What Is Personal Data Protection Act, No. 9 of 2022?
Sri Lanka's governing statute is the Personal Data Protection Act, No. 9 of 2022, as amended by the Personal Data Protection (Amendment) Act, No. 22 of 2025. Part V, establishing the Data Protection Authority, has been in force since 17 July 2023, while Parts VI, VIII, IX, and X have been in force since 1 December 2023. The framework is not fully operative. Part II, which contains data-subject rights, is not currently in force because the March 2025 commencement date was revoked, and no later commencement order was located. Part VII, containing penalties, is also not currently in force. Part I, Part III, and sections 2-3, including territorial-scope provisions, are scheduled to commence on 1 January 2027. The DPA's older webpage still describes 18 March 2025 as the enforcement date, but that statement is stale and overtaken by the later revocation and commencement Gazette instruments. The DPA's published inquiry, rights, appeal, and cross-border instruments were identified as drafts, and no final prescribed procedure was located.
At a glance
- Full name
- Personal Data Protection Act, No. 9 of 2022
- Short code
- PDPA
- Jurisdiction
- Sri Lanka
- Enacted
- 2022
- Last major update
- Amended by the Personal Data Protection (Amendment) Act, No. 22 of 2025; Parts I, III, and sections 2-3 are scheduled for 1 January 2027, while Part II and Part VII are not currently in force
- Regulator
- Data Protection Authority
- Private right of action
- Limited
Scope, who PDPA covers
Protected data
Data subject rights
Right of access under section 13, enacted but not currently operative
Right to withdraw consent or object under section 14, enacted but not currently operative
Right to rectification or completion under section 15, enacted but not currently operative
Right to erasure under section 16 for specified unlawful processing, consent withdrawal, or legal or court-ordered grounds, enacted but not currently operative
Right to review certain irreversible or continuously impactful automated decisions under section 18, enacted but not currently operative
Right to appeal a controller decision to the DPA under amended section 19, enacted but not currently operative
Rights may be exercised through parents, guardians, written representatives, and heirs for 10 years after death
Right to complain to the DPA under the currently operative Part V framework
Notable features
Sri Lanka has an unusually consequential staged-commencement structure. The DPA exists and can inquire into suspected violations, but the principal data-subject rights, penalties, territorial scope, and cross-border-transfer rules are not currently operative. The amended cross-border regime is tied to provisions scheduled for 1 January 2027, and the DPA’s published cross-border instrument remains a draft directive.
Enforcement & penalties
Regulator: Data Protection Authority
Penalties: Section 38 provides a penalty of up to LKR 10 million per non-compliance with a section 35 DPA directive, doubling for repeat non-compliance after a prior penalty. These penalties are enacted but not currently operative because Part VII has not commenced. An appeal against an administrative penalty is stated as 21 working days from communication, but that appeal route likewise concerns the inoperative Part VII framework.
Private right of action: The DPA may issue binding directives requiring cessation, corrective action, or compensation, and section 19(5) provides a 30-day appeal route to the Court of Appeal for a DPA rights determination once Part II is operative. A general private damages action was not located in the report.
Relevance to data brokers
No Sri Lanka-specific data-broker, people-search, or public-record-specific complaint/deletion route was located. The future general framework would require certain indirect-collection controllers to disclose source or public-accessibility status and would provide a general erasure right, but these provisions are not currently operative.
Generate requests in under 60 seconds
Generate removal requests for 1,034 US/global profiles, $9
FAQ
Is Sri Lanka’s data-protection law fully in force?+
No. Part II data-subject rights and Part VII penalties are not currently in force. Part I, Part III, and sections 2-3, including territorial-scope provisions, are scheduled for 1 January 2027.
Can I use Sri Lanka’s data-protection rights?+
The rights in sections 13-19 are enacted but not currently operative. The DPA’s currently operative Part V framework allows inquiries on complaint or otherwise where it has reason to believe a violation occurred.
Is there a dedicated Sri Lankan data-broker deletion route?+
No Sri Lanka-specific data-broker, people-search, or public-record-specific complaint/deletion route was located. The future general erasure and indirect-collection rules are not currently operative.
Official sources & citations
Other international privacy regimes
PDPA sits in a global ecosystem of data-protection laws. Compare with other jurisdictions that shape cross-border data flows:
