Skip to the content
Global Data RulesData governance rules, country by country

Sri Lanka

Not part of a rule-making bloc: national and industry rules are the whole picture. Checked today.

The answer

Yes, with paperworkWork: MediumEnforcement: Waking up

Sri Lanka has a full privacy law on the books, but almost none of the parts that create duties for companies are switched on yet. The government has now fixed 1 January 2027 as the day the core duties start. Data may leave the country freely today. From 2027 you will need a written contract or similar promise from whoever receives it abroad. No fines have ever been issued.

Eight questions about Sri Lanka

The questions a team asks when they are deciding where to store their users' data. Every country on this site answers the same eight, in the same order.

Do Sri Lanka's rules apply to my company?

Yes. The law reaches a company with no office in Sri Lanka if it offers goods or services to people in Sri Lanka, or watches how they behave online. It also catches anyone processing data inside the country. There is no size or revenue floor to fall below, and no requirement to appoint a local representative. But none of this bites until 1 January 2027, because the scope section itself has not started yet.

High confidenceNational rulesPartly in force

Can I store my users' data outside Sri Lanka?

Today, yes, with nothing to sign — the transfer section is not in force. From 1 January 2027 data can still leave, but you must first get a binding promise from the receiver abroad that Sri Lankan protections will be honoured. There is no banned-country list and no approved-country list: Sri Lanka scrapped its country-approval system in October 2025. No industry has a rule forcing data to stay in Sri Lanka.

High confidenceYes, with paperworkNo restrictionStandard contract clausesApproved group rulesCertification schemeApproved code of conduct

What do I need in place before data leaves Sri Lanka?

Right now, nothing. There is no approval to get, no list to check and no form to file, because the transfer section has not started. From 1 January 2027 you will need a written, binding commitment from the overseas receiver. The Authority is supposed to say exactly what form that takes, and it has not done so — only a draft from October 2024 exists, and that draft was written for a version of the law that no longer exists.

High confidenceNo restrictionStandard contract clausesApproved group rulesCertification schemeApproved code of conductExplicit consentNeeded for a contractLegal claimsImportant public interestSomeone's life is at risk

Who enforces the rules in Sri Lanka, and what can they do?

The Data Protection Authority of Sri Lanka. It genuinely exists: it has a chairman, a seven-person board, a director-general, an office in Colombo and it publishes circulars and draft rules. But it has never issued a fine or a decision, and legally it cannot yet. The Authority itself says in writing that it will only investigate complaints once the relevant sections are switched on. The penalty section still has no start date.

High confidenceWaking up

How long do I have to keep the data?

The floor is clearer than the ceiling. Banks, finance companies and other reporting institutions must keep transaction records for six years, and identity records for six years after the account closes. The ceiling is a principle, not a number: from 1 January 2027 you must not keep personal data in a form that identifies someone for longer than the purpose needs. Where the two clash, the six-year legal duty wins.

High confidenceKeep data for a minimum periodDelete data after a period

What happens if there is a breach?

There is no deadline, because there is no duty yet. This is unusual and worth saying plainly: as of 18 August 2026 a company suffering a data breach in Sri Lanka has no legal obligation to tell anyone. Reporting to the national cyber team is voluntary. From 1 January 2027 you must notify the Authority, but the rules that set the form and the clock are still a draft. Banks are the exception and must report technology and cyber incidents to the Central Bank.

High confidenceReport breaches to the regulatorTell affected peopleReport cyber incidents

What trips people up in Sri Lanka?

Five things that will cost you a weekend. A child in Sri Lanka is anyone under sixteen, not eighteen, and a parent must consent for them. Fines are small but personal: directors can be made to pay unless they prove they did not know. The advertised start date of 18 March 2025 was cancelled four days before it arrived, so anything written before November 2025 is wrong. Company data is not protected the way you would expect, because the individual-rights section still has no start date. And the published transfer guidance describes a law that no longer exists.

High confidenceGet a parent's consent for childrenFixed maximum finePartly in forcePassed, not yet fully in force

What is changing soon in Sri Lanka?

One hard date and four switches. On 1 January 2027 the scope, the processing duties and the controller duties all start, and the Central Bank's new outsourcing rules for banks start the same day. Before then the Authority is expected to finalise its rules on breach reporting, impact assessments, data protection officers and overseas transfers. Watch also for a second gazette bringing individual rights and the penalty section into force — without it, the law has duties but no teeth.

High confidencePartly in forcePassed, not yet fully in force

The rules, layer by layer

Rules stack in layers. Knowing which layer a rule sits in tells you whether your industry, your state, or a contract can override it.

  1. Layer 1

    National rules

    Added by this country on top of any bloc rules.

    3 rules here

  2. Layer 2

    Industry rules

    Made by an industry regulator. These usually beat the general position.

    5 rules here

Read the stack from the top down. Anything lower normally wins: an industry rule beats the national position, and the national position sits on top of the bloc rules.

National rules3 rules

Personal Data Protection Act, No. 9 of 2022

Act of parliament · Act No. 9 of 2022, certified 19 March 2022

Partly in forceYes — store it anywhere

Sri Lanka's general privacy law, the first in South Asia. It is only partly switched on. The regulator's own section started in 2023; the duties on companies start on 1 January 2027; the individual-rights section and the penalty section have no start date at all. Penalties are capped at 10 million rupees (about $33,000) per breach and can be recovered personally from directors.

In force since 17 July 2023But only enforceable from 1 January 2027

Enforced by Data Protection Authority of Sri Lanka

Transfer model: No restriction · Accepted routes: Nothing required

High confidence

Personal Data Protection (Amendment) Act, No. 22 of 2025

Act of parliament · Act No. 22 of 2025, certified 30 October 2025, published 31 October 2025

In forceYes, with paperwork

The amendment that rewrote Sri Lanka's transfer rule. It deleted the old system of government-approved 'adequate' countries and the ban on public bodies processing abroad. In their place: send data anywhere, provided you can show the receiver is contractually bound to protect it. It also removed all fixed deadlines for switching on the rest of the law.

In force since 30 October 2025But only enforceable from 1 January 2027

Enforced by Data Protection Authority of Sri Lanka

Transfer model: No restriction · Accepted routes: Standard contract clauses, Approved group rules, Certification scheme, Approved code of conduct, Explicit consent, Needed for a contract, Legal claims, Important public interest, Someone's life is at risk

High confidence

Personal Data Protection Act Part IV — Use of Personal Data to Disseminate Solicited Messages

Act of parliament · Act No. 9 of 2022, section 27

Passed, not yet fully in forceYes — store it anywhere

The direct marketing section of Sri Lanka's privacy law has never been switched on. The original Act said it had to start within four years of March 2022; the 2025 amendment deleted that deadline, so it can now stay dormant indefinitely or be switched on by a single gazette notice.

Enforced by Data Protection Authority of Sri Lanka

Transfer model: No restriction · Accepted routes: Nothing required

High confidence

Industry rules5 rules

Personal Data Protection Act section 26(4) and 26(5), as substituted by Act No. 22 of 2025

Act of parliament · Act No. 9 of 2022 s.26(4)-(5) as substituted · Government

Passed, not yet fully in forceNo — it stays put

A loaded gun with no bullets in it. Ministries, departments, provincial councils and local authorities will be banned from sending certain kinds of personal data out of Sri Lanka — but only once a minister names those kinds. None have been named. The list can be created by gazette with no consultation.

In force since 1 January 2027

Enforced by Ministry of Digital Economy

Transfer model: Not allowed (the list is currently empty)

High confidence

Personal Data Protection Circular No. 01/2026 — Application of PDPA in the Public Sector

Regulator directive · DPA/Legal/01/02, 7 August 2026; supersedes Circular No. 01/2024 of 13 September 2024 · Government

In forceYes — store it anywhere

The only Sri Lankan data protection instrument actually in force today, and it binds the public sector only. It orders every ministry and department to appoint a data protection officer and start preparing, and it confirms in writing that the regulator will not investigate anything until the law is switched on.

In force since 7 August 2026

Enforced by Data Protection Authority of Sri Lanka

Transfer model: No restriction · Accepted routes: Nothing required

High confidence

Information and Cyber Security Policy for Government Organizations

Government policy document · Sri Lanka CERT, first print January 2023; implemented by Ministry circulars MOT/2023/01 of 2 May 2023 and MODE/2026/02 of 22 June 2026 · Government

In forceYes — store it anywhere

The closest thing Sri Lanka has to a government data residency rule, and it is not one. Public bodies are told to give priority to the state-run Lanka Government Cloud and to assess the risk of foreign clouds carefully. Using an overseas cloud is discouraged, not forbidden.

In force since 2 May 2023

Enforced by Sri Lanka Computer Emergency Readiness Team

Transfer model: No restriction · Accepted routes: Nothing required

High confidence

Who you would hear from

  • Data Protection Authority of Sri Lanka

    General personal data protection, all sectors

    Constituted and staffed: chairman Rajeeva Bandaranaike, a seven-member board and director-general Dimuth Bhashitha Atapattu, with an office at the BMICH in Colombo. It publishes circulars, drafts and consultations. But it has never issued a decision or a fine, and it states in its own Circular No. 01/2026 that it will only investigate complaints and hear appeals once the relevant provisions are brought into operation. The penalty section of the Act has no commencement date.

  • Commencement orders under the privacy law, government cyber security circulars, digital identity

    The President holds this portfolio and signs the commencement gazettes personally. Issued MODE/2026/02 on government cyber security in June 2026.

  • Banking, finance companies, payments and settlements

    Issues directions and circulars regularly; several in 2026, including the new outsourcing directions and incident reporting for banks.

  • Sri Lanka CERT|CC

    National cyber security agency; government information security policy

    Active: publishes alerts and policies and runs an incident reporting portal. It has no statutory power to compel incident reports — there is still no Cyber Security Act, so reporting is voluntary outside regulated sectors.

  • Anti-money-laundering record-keeping and reporting by financial institutions

  • Telecom licensing, SIM registration, network rules

    Operational as a licensing body. Its website publishes very little subsidiary legislation, so the absence of a telecom data localisation rule is recorded at medium confidence rather than high.

  • Securities markets and market intermediaries

    Issues directives regularly through 2026, but none found on data storage location, cyber security or outsourcing.

What we're not sure about

An honest gap is more useful than a confident guess. These are the claims we could not verify from an official source on the last check.

  • That no data localisation rule exists in the insurance sector

    The Insurance Regulatory Commission of Sri Lanka website at ircsl.gov.lk requires JavaScript and returned no readable content or rate-limited on 18 August 2026. We could not read its directions index. Treat insurance as unchecked, not as clear.

  • That no data localisation or subscriber-data rule exists in telecom licences

    The Telecommunications Regulatory Commission's site has a JavaScript-only menu and its 'Rules & Guidelines', 'Statutes' and 'Subsidiary Legislation' pages returned no document links. Individual telecom licence conditions are not published. A residency condition could sit inside a licence we cannot read.

  • The incident reporting deadline in Central Bank Circular No. 2/2025 for licensed banks

    The PDF on the Central Bank's site contains no machine-readable text, so the number of hours could not be extracted. The circular's existence and title are confirmed from the Central Bank's own index.

  • Whether a further gazette has appointed a commencement date for Part II (rights of data subjects) or Part VII (penalties) between 22 July and 18 August 2026

    We can evidence the position from the Authority's own gazette page as at 18 August 2026, on which Extraordinary Gazette No. 2498/16 is the most recent entry. We cannot prove that no later order exists but is unpublished on that page.

  • Minimum record-keeping periods under Sri Lanka's tax and company law

    The Inland Revenue Department page we could open does not state a retention period, and we did not locate an official consolidated text of the Companies Act, No. 7 of 2007 on a government domain. Only the six-year anti-money-laundering floor is verified.

  • That there is no health-sector or geospatial data localisation rule

    The Ministry of Health site returned only a JavaScript landing page and the Survey Department site blocked automated access with a 406 error. Recorded as not found rather than not existing.

  • The exact relationship between Circular No. 01/2026 of 7 August 2026 and the gazette of 22 July 2026

    The circular says new enforcement dates are 'expected to be announced soon', but the gazette appointing 1 January 2027 was published sixteen days earlier. The gazette is the legally operative instrument; the circular text appears to have been drafted before it. Plan to the gazette.

30-day cadence. Sri Lanka is mid-commencement: a hard date of 1 January 2027 is approaching, three further gazette orders are expected (Part II rights, Part IV marketing, Part VII penalties), and seven draft regulations plus the section 33(c) transfer directive could be finalised at any time. The Minister can now appoint any commencement date by gazette with no notice period at all, because the 2025 amendment deleted the statutory timing constraints. A 90-day cadence would risk publishing a picture that is a full commencement stage out of date.

Freshness and refresh

Freshness

Checked today — on 18 August 2026.

Re-checked every 30 days. Next check due 17 September 2026.

Read the exact prompt used to research this page

Compare with

This is a map, not legal advice. It tells you which questions to ask. It cannot tell you whether your specific setup is lawful — for that you need a qualified adviser looking at your actual data flows.

Every claim on this page links to the government's own website. Click any source to verify it yourself.