Monday Aug 10, 2026
Monday, 10 August 2026 00:21 - - {{hitsCtrl.values.hits}}
Sri Lanka’s core personal data protection compliance framework will become operational on 1 January 2027, bringing businesses and other entities handling personal data under requirements governing processing, data breaches, contractual arrangements, and cross-border transfers.
The Data Protection Authority of Sri Lanka (DPA) said Extraordinary Gazette No. 2498/16, published on 22 July 2026, has appointed 1 January 2027 as the effective date for key provisions of the Personal Data Protection Act, No. 9 of 2022, as amended.
The provisions coming into force include Section 2, which determines the scope of application of the Act, and Section 3, governing its effect in relation to other written law.
Part I of the Act, covering the core requirements for lawful and transparent processing of personal data, will also become operational on the same date.
Part III, governing data controllers and processors, will introduce a series of compliance requirements where applicable, including the designation of Data Protection Officers, personal data breach notifications, and Data Protection Impact Assessments.
The framework will also cover obligations between data controllers and processors, including contractual requirements, as well as provisions governing cross-border processing and transfers of personal data.
The DPA said these provisions together constitute the core compliance framework under the Act for controllers and processors falling within its scope.
With less than six months remaining before the provisions take effect, the DPA urged data controllers and processors to use the transition period to review their governance arrangements, policies, operational processes, contracts, and technical and organisational measures to ensure compliance by 1 January 2027.