Sri Lanka
Not part of a rule-making bloc: national and industry rules are the whole picture. Checked about 2 months ago, on 18 August 2026.
If you collect data about people in Sri Lanka — customers, users, employees — these are the rules you have to follow. Here is the short version.
The short version
Sri Lanka has a full privacy law on the books. But almost none of the parts that create duties for companies are switched on yet. The government has now fixed 1 January 2027 as the day the main duties start. Data may leave the country freely today. From 2027 you will need a written contract, or a similar promise, from whoever receives it abroad. No fines have ever been issued.
Data governance in Sri Lanka
The eight things that decide how you handle data about people in Sri Lanka. Same eight on every country page, so you can compare.
Who has to follow these rules
Yes. The law reaches a company with no office in Sri Lanka if it offers goods or services to people in Sri Lanka. It also reaches you if you watch how they behave online. It catches anyone using or storing data inside the country. There is no size or revenue floor to fall below. There is no requirement to appoint a local representative. But none of this applies until 1 January 2027, because the section that sets the scope has not started yet.
Section 2 of the Personal Data Protection Act, No. 9 of 2022 sets out four hooks. Work that happens wholly or partly in Sri Lanka. A company or person that decides how data is used, or handles it for someone else. That party must be based or ordinarily resident in Sri Lanka, or set up under Sri Lankan law. A company that offers goods or services to people in Sri Lanka, including by targeting them specifically. And one that specifically monitors their behaviour, including profiling. Extraordinary Gazette No. 2498/16 of 22 July 2026 sets 1 January 2027 as the start date for sections 2 and 3, and for Part I and Part III. Section 3(1) gives the Act priority over other written laws on data protection. Unlike India or the European Union, Sri Lanka does not require a foreign company to appoint an in-country representative. You only need a Data Protection Officer where section 20 applies. Since the 2025 amendment, that officer may be an outsourced third party.
Sources
- Official sourceData Protection Authority of Sri LankaPersonal Data Protection Act, No. 9 of 2022, section 2 (application of this Act)
dpa.gov.lk
“This Act shall apply to the processing of personal data— (a) where the processing of personal data takes place wholly or partly within Sri Lanka; or (b) where the processing of personal data is carried out by a controller or processor who ... offers goods or services to data subjects in Sri Lanka ... or specifically monitors the behaviour of data subjects in Sri Lanka.”
Link checked 18 August 2026
- Official sourceGovernment of Sri Lanka / Ministry of Digital EconomyExtraordinary Gazette No. 2498/16, 22 July 2026 — appoints 1 January 2027 for section 2, section 3, Part I and Part III
dpa.gov.lk
Link checked 18 August 2026
- Official sourceData Protection Authority of Sri LankaPersonal Data Protection Circular No. 01/2026, 7 August 2026, paragraph 1.5
dpa.gov.lk
“The PDPA applies territorially to the processing of personal data where such processing takes place wholly or partly within Sri Lanka, or by a person or entity within Sri Lanka; and also applies extraterritorially if a person or entity outside Sri Lanka specifically provides goods or services to "data subjects" within Sri Lanka or monitors their behavior within Sri Lanka.”
Link checked 18 August 2026
Where the data is allowed to live
Today, yes, with nothing to sign. The transfer section is not in force. From 1 January 2027 data can still leave. But you must first get a binding promise from the receiver abroad that Sri Lankan protections will be honoured. There is no banned-country list and no approved-country list. Sri Lanka scrapped its country-approval system in October 2025. No industry has a rule forcing data to stay in Sri Lanka.
- Ways to send data out:
- Standard contract clauses · Approved group rules · Certification scheme · Approved code of conduct
This is the single most important thing to understand about Sri Lanka. The original section 26 of the 2022 Act set up a European-style system of safe countries. The Minister would declare which countries protected data well enough. Public authorities had to keep their work inside Sri Lanka unless a declaration covered them. The Personal Data Protection (Amendment) Act, No. 22 of 2025, certified on 30 October 2025, repealed that section outright and replaced it. The new section 26 is about accountability instead. You may send data abroad only if Part I, Part II and sections 20 to 25 are complied with. That applies wherever the data sits. You must also use the documents specified by a directive of the Authority, so that the overseas recipient's promises are binding and enforceable. No list of safe countries exists any more, and none is coming back. Industry by industry, checked on 18 August 2026. BANKING: Banking Act Direction No. 01/2026 on outsourcing, effective 1 January 2027, allows outsourcing and cloud abroad with board approval and annual notice to the Director of Bank Supervision. We found no rule that the data must stay in the country. PAYMENTS: the Payment Cards and Mobile Payment Systems Regulations No. 1 of 2013 set no storage-location rule. SECURITIES: we found no data-location rule in the regulator's published directives and circulars. INSURANCE: we could not read the regulator's website, so this is recorded as unconfirmed rather than clear. HEALTH, TELECOMS, EDUCATION, GAMING and GEOSPATIAL: we found no rule about where data must sit on the responsible bodies' own sites. GOVERNMENT: the only area where location is addressed at all, and it is a preference. The national cyber policy tells public bodies to give priority to the Lanka Government Cloud. It does not tell them to keep data in Sri Lanka. The one real ban is unused. The new section 26(4) lets the Minister name categories of personal data that public authorities may never send abroad. No categories have been named.
Sources
- Official sourceParliament of Sri Lanka, via the Data Protection AuthorityPersonal Data Protection (Amendment) Act, No. 22 of 2025, section 10 — replacement of section 26 (cross-border data flow)
dpa.gov.lk
“A controller or processor may engage in cross-border data flows, only where such controller or processor, ensures compliance with the provisions of Part I, Part II and sections 20, 21, 22, 23, 24 and 25, as the case may be. ... a controller or processor shall adopt such instruments as may be specified by a directive issued by the Authority under paragraph (c) of section 33, to ensure binding and enforceable commitments of the recipient in the third country.”
Link checked 18 August 2026
- Official sourceData Protection Authority of Sri LankaPersonal Data Protection Circular No. 01/2026, 7 August 2026, paragraph 4.6 — cross-border limits lifted, cloud enabled
dpa.gov.lk
“Although some limitations existed earlier on cross-border data flows (ability to use cloud services) for the processing of personal data, the PDPA Amendment Act No. 22 of 2025 provides a discretion for a "Controller" to engage in cross-border data transfers.”
Link checked 18 August 2026
- Official sourceCentral Bank of Sri LankaBanking Act Directions No. 01 of 2026 — Outsourcing of Business Operations of Licensed Banks (checked for a residency clause; none found)
cbsl.gov.lk
Link checked 18 August 2026
- Official sourceCentral Bank of Sri LankaPayment Cards and Mobile Payment Systems Regulations No. 1 of 2013 (checked for a storage-location clause; none found)
cbsl.gov.lk
Link checked 18 August 2026
- Official sourceSri Lanka Computer Emergency Readiness TeamInformation and Cyber Security Policy for Government Organizations, first print January 2023, clause 4.3.6 (Data Sovereignty and Cloud Computing)
cert.gov.lk
“In fulfilling their cloud service needs, organizations shall give priority to obtaining services through the Lanka Government Cloud (LGC).”
Link checked 18 August 2026
What to do: Get the paperwork for one of the routes below signed before any data leaves Sri Lanka.
Sending data out of the country
Right now, nothing. There is no approval to get, no list to check and no form to file, because the transfer section has not started. From 1 January 2027 you will need a written, binding commitment from the overseas receiver. The Authority is supposed to say what form that takes. It has not done so. Only a draft from October 2024 exists, and that draft was written for a version of the law that no longer exists.
- Ways to send data out:
- Standard contract clauses · Approved group rules · Certification scheme · Approved code of conduct · Explicit consent · Needed for a contract · Legal claims · Important public interest · To save someone’s life
Sri Lanka has neither a list of banned countries nor a list of approved ones. The closest description is open transfers with a contract requirement on top. It works like Europe's standard contract clauses, but with no published template. Section 26(2) of the amended Act ties the required paperwork to a directive that the Authority issues under section 33(c). The Authority published a document titled 'Specification of Documents for Processing Personal Data Outside Sri Lanka Directive, 2024' for public consultation in October 2024. It is still marked DRAFT 1.0 on the Authority's own downloads page as at 18 August 2026. It lists five acceptable options. Binding corporate rules. Contracts. Codes of conduct. Certification schemes, including APEC Cross-Border Privacy Rules and schemes equivalent to the European General Data Protection Regulation. And a cross-border impact assessment. The draft is built around ministerial decisions that a country is safe enough, and the 2025 amendment abolished those. So it will have to be rewritten before it can be issued. Section 26(3) gives seven escape routes that need no paperwork at all. Explicit informed consent. Necessity for a contract with the person. Legal claims. Public interest as defined in Schedule I. An emergency threatening life, health or safety. Data merely passing through Sri Lanka. And any other condition that may be prescribed. These are written as full alternatives to the main rule, not as narrow exceptions, which makes them unusually generous.
Sources
- Official sourceParliament of Sri Lanka, via the Data Protection AuthorityPersonal Data Protection (Amendment) Act, No. 22 of 2025, new section 26(2) and 26(3)
dpa.gov.lk
Link checked 18 August 2026
- Official sourceData Protection Authority of Sri LankaDRAFT 1.0 — Specification of Instruments for Processing Personal Data Outside Sri Lanka Directive, 2024
dpa.gov.lk
Link checked 18 August 2026
- Official sourceData Protection Authority of Sri LankaData Protection Authority downloads page — all seven regulations and directives still listed under 'Draft Regulations and Directives'
dpa.gov.lk
Link checked 18 August 2026
What to do: Get the approved standard contract clauses signed with every vendor that touches this data, before it leaves.
The regulator, and whether it actually acts
The Data Protection Authority of Sri Lanka. It really exists. It has a chairman, a seven-person board, a director-general and an office in Colombo. It publishes circulars and draft rules. But it has never issued a fine or a decision, and legally it cannot yet. The Authority says in writing that it will only investigate complaints once the relevant sections are switched on. The penalty section still has no start date.
Part V of the Act, which creates the Authority, came into force on 17 July 2023 by Extraordinary Gazette No. 2341/59. The board was appointed in August 2023. The chairman is Rajeeva Bandaranaike. The director-general is Dimuth Bhashitha Atapattu. The Authority has published one binding circular, No. 01/2026 of 7 August 2026, addressed to the public sector. It also published seven draft regulations and directives for public consultation in October 2024. None of them has been finalised. Its enforcement route under section 38 has two steps, which most summaries miss. The Authority must first issue a directive under section 35. Only a failure to follow that directive brings a penalty. Industry regulators are separately active. The Central Bank of Sri Lanka issues directions and circulars regularly, including Circular No. 2/2025 on reporting information technology and cyber security incidents. The Financial Intelligence Unit supervises anti-money-laundering record-keeping. Sri Lanka CERT works as the national cyber agency, but it has no legal power to force incident reports. Its reporting portal is voluntary, and there is still no Cyber Security Act.
Sources
- Official sourceData Protection Authority of Sri LankaPersonal Data Protection Circular No. 01/2026, 7 August 2026, paragraph 2.2
dpa.gov.lk
“NOTE - the Data Protection Authority would only investigate complaints, hear appeals, etc., once the relevant governing provisions are brought into operation.”
Link checked 18 August 2026
- Official sourceData Protection Authority of Sri LankaBoard of Directors of the Data Protection Authority — chairman and six directors named
dpa.gov.lk
Link checked 18 August 2026
- Official sourceGovernment of Sri LankaExtraordinary Gazette No. 2341/59, 21 July 2023 — Part V (Data Protection Authority) in force from 17 July 2023
dpa.gov.lk
Link checked 18 August 2026
- Official sourceSri Lanka Computer Emergency Readiness TeamSri Lanka CERT incident reporting portal — offered as a service, with no statutory reporting duty or deadline stated
cert.gov.lk
Link checked 18 August 2026
How long you must keep it — and when to delete it
The floor is clearer than the ceiling. Banks, finance companies and other reporting institutions must keep transaction records for six years. They must keep identity records for six years after the account closes. The ceiling is a principle, not a number. From 1 January 2027 you must not keep personal data in a form that identifies someone for longer than the purpose needs. Where the two clash, the six-year legal duty wins.
- What you have to do here:
- Keep data for a minimum period · Delete data after a period
The floor comes from section 4 of the Financial Transactions Reporting Act, No. 6 of 2006. Six years from the date of the transaction, correspondence or report. Six years from closure of the account, or from the end of the business relationship, for identity records. The Financial Intelligence Unit can direct a longer period. Section 4(3) adds a catch that matters if you store records abroad. The institution must be able to comply IMMEDIATELY with a request from the Financial Intelligence Unit or a law enforcement agency. Records must be kept in a manner and form that allows that. That is about how fast you can produce them, not about where they sit. But a cold archive in another time zone will fail it. The ceiling is section 9 of the Personal Data Protection Act, the duty to limit how long you keep data. It allows longer storage for public-interest archiving, scientific or historical research and statistics. Section 9 sits in Part I, so it starts on 1 January 2027. The Act only partly resolves conflicts. Section 3(1) makes the Act override other written laws on data protection. But a public authority governed by another law may work under that law so far as it is consistent. A legal duty to keep records is treated as a lawful purpose, so six years beats delete-when-done.
Sources
- Official sourceFinancial Intelligence Unit of Sri LankaFinancial Transactions Reporting Act, No. 6 of 2006, section 4 (institutions to maintain and retain records)
fiusrilanka.gov.lk
“records of transactions and of correspondence relating to transactions and records of all reports furnished to the Financial Intelligence Unit for a period of six years from the date of the transaction ... and records of identity obtained in terms of section 2 for a period of six years from the date of closure of the account or cessation of the business relationship”
Link checked 18 August 2026
- Official sourceData Protection Authority of Sri LankaPersonal Data Protection Act, No. 9 of 2022, section 9 (obligation to limit the period of retention)
dpa.gov.lk
Link checked 18 August 2026
What to do: Write one deletion schedule that respects both the minimum keep-period and the deletion deadline.
If something goes wrong
There is no deadline, because there is no duty yet. This is unusual, so it is worth saying plainly. As of 18 August 2026 a company suffering a data breach in Sri Lanka does not have to tell anyone. Reporting to the national cyber team is voluntary. From 1 January 2027 you must notify the Authority. But the rules that set the form and the clock are still a draft. Banks are the exception. They must report technology and cyber incidents to the Central Bank.
- What you have to do here:
- Report breaches to the regulator · Tell affected people · Report cyber incidents
Section 23 of the Act requires you to notify the Authority of a personal data breach. The form, the manner and the time limit are all left to rules made under the Act. The Authority also decides when individuals must be told. Section 23 sits in Part III, which starts on 1 January 2027. The Data Breach Notification Rules were published for public consultation on 1 October 2024. They are still listed as a draft on the Authority's downloads page. So from 1 January 2027 there will be a duty with no clock attached, until those rules are finalised. Count the other clocks. Sri Lanka CERT runs an incident reporting portal, but there is no Cyber Security Act and no legal deadline. The Central Bank issued Circular No. 2/2025 of 7 May 2025 on reporting information technology and cyber security incidents at licensed banks. We could not read its text, so its deadline is recorded as unconfirmed. So Sri Lanka currently has at most one compulsory incident clock, and it applies only to banks.
Sources
- Official sourceData Protection Authority of Sri LankaPersonal Data Protection Act, No. 9 of 2022, section 23 (personal data breach notifications)
dpa.gov.lk
“In the event of a personal data breach, a controller shall notify the Authority, regarding such personal data breach in such form, manner and within such period of time as may be determined by rules made under this Act.”
Link checked 18 August 2026
- Official sourceData Protection Authority of Sri LankaDraft Data Breach Notification Rules, version 1.0, published for public consultation 1 October 2024 — still a draft
dpa.gov.lk
Link checked 18 August 2026
- Official sourceCentral Bank of Sri LankaCircular No. 2/2025, 7 May 2025 — Reporting of Information Technology and Cybersecurity Incidents of Licensed Banks
cbsl.gov.lk
Link checked 18 August 2026
What to do: Your breach process has to reach both the regulator and the affected people inside the deadline above.
What catches people out
Five things that will cost you a weekend. One: a child in Sri Lanka is anyone under sixteen, not eighteen, and a parent must consent for them. Two: fines are small but personal. Directors can be made to pay unless they prove they did not know. Three: the advertised start date of 18 March 2025 was cancelled four days before it arrived, so anything written before November 2025 is wrong. Four: people do not have the rights you would expect, because the section on individual rights still has no start date. Five: the published transfer guidance describes a law that no longer exists.
- What you have to do here:
- Get a parent's consent for children
- What it costs if you get it wrong:
- Fixed maximum fine
(1) AGE SIXTEEN. The Act defines a child as a person below the age of sixteen years. Consent for a child means consent from the parent or legal guardian. That is lower than India's eighteen, and lower than most of Asia. It also means a fifteen-year-old cannot consent for themselves. (2) DIRECTORS PAY PERSONALLY. Section 38(6) covers penalties imposed on a company. Every director and other officer responsible for management and control is liable to pay it. The only way out is to prove you had no knowledge of the failure. The maximum is 10 million rupees (about $33,000) for each failure, doubling for each repeat. That is small by global standards, but it attaches to individuals. (3) THE CANCELLED DATE. Extraordinary Gazette No. 2366/08 of 8 January 2024 set 18 March 2025 for Parts I, II, III and VII. Extraordinary Gazette No. 2427/34 of 14 March 2025 repealed that paragraph, four days before it took effect. The 2025 amendment then validated past acts only under Parts V, VI, VIII, IX and X. That deliberate omission confirms Parts I, II, III and VII were never in force. Any adviser working from the Authority's own news page, which still says 'Enforcement Begins on March 18, 2025', is working from a dead date. (4) RIGHTS ARE STILL UNSCHEDULED. The July 2026 gazette appointed sections 2 and 3, and Parts I and III. It did not mention Part II (rights of individuals), Part IV (marketing messages) or Part VII (penalties). So from 1 January 2027 there will be duties on companies, but no individual rights in force and no penalty section in force. Meanwhile section 26 requires you to 'ensure compliance with Part II' abroad. (5) STALE GUIDANCE. The Authority's draft cross-border directive is built around ministerial decisions that a country is safe enough. The 2025 amendment deleted those. Read it as current guidance and you will go looking for an approved-country list that does not exist and never will.
Sources
- Official sourceData Protection Authority of Sri LankaPersonal Data Protection Act, No. 9 of 2022 — section 56 definition of 'child', Schedule I on consent, and section 38 on penalties
dpa.gov.lk
“"child" means, a natural person who is below the age of sixteen years”
Link checked 18 August 2026
- Official sourceGovernment of Sri LankaExtraordinary Gazette No. 2427/34, 14 March 2025 — repeals paragraph (b) of the commencement order, cancelling the 18 March 2025 start date
dpa.gov.lk
Link checked 18 August 2026
- Official sourceGovernment of Sri LankaExtraordinary Gazette No. 2366/08, 8 January 2024 — the now-repealed order appointing 18 March 2025 for Parts I, II, III and VII
dpa.gov.lk
Link checked 18 August 2026
- Official sourceParliament of Sri Lanka, via the Data Protection AuthorityPersonal Data Protection (Amendment) Act, No. 22 of 2025, section 2(2) — validation limited to Parts V, VI, VIII, IX and X
dpa.gov.lk
“Notwithstanding the repeal of subsection (3) of section 1 of the principal enactment, anything duly done under Parts V, VI, VIII, IX and X prior to the date of commencement of this section, shall be deemed to be valid and continue to be in force.”
Link checked 18 August 2026
What's changing next
One firm date and four switches. On 1 January 2027 the scope section starts, along with the duties on companies that use or store personal data. The Central Bank's new outsourcing rules for banks start the same day. Before then the Authority is expected to finalise its rules on breach reporting, impact assessments, data protection officers and overseas transfers. Watch also for a second gazette bringing individual rights and the penalty section into force. Without it, the law has duties but no teeth.
CONFIRMED DATES. 1 January 2027: section 2, section 3, Part I and Part III of the Personal Data Protection Act start, under Extraordinary Gazette No. 2498/16 of 22 July 2026. 1 January 2027: Banking Act Directions No. 01 of 2026 on outsourcing take effect and revoke the 2012 directions. EXPECTED. The Authority's Circular No. 01/2026 of 7 August 2026 says new enforcement dates are 'expected to be announced soon'. It also says advisory committees will be formed for finance and banking, insurance, health, telecommunications, civil registration and tourism. Guidelines for each industry will follow under the new section 51A. Seven draft regulations and directives from October 2024 are still unfinished. UNUSED POWERS, each of which can change the answer without consultation. (1) The Minister may name categories of personal data that public authorities may never send abroad, under new section 26(4) and (5). Nothing has been named. (2) The Minister may by gazette order set a start date for any remaining part of the Act at any time. That includes the Part VII penalties, and there is no minimum notice. The 2025 amendment removed the old timing limits entirely. (3) The Authority may issue the section 33(c) directive specifying what transfer paperwork you need. That turns a paper duty into a concrete contracting project overnight. (4) Regulations under section 20(1)(b) may set the scale of activity that forces a private company to appoint a data protection officer. None have been made. Separately, Part IV, on using personal data to send marketing messages, has never been started. It now has no deadline for starting at all, because the amendment repealed the eighteen-to-forty-eight-month window in the original section 1.
Sources
- Official sourceGovernment of Sri LankaExtraordinary Gazette No. 2498/16, 22 July 2026 — 1 January 2027 commencement order
dpa.gov.lk
Link checked 18 August 2026
- Official sourceData Protection Authority of Sri LankaPersonal Data Protection Circular No. 01/2026, 7 August 2026, paragraphs 2.2 and 4.7
dpa.gov.lk
“Therefore, public authorities should take note of the new enforcement dates, which is expected to be announced soon.”
Link checked 18 August 2026
- Official sourceParliament of Sri Lanka, via the Data Protection AuthorityPersonal Data Protection (Amendment) Act, No. 22 of 2025, section 2 and new section 26(4)-(5)
dpa.gov.lk
“A controller or processor who is a public authority shall not engage in cross-border data flows in respect of the categories of personal data as may be prescribed under subsection (5).”
Link checked 18 August 2026
- Official sourceCentral Bank of Sri LankaBanking Act Directions No. 01 of 2026 — effective 1 January 2027
cbsl.gov.lk
Link checked 18 August 2026
What to do: Diarise 1 January 2027 — that is the date this changes.
The actual laws
Everything above comes from these. Industry rules beat the general ones — if you're in a listed industry, read that group first.
Applies only to certain industries5 rules
If your product does one of these things, read this group first — industry rules beat the general position.
Government data must stay in the country
Official name: Personal Data Protection Act section 26(4) and 26(5), as substituted by Act No. 22 of 2025 · Act No. 9 of 2022 s.26(4)-(5) as substituted · Act of parliament
This ban exists but covers nothing yet. Ministries, departments, provincial councils and local authorities will be barred from sending certain kinds of personal data out of Sri Lanka. That only happens once a minister names those kinds. None have been named. The list can be created by gazette with no consultation.
Enforced by Ministry of Digital Economy
How this country controls where data goes: Not allowed (no country is on the approved list yet)
What you have to do
- Keep the data in the country — from 1 January 2027This applies only to categories of personal data the Minister names. No categories had been named as at 18 August 2026, so the ban currently covers nothing.
Sources
- Official sourceParliament of Sri Lanka, via the Data Protection AuthorityPersonal Data Protection (Amendment) Act, No. 22 of 2025, new section 26(4) and (5), and amended definition of 'public authority'
dpa.gov.lk
“A controller or processor who is a public authority shall not engage in cross-border data flows in respect of the categories of personal data as may be prescribed under subsection (5).”
Link checked 18 August 2026
- Official sourceGovernment of Sri LankaExtraordinary Gazette No. 2498/16 — Part III (which contains section 26) commences 1 January 2027
dpa.gov.lk
Link checked 18 August 2026
Government data rules
Official name: Personal Data Protection Circular No. 01/2026 — Application of PDPA in the Public Sector · DPA/Legal/01/02, 7 August 2026; supersedes Circular No. 01/2024 of 13 September 2024 · Regulator directive
This is the only Sri Lankan data protection rule actually in force today, and it binds the public sector only. It orders every ministry and department to appoint a data protection officer and start preparing. It also confirms in writing that the regulator will not investigate anything until the law is switched on.
Enforced by Data Protection Authority of Sri Lanka
How this country controls where data goes: No restriction · Accepted routes: Nothing required
What you have to do
- Appoint a data protection officerEvery ministry and government department that uses personal data must appoint a data protection officer. It must publish the contact details on its website and report them to the Authority.
- Keep records of how you use dataInstitutions are told to run a personal data audit and a gap assessment and to build a Data Protection Management Programme.
Sources
- Official sourceData Protection Authority of Sri LankaPersonal Data Protection Circular No. 01/2026, 7 August 2026
dpa.gov.lk
“Every Ministry or Government Department processing personal data shall appoint a DPO to ensure compliance with the provisions of the Act.”
Link checked 18 August 2026
- Official sourceMinistry of Digital Economy, Sri LankaMinistry of Digital Economy circulars index — PDP/2026/01 dated 07/08/2026
mode.gov.lk
Link checked 18 August 2026
Cyber security rules
Official name: Information and Cyber Security Policy for Government Organizations · Sri Lanka CERT, first print January 2023; implemented by Ministry circulars MOT/2023/01 of 2 May 2023 and MODE/2026/02 of 22 June 2026 · Government policy document
This is the closest thing Sri Lanka has to a rule that government data must stay in the country, and it is not one. Public bodies are told to give priority to the state-run Lanka Government Cloud. They are told to assess the risk of foreign clouds carefully. Using a cloud abroad is discouraged, not forbidden.
Enforced by Sri Lanka Computer Emergency Readiness Team
How this country controls where data goes: No restriction · Accepted routes: Nothing required
What you have to do
- Secure the dataApplicable to all government organizations.
- Assess high-risk projectsA proper risk assessment is required before taking services from any cloud provider.
Sources
- Official sourceSri Lanka Computer Emergency Readiness TeamInformation and Cyber Security Policy for Government Organizations, clause 4.3.6 — Policy on Data Sovereignty and Cloud Computing
cert.gov.lk
“In fulfilling their cloud service needs, organizations shall give priority to obtaining services through the Lanka Government Cloud (LGC). ... It is, however, strictly recommended to the organizations to perform a proper risk assessment prior to obtaining services from any cloud service provider.”
Link checked 18 August 2026
- Official sourceMinistry of Digital Economy, Sri LankaMinistry of Digital Economy circular MODE/2026/02, 22 June 2026 — Implementation of Information and Cyber Security Policy for Government Organizations
mode.gov.lk
Link checked 18 August 2026
Cloud and outsourcing rules
Official name: Banking Act Directions No. 01 of 2026 — Outsourcing of Business Operations of Licensed Banks · Banking Act Direction No. 01/2026, issued 25 March 2026 · Directly binding regulation
Sri Lankan banks may outsource abroad and use foreign cloud services. There is no requirement to keep banking data in the country and no need to ask the Central Bank first. The bank must get its own board's approval and manage the country risk. It must keep the paperwork available for inspection and file an annual list every January.
Enforced by Central Bank of Sri Lanka
How this country controls where data goes: No restriction · Accepted routes: Nothing required
What you have to do
- Written vendor contract — from 1 January 2027Board approval required for each outsourcing arrangement, including offshore ones. Measures must address data accessibility, confidentiality, integrity, sovereignty, recoverability and regulatory compliance.
- Register or notify — from 1 January 2027Banks must inform the Director of Bank Supervision of existing and proposed outsourced business operations by 31 January each year. This is notification, not pre-approval.
- Independent audit — from 1 January 2027Documents must be readily available to the Central Bank on request.
What it costs if you get it wrong
- Loss of your licenceBreach of directions issued under the Banking Act
Sources
- Official sourceCentral Bank of Sri LankaBanking Act Directions No. 01 of 2026 — Outsourcing of Business Operations of Licensed Banks
cbsl.gov.lk
“Licensed banks shall ensure that effective measures are in place to address risks associated with data accessibility, confidentiality, integrity, sovereignty, recoverability, and regulatory compliance.”
Link checked 18 August 2026
- Official sourceCentral Bank of Sri LankaCentral Bank of Sri Lanka — index of banking directions, circulars and guidelines (issue date 25.03.2026)
cbsl.gov.lk
Link checked 18 August 2026
Banking rules
Official name: Financial Transactions Reporting Act, No. 6 of 2006 · Act No. 6 of 2006, section 4; amended by Act No. 17 of 2026 · Act of parliament
Sri Lanka's main retention floor. Banks, finance companies, insurers, brokers and other reporting institutions must keep transaction and identity records for six years. The records may sit abroad, but they must be producible immediately on request, which rules out slow offshore archives.
Enforced by Financial Intelligence Unit of Sri Lanka
How this country controls where data goes: No restriction · Accepted routes: Nothing required
What you have to do
- Keep data for a minimum period — 6 yearsSix years from the transaction, correspondence or report; and six years from account closure or the end of the business relationship for identity records. The Financial Intelligence Unit can direct a longer period.
- Keep records of how you use dataRecords must be kept so that the institution can comply IMMEDIATELY with a request from the Financial Intelligence Unit or a law enforcement agency. Electronic and machine-readable copies are allowed if a paper copy can be readily produced.
What it costs if you get it wrong
- Fixed maximum fineFailure to keep required records under the anti-money-laundering regime
Sources
- Official sourceFinancial Intelligence Unit of Sri LankaFinancial Transactions Reporting Act, No. 6 of 2006, section 4
fiusrilanka.gov.lk
“it shall be maintained in a manner and form that will enable an Institution to comply immediately with requests for information from the Financial Intelligence Unit or a law enforcement agency”
Link checked 18 August 2026
- Official sourceFinancial Intelligence Unit of Sri LankaFinancial Intelligence Unit — Acts and Regulations index, including the Financial Transactions Reporting (Amendment) Act No. 17 of 2026
fiusrilanka.gov.lk
Link checked 18 August 2026
Applies to every company3 rules
These bind you whatever business you are in, once the country's rules reach you.
Breach reporting rules
Official name: Personal Data Protection Act, No. 9 of 2022 · Act No. 9 of 2022, certified 19 March 2022 · Act of parliament
This is Sri Lanka's general privacy law, the first in South Asia. It is only partly switched on. The regulator's own section started in 2023. The duties on companies start on 1 January 2027. The section on individual rights and the penalty section have no start date at all. Penalties are capped at 10 million rupees (about $33,000) per breach, and can be recovered personally from directors.
That is a long gap: the duty is real law today, but no penalty can follow until 1 January 2027. A contract you sign can still hold you to it from day one — and government contracts often do.
Enforced by Data Protection Authority of Sri Lanka
How this country controls where data goes: No restriction · Accepted routes: Nothing required
What you have to do
- Get consent — from 1 January 2027
- Tell people what you do — from 1 January 2027Transparency duty in section 11 and Schedule; includes telling people about any planned transfer abroad.
- Secure the data — from 1 January 2027Section 10, integrity and confidentiality.
- Delete data after a period — from 1 January 2027Section 9. No fixed number of months. Keep the data only as long as the purpose needs, with an exception for archiving and research.
- Keep records of how you use data — from 1 January 2027Section 12 requires a documented Data Protection Management Programme.
- Assess high-risk projects — from 1 January 2027Section 24. Triggered by systematic and extensive evaluation, or systematic monitoring of public areas or telecom networks. Form and manner still in draft.
- Appoint a data protection officer — applies at: Every ministry, government department and public corporation; private bodies only once scale and magnitude are prescribed, from 1 January 2027May be an outsourced third party since the 2025 amendment. Contact details must be published and given to the Authority. The officer does not have to live in Sri Lanka.
- Report breaches to the regulator — from 1 January 2027Section 23. No deadline exists. The form, the manner and the time limit are left to rules that are still a draft.
- Get a parent's consent for children — applies at: under 16, from 1 January 2027
- Let people see their dataPart II. Not commenced and no commencement date appointed as at 18 August 2026.
- Let people correct their dataPart II. Not commenced.
- Let people delete their dataPart II. Not commenced.
- Limit automated decisionsSection 18, review of automated decisions, widened by the 2025 amendment to cover effects on constitutional rights such as equality and non-discrimination. Not commenced.
What it costs if you get it wrong
- Fixed maximum fine: LKR 10,000,000 per non-compliance — about $33 thousandFailure to comply with a directive issued by the Authority under section 35. Part VII is not yet commenced.
- Fixed maximum fine: Twice the previous penalty, for each repeat — about $66 thousandRepeat failure to conform to a directive
- Claims by individualsCompensation payable to an affected person out of the collected penalty, under section 38(3)
Sources
- Official sourceData Protection Authority of Sri LankaPersonal Data Protection Act, No. 9 of 2022 (English text)
dpa.gov.lk
Link checked 18 August 2026
- Official sourceGovernment of Sri LankaExtraordinary Gazette No. 2498/16, 22 July 2026
dpa.gov.lk
Link checked 18 August 2026
- Official sourceGovernment of Sri LankaExtraordinary Gazette No. 2341/59, 21 July 2023 — Part V in force 17 July 2023
dpa.gov.lk
Link checked 18 August 2026
Rules for sending data abroad
Official name: Personal Data Protection (Amendment) Act, No. 22 of 2025 · Act No. 22 of 2025, certified 30 October 2025, published 31 October 2025 · Act of parliament
This is the amendment that rewrote Sri Lanka's transfer rule. It deleted the old system of government-approved safe countries. It also deleted the ban on public bodies handling data abroad. In their place: send data anywhere, as long as you can show the receiver is bound by contract to protect it. It also removed all fixed deadlines for switching on the rest of the law.
That is a long gap: the duty is real law today, but no penalty can follow until 1 January 2027. A contract you sign can still hold you to it from day one — and government contracts often do.
Enforced by Data Protection Authority of Sri Lanka
How this country controls where data goes: No restriction · Accepted routes: Standard contract clauses, Approved group rules, Certification scheme, Approved code of conduct, Explicit consent, Needed for a contract, Legal claims, Important public interest, To save someone’s life
What you have to do
- Put a transfer safeguard in place — from 1 January 2027You must use the paperwork specified by a directive of the Authority. No such directive has been issued. Only a draft from October 2024 exists, and it is written around the safe-country system this amendment deleted.
- Written vendor contract — from 1 January 2027The overseas recipient's commitments must be binding and enforceable.
Sources
- Official sourceParliament of Sri Lanka, via the Data Protection AuthorityPersonal Data Protection (Amendment) Act, No. 22 of 2025, section 10 (replacement of section 26)
dpa.gov.lk
“Section 26 of the principal enactment is hereby repealed and the following section is substituted therefor”
Link checked 18 August 2026
- Official sourceData Protection Authority of Sri LankaPersonal Data Protection Circular No. 01/2026, paragraph 4.6
dpa.gov.lk
Link checked 18 August 2026
General data protection law
Official name: Personal Data Protection Act Part IV — Use of Personal Data to Disseminate Solicited Messages · Act No. 9 of 2022, section 27 · Act of parliament
The direct marketing section of Sri Lanka's privacy law has never been switched on. The original Act said it had to start within four years of March 2022. The 2025 amendment deleted that deadline. So it can stay off indefinitely, or be switched on by a single gazette notice.
Enforced by Data Protection Authority of Sri Lanka
How this country controls where data goes: No restriction · Accepted routes: Nothing required
What you have to do
- Get consentNot in force. No commencement date has ever been appointed for Part IV.
Sources
- Official sourceParliament of Sri Lanka, via the Data Protection AuthorityPersonal Data Protection (Amendment) Act, No. 22 of 2025, section 2(1)(b) — repeal of subsections (4) and (5) of section 1
dpa.gov.lk
“All other provisions of this Act except this section, shall come into operation on such date or dates as the Minister may appoint, by Order published in the Gazette.”
Link checked 18 August 2026
- Official sourceGovernment of Sri LankaExtraordinary Gazette No. 2498/16 — appoints only section 2, section 3, Part I and Part III; Part IV not mentioned
dpa.gov.lk
Link checked 18 August 2026
What we're not sure about
An honest gap is more useful than a confident guess. These are the claims we could not verify against a government source.
That no rule forcing data to stay in the country rule exists in the insurance sector
We could not read the Insurance Regulatory Commission of Sri Lanka's website on 18 August 2026, so we could not check its list of directions. Treat insurance as unchecked, not as clear. If you are an insurer, ask the regulator.
That no rule forcing data to stay in the country or subscriber-data rule exists in telecom licences
The Telecommunications Regulatory Commission's rules, statutes and subsidiary legislation pages returned no documents we could read. Individual telecom licence conditions are not published. A rule that data must stay in the country could sit inside a licence we cannot see. Check your own licence.
The incident reporting deadline in Central Bank Circular No. 2/2025 for licensed banks
The circular's existence and title are confirmed from the Central Bank's own index. The document itself holds no readable text, so we could not extract the number of hours. If you are a bank, take the deadline from the circular itself.
Whether a further gazette has appointed a commencement date for Part II (rights of the people the data is about) or Part VII (penalties) between 22 July and 18 August 2026
The Authority's own gazette page, as at 18 August 2026, shows Extraordinary Gazette No. 2498/16 as the most recent entry. A later order could exist without appearing there. Check that page before you rely on the dates given here.
Minimum record-keeping periods under Sri Lanka's tax and company law
The Inland Revenue Department page we could read does not state a keeping period. We found no official consolidated text of the Companies Act, No. 7 of 2007 on a government website. Only the six-year anti-money-laundering floor is confirmed. Check tax and company periods with a local accountant.
That there is no health-sector or geospatial keeping data in the country rule
We found no rule requiring health or mapping data to stay in Sri Lanka. We could not confirm that against the Ministry of Health or Survey Department websites. If you work in either area, check before you rely on it.
The exact relationship between Circular No. 01/2026 of 7 August 2026 and the gazette of 22 July 2026
The circular says new enforcement dates are 'expected to be announced soon'. But the gazette setting 1 January 2027 was published sixteen days earlier. The gazette is the one with legal force. The circular text appears to have been drafted before it. Plan to the gazette.
Freshness and refresh
Freshness
Checked about 2 months ago, on 18 August 2026.
Re-checked every 30 days. Next check due 17 September 2026.