← All posts
Governance & Risk8 Sept 2026·4 min read·By

PDPA for small companies: where we'd start

Updated 5 Oct 2026

Share

The core of the Personal Data Protection Act comes into operation on 1 January 2027. Not legal advice, just the practical first steps we suggest.

We're not lawyers and this isn't legal advice. But the Personal Data Protection Act, No. 9 of 2022, now comes up in most conversations we have with Sri Lankan companies, usually as "does this apply to us?" followed by "what do we actually have to do?"

Some context first. The Act was amended in 2025, and in July 2026 a gazette notice (Extraordinary No. 2498/16) set 1 January 2027 as the date the core parts come into operation: the scope sections, Part I on processing personal data, and Part III on controllers and processors. Other parts, including data subject rights and penalties, are due to follow through later orders. Check the Data Protection Authority's website for the current position rather than relying on a blog post, this one included.

As for whether it applies to you: if you collect personal data about people in Sri Lanka (customers, staff, job applicants, even a list of phone numbers for delivery updates), assume it very likely does in some way.

The second question is where we can help a bit, because a lot of what the Act expects is ordinary security and housekeeping.

Find out what personal data you have

This is the step everyone wants to skip, and everything else depends on it. Make a simple spreadsheet. For each kind of data, note what it is, where it lives (the ERP, a shared drive, someone's Gmail, a WhatsApp group), who can get to it, why you have it, and how long you keep it.

When companies do this for the first time, it's common to find something like a folder of scanned NIC copies from old job applicants on a shared drive the whole office can open. Nobody decided to keep them. They just never got deleted.

Collect less, and keep it for less time

Once you can see it, a surprising amount of risk goes away by deleting things. Do you need a copy of the NIC, or only the number? Do you need CVs from unsuccessful applicants from 2019? Pick a retention period for each kind of data and actually clear out the old records.

Lock down the obvious places

The Act expects appropriate technical and organisational measures. For a small company, in practice:

  • MFA on email and on any cloud system holding customer or staff data
  • No personal data in folders that "everyone" can open
  • Disk encryption on laptops (BitLocker is already included in Windows Pro)
  • Protected backups, since a backup is just another copy of the same data

If you've read our other posts, this list will look familiar. That's partly the point.

Know what you'd do if something leaks

Part III includes breach notification. Decide now who looks at a possible breach, who decides whether it has to be reported to the Authority or to the people affected, and who talks to customers. Write the names down. A one-page plan people have read is worth more than a thick policy nobody has opened.

Check your vendors

If a payroll provider, courier or marketing agency handles personal data for you, you're still responsible for how it's handled. Part III expects a proper contract with processors. Ask them the basic questions (we wrote a short list in our vendor post) and get data protection terms into the agreement.

Do the privacy notice last

Plenty of companies start by copying a privacy policy from a bigger company's website. We'd leave it until the end. Once you know what data you have and why, writing an honest notice is quick. Writing it first usually means it describes a company that doesn't exist.

A note on Data Protection Officers: whether you need to appoint one depends on what kind of data you process and how much of it, and the Authority has been publishing rules and guidance on this. Read the current material for your situation rather than assuming you're exempt.

Share

Comments (1)

vvvv

5 Oct 2026

not good

Leave a comment

Comments are checked by hand before they go live.

Most read on the blog

  1. 1Zero trust when you have one IT person and three branches
  2. 2What we'd put on a one-page security update for the board
  3. 3Logging for companies that can't justify a SIEM yet
  4. 4Ransomware prep for mid-sized companies: start with the restore
  5. 5Is your guest Wi-Fi on the same network as the accounts PC?

Related posts