Sri Lanka
Not part of a rule-making bloc: national and industry rules are the whole picture. Checked today.
The answer
Sri Lanka has a full privacy law on the books, but almost none of the parts that create duties for companies are switched on yet. The government has now fixed 1 January 2027 as the day the core duties start. Data may leave the country freely today. From 2027 you will need a written contract or similar promise from whoever receives it abroad. No fines have ever been issued.
Eight questions about Sri Lanka
The questions a team asks when they are deciding where to store their users' data. Every country on this site answers the same eight, in the same order.
Do Sri Lanka's rules apply to my company?
Yes. The law reaches a company with no office in Sri Lanka if it offers goods or services to people in Sri Lanka, or watches how they behave online. It also catches anyone processing data inside the country. There is no size or revenue floor to fall below, and no requirement to appoint a local representative. But none of this bites until 1 January 2027, because the scope section itself has not started yet.
Section 2 of the Personal Data Protection Act, No. 9 of 2022 sets out four hooks: processing that happens wholly or partly in Sri Lanka; a controller or processor domiciled or ordinarily resident in Sri Lanka; one incorporated under Sri Lankan law; one that offers goods or services to data subjects in Sri Lanka including specific targeting; and one that specifically monitors their behaviour, including profiling. Extraordinary Gazette No. 2498/16 of 22 July 2026 appoints 1 January 2027 as the commencement date for section 2 and section 3 as well as Part I and Part III. Section 3(1) gives the Act priority over other written laws on data protection. Unlike India or the EU, there is no obligation on a foreign controller to appoint an in-country representative — only a Data Protection Officer where section 20 triggers apply, and that officer may now be an outsourced third party following the 2025 amendment.
Sources
- Official sourceData Protection Authority of Sri LankaPersonal Data Protection Act, No. 9 of 2022, section 2 (application of this Act)
dpa.gov.lk
“This Act shall apply to the processing of personal data— (a) where the processing of personal data takes place wholly or partly within Sri Lanka; or (b) where the processing of personal data is carried out by a controller or processor who ... offers goods or services to data subjects in Sri Lanka ... or specifically monitors the behaviour of data subjects in Sri Lanka.”
Link checked 18 August 2026
- Official sourceGovernment of Sri Lanka / Ministry of Digital EconomyExtraordinary Gazette No. 2498/16, 22 July 2026 — appoints 1 January 2027 for section 2, section 3, Part I and Part III
dpa.gov.lk
Link checked 18 August 2026
- Official sourceData Protection Authority of Sri LankaPersonal Data Protection Circular No. 01/2026, 7 August 2026, paragraph 1.5
dpa.gov.lk
“The PDPA applies territorially to the processing of personal data where such processing takes place wholly or partly within Sri Lanka, or by a person or entity within Sri Lanka; and also applies extraterritorially if a person or entity outside Sri Lanka specifically provides goods or services to "data subjects" within Sri Lanka or monitors their behavior within Sri Lanka.”
Link checked 18 August 2026
Can I store my users' data outside Sri Lanka?
Today, yes, with nothing to sign — the transfer section is not in force. From 1 January 2027 data can still leave, but you must first get a binding promise from the receiver abroad that Sri Lankan protections will be honoured. There is no banned-country list and no approved-country list: Sri Lanka scrapped its country-approval system in October 2025. No industry has a rule forcing data to stay in Sri Lanka.
This is the single most important thing to understand about Sri Lanka. The original section 26 of the 2022 Act built a European-style adequacy system: the Minister would declare which countries were safe enough, and public authorities had to process inside Sri Lanka unless a declaration covered them. The Personal Data Protection (Amendment) Act, No. 22 of 2025, certified on 30 October 2025, repealed that section outright and replaced it. The new section 26 is a pure accountability model: you may engage in cross-border data flows only where you ensure compliance with Part I, Part II and sections 20 to 25 wherever the data sits, and you must adopt instruments specified by a directive of the Authority to make the overseas recipient's commitments binding and enforceable. No adequacy list exists any more, and none is coming back. Sector by sector, checked on 18 August 2026: BANKING — Banking Act Direction No. 01/2026 on outsourcing, effective 1 January 2027, permits cross-border outsourcing and cloud with board approval and annual notification to the Director of Bank Supervision; no residency clause found. PAYMENTS — the Payment Cards and Mobile Payment Systems Regulations No. 1 of 2013 contain no storage-location clause. SECURITIES — no data-location directive found in the regulator's published directives and circulars. INSURANCE — the regulator's website could not be read by automated tools, so this is recorded as unconfirmed rather than clear. HEALTH, TELECOM, EDUCATION, GAMING, GEOSPATIAL — no localisation instrument found on the responsible bodies' own sites. GOVERNMENT — the only sector where location is addressed at all, and it is a preference: the national cyber policy tells public bodies to give priority to the Lanka Government Cloud, not to stay in Sri Lanka. The one real wall is dormant: the new section 26(4) lets the Minister prescribe categories of personal data that public authorities may never send abroad. No categories have been prescribed.
Sources
- Official sourceParliament of Sri Lanka, via the Data Protection AuthorityPersonal Data Protection (Amendment) Act, No. 22 of 2025, section 10 — replacement of section 26 (cross-border data flow)
dpa.gov.lk
“A controller or processor may engage in cross-border data flows, only where such controller or processor, ensures compliance with the provisions of Part I, Part II and sections 20, 21, 22, 23, 24 and 25, as the case may be. ... a controller or processor shall adopt such instruments as may be specified by a directive issued by the Authority under paragraph (c) of section 33, to ensure binding and enforceable commitments of the recipient in the third country.”
Link checked 18 August 2026
- Official sourceData Protection Authority of Sri LankaPersonal Data Protection Circular No. 01/2026, 7 August 2026, paragraph 4.6 — cross-border limits lifted, cloud enabled
dpa.gov.lk
“Although some limitations existed earlier on cross-border data flows (ability to use cloud services) for the processing of personal data, the PDPA Amendment Act No. 22 of 2025 provides a discretion for a "Controller" to engage in cross-border data transfers.”
Link checked 18 August 2026
- Official sourceCentral Bank of Sri LankaBanking Act Directions No. 01 of 2026 — Outsourcing of Business Operations of Licensed Banks (checked for a residency clause; none found)
cbsl.gov.lk
Link checked 18 August 2026
- Official sourceCentral Bank of Sri LankaPayment Cards and Mobile Payment Systems Regulations No. 1 of 2013 (checked for a storage-location clause; none found)
cbsl.gov.lk
Link checked 18 August 2026
- Official sourceSri Lanka Computer Emergency Readiness TeamInformation and Cyber Security Policy for Government Organizations, first print January 2023, clause 4.3.6 (Data Sovereignty and Cloud Computing)
cert.gov.lk
“In fulfilling their cloud service needs, organizations shall give priority to obtaining services through the Lanka Government Cloud (LGC).”
Link checked 18 August 2026
What do I need in place before data leaves Sri Lanka?
Right now, nothing. There is no approval to get, no list to check and no form to file, because the transfer section has not started. From 1 January 2027 you will need a written, binding commitment from the overseas receiver. The Authority is supposed to say exactly what form that takes, and it has not done so — only a draft from October 2024 exists, and that draft was written for a version of the law that no longer exists.
The model is neither a blocklist nor an allowlist. It is closest to an unrestricted regime with a contractual accountability overlay, similar to standard contractual clauses but without a published template. Section 26(2) of the amended Act ties the required instrument to a directive issued by the Authority under section 33(c). The Authority published a document titled 'Specification of Instruments for Processing Personal Data Outside Sri Lanka Directive, 2024' for public consultation in October 2024. It is still marked DRAFT 1.0 on the Authority's own downloads page as at 18 August 2026. It lists five acceptable instruments: binding corporate rules, contractual agreements, codes of conduct, certification schemes including APEC Cross-Border Privacy Rules and schemes equivalent to the European General Data Protection Regulation, and a cross-border processing impact assessment. Critically, the draft is framed around ministerial adequacy decisions, which the 2025 amendment abolished, so it will have to be rewritten before it can be issued. Section 26(3) provides seven escape routes that do not need any instrument: explicit informed consent, necessity for a contract with the person, legal claims, public interest as defined in Schedule I, an emergency threatening life, health or safety, mere transit through Sri Lanka, and any other prescribed condition. These are drafted as full alternatives to the main rule, not as narrow exceptions, which makes them unusually generous.
Sources
- Official sourceParliament of Sri Lanka, via the Data Protection AuthorityPersonal Data Protection (Amendment) Act, No. 22 of 2025, new section 26(2) and 26(3)
dpa.gov.lk
Link checked 18 August 2026
- Official sourceData Protection Authority of Sri LankaDRAFT 1.0 — Specification of Instruments for Processing Personal Data Outside Sri Lanka Directive, 2024
dpa.gov.lk
Link checked 18 August 2026
- Official sourceData Protection Authority of Sri LankaData Protection Authority downloads page — all seven regulations and directives still listed under 'Draft Regulations and Directives'
dpa.gov.lk
Link checked 18 August 2026
Who enforces the rules in Sri Lanka, and what can they do?
The Data Protection Authority of Sri Lanka. It genuinely exists: it has a chairman, a seven-person board, a director-general, an office in Colombo and it publishes circulars and draft rules. But it has never issued a fine or a decision, and legally it cannot yet. The Authority itself says in writing that it will only investigate complaints once the relevant sections are switched on. The penalty section still has no start date.
Part V of the Act, which creates the Authority, was brought into force on 17 July 2023 by Extraordinary Gazette No. 2341/59, and the board was appointed in August 2023. The chairman is Rajeeva Bandaranaike; the director-general is Dimuth Bhashitha Atapattu. The Authority has published one binding circular (No. 01/2026, 7 August 2026, addressed to the public sector) and seven draft regulations and directives issued for public consultation in October 2024, none of which has been finalised. Its enforcement route under section 38 is a two-step process that most summaries miss: the Authority must first issue a directive under section 35, and only a failure to comply with that directive triggers a penalty. Sector regulators are separately active. The Central Bank of Sri Lanka issues directions and circulars regularly, including Circular No. 2/2025 on reporting information technology and cyber security incidents. The Financial Intelligence Unit supervises anti-money-laundering record-keeping. Sri Lanka CERT is operational as the national cyber agency but has no statutory power to compel incident reports — its reporting portal is voluntary and there is still no Cyber Security Act.
Sources
- Official sourceData Protection Authority of Sri LankaPersonal Data Protection Circular No. 01/2026, 7 August 2026, paragraph 2.2
dpa.gov.lk
“NOTE - the Data Protection Authority would only investigate complaints, hear appeals, etc., once the relevant governing provisions are brought into operation.”
Link checked 18 August 2026
- Official sourceData Protection Authority of Sri LankaBoard of Directors of the Data Protection Authority — chairman and six directors named
dpa.gov.lk
Link checked 18 August 2026
- Official sourceGovernment of Sri LankaExtraordinary Gazette No. 2341/59, 21 July 2023 — Part V (Data Protection Authority) in force from 17 July 2023
dpa.gov.lk
Link checked 18 August 2026
- Official sourceSri Lanka Computer Emergency Readiness TeamSri Lanka CERT incident reporting portal — offered as a service, with no statutory reporting duty or deadline stated
cert.gov.lk
Link checked 18 August 2026
How long do I have to keep the data?
The floor is clearer than the ceiling. Banks, finance companies and other reporting institutions must keep transaction records for six years, and identity records for six years after the account closes. The ceiling is a principle, not a number: from 1 January 2027 you must not keep personal data in a form that identifies someone for longer than the purpose needs. Where the two clash, the six-year legal duty wins.
The floor comes from section 4 of the Financial Transactions Reporting Act, No. 6 of 2006: six years from the date of the transaction, correspondence or report, and six years from closure of the account or cessation of the business relationship for identity records, extendable by direction of the Financial Intelligence Unit. Section 4(3) adds an operational catch that matters for offshore storage: records must be kept in a manner and form that lets the institution comply IMMEDIATELY with a request from the Financial Intelligence Unit or a law enforcement agency. That is an accessibility requirement, not a location requirement, but a cold archive in another time zone will fail it. The ceiling is section 9 of the Personal Data Protection Act — the obligation to limit the period of retention — with a carve-out allowing longer storage for public-interest archiving, scientific or historical research and statistics. Section 9 sits in Part I and therefore starts on 1 January 2027. The Act resolves conflicts in favour of other laws only partially: section 3(1) makes the Act override other written laws on data protection, but a public authority governed by another law may process under that law so far as it is consistent. In practice a statutory keep-it duty is treated as a lawful purpose, so six years beats delete-when-done.
Sources
- Official sourceFinancial Intelligence Unit of Sri LankaFinancial Transactions Reporting Act, No. 6 of 2006, section 4 (institutions to maintain and retain records)
fiusrilanka.gov.lk
“records of transactions and of correspondence relating to transactions and records of all reports furnished to the Financial Intelligence Unit for a period of six years from the date of the transaction ... and records of identity obtained in terms of section 2 for a period of six years from the date of closure of the account or cessation of the business relationship”
Link checked 18 August 2026
- Official sourceData Protection Authority of Sri LankaPersonal Data Protection Act, No. 9 of 2022, section 9 (obligation to limit the period of retention)
dpa.gov.lk
Link checked 18 August 2026
What happens if there is a breach?
There is no deadline, because there is no duty yet. This is unusual and worth saying plainly: as of 18 August 2026 a company suffering a data breach in Sri Lanka has no legal obligation to tell anyone. Reporting to the national cyber team is voluntary. From 1 January 2027 you must notify the Authority, but the rules that set the form and the clock are still a draft. Banks are the exception and must report technology and cyber incidents to the Central Bank.
Section 23 of the Act requires a controller to notify the Authority of a personal data breach in such form, manner and within such period of time as may be determined by rules made under the Act, and leaves it to the Authority to decide when individuals must be told. Section 23 sits in Part III, which starts on 1 January 2027. The Data Breach Notification Rules were published for public consultation on 1 October 2024 and are still listed as a draft on the Authority's downloads page. So from 1 January 2027 there will be a duty with no clock attached until those rules are finalised. Count the other clocks: Sri Lanka CERT operates an incident reporting portal but there is no Cyber Security Act and no statutory hours; the Central Bank issued Circular No. 2/2025 of 7 May 2025 on the reporting of information technology and cyber security incidents of licensed banks, whose text could not be machine-read, so its deadline is recorded as unconfirmed. Sri Lanka therefore currently has, at most, one mandatory incident clock, and it applies only to banks.
Sources
- Official sourceData Protection Authority of Sri LankaPersonal Data Protection Act, No. 9 of 2022, section 23 (personal data breach notifications)
dpa.gov.lk
“In the event of a personal data breach, a controller shall notify the Authority, regarding such personal data breach in such form, manner and within such period of time as may be determined by rules made under this Act.”
Link checked 18 August 2026
- Official sourceData Protection Authority of Sri LankaDraft Data Breach Notification Rules, version 1.0, published for public consultation 1 October 2024 — still a draft
dpa.gov.lk
Link checked 18 August 2026
- Official sourceCentral Bank of Sri LankaCircular No. 2/2025, 7 May 2025 — Reporting of Information Technology and Cybersecurity Incidents of Licensed Banks
cbsl.gov.lk
Link checked 18 August 2026
What trips people up in Sri Lanka?
Five things that will cost you a weekend. A child in Sri Lanka is anyone under sixteen, not eighteen, and a parent must consent for them. Fines are small but personal: directors can be made to pay unless they prove they did not know. The advertised start date of 18 March 2025 was cancelled four days before it arrived, so anything written before November 2025 is wrong. Company data is not protected the way you would expect, because the individual-rights section still has no start date. And the published transfer guidance describes a law that no longer exists.
(1) AGE SIXTEEN. The Act defines a child as a natural person below the age of sixteen years, and consent for a child means the consent of the parent or legal guardian. This is lower than India's eighteen and lower than most of Asia, and it also means a fifteen-year-old cannot consent for themselves. (2) PERSONAL LIABILITY OF DIRECTORS. Section 38(6) says that where a penalty is imposed on a body corporate, every director and other officer responsible for management and control is liable to pay it unless he proves he had no knowledge of the failure. The maximum is 10 million rupees (about $33,000) per non-compliance, doubling for each repeat — small by global standards, but it attaches to individuals. (3) THE CANCELLED DATE. Extraordinary Gazette No. 2366/08 of 8 January 2024 appointed 18 March 2025 for Parts I, II, III and VII. Extraordinary Gazette No. 2427/34 of 14 March 2025 repealed that paragraph, four days before it took effect. The 2025 amendment then validated past acts only under Parts V, VI, VIII, IX and X — a deliberate omission that confirms Parts I, II, III and VII were never in force. Any adviser working from the Authority's own news page, which still says 'Enforcement Begins on March 18, 2025', is working from a dead date. (4) RIGHTS ARE STILL UNSCHEDULED. The July 2026 gazette appointed sections 2 and 3 and Parts I and III. It did not mention Part II (rights of data subjects), Part IV (marketing messages) or Part VII (penalties). So from 1 January 2027 there will be duties on companies but no commenced individual rights and no commenced penalty section — while section 26 simultaneously requires you to 'ensure compliance with Part II' abroad. (5) STALE GUIDANCE. The Authority's draft cross-border directive is built around ministerial adequacy decisions that the 2025 amendment deleted. Reading it as current guidance will send you looking for an approved-country list that does not and will not exist.
Sources
- Official sourceData Protection Authority of Sri LankaPersonal Data Protection Act, No. 9 of 2022 — section 56 definition of 'child', Schedule I on consent, and section 38 on penalties
dpa.gov.lk
“"child" means, a natural person who is below the age of sixteen years”
Link checked 18 August 2026
- Official sourceGovernment of Sri LankaExtraordinary Gazette No. 2427/34, 14 March 2025 — repeals paragraph (b) of the commencement order, cancelling the 18 March 2025 start date
dpa.gov.lk
Link checked 18 August 2026
- Official sourceGovernment of Sri LankaExtraordinary Gazette No. 2366/08, 8 January 2024 — the now-repealed order appointing 18 March 2025 for Parts I, II, III and VII
dpa.gov.lk
Link checked 18 August 2026
- Official sourceParliament of Sri Lanka, via the Data Protection AuthorityPersonal Data Protection (Amendment) Act, No. 22 of 2025, section 2(2) — validation limited to Parts V, VI, VIII, IX and X
dpa.gov.lk
“Notwithstanding the repeal of subsection (3) of section 1 of the principal enactment, anything duly done under Parts V, VI, VIII, IX and X prior to the date of commencement of this section, shall be deemed to be valid and continue to be in force.”
Link checked 18 August 2026
What is changing soon in Sri Lanka?
One hard date and four switches. On 1 January 2027 the scope, the processing duties and the controller duties all start, and the Central Bank's new outsourcing rules for banks start the same day. Before then the Authority is expected to finalise its rules on breach reporting, impact assessments, data protection officers and overseas transfers. Watch also for a second gazette bringing individual rights and the penalty section into force — without it, the law has duties but no teeth.
CONFIRMED DATES. 1 January 2027: section 2, section 3, Part I and Part III of the Personal Data Protection Act commence, per Extraordinary Gazette No. 2498/16 of 22 July 2026. 1 January 2027: Banking Act Directions No. 01 of 2026 on outsourcing take effect and revoke the 2012 directions. EXPECTED. The Authority's Circular No. 01/2026 of 7 August 2026 says new enforcement dates are 'expected to be announced soon' and that advisory committees will be formed for finance and banking, insurance, health, telecommunications, civil registration and tourism, with sectoral guidelines to follow under the new section 51A. Seven draft regulations and directives from October 2024 remain unfinalised. DORMANT SWITCHES, each of which can change the picture without consultation. (1) The Minister may prescribe categories of personal data that public authorities may never send abroad, under new section 26(4) and (5). Nothing prescribed. (2) The Minister may by gazette order appoint a commencement date for any remaining provision at any time, including Part VII penalties, with no minimum notice — the 2025 amendment removed the old timing constraints entirely. (3) The Authority may issue the section 33(c) directive specifying transfer instruments, which turns a paper obligation into a concrete contracting project overnight. (4) Regulations under section 20(1)(b) may prescribe the scale and magnitude of processing that forces a private company to appoint a data protection officer. None prescribed. Separately, Part IV, on using personal data to send marketing messages, has never been commenced and now has no deadline for commencement at all, because the amendment repealed the eighteen-to-forty-eight-month window in the original section 1.
Sources
- Official sourceGovernment of Sri LankaExtraordinary Gazette No. 2498/16, 22 July 2026 — 1 January 2027 commencement order
dpa.gov.lk
Link checked 18 August 2026
- Official sourceData Protection Authority of Sri LankaPersonal Data Protection Circular No. 01/2026, 7 August 2026, paragraphs 2.2 and 4.7
dpa.gov.lk
“Therefore, public authorities should take note of the new enforcement dates, which is expected to be announced soon.”
Link checked 18 August 2026
- Official sourceParliament of Sri Lanka, via the Data Protection AuthorityPersonal Data Protection (Amendment) Act, No. 22 of 2025, section 2 and new section 26(4)-(5)
dpa.gov.lk
“A controller or processor who is a public authority shall not engage in cross-border data flows in respect of the categories of personal data as may be prescribed under subsection (5).”
Link checked 18 August 2026
- Official sourceCentral Bank of Sri LankaBanking Act Directions No. 01 of 2026 — effective 1 January 2027
cbsl.gov.lk
Link checked 18 August 2026
The rules, layer by layer
Rules stack in layers. Knowing which layer a rule sits in tells you whether your industry, your state, or a contract can override it.
Layer 1
National rules
Added by this country on top of any bloc rules.
3 rules here
Layer 2
Industry rules
Made by an industry regulator. These usually beat the general position.
5 rules here
Read the stack from the top down. Anything lower normally wins: an industry rule beats the national position, and the national position sits on top of the bloc rules.
National rules3 rules
Personal Data Protection Act, No. 9 of 2022
Act of parliament · Act No. 9 of 2022, certified 19 March 2022
Sri Lanka's general privacy law, the first in South Asia. It is only partly switched on. The regulator's own section started in 2023; the duties on companies start on 1 January 2027; the individual-rights section and the penalty section have no start date at all. Penalties are capped at 10 million rupees (about $33,000) per breach and can be recovered personally from directors.
Enforced by Data Protection Authority of Sri Lanka
Transfer model: No restriction · Accepted routes: Nothing required
What it makes you do
- Get consent — from 1 January 2027
- Tell people what you do — from 1 January 2027Transparency duty in section 11 and Schedule; includes telling people about any planned transfer abroad.
- Secure the data — from 1 January 2027Section 10, integrity and confidentiality.
- Delete data after a period — from 1 January 2027Section 9. No fixed number of months; keep only as long as the purpose needs, with an archiving and research carve-out.
- Keep records of processing — from 1 January 2027Section 12 requires a documented Data Protection Management Programme.
- Assess high-risk projects — from 1 January 2027Section 24. Triggered by systematic and extensive evaluation, or systematic monitoring of public areas or telecom networks. Form and manner still in draft.
- Appoint a data protection officer — applies at: Every ministry, government department and public corporation; private bodies only once scale and magnitude are prescribed, from 1 January 2027May be an outsourced third party since the 2025 amendment. Contact details must be published and given to the Authority. No residence requirement.
- Report breaches to the regulator — from 1 January 2027Section 23. No deadline exists: the form, manner and period are left to rules that are still a draft.
- Get a parent's consent for children — applies at: under 16, from 1 January 2027
- Let people see their dataPart II. Not commenced and no commencement date appointed as at 18 August 2026.
- Let people correct their dataPart II. Not commenced.
- Let people delete their dataPart II. Not commenced.
- Limit automated decisionsSection 18, review of automated decisions, widened by the 2025 amendment to cover effects on constitutional rights such as equality and non-discrimination. Not commenced.
What it costs if you get it wrong
- Fixed maximum fine: LKR 10,000,000 per non-compliance — about $33 thousandFailure to comply with a directive issued by the Authority under section 35. Part VII is not yet commenced.
- Fixed maximum fine: Twice the previous penalty, for each repeat — about $66 thousandRepeat failure to conform to a directive
- Claims by individualsCompensation payable to an affected person out of the collected penalty, under section 38(3)
Sources
- Official sourceData Protection Authority of Sri LankaPersonal Data Protection Act, No. 9 of 2022 (English text)
dpa.gov.lk
Link checked 18 August 2026
- Official sourceGovernment of Sri LankaExtraordinary Gazette No. 2498/16, 22 July 2026
dpa.gov.lk
Link checked 18 August 2026
- Official sourceGovernment of Sri LankaExtraordinary Gazette No. 2341/59, 21 July 2023 — Part V in force 17 July 2023
dpa.gov.lk
Link checked 18 August 2026
Personal Data Protection (Amendment) Act, No. 22 of 2025
Act of parliament · Act No. 22 of 2025, certified 30 October 2025, published 31 October 2025
The amendment that rewrote Sri Lanka's transfer rule. It deleted the old system of government-approved 'adequate' countries and the ban on public bodies processing abroad. In their place: send data anywhere, provided you can show the receiver is contractually bound to protect it. It also removed all fixed deadlines for switching on the rest of the law.
Enforced by Data Protection Authority of Sri Lanka
Transfer model: No restriction · Accepted routes: Standard contract clauses, Approved group rules, Certification scheme, Approved code of conduct, Explicit consent, Needed for a contract, Legal claims, Important public interest, Someone's life is at risk
What it makes you do
- Put a transfer safeguard in place — from 1 January 2027You must adopt an instrument specified by a directive of the Authority. No such directive has been issued; only a draft from October 2024 exists, and it is written around the adequacy system this amendment deleted.
- Written vendor contract — from 1 January 2027The overseas recipient's commitments must be binding and enforceable.
Sources
- Official sourceParliament of Sri Lanka, via the Data Protection AuthorityPersonal Data Protection (Amendment) Act, No. 22 of 2025, section 10 (replacement of section 26)
dpa.gov.lk
“Section 26 of the principal enactment is hereby repealed and the following section is substituted therefor”
Link checked 18 August 2026
- Official sourceData Protection Authority of Sri LankaPersonal Data Protection Circular No. 01/2026, paragraph 4.6
dpa.gov.lk
Link checked 18 August 2026
Personal Data Protection Act Part IV — Use of Personal Data to Disseminate Solicited Messages
Act of parliament · Act No. 9 of 2022, section 27
The direct marketing section of Sri Lanka's privacy law has never been switched on. The original Act said it had to start within four years of March 2022; the 2025 amendment deleted that deadline, so it can now stay dormant indefinitely or be switched on by a single gazette notice.
Enforced by Data Protection Authority of Sri Lanka
Transfer model: No restriction · Accepted routes: Nothing required
What it makes you do
- Get consentNot in force. No commencement date has ever been appointed for Part IV.
Sources
- Official sourceParliament of Sri Lanka, via the Data Protection AuthorityPersonal Data Protection (Amendment) Act, No. 22 of 2025, section 2(1)(b) — repeal of subsections (4) and (5) of section 1
dpa.gov.lk
“All other provisions of this Act except this section, shall come into operation on such date or dates as the Minister may appoint, by Order published in the Gazette.”
Link checked 18 August 2026
- Official sourceGovernment of Sri LankaExtraordinary Gazette No. 2498/16 — appoints only section 2, section 3, Part I and Part III; Part IV not mentioned
dpa.gov.lk
Link checked 18 August 2026
Industry rules5 rules
Personal Data Protection Act section 26(4) and 26(5), as substituted by Act No. 22 of 2025
Act of parliament · Act No. 9 of 2022 s.26(4)-(5) as substituted · Government
A loaded gun with no bullets in it. Ministries, departments, provincial councils and local authorities will be banned from sending certain kinds of personal data out of Sri Lanka — but only once a minister names those kinds. None have been named. The list can be created by gazette with no consultation.
Enforced by Ministry of Digital Economy
Transfer model: Not allowed (the list is currently empty)
What it makes you do
- Keep the data in the country — from 1 January 2027Applies only to categories of personal data the Minister prescribes. No categories prescribed as at 18 August 2026, so the ban currently bites on nothing.
Sources
- Official sourceParliament of Sri Lanka, via the Data Protection AuthorityPersonal Data Protection (Amendment) Act, No. 22 of 2025, new section 26(4) and (5), and amended definition of 'public authority'
dpa.gov.lk
“A controller or processor who is a public authority shall not engage in cross-border data flows in respect of the categories of personal data as may be prescribed under subsection (5).”
Link checked 18 August 2026
- Official sourceGovernment of Sri LankaExtraordinary Gazette No. 2498/16 — Part III (which contains section 26) commences 1 January 2027
dpa.gov.lk
Link checked 18 August 2026
Personal Data Protection Circular No. 01/2026 — Application of PDPA in the Public Sector
Regulator directive · DPA/Legal/01/02, 7 August 2026; supersedes Circular No. 01/2024 of 13 September 2024 · Government
The only Sri Lankan data protection instrument actually in force today, and it binds the public sector only. It orders every ministry and department to appoint a data protection officer and start preparing, and it confirms in writing that the regulator will not investigate anything until the law is switched on.
Enforced by Data Protection Authority of Sri Lanka
Transfer model: No restriction · Accepted routes: Nothing required
What it makes you do
- Appoint a data protection officerEvery ministry and government department processing personal data must appoint a data protection officer, publish the contact details on its website and report them to the Authority.
- Keep records of processingInstitutions are told to run a personal data audit and a gap assessment and to build a Data Protection Management Programme.
Sources
- Official sourceData Protection Authority of Sri LankaPersonal Data Protection Circular No. 01/2026, 7 August 2026
dpa.gov.lk
“Every Ministry or Government Department processing personal data shall appoint a DPO to ensure compliance with the provisions of the Act.”
Link checked 18 August 2026
- Official sourceMinistry of Digital Economy, Sri LankaMinistry of Digital Economy circulars index — PDP/2026/01 dated 07/08/2026
mode.gov.lk
Link checked 18 August 2026
Information and Cyber Security Policy for Government Organizations
Government policy document · Sri Lanka CERT, first print January 2023; implemented by Ministry circulars MOT/2023/01 of 2 May 2023 and MODE/2026/02 of 22 June 2026 · Government
The closest thing Sri Lanka has to a government data residency rule, and it is not one. Public bodies are told to give priority to the state-run Lanka Government Cloud and to assess the risk of foreign clouds carefully. Using an overseas cloud is discouraged, not forbidden.
Enforced by Sri Lanka Computer Emergency Readiness Team
Transfer model: No restriction · Accepted routes: Nothing required
What it makes you do
- Secure the dataApplicable to all government organizations.
- Assess high-risk projectsA proper risk assessment is required before taking services from any cloud provider.
Sources
- Official sourceSri Lanka Computer Emergency Readiness TeamInformation and Cyber Security Policy for Government Organizations, clause 4.3.6 — Policy on Data Sovereignty and Cloud Computing
cert.gov.lk
“In fulfilling their cloud service needs, organizations shall give priority to obtaining services through the Lanka Government Cloud (LGC). ... It is, however, strictly recommended to the organizations to perform a proper risk assessment prior to obtaining services from any cloud service provider.”
Link checked 18 August 2026
- Official sourceMinistry of Digital Economy, Sri LankaMinistry of Digital Economy circular MODE/2026/02, 22 June 2026 — Implementation of Information and Cyber Security Policy for Government Organizations
mode.gov.lk
Link checked 18 August 2026
Banking Act Directions No. 01 of 2026 — Outsourcing of Business Operations of Licensed Banks
Directly binding regulation · Banking Act Direction No. 01/2026, issued 25 March 2026 · Banking
Sri Lankan banks may outsource abroad and use foreign cloud services. There is no requirement to keep banking data in the country and no need to ask the Central Bank first. What the bank must do is get its own board's approval, manage the country risk, keep the paperwork available for inspection, and file an annual list every January.
Enforced by Central Bank of Sri Lanka
Transfer model: No restriction · Accepted routes: Nothing required
What it makes you do
- Written vendor contract — from 1 January 2027Board approval required for each outsourcing arrangement, including offshore ones. Measures must address data accessibility, confidentiality, integrity, sovereignty, recoverability and regulatory compliance.
- Register or notify — from 1 January 2027Banks must inform the Director of Bank Supervision of existing and proposed outsourced business operations by 31 January each year. This is notification, not pre-approval.
- Independent audit — from 1 January 2027Documents must be readily available to the Central Bank on request.
What it costs if you get it wrong
- Loss of your licenceBreach of directions issued under the Banking Act
Sources
- Official sourceCentral Bank of Sri LankaBanking Act Directions No. 01 of 2026 — Outsourcing of Business Operations of Licensed Banks
cbsl.gov.lk
“Licensed banks shall ensure that effective measures are in place to address risks associated with data accessibility, confidentiality, integrity, sovereignty, recoverability, and regulatory compliance.”
Link checked 18 August 2026
- Official sourceCentral Bank of Sri LankaCentral Bank of Sri Lanka — index of banking directions, circulars and guidelines (issue date 25.03.2026)
cbsl.gov.lk
Link checked 18 August 2026
Financial Transactions Reporting Act, No. 6 of 2006
Act of parliament · Act No. 6 of 2006, section 4; amended by Act No. 17 of 2026 · Finance
Sri Lanka's main retention floor. Banks, finance companies, insurers, brokers and other reporting institutions must keep transaction and identity records for six years. The records may sit abroad, but they must be producible immediately on request, which rules out slow offshore archives.
Enforced by Financial Intelligence Unit of Sri Lanka
Transfer model: No restriction · Accepted routes: Nothing required
What it makes you do
- Keep data for a minimum period — 6 yearsSix years from the transaction, correspondence or report; and six years from account closure or the end of the business relationship for identity records. The Financial Intelligence Unit can direct a longer period.
- Keep records of processingRecords must be kept so that the institution can comply IMMEDIATELY with a request from the Financial Intelligence Unit or a law enforcement agency. Electronic and machine-readable copies are allowed if a paper copy can be readily produced.
What it costs if you get it wrong
- Fixed maximum fineFailure to keep required records under the anti-money-laundering regime
Sources
- Official sourceFinancial Intelligence Unit of Sri LankaFinancial Transactions Reporting Act, No. 6 of 2006, section 4
fiusrilanka.gov.lk
“it shall be maintained in a manner and form that will enable an Institution to comply immediately with requests for information from the Financial Intelligence Unit or a law enforcement agency”
Link checked 18 August 2026
- Official sourceFinancial Intelligence Unit of Sri LankaFinancial Intelligence Unit — Acts and Regulations index, including the Financial Transactions Reporting (Amendment) Act No. 17 of 2026
fiusrilanka.gov.lk
Link checked 18 August 2026
What we're not sure about
An honest gap is more useful than a confident guess. These are the claims we could not verify from an official source on the last check.
That no data localisation rule exists in the insurance sector
The Insurance Regulatory Commission of Sri Lanka website at ircsl.gov.lk requires JavaScript and returned no readable content or rate-limited on 18 August 2026. We could not read its directions index. Treat insurance as unchecked, not as clear.
That no data localisation or subscriber-data rule exists in telecom licences
The Telecommunications Regulatory Commission's site has a JavaScript-only menu and its 'Rules & Guidelines', 'Statutes' and 'Subsidiary Legislation' pages returned no document links. Individual telecom licence conditions are not published. A residency condition could sit inside a licence we cannot read.
The incident reporting deadline in Central Bank Circular No. 2/2025 for licensed banks
The PDF on the Central Bank's site contains no machine-readable text, so the number of hours could not be extracted. The circular's existence and title are confirmed from the Central Bank's own index.
Whether a further gazette has appointed a commencement date for Part II (rights of data subjects) or Part VII (penalties) between 22 July and 18 August 2026
We can evidence the position from the Authority's own gazette page as at 18 August 2026, on which Extraordinary Gazette No. 2498/16 is the most recent entry. We cannot prove that no later order exists but is unpublished on that page.
Minimum record-keeping periods under Sri Lanka's tax and company law
The Inland Revenue Department page we could open does not state a retention period, and we did not locate an official consolidated text of the Companies Act, No. 7 of 2007 on a government domain. Only the six-year anti-money-laundering floor is verified.
That there is no health-sector or geospatial data localisation rule
The Ministry of Health site returned only a JavaScript landing page and the Survey Department site blocked automated access with a 406 error. Recorded as not found rather than not existing.
The exact relationship between Circular No. 01/2026 of 7 August 2026 and the gazette of 22 July 2026
The circular says new enforcement dates are 'expected to be announced soon', but the gazette appointing 1 January 2027 was published sixteen days earlier. The gazette is the legally operative instrument; the circular text appears to have been drafted before it. Plan to the gazette.
30-day cadence. Sri Lanka is mid-commencement: a hard date of 1 January 2027 is approaching, three further gazette orders are expected (Part II rights, Part IV marketing, Part VII penalties), and seven draft regulations plus the section 33(c) transfer directive could be finalised at any time. The Minister can now appoint any commencement date by gazette with no notice period at all, because the 2025 amendment deleted the statutory timing constraints. A 90-day cadence would risk publishing a picture that is a full commencement stage out of date.
Freshness and refresh
Freshness
Checked today — on 18 August 2026.
Re-checked every 30 days. Next check due 17 September 2026.
Compare with
- Sri Lanka versus Argentina
- Sri Lanka versus Armenia
- Sri Lanka versus Australia
- Sri Lanka versus Austria
- Sri Lanka versus Azerbaijan
- Sri Lanka versus Brazil
- Sri Lanka versus Bulgaria
- Sri Lanka versus Cambodia
- Sri Lanka versus Canada
- Sri Lanka versus China
- Sri Lanka versus Croatia
- Sri Lanka versus Cyprus
- Sri Lanka versus Estonia
- Sri Lanka versus France
- Sri Lanka versus Georgia
- Sri Lanka versus Germany
- Sri Lanka versus Greece
- Sri Lanka versus Hong Kong SAR
- Sri Lanka versus Hungary
- Sri Lanka versus Iceland
- Sri Lanka versus India
- Sri Lanka versus Indonesia
- Sri Lanka versus Ireland
- Sri Lanka versus Israel
- Sri Lanka versus Italy
- Sri Lanka versus Japan
- Sri Lanka versus Latvia
- Sri Lanka versus Lithuania
- Sri Lanka versus Luxembourg
- Sri Lanka versus Malta
- Sri Lanka versus Mexico
- Sri Lanka versus Mongolia
- Sri Lanka versus Nepal
- Sri Lanka versus Netherlands
- Sri Lanka versus Poland
- Sri Lanka versus Russia
- Sri Lanka versus Saudi Arabia
- Sri Lanka versus Serbia
- Sri Lanka versus Singapore
- Sri Lanka versus Slovakia
- Sri Lanka versus Slovenia
- Sri Lanka versus South Korea
- Sri Lanka versus Spain
- Sri Lanka versus Sweden
- Sri Lanka versus Switzerland
- Sri Lanka versus Taiwan
- Sri Lanka versus Thailand
- Sri Lanka versus Turkey
- Sri Lanka versus Ukraine
- Sri Lanka versus United Arab Emirates
- Sri Lanka versus United Kingdom
- Sri Lanka versus United States
- Sri Lanka versus Uzbekistan