

No PDPA provision or Authority guidance addressing age of consent, parental-consent mechanisms, minor-profiling bans, education-setting-specific rules, or dependent-adult protections was located in available sources.

#

Enforcement powers exist on the statute's face, but no confirmed enforcement decisions/fines were located, and the underlying substantive obligations remain subject to a shifting commencement timetable.

Primary frameworkPersonal Data Protection Act, No. 9 of 2022 (PDPA)
Supervisory authorityData Protection Authority of Sri Lanka
Traffic-light rationale — AmberEnforcement powers exist on the statute's face, but no confirmed enforcement decisions/fines were located, and the underlying substantive obligations remain subject to a shifting commencement timetable.

Sub-modules (6)

Regulator Powers And PenaltiesAmber

The Authority may impose fines payable into the Consolidated Fund; non-payment is enforceable via application to the Magistrate Court of Colombo, and penalty imposition does not preclude other regulatory measures such as suspension or licence cancellation.

Claims: CLM-LK-c3e4f5a6, CLM-LK-d4f5a6b7

Enforcement Activity IndexRed

No published enforcement decisions or fines were located; Authority activity to date has centred on consultations, circulars and draft directives.

Absence provenance: not recorded. Searched: Sri Lanka Data Protection Authority fine enforcement decision.

Claims: CLM-LK-e5f6a7c8

Regulator Funding And CapacityAmber

The 2023 budget speech committed to an independent Authority, but no headcount or budget figures were located.

Absence provenance: not recorded. Searched: Sri Lanka Data Protection Authority budget staffing headcount.

Claims: CLM-LK-a5b6c7d9

Collective Redress And Class ActionsRed

No collective-redress or class-action mechanism specific to the PDPA was identified.

Absence provenance: not recorded. Searched: Sri Lanka PDPA class action collective redress.

Private Right Of ActionRed

No private right of direct court action distinct from Authority-mediated enforcement was identified.

Absence provenance: not recorded. Searched: Sri Lanka PDPA private right of action civil suit.

Recent Developments 180DAmber

Sri Lanka's Parliament adopted amendments to the PDPA on 21 October 2025, and a Gazette reportedly repealed prior PDPA enforcement dates pending amendments tied to AI and technology adoption.

Claims: CLM-LK-d4e5f6a7, CLM-LK-f0a1b2c3

Category narrative91 words

The PDPA gives the Authority power to impose financial penalties (payable into the Consolidated Fund) enforceable through the Magistrate Court of Colombo for non-payment, and other regulatory measures including suspension of business/profession or cancellation of licences, without precluding sectoral regulators' own powers. As of the last confirmed update the Authority's public activity has been dominated by consultations, draft directives and circulars rather than published enforcement decisions, consistent with the still-staggered commencement of the Act's substantive Parts. The most recent material development is the 21 October 2025 Parliamentary adoption of PDPA amendments.

Sources and claims (4)
  1. ProbableParliament of Sri Lanka (hosted via DataGuidance)A person liable to a fine under the PDPA who fails to pay may have the Authority apply to the Magistrate Court of Colombo for an order requiring payment, recoverable in like manner as a court-imposed fine even if it exceeds the court's ordinary fining jurisdiction.
  2. ProbableParliament of Sri Lanka (hosted via DataGuidance)Imposition of a penalty under the PDPA does not preclude a supervisory or regulatory authority from taking other regulatory measures, including suspension of a business/profession or cancellation of a licence.
  3. ProbableDataGuidanceThe Data Protection Authority's public activity to date includes issuing a compliance circular for public-sector authorities and multiple public consultations on draft directives/regulations, rather than published enforcement decisions.
  4. ProbableDataGuidanceSri Lanka's 2023 budget speech confirmed government commitment to establishing an independent Data Protection Authority.
No categories match.

Filters combine as OR inside a group and AND across groups.

Editorial metadata

Provenance only. Nothing below gates publication or affects the render.

Editorial metadata for Sri Lanka
FieldValue
trust.lawyer_review.statusnever_reviewed
trust.lawyer_review.reviewernot recorded
trust.content_sourceai_generated

Provenance and declared absence

Disclosure model: category cards load OPEN; narratives render in full; standing narratives load as a clamped teaser with an explicit “read full” control carrying the true word count. No text is hidden without disclosing how much of it there is.

Sub-modules are DP-specific nested subsections with their own real per-sub-module traffic light, rendered under each category (BRIEF section 2b.5). Neither WPM nor the crypto monitor carries this field.

Traffic-light dots are REAL data (baseline.<category>.traffic_light), not renderer-invented taxonomy, and are never suppressed -- unlike WPM, where a RAG dot would be forbidden as invented severity.

Family/accent taxonomy is renderer-level presentation config, not a JID field; it decorates the RAG dot, it does not replace it. Colour is always duplicated in text and is never the sole carrier of meaning.

Suppressed by doctrine: derived risk score; derived_scores = {}.

Band honesty: uncertainty bands are computed against a frozen build clock of 2026-08-05. A year-precision row is never promoted into a tighter band.

Envelope: baseline resolved at jurisdiction_json.baseline; 10 categories, 57 sub-module(s), 36 claim(s), 15 source(s) in the cumulative register.