Skip to the content
Global Data RulesData governance rules, country by country

Compare countries

Two or three countries, side by side, one row per question. Pick up to 3.

Countries
Sri LankaChecked 18 August 2026
Yes, with paperworkWork: MediumEnforcement: Waking up
In one paragraph
Sri Lanka has a full privacy law on the books, but almost none of the parts that create duties for companies are switched on yet. The government has now fixed 1 January 2027 as the day the core duties start. Data may leave the country freely today. From 2027 you will need a written contract or similar promise from whoever receives it abroad. No fines have ever been issued.
The catch
The 'conditional' rating describes 1 January 2027, not today. As of 18 August 2026 the transfer rule is not in force, the individual-rights section has no start date at all, and the penalty section has no start date either. There are no industry data-storage walls: banking, payments, insurance, securities, health and telecom all lack a localisation rule. The only place data location is even mentioned is government, and there it is a preference, not a ban.
Does this apply to me?
Yes. The law reaches a company with no office in Sri Lanka if it offers goods or services to people in Sri Lanka, or watches how they behave online. It also catches anyone processing data inside the country. There is no size or revenue floor to fall below, and no requirement to appoint a local representative. But none of this bites until 1 January 2027, because the scope section itself has not started yet.High confidence
Can the data leave the country?
Today, yes, with nothing to sign — the transfer section is not in force. From 1 January 2027 data can still leave, but you must first get a binding promise from the receiver abroad that Sri Lankan protections will be honoured. There is no banned-country list and no approved-country list: Sri Lanka scrapped its country-approval system in October 2025. No industry has a rule forcing data to stay in Sri Lanka.High confidence
What do I have to do to send it abroad?
Right now, nothing. There is no approval to get, no list to check and no form to file, because the transfer section has not started. From 1 January 2027 you will need a written, binding commitment from the overseas receiver. The Authority is supposed to say exactly what form that takes, and it has not done so — only a draft from October 2024 exists, and that draft was written for a version of the law that no longer exists.High confidence
Who enforces this — and are they actually working?
The Data Protection Authority of Sri Lanka. It genuinely exists: it has a chairman, a seven-person board, a director-general, an office in Colombo and it publishes circulars and draft rules. But it has never issued a fine or a decision, and legally it cannot yet. The Authority itself says in writing that it will only investigate complaints once the relevant sections are switched on. The penalty section still has no start date.High confidence
How long must I keep it, and when must I delete it?
The floor is clearer than the ceiling. Banks, finance companies and other reporting institutions must keep transaction records for six years, and identity records for six years after the account closes. The ceiling is a principle, not a number: from 1 January 2027 you must not keep personal data in a form that identifies someone for longer than the purpose needs. Where the two clash, the six-year legal duty wins.High confidence
What happens when something goes wrong?
There is no deadline, because there is no duty yet. This is unusual and worth saying plainly: as of 18 August 2026 a company suffering a data breach in Sri Lanka has no legal obligation to tell anyone. Reporting to the national cyber team is voluntary. From 1 January 2027 you must notify the Authority, but the rules that set the form and the clock are still a draft. Banks are the exception and must report technology and cyber incidents to the Central Bank.High confidence
What's the trap?
Five things that will cost you a weekend. A child in Sri Lanka is anyone under sixteen, not eighteen, and a parent must consent for them. Fines are small but personal: directors can be made to pay unless they prove they did not know. The advertised start date of 18 March 2025 was cancelled four days before it arrived, so anything written before November 2025 is wrong. Company data is not protected the way you would expect, because the individual-rights section still has no start date. And the published transfer guidance describes a law that no longer exists.High confidence
What's about to change?
One hard date and four switches. On 1 January 2027 the scope, the processing duties and the controller duties all start, and the Central Bank's new outsourcing rules for banks start the same day. Before then the Authority is expected to finalise its rules on breach reporting, impact assessments, data protection officers and overseas transfers. Watch also for a second gazette bringing individual rights and the penalty section into force — without it, the law has duties but no teeth.High confidence
Hardest industry wall
  • Government Personal Data Protection Act section 26(4) and 26(5), as substituted by Act No. 22 of 2025
IndiaChecked 18 August 2026
Depends on your industryWork: HighEnforcement: Waking up
In one paragraph
India's general privacy law is unusually relaxed about sending data abroad — it bans transfers only to countries on a government blacklist, and that blacklist is currently empty. But specific industries have hard walls: payments data, insurance records and telecom network data must stay inside India. The main law is passed but most of it only becomes enforceable in May 2027, and the regulator has no members yet.
The catch
The permissive headline is true only until you touch payments, insurance, telecom infrastructure, government cloud, public-health records or detailed mapping data. In those six areas India is one of the strictest jurisdictions in the world.
Does this apply to me?
Yes, it reaches you even with no office in India. The law applies to any organisation anywhere in the world that processes Indians' data in connection with offering goods or services to people in India. There is no size or revenue threshold to fall below.High confidence
Can the data leave the country?
In general, yes — freely. India's approach is a blacklist: the government may name countries you cannot send data to, and as of today it has named none. Six industries are the exception and are covered below.High confidence
What do I have to do to send it abroad?
Nothing to sign, no government approval, no standard contract. Unlike Europe, India requires no paperwork to send personal data abroad under the general law — the only question is whether the destination is on the blacklist, and nothing is. Sector rules override this completely.High confidence
Who enforces this — and are they actually working?
On paper, the Data Protection Board of India. In practice, nobody yet — the Board legally exists but as of August 2026 has no chairperson and no members. The government advertised the five posts in May 2026 and re-advertised in June, and they were still vacant in August. Sector regulators, by contrast, are fully active: the central bank, the insurance and securities regulators, the telecom department and the national cyber agency all enforce today.High confidence
How long must I keep it, and when must I delete it?
There is both a floor and a ceiling. From May 2027 every organisation must keep processing logs for at least one year. Tax records run six years, company books eight, and security logs 180 days. In the other direction, large consumer platforms must delete a user's data three years after they last engaged — with 48 hours' warning to the user first.High confidence
What happens when something goes wrong?
Two clocks, and this trips up almost everyone. You have SIX HOURS to report a cyber incident to India's national cyber agency — one of the shortest deadlines in the world. Separately, from May 2027, you must tell the privacy regulator and affected individuals without delay, then file a detailed report within 72 hours.High confidence
What's the trap?
Four things that catch people out. (1) A child is anyone under 18 — there is no lower age of digital consent as there is in Europe, and targeted advertising to under-18s is banned outright. (2) A consent manager must be an Indian company with about $2.3m of net worth, so a foreign entity cannot be one. (3) If designated a 'significant' organisation you must have a data protection officer physically based in India who answers to the board. (4) The general law expressly preserves stricter sector rules, so its liberal transfer regime gives you nothing if you touch payments, insurance or telecom.High confidence
What's about to change?
Three dates matter. 13 November 2026: consent managers must register. 13 May 2027: the whole law becomes enforceable, and the government has publicly refused to extend it or exempt startups. At some point before then, the Board should get its members — at which point enforcement switches on.High confidence
Hardest industry wall
  • Payments Storage of Payment System Data
  • Telecoms Telecommunications (Authorisation) Rules, 2026
  • Insurance IRDAI (Maintenance of Information by Regulated Entities and Sharing of Information by the Authority) Regulations, 2025
  • Securities Cybersecurity and Cyber Resilience Framework, control PR.DS.S2
  • All industries Directions under section 70B(6) of the Information Technology Act, 2000