The core of the Personal Data Protection Act comes into operation on 1 January 2027. Not legal advice, just the practical first steps we suggest.
We're not lawyers and this isn't legal advice. But the Personal Data Protection Act, No. 9 of 2022, now comes up in most conversations we have with Sri Lankan companies, usually as "does this apply to us?" followed by "what do we actually have to do?"
Some context first. The Act was amended in 2025, and in July 2026 a gazette notice (Extraordinary No. 2498/16) set 1 January 2027 as the date the core parts come into operation: the scope sections, Part I on processing personal data, and Part III on controllers and processors. Other parts, including data subject rights and penalties, are due to follow through later orders. Check the Data Protection Authority's website for the current position rather than relying on a blog post, this one included.
As for whether it applies to you: if you collect personal data about people in Sri Lanka (customers, staff, job applicants, even a list of phone numbers for delivery updates), assume it very likely does in some way.
The second question is where we can help a bit, because a lot of what the Act expects is ordinary security and housekeeping.
Find out what personal data you have
This is the step everyone wants to skip, and everything else depends on it. Make a simple spreadsheet. For each kind of data, note what it is, where it lives (the ERP, a shared drive, someone's Gmail, a WhatsApp group), who can get to it, why you have it, and how long you keep it.
When companies do this for the first time, it's common to find something like a folder of scanned NIC copies from old job applicants on a shared drive the whole office can open. Nobody decided to keep them. They just never got deleted.
Collect less, and keep it for less time
Once you can see it, a surprising amount of risk goes away by deleting things. Do you need a copy of the NIC, or only the number? Do you need CVs from unsuccessful applicants from 2019? Pick a retention period for each kind of data and actually clear out the old records.
Lock down the obvious places
The Act expects appropriate technical and organisational measures. For a small company, in practice:
- MFA on email and on any cloud system holding customer or staff data
- No personal data in folders that "everyone" can open
- Disk encryption on laptops (BitLocker is already included in Windows Pro)
- Protected backups, since a backup is just another copy of the same data
If you've read our other posts, this list will look familiar. That's partly the point.
Know what you'd do if something leaks
Part III includes breach notification. Decide now who looks at a possible breach, who decides whether it has to be reported to the Authority or to the people affected, and who talks to customers. Write the names down. A one-page plan people have read is worth more than a thick policy nobody has opened.
Check your vendors
If a payroll provider, courier or marketing agency handles personal data for you, you're still responsible for how it's handled. Part III expects a proper contract with processors. Ask them the basic questions (we wrote a short list in our vendor post) and get data protection terms into the agreement.
Do the privacy notice last
Plenty of companies start by copying a privacy policy from a bigger company's website. We'd leave it until the end. Once you know what data you have and why, writing an honest notice is quick. Writing it first usually means it describes a company that doesn't exist.
A note on Data Protection Officers: whether you need to appoint one depends on what kind of data you process and how much of it, and the Authority has been publishing rules and guidance on this. Read the current material for your situation rather than assuming you're exempt.





Comments (1)
vvvv
5 Oct 2026
not good