Skip to the content
Global Data RulesData governance rules, country by country

Sri Lanka

Not part of a rule-making bloc: national and industry rules are the whole picture. Checked about 2 months ago, on 18 August 2026.

If you collect data about people in Sri Lanka — customers, users, employees — these are the rules you have to follow. Here is the short version.

The short version

Yes, with paperworkWork: MediumEnforcement: Waking up

Sri Lanka has a full privacy law on the books. But almost none of the parts that create duties for companies are switched on yet. The government has now fixed 1 January 2027 as the day the main duties start. Data may leave the country freely today. From 2027 you will need a written contract, or a similar promise, from whoever receives it abroad. No fines have ever been issued.

Data governance in Sri Lanka

The eight things that decide how you handle data about people in Sri Lanka. Same eight on every country page, so you can compare.

Who has to follow these rules

Yes. The law reaches a company with no office in Sri Lanka if it offers goods or services to people in Sri Lanka. It also reaches you if you watch how they behave online. It catches anyone using or storing data inside the country. There is no size or revenue floor to fall below. There is no requirement to appoint a local representative. But none of this applies until 1 January 2027, because the section that sets the scope has not started yet.

Where the data is allowed to live

Today, yes, with nothing to sign. The transfer section is not in force. From 1 January 2027 data can still leave. But you must first get a binding promise from the receiver abroad that Sri Lankan protections will be honoured. There is no banned-country list and no approved-country list. Sri Lanka scrapped its country-approval system in October 2025. No industry has a rule forcing data to stay in Sri Lanka.

Ways to send data out:
Standard contract clauses · Approved group rules · Certification scheme · Approved code of conduct

What to do: Get the paperwork for one of the routes below signed before any data leaves Sri Lanka.

Sending data out of the country

Right now, nothing. There is no approval to get, no list to check and no form to file, because the transfer section has not started. From 1 January 2027 you will need a written, binding commitment from the overseas receiver. The Authority is supposed to say what form that takes. It has not done so. Only a draft from October 2024 exists, and that draft was written for a version of the law that no longer exists.

Ways to send data out:
Standard contract clauses · Approved group rules · Certification scheme · Approved code of conduct · Explicit consent · Needed for a contract · Legal claims · Important public interest · To save someone’s life

What to do: Get the approved standard contract clauses signed with every vendor that touches this data, before it leaves.

The regulator, and whether it actually acts

The Data Protection Authority of Sri Lanka. It really exists. It has a chairman, a seven-person board, a director-general and an office in Colombo. It publishes circulars and draft rules. But it has never issued a fine or a decision, and legally it cannot yet. The Authority says in writing that it will only investigate complaints once the relevant sections are switched on. The penalty section still has no start date.

How long you must keep it — and when to delete it

The floor is clearer than the ceiling. Banks, finance companies and other reporting institutions must keep transaction records for six years. They must keep identity records for six years after the account closes. The ceiling is a principle, not a number. From 1 January 2027 you must not keep personal data in a form that identifies someone for longer than the purpose needs. Where the two clash, the six-year legal duty wins.

What you have to do here:
Keep data for a minimum period · Delete data after a period

What to do: Write one deletion schedule that respects both the minimum keep-period and the deletion deadline.

If something goes wrong

There is no deadline, because there is no duty yet. This is unusual, so it is worth saying plainly. As of 18 August 2026 a company suffering a data breach in Sri Lanka does not have to tell anyone. Reporting to the national cyber team is voluntary. From 1 January 2027 you must notify the Authority. But the rules that set the form and the clock are still a draft. Banks are the exception. They must report technology and cyber incidents to the Central Bank.

What you have to do here:
Report breaches to the regulator · Tell affected people · Report cyber incidents

What to do: Your breach process has to reach both the regulator and the affected people inside the deadline above.

What catches people out

Five things that will cost you a weekend. One: a child in Sri Lanka is anyone under sixteen, not eighteen, and a parent must consent for them. Two: fines are small but personal. Directors can be made to pay unless they prove they did not know. Three: the advertised start date of 18 March 2025 was cancelled four days before it arrived, so anything written before November 2025 is wrong. Four: people do not have the rights you would expect, because the section on individual rights still has no start date. Five: the published transfer guidance describes a law that no longer exists.

What you have to do here:
Get a parent's consent for children
What it costs if you get it wrong:
Fixed maximum fine

What's changing next

One firm date and four switches. On 1 January 2027 the scope section starts, along with the duties on companies that use or store personal data. The Central Bank's new outsourcing rules for banks start the same day. Before then the Authority is expected to finalise its rules on breach reporting, impact assessments, data protection officers and overseas transfers. Watch also for a second gazette bringing individual rights and the penalty section into force. Without it, the law has duties but no teeth.

What to do: Diarise 1 January 2027 — that is the date this changes.

The actual laws

Everything above comes from these. Industry rules beat the general ones — if you're in a listed industry, read that group first.

Applies only to certain industries5 rules

If your product does one of these things, read this group first — industry rules beat the general position.

Government

Government data must stay in the country

Official name: Personal Data Protection Act section 26(4) and 26(5), as substituted by Act No. 22 of 2025 · Act No. 9 of 2022 s.26(4)-(5) as substituted · Act of parliament

Passed, not yet fully in forceNo — it stays put

This ban exists but covers nothing yet. Ministries, departments, provincial councils and local authorities will be barred from sending certain kinds of personal data out of Sri Lanka. That only happens once a minister names those kinds. None have been named. The list can be created by gazette with no consultation.

In force since 1 January 2027

Enforced by Ministry of Digital Economy

How this country controls where data goes: Not allowed (no country is on the approved list yet)

Government

Government data rules

Official name: Personal Data Protection Circular No. 01/2026 — Application of PDPA in the Public Sector · DPA/Legal/01/02, 7 August 2026; supersedes Circular No. 01/2024 of 13 September 2024 · Regulator directive

In forceYes — store it anywhere

This is the only Sri Lankan data protection rule actually in force today, and it binds the public sector only. It orders every ministry and department to appoint a data protection officer and start preparing. It also confirms in writing that the regulator will not investigate anything until the law is switched on.

In force since 7 August 2026

Enforced by Data Protection Authority of Sri Lanka

How this country controls where data goes: No restriction · Accepted routes: Nothing required

Government

Cyber security rules

Official name: Information and Cyber Security Policy for Government Organizations · Sri Lanka CERT, first print January 2023; implemented by Ministry circulars MOT/2023/01 of 2 May 2023 and MODE/2026/02 of 22 June 2026 · Government policy document

In forceYes — store it anywhere

This is the closest thing Sri Lanka has to a rule that government data must stay in the country, and it is not one. Public bodies are told to give priority to the state-run Lanka Government Cloud. They are told to assess the risk of foreign clouds carefully. Using a cloud abroad is discouraged, not forbidden.

In force since 2 May 2023

Enforced by Sri Lanka Computer Emergency Readiness Team

How this country controls where data goes: No restriction · Accepted routes: Nothing required

Applies to every company3 rules

These bind you whatever business you are in, once the country's rules reach you.

Breach reporting rules

Official name: Personal Data Protection Act, No. 9 of 2022 · Act No. 9 of 2022, certified 19 March 2022 · Act of parliament

Partly in forceYes — store it anywhere

This is Sri Lanka's general privacy law, the first in South Asia. It is only partly switched on. The regulator's own section started in 2023. The duties on companies start on 1 January 2027. The section on individual rights and the penalty section have no start date at all. Penalties are capped at 10 million rupees (about $33,000) per breach, and can be recovered personally from directors.

In force since 17 July 2023In force now, but not enforced until 1 January 2027

That is a long gap: the duty is real law today, but no penalty can follow until 1 January 2027. A contract you sign can still hold you to it from day one — and government contracts often do.

Enforced by Data Protection Authority of Sri Lanka

How this country controls where data goes: No restriction · Accepted routes: Nothing required

Rules for sending data abroad

Official name: Personal Data Protection (Amendment) Act, No. 22 of 2025 · Act No. 22 of 2025, certified 30 October 2025, published 31 October 2025 · Act of parliament

In forceYes, with paperwork

This is the amendment that rewrote Sri Lanka's transfer rule. It deleted the old system of government-approved safe countries. It also deleted the ban on public bodies handling data abroad. In their place: send data anywhere, as long as you can show the receiver is bound by contract to protect it. It also removed all fixed deadlines for switching on the rest of the law.

In force since 30 October 2025In force now, but not enforced until 1 January 2027

That is a long gap: the duty is real law today, but no penalty can follow until 1 January 2027. A contract you sign can still hold you to it from day one — and government contracts often do.

Enforced by Data Protection Authority of Sri Lanka

How this country controls where data goes: No restriction · Accepted routes: Standard contract clauses, Approved group rules, Certification scheme, Approved code of conduct, Explicit consent, Needed for a contract, Legal claims, Important public interest, To save someone’s life

General data protection law

Official name: Personal Data Protection Act Part IV — Use of Personal Data to Disseminate Solicited Messages · Act No. 9 of 2022, section 27 · Act of parliament

Passed, not yet fully in forceYes — store it anywhere

The direct marketing section of Sri Lanka's privacy law has never been switched on. The original Act said it had to start within four years of March 2022. The 2025 amendment deleted that deadline. So it can stay off indefinitely, or be switched on by a single gazette notice.

Enforced by Data Protection Authority of Sri Lanka

How this country controls where data goes: No restriction · Accepted routes: Nothing required

Who you would hear from

  • Data Protection Authority of Sri Lanka

    General personal data protection, all sectors

    Set up and staffed. Chairman Rajeeva Bandaranaike, a seven-member board, and director-general Dimuth Bhashitha Atapattu, with an office at the BMICH in Colombo. It publishes circulars, drafts and consultations. But it has never issued a decision or a fine. It states in its own Circular No. 01/2026 that it will only investigate complaints and hear appeals once the relevant sections are brought into operation. The penalty section of the Act has no start date.

  • Commencement orders under the privacy law, government cyber security circulars, digital identity

    The President holds this portfolio and signs the commencement gazettes personally. Issued MODE/2026/02 on government cyber security in June 2026.

  • Banking, finance companies, payments and settlements

    Issues directions and circulars regularly; several in 2026, including the new outsourcing directions and incident reporting for banks.

  • Sri Lanka CERT|CC

    National cyber security agency; government information security policy

    Active. It publishes alerts and policies and runs an incident reporting portal. It has no legal power to force incident reports. There is still no Cyber Security Act, so reporting is voluntary outside regulated industries.

  • Anti-money-laundering record-keeping and reporting by financial institutions

  • Telecom licensing, SIM registration, network rules

    Working as a licensing body. So our finding that telecoms data need not stay in the country is recorded at medium confidence rather than high.

  • Securities markets and market intermediaries

    Issues directives regularly through 2026, but none found on data storage location, cyber security or outsourcing.

What we're not sure about

An honest gap is more useful than a confident guess. These are the claims we could not verify against a government source.

  • That no rule forcing data to stay in the country rule exists in the insurance sector

    We could not read the Insurance Regulatory Commission of Sri Lanka's website on 18 August 2026, so we could not check its list of directions. Treat insurance as unchecked, not as clear. If you are an insurer, ask the regulator.

  • That no rule forcing data to stay in the country or subscriber-data rule exists in telecom licences

    The Telecommunications Regulatory Commission's rules, statutes and subsidiary legislation pages returned no documents we could read. Individual telecom licence conditions are not published. A rule that data must stay in the country could sit inside a licence we cannot see. Check your own licence.

  • The incident reporting deadline in Central Bank Circular No. 2/2025 for licensed banks

    The circular's existence and title are confirmed from the Central Bank's own index. The document itself holds no readable text, so we could not extract the number of hours. If you are a bank, take the deadline from the circular itself.

  • Whether a further gazette has appointed a commencement date for Part II (rights of the people the data is about) or Part VII (penalties) between 22 July and 18 August 2026

    The Authority's own gazette page, as at 18 August 2026, shows Extraordinary Gazette No. 2498/16 as the most recent entry. A later order could exist without appearing there. Check that page before you rely on the dates given here.

  • Minimum record-keeping periods under Sri Lanka's tax and company law

    The Inland Revenue Department page we could read does not state a keeping period. We found no official consolidated text of the Companies Act, No. 7 of 2007 on a government website. Only the six-year anti-money-laundering floor is confirmed. Check tax and company periods with a local accountant.

  • That there is no health-sector or geospatial keeping data in the country rule

    We found no rule requiring health or mapping data to stay in Sri Lanka. We could not confirm that against the Ministry of Health or Survey Department websites. If you work in either area, check before you rely on it.

  • The exact relationship between Circular No. 01/2026 of 7 August 2026 and the gazette of 22 July 2026

    The circular says new enforcement dates are 'expected to be announced soon'. But the gazette setting 1 January 2027 was published sixteen days earlier. The gazette is the one with legal force. The circular text appears to have been drafted before it. Plan to the gazette.

Freshness and refresh

Freshness

Checked about 2 months ago, on 18 August 2026.

Re-checked every 30 days. Next check due 17 September 2026.

Read the exact prompt used to research this page

This is a map, not legal advice. It tells you which questions to ask. It cannot tell you whether your specific setup is lawful — for that you need a qualified adviser looking at your actual data flows.

Every claim on this page links to the government's own website. Click any source to verify it yourself.