SRI LANKA PDPA LEGAL LIBRARY

The sources behind accountable action.

A curated library of primary legislation, regulator publications, consultation materials, circulars, and practical resources for PDPA readiness and implementation.

HOW TO USE THIS LIBRARY

1

Start with the Act

Use the primary legislation to understand the legal framework.

2

Check current official notices

Review DPA publications and Gazette-linked operational updates.

3

Turn sources into controls

Use the checklist and playbook to translate obligations into evidence.

IMPORTANT LEGAL NOTE

This library is a practical research starting point, not legal advice. Verify current status, commencement dates, regulations, and official interpretations directly against the latest official Gazette and Data Protection Authority publications before relying on a source.

PRIMARY LEGAL SOURCES

Start with official law and regulator materials.

Visit the DPA website ↗
Primary law01

ACT · 2022

Personal Data Protection Act, No. 9 of 2022

Sri Lanka’s primary personal-data protection legislation. Start here for the statutory framework governing processing, data-subject rights, controllers, processors, the DPA, and related obligations.

Parliament of Sri LankaOpen resource
Official02

REGULATOR · Current

Data Protection Authority of Sri Lanka

The official regulator website for announcements, guidance, publications, consultation materials, contact details, and PDPA-related updates.

Data Protection Authority of Sri LankaOpen resource
Official guidance03

GUIDANCE HUB · Current

Official PDPA guidance and public consultations

Official DPA page hosting the Act and consultation materials, including proposed regulations on DPIAs, DPO appointments, and data-subject rights.

Data Protection Authority of Sri LankaOpen resource
Official04

OPERATIONALISATION · Published notice

PDPA dates of operation announcement

Official DPA summary of operationalisation notices and dates. Check this source together with the latest Gazette notices, as operational dates can change.

Data Protection Authority of Sri LankaOpen resource

REGULATIONS, CIRCULARS, AND GUIDANCE

Track the instruments that shape implementation.

Regulations and guidance can materially affect how organisations appoint privacy leadership, conduct DPIAs, handle rights requests, and implement controls. Draft and consultation documents should be treated as informative until formally issued or enacted.

Draft / consultation01

DPIA REGULATION · 2024 consultation

Draft Personal Data Protection Impact Assessment Regulations

Draft framework for when and how organisations should assess privacy impacts of high-risk processing before proceeding.

Data Protection Authority of Sri LankaOpen resource
Draft / consultation02

DPO REGULATION · 2024 consultation

Draft Data Protection Officer Regulations

Consultation material on DPO appointment, scale, qualification, and related requirements.

Data Protection Authority of Sri LankaOpen resource
Draft / consultation03

RIGHTS REGULATION · 2024 consultation

Draft Regulations on Data Subjects’ Rights and Appeals

Consultation material concerning the exercise of data-subject rights and appeals procedures.

Data Protection Authority of Sri LankaOpen resource
Official04

PUBLIC-SECTOR CIRCULAR · 13 September 2024

DPA Circular No. 01/2024

Official circular concerning application of the PDPA in the public sector.

Data Protection Authority of Sri LankaOpen resource

THE PDPA, IN PRACTICE

Legal reading should lead to practical implementation.

A defensible privacy programme connects legal obligations to accountable people, transparent processing, secure systems, working rights processes, vendor oversight, evidence, and ongoing review.

1

Governance

Leadership oversight, DPO capability, policies, and accountability.

2

Data operations

Inventory, processing records, purpose, lawful basis, and retention.

3

Rights and trust

Notices, consent where relevant, rights workflows, and response records.

4

Security and assurance

Safeguards, incidents, vendors, DPIAs, testing, metrics, and remediation.

Reference01

IMPLEMENTATION TOOL · PDPA.COM.LK

Advanced PDPA Compliance Checklist

Interactive, evidence-led control tracker across governance, processing records, rights, security, retention, vendors, DPIAs, and assurance.

Reference02

IMPLEMENTATION GUIDE · PDPA.COM.LK

PDPA Implementation Playbook

A structured route from mobilisation and data mapping through control implementation, evidence, testing, and continuous improvement.

Reference03

READINESS TOOL · PDPA.COM.LK

PDPA Readiness Assessment

Structured assessment to help identify privacy maturity, material gaps, priority actions, and an executive-ready starting view.

Official04

REGULATOR OVERVIEW · Current

Data Protection Authority introduction

Overview of the Authority, its purpose, and its role in implementing and overseeing Sri Lanka’s PDPA framework.

Data Protection Authority of Sri LankaOpen resource

FROM LEGAL SOURCE TO DELIVERY PLAN

Know the rules. Then make the controls work.

Use the readiness assessment to identify gaps, the advanced checklist to assign and evidence controls, and the implementation playbook to structure the work.