Sri Lanka’s PDPA Countdown Has Begun: Compliance Priorities for Businesses 

Sri Lanka’s PDPA Countdown Has Begun: Compliance Priorities for Businesses 

July 31, 2026

Introduction   

After years of delays, Sri Lanka’s Personal Data Protection Act (PDPA) has finally reached a major milestone. The Government has confirmed that key operational provisions of the Act will come into force on 1 January 2027, giving organizations a clear timeline to prepare for the next phase of privacy compliance. 

For many businesses, this marks the transition from planning for privacy compliance to actively demonstrating it. Organizations can no longer view data protection as a future requirement, they must now focus on implementing practical controls, establishing governance structures, and ensuring they can demonstrate accountability. 

From maintaining accurate Records of Processing Activities (ROPA) and reviewing lawful processing practices to strengthening breach management processes and determining Data Protection Officer (DPO) requirements, organizations should begin prioritizing implementation rather than waiting for further announcements. 

How Sri Lanka’s PDPA Journey Reached This Point 

Gazette / Act Date What it did 
Gazette 2341/59 21 Jul 2023 Set up the Data Protection Authority (DPA), effective from 17 July 2023. 
Gazette 2366/08 8 Jan 2024 Brought the DPA’s internal admin sections into force from 1 Dec 2023 and set 18 March 2025 as the date the main compliance rules (Parts I, II, III, VII) would start. 
Gazette 2427/34 14 Mar 2025 Cancelled that 18 March 2025 start date, just four days before it would have taken effect. 
Amendment Act No. 22 of 2025 Certified 30 Oct 2025 Changed the law so there’s no longer a fixed deadline for the remaining Parts. The Minister can now bring in sections one at a time, whenever ready. Also rewrote several sections, including the cross-border data transfer rules. 
Gazette 2498/16 22 Jul 2026 This is the new notice: it sets 1 January 2027 as the date on which Section 2, Section 3, Part I, and Part III come into force. 

Full Commencement Status  

Status What it covers Date 
Already in force Part V – the DPA itself: its powers, duties, and ability to issue directives 17 July 2023 
Already in force Parts VI, VIII, IX, X – the DPA’s staffing, funding and other internal/admin matters 1 December 2023 
Coming into force Section 2 (who the Act applies to), Section 3 (the Act overrides other conflicting laws), Part I (core rules on processing personal data), Part III (rules for controllers and processors, including DPOs, breach notification, DPIAs, and cross-border transfers) 1 January 2027 
Not yet in force Part II (rights of data subjects – access, correction, deletion, etc.), Part IV (rules on marketing messages), Part VII (penalties for non-compliance) No date set 

What Comes into Force on 1 January 2027? 

5.1 Section 2 – Scope of Application 

Who the Act applies to. This covers any organization processing personal data in Sri Lanka, and reaches foreign companies that sell to, or track the behavior of, people in Sri Lanka even if they have no local office. 

5.2 Section 3 – The provisions of this Act to prevail in case of any inconsistency 

PDPA takes priority over other laws where there’s a conflict on data protection matters. 

5.3 Part I – Processing of Personal Data (ss. 4 – 12) 
Section Obligation on the controller 
s.4 Process personal data in compliance with the obligations set out in the Act. 
s.5 Lawfulness – Schedule I condition; Schedule II condition for special-category data; all Schedule III conditions where consent is the basis; all Schedule IV conditions for criminal-investigation processing. 
s.6 Purpose limitation – specified, explicit, legitimate purpose; no incompatible further processing (archiving/research/statistics carved out, subject to s.10). 
s.7 Data minimization – adequate, relevant, proportionate to the purpose. 
s.8 Accuracy – kept up to date; reasonable steps to erase or rectify without undue delay. 
s.9 Storage limitation – identifiable data kept only as long as necessary. 
s.10 Integrity & confidentiality – appropriate technical/organizational measures: encryption, pseudonymization, anonymization, access controls. 
s.11 Transparency – provide Schedule V information and decisions on Part II-type requests, in clear, accessible form. 
s.12 Implement a Data Protection Management Programme (DPMP): catalogued compliance records, risk-based design, governance integration, internal oversight, complaint/breach mechanisms, periodic review. 
5.4 Part III – Controllers and Processors (ss. 20–26) 
Section Obligation on the controller / processor 
s.20 Designate a DPO is required where processing involves,      (i) regular/systematic monitoring at scale,       (ii) special-category data at scale, or       (iii) risk of harm to data subjects thresholds still to be prescribed. Can be outsourced or shared across a group. 
s.21 Use only processors offering appropriate safeguards, bound by written contract (subject matter, duration, nature, purpose, data types, data-subject categories, controller obligations). 
s.22 Processor duties: act only on written instructions; bind personnel to confidentiality; support audits; return/erase data on completion; flows down to sub-processors. 
s.23 Notify the DPA of a personal data breach in the form/manner/timeframe it prescribes (rules currently in draft only). 
s.24 Conduct a DPIA before high-risk processing (profiling, large-scale monitoring, etc.); mandatory DPO involvement; re-assess on any change of methodology/technology. 
s.25 Where a DPIA shows likely risk of harm, mitigate before processing begins; consult the DPA on national security / public order / public health processing. 
s.26 Cross-border transfers – wholly rewritten permitted only via a DPA-specified instrument (not yet issued), or under a defined derogation list (explicit informed consent, contract necessity, legal claims, public interest, vital-interest emergency, mere transit). 

What has not yet commenced? 

While important operational requirements will commence on 1 January 2027, some provisions remain pending. 

These include: 

  1. Part II – Rights of Data Subjects (ss. 13–19) 

Requirements relating to rights such as: 

  • Access to personal data  
  • Correction of information  
  • Erasure requests  
  • Objection rights  
  • Appeals to the Data Protection Authority  

Although these requirements are not yet enforceable, organizations should begin preparing their processes because implementing effective rights management requires coordination across business functions. 

  1. Part IV – Solicited Messages (s. 27) 

Rules relating to solicited messages and marketing consent management are also pending commencement. 

Organizations should continue reviewing their marketing practices and consent mechanisms to ensure future readiness. 

  1. Part VII – Penalties, Exemptions & Derogations (ss. 38–40) 

The dedicated penalty framework under Part VII has not yet commenced. 

Note – penalty nuance: Part VII hasn’t commenced, but Section 38 already sets penalties of up to Rs 10 million per instance of non-compliance with Part I/III obligations, independent of Part VII’s status. The DPA can also inquire and issue directions on non-compliance in the meantime. 

Compliance readiness requires significant planning, documentation, and operational changes that cannot be completed overnight. 

The 12 Actions Organizations Should Prioritize Now 

1. Establish and Maintain Records of Processing Activities (ROPA) 

ROPA is the foundation of a privacy compliance programme. 

Organizations should document: 

  • What personal data is collected  
  • Why it is processed  
  • Where it is stored  
  • Who has access  
  • Who it is shared with  
  • How long it is retained  

Without visibility into personal data processing activities, organizations cannot effectively manage privacy risks. 

2. Review Vendor and Processor Agreements  

Review and update processor and sub-processor agreements to cover subject matter, duration, nature, purpose, data types, data-subject categories, controller obligations, confidentiality bindings, audit facilitation, and return/deletion on instruction, with flow-down to sub-processors. 

This takes the longest because it involves negotiating with other parties 

3. Map Cross-Border Data Transfers 

Organizations should identify where personal data moves outside Sri Lanka, including: 

  • Cloud platforms  
  • SaaS applications  
  • Group systems  
  • External service providers 
4. Review Lawful Processing Activities 

Organizations should map processing activities against the relevant lawful basis requirements. 

This includes reviewing whether current processing activities have a valid justification and whether consent mechanisms meet required conditions. 

5. Board / DPSC governance ownership 

Establish clear board or DPSC-level ownership and reporting for the data protection programme.  

This isn’t about pre-empting Part VII penalties, which have no commencement date set. It’s about the DPMP, DPO appointment, and vendor/policy signoffs already underway need a governing body to own and approve them. 

6. Determine DPO Requirements 

Organizations should evaluate whether they require a Data Protection Officer and plan the appointment process where necessary. 

7. Update Privacy Notices 

Privacy notices should clearly communicate: 

  • What information is collected  
  • Why it is collected  
  • How it is used  
  • Individual rights  
  • Data sharing practices  
8. Establish Retention and Deletion Processes 

Set clear rules for how long you keep different types of data and make sure you can actually delete it when the time comes (not just on paper). 

9. Strengthen Security Controls 

Organizations should implement appropriate technical and organizational safeguards, including: 

  • Access controls  
  • Encryption  
  • Data protection measures  
  • Security monitoring  
10. Develop DPIA Processes 

Stand up a DPIA methodology and templates; sweep existing profiling/monitoring activities for a backlog of assessments; ensure DPO involvement is built into the process (now mandatory) and that DPIAs are re-triggered on any change of methodology or technology. 

11. Prepare Breach Response Processes 

Organizations should ensure they can detect, assess, manage, and respond to personal data breaches. 

Build detection, triage, and notification capability now; the process should be parameter-driven so it can be adjusted once the DPA’s breach-notification rules are finalized. 

12. Build a Complete Data Protection Management Programme 

Assemble the overarching programme that ties items 1 to11 together. This is the artefact the DPA evaluates under s.32(h), and a mitigating factor in any future penalty determination. 

How Businesses Should Prepare Over the Next Few Months 

The commencement of the PDPA should be viewed as an opportunity for organizations to strengthen trust and accountability. 

Businesses should focus on: 

  • Understanding their personal data landscape  
  • Embedding privacy into business processes  
  • Strengthening governance structures  
  • Improving third-party oversight  
  • Aligning security practices with privacy requirements  

Organizations that begin preparation early will have a significant advantage compared to those waiting until the enforcement date approaches. 

Beyond Immediate Compliance: Preparing for What Comes Next 

Area What we need to do Priority  
13. Data subject request readiness Build the intake and fulfilment process now, even though Part II isn’t commencing: one-month response clock, extension notice before month one expires, three-month hard cap, free-of-charge by default, refusal reasons recorded, appeal-rights notice. not yet enforceable 
14. Marketing consent & opt-out Prepare consent capture and per-message opt-out mechanisms with sender identification, ready for when Part IV commences.  no date set 
15. Automated-decision register Maintain a register of solely automated decisions with a human-review path and the Schedule V(m) logic disclosure. not yet enforceable  

ISMS.Online – What Needs Attention Today 

Our PDPA advisory practice covers the full readiness programme end to end. As a value-added service, we can also configure and maintain your entire PDPA compliance programme within ISMS.online, providing a live, evidence-backed view of your compliance status, documentation, controls, and ongoing activities, all in one place. 

Framework – level work areas 

  • Records of Processing Activity / ROPA – This is the base everything else sits on and the first thing the DPA is likely to ask for.  
  • Breach Register – maps to the Part III breach notification duty.  
  • Data Protection Impact Assessment / DPIA – maps to Part III’s impact assessment duty, also Near-term. Keep progressing in parallel with the Breach Register. 

PDPA checklist for data controllers  

  • Data Protection Management Programme / DPMP – Covers Part III’s governance programme and DPO obligations. Priority 1. 
  • Lawfulness of Processing – Part I’s core lawful-basis requirement. Priority 2. 
  • Transparency – maps to privacy notices, a Near-term item. 

PDPA checklist for data processors  

  • Lawfulness of Processing, DPMP, and Transparency – mirror the same Part I/III obligations above but applied to processor relationships.  

Information security  

  • Management and organizational information security and Physical security, Operational Security – Part I’s security obligation. Prioritize this next after DPMP and Lawfulness of Processing. 
Preparing for the Next Phase of PDPA  

Data Subject Rights (controllers, processors) – falls under Part II, which has no commencement date yet  

Training and Awareness  

  • Information Security Training & Awareness and Personal Data Protection Training & Awareness – not urgent. 

Use of Personal Data to Disseminate Solicited Messages 

  • Marketing Communication Consent Management, Opt-Out and Unsubscribe Management, Direct Marketing Communication Governance, and Third-Party Marketing and Communication Control – this entire module maps to Part IV, which also has no commencement date.