02/08/2026
🚨 HEALTH DATA PROTECTION: SRI LANKA AND THE EUROPEAN UNION
Health data is one of the most sensitive forms of personal information. It includes information about a person’s physical or psychological health, medical condition, diagnosis, treatment, medication, test results, disability, mental health, hospital records and other information revealing health status.
Under Sri Lanka’s Personal Data Protection Act, health data is classified as a special category of personal data.
Under the EU General Data Protection Regulation, health data is also treated as a special category, subject to stricter legal safeguards.
🔐 KEY LEGAL PROTECTIONS
✅ Health data must be processed for a lawful and specified purpose.
✅ Special legal conditions must be satisfied before processing.
✅ Consent is one legal basis, but health data may also be processed for diagnosis, treatment, public health, emergencies and healthcare management.
✅ Controllers must use strong safeguards, including access controls, encryption and appropriate organisational measures.
⚠️ WHAT COUNTS AS A HEALTH-DATA BREACH?
A breach may include:
• Hacking of hospital or laboratory systems
• Sending a medical report to the wrong person
• Loss of an unencrypted device containing patient records
• Unauthorised access by staff
• Ransomware affecting medical records
• Accidental publication of diagnoses or treatment details
Sri Lankan law defines a personal-data breach as accidental or unlawful destruction, loss, alteration, unauthorised disclosure or unauthorised access.
🇱🇰 SRI LANKA
The controller must notify the Data Protection Authority in the manner and period prescribed by rules. The Authority will also determine when affected individuals must be informed.
The Authority may investigate, issue corrective directions, order compensation and impose penalties for non-compliance.
🇪🇺 EUROPEAN UNION
Under the GDPR:
⏱️ The supervisory authority must generally be notified within 72 hours where the breach creates a risk.
📢 Affected individuals must be informed without undue delay where there is a high risk to their rights and freedoms.
💶 Serious violations may result in substantial fines and compensation claims.
📌 MAIN DIFFERENCE
The EU GDPR contains a clear 72-hour reporting rule. Sri Lankan law leaves the detailed reporting period and notification thresholds to rules made by the Data Protection Authority.
Health data requires the highest level of care. A single disclosure can cause discrimination, stigma, financial loss and serious personal harm.
Sri Lanka Data Protection Watch
Stay informed. Protect personal data.