Sri Lanka Data Protection Watch

Sri Lanka Data Protection Watch Empowering Sri Lankans to understand their digital rights under the Personal Data Protection Act No. 09 of 2022.

Learn how to protect your personal data and stay safe in the digital age. 🇱🇰🔐

🚨 HEALTH DATA PROTECTION: SRI LANKA AND THE EUROPEAN UNIONHealth data is one of the most sensitive forms of personal inf...
02/08/2026

🚨 HEALTH DATA PROTECTION: SRI LANKA AND THE EUROPEAN UNION

Health data is one of the most sensitive forms of personal information. It includes information about a person’s physical or psychological health, medical condition, diagnosis, treatment, medication, test results, disability, mental health, hospital records and other information revealing health status.

Under Sri Lanka’s Personal Data Protection Act, health data is classified as a special category of personal data.

Under the EU General Data Protection Regulation, health data is also treated as a special category, subject to stricter legal safeguards.

🔐 KEY LEGAL PROTECTIONS

✅ Health data must be processed for a lawful and specified purpose.

✅ Special legal conditions must be satisfied before processing.

✅ Consent is one legal basis, but health data may also be processed for diagnosis, treatment, public health, emergencies and healthcare management.

✅ Controllers must use strong safeguards, including access controls, encryption and appropriate organisational measures.

⚠️ WHAT COUNTS AS A HEALTH-DATA BREACH?

A breach may include:

• Hacking of hospital or laboratory systems
• Sending a medical report to the wrong person
• Loss of an unencrypted device containing patient records
• Unauthorised access by staff
• Ransomware affecting medical records
• Accidental publication of diagnoses or treatment details

Sri Lankan law defines a personal-data breach as accidental or unlawful destruction, loss, alteration, unauthorised disclosure or unauthorised access.

🇱🇰 SRI LANKA

The controller must notify the Data Protection Authority in the manner and period prescribed by rules. The Authority will also determine when affected individuals must be informed.

The Authority may investigate, issue corrective directions, order compensation and impose penalties for non-compliance.

🇪🇺 EUROPEAN UNION

Under the GDPR:

⏱️ The supervisory authority must generally be notified within 72 hours where the breach creates a risk.

📢 Affected individuals must be informed without undue delay where there is a high risk to their rights and freedoms.

💶 Serious violations may result in substantial fines and compensation claims.

📌 MAIN DIFFERENCE

The EU GDPR contains a clear 72-hour reporting rule. Sri Lankan law leaves the detailed reporting period and notification thresholds to rules made by the Data Protection Authority.

Health data requires the highest level of care. A single disclosure can cause discrimination, stigma, financial loss and serious personal harm.

Sri Lanka Data Protection Watch
Stay informed. Protect personal data.

🚨 CYBERSECURITY ALERT: Major UK Government Data BreachMore than 740,000 records linked to the UK Department for Educatio...
02/08/2026

🚨 CYBERSECURITY ALERT: Major UK Government Data Breach

More than 740,000 records linked to the UK Department for Education and the Police National Legal Database have reportedly been stolen in a cyberattack.

The exposed information may include:

• Full names
• Email addresses
• Telephone numbers
• Job titles and organisational details
• Police database login passwords
• Contact details of some parents, school staff, university employees, police officers and members of the public

A hacking group calling itself ExfilSquad has claimed responsibility and is reportedly demanding payment to prevent the publication of the remaining data.

The Department for Education says the compromised information was limited to customer-service contact details and that no other data was accessed. The incident has been reported to the Information Commissioner’s Office, while the National Cyber Security Centre and National Crime Agency are assisting with the investigation.

⚠️ Anyone who may be affected should change reused passwords immediately, enable multi-factor authentication, and remain alert to phishing emails, fraudulent calls and suspicious messages.

Source: The Guardian, 29 July 2026

Sri Lanka’s Key Personal Data Protection Obligations to Take Effect from 1 January 2027By Extraordinary Gazette No. 2498...
26/07/2026

Sri Lanka’s Key Personal Data Protection Obligations to Take Effect from 1 January 2027

By Extraordinary Gazette No. 2498/16 dated 22 July 2026, the Minister of Digital Economy has appointed 1 January 2027 as the commencement date for Sections 2 and 3, Part I and Part III of the Personal Data Protection Act, No. 9 of 2022.

This represents a significant step in the implementation of Sri Lanka’s personal data protection framework.

What will become effective?

Section 2: Application of the Act

This provision determines the persons, organisations, and processing activities that fall within the scope of the Act. It may apply to the processing of personal data carried out within Sri Lanka and, in certain circumstances, to entities outside Sri Lanka that offer goods or services to individuals in Sri Lanka or monitor their behaviour.

Section 3: Effect in relation to other written laws

Where another written law relating to personal data protection is inconsistent with the Act, the Personal Data Protection Act may prevail to the extent of that inconsistency.

Part I: Core obligations relating to personal data processing

Controllers will be expected to ensure that personal data is:

processed lawfully, fairly and transparently
collected for specified, explicit and legitimate purposes
adequate, relevant and limited to what is necessary
accurate and kept up to date
retained only for as long as reasonably required
protected through appropriate technical and organisational safeguards
processed in a manner that demonstrates accountability

Organisations should also identify and document the lawful basis relied upon for each processing activity. Consent is only one possible lawful basis and may not be appropriate in every case.

Part III: Duties of controllers and processors

Part III introduces important operational and governance obligations, including the following:

defining the responsibilities of controllers and processors
entering into suitable contractual arrangements with processors
implementing data protection policies and internal controls
assessing whether a Data Protection Officer must be appointed
conducting impact assessments for high-risk processing
establishing procedures for managing personal data breaches
maintaining appropriate security measures
reviewing international and cross-border data transfers
adopting safeguards when using cloud services and external service providers
What organisations should do before 1 January 2027

Businesses, professional firms, financial institutions, schools, hospitals, employers, online platforms, public authorities and other entities handling personal data should begin compliance preparations without delay.

Priority actions should include:

conducting a personal data inventory
identifying processing purposes and lawful bases
reviewing privacy notices and consent forms
updating contracts with service providers
introducing retention and deletion schedules
strengthening cybersecurity and access controls
preparing a data breach response procedure
assessing the need for a Data Protection Officer
identifying high-risk processing activities
reviewing overseas and cloud-based data transfers
training employees who handle personal data
Important legal point

The Gazette specifically brings Sections 2 and 3, Part I and Part III into operation from 1 January 2027. Other provisions of the Act may require separate commencement orders.

Organisations should therefore carefully distinguish between the provisions expressly activated by this Gazette and those that may come into force at a later stage.

This publication is intended solely for general legal information and does not constitute legal advice.

PDPA

Global data privacy compliance is changing rapidly, and privacy professionals must keep pace with new legal, technologic...
24/07/2026

Global data privacy compliance is changing rapidly, and privacy professionals must keep pace with new legal, technological, and regulatory risks.

Key areas requiring close attention include the following:

• AI and automated decision-making
• Children’s data and age assurance
• Biometric and health information
• International data transfers
• Privacy by design and data mapping
• Cybersecurity and breach response
• Consumer complaint procedures
• Data minimisation and retention

For professionals working in the EU, the immediate priorities include the GDPR, the EU AI Act, the UK Data (Use and Access) Act, international transfer requirements, India’s phased DPDP framework, California’s updated privacy regulations, and China’s network data rules.

These developments show that privacy compliance is no longer limited to legal interpretation. It now requires practical knowledge of technology, risk management, governance, and cross-border regulatory cooperation.

SLDPW provides an important platform to discuss these changes and strengthen awareness of responsible data governance.

New UK Data Protection Law: What Businesses Should KnowThe UK has introduced the Data (Use and Access) Act 2025, bringin...
19/06/2026

New UK Data Protection Law: What Businesses Should Know

The UK has introduced the Data (Use and Access) Act 2025, bringing important reforms to the UK GDPR and the Privacy and Electronic Communications Regulations.

The purpose of the Act is to make data use easier for organisations while keeping core privacy protections in place.

Key changes include:

1. Mandatory internal complaints process
Organisations must now maintain a clear process for handling data protection complaints. Complaints must be acknowledged within 30 days and handled without undue delay.

2. Recognised legitimate interests
For certain purposes, including crime prevention, public security, safeguarding, and emergency response, organisations may rely on recognised legitimate interests without carrying out the usual balancing test.

3. Wider use of automated decision-making
The Act gives organisations more flexibility to use automated decision-making, including decisions with legal or similarly significant effects. However, safeguards remain necessary, including human intervention and the right to challenge the decision.

4. Scientific research and broad consent
The Act clarifies that scientific research may include commercial research. It also allows broader consent for related areas of research, which may make research compliance easier to manage.

5. Cookies without consent in limited cases
Some cookies may now be used without consent, particularly where they are used for statistical purposes or to improve website functionality.

6. Subject Access Requests
The Act clarifies response timeframes and introduces a formal “stop the clock” rule where organisations are waiting for further information from the requester.

The Information Commissioner’s Office has also published guidance to help organisations prepare for these changes.

For businesses, this is more than a legal update. It is a reminder to review privacy notices, complaints procedures, cookie practices, legitimate interest assessments, and automated decision-making systems.

Data compliance is no longer just paperwork. It is becoming a matter of operational accountability.

What is “Privacy by Design and by Default” and why does it matter?In today’s data-driven world, protecting personal info...
30/04/2026

What is “Privacy by Design and by Default” and why does it matter?

In today’s data-driven world, protecting personal information cannot be an afterthought. Privacy must be built into systems, technologies, and business practices from the very beginning.
Privacy by Design means that privacy safeguards are included at the design stage. Organisations must anticipate risks and prevent harm before it happens.

Privacy by Default means that only the minimum necessary personal data should be collected and processed by default. Users should not have to take extra steps to protect their privacy. The system should protect them automatically.

This matters because it:
✅ Reduces the risk of data breaches and misuse
✅ Builds trust between organisations and individuals
✅ Supports compliance with modern data protection laws
✅ Protects dignity, autonomy, and digital rights
✅ Shifts responsibility from the user to the system provider
Good data protection is not about reacting after something goes wrong. It is about preventing problems through careful design and responsible default settings.

📘 In a digital society, privacy is not optional. It is a legal and ethical obligation.

Sri Lanka Data Protection Watch🌞✨ Happy Sinhala and Tamil New Year 2026 ✨🌞As we welcome this season of renewal, peace, a...
13/04/2026

Sri Lanka Data Protection Watch

🌞✨ Happy Sinhala and Tamil New Year 2026 ✨🌞

As we welcome this season of renewal, peace, and prosperity, Sri Lanka Data Protection Watch extends warm wishes to you and your loved ones.

May this New Year bring happiness to your home, success to your work, and strength to protect what matters most.

Just as we value tradition, let us also value trust, privacy, and responsibility in the digital age.

🌼 Wishing you joy, harmony, and a secure future. 🌼

සුභ අලුත් අවුරුද්දක් වේවා
இனிய சிங்கள தமிழ் புத்தாண்டு நல்வாழ்த்துக்கள்

06/03/2026

📢 Marketing Rules under Sri Lanka’s Personal Data Protection Act (PDPA)

Businesses often promote their products through email, SMS, WhatsApp, and other digital platforms. Under Sri Lanka’s Personal Data Protection Act No. 9 of 2022, marketing activities must follow clear legal standards that protect personal data and privacy.

B2C Marketing (Business to Consumer)
When a company markets directly to individuals, it must first obtain clear consent before sending promotional messages. Emails, SMS promotions, automated calls, or similar communications can be sent only after the person has agreed to receive them.

Each marketing message must also include a simple and free option to opt out, allowing the recipient to stop receiving future messages at any time.

B2B Marketing (Business to Business)
Marketing between businesses is generally less restrictive. However, if the communication uses the personal contact details of a specific employee or individual, the PDPA requirements still apply. Businesses must therefore ensure transparency and allow recipients to refuse further communications.

Transparency and Accountability
Marketing communications must clearly identify:
• the sender
• the purpose of the message
• the method for unsubscribing

These rules help prevent unsolicited marketing and strengthen trust in the digital economy.


✍️ Eranda Kandegama
Author – Your Questions Answered: Personal Data Protection Act No. 9 of 2022










06/02/2026

What is a Data Protection Impact Assessment (DPIA) Test?

A Data Protection Impact Assessment (DPIA) test is a preventive legal assessment used to identify and reduce risks to individuals when personal data is processed in a way that may seriously affect their rights and freedoms.

It is not a technical checklist or an IT audit. It is a legal accountability tool required under the General Data Protection Regulation (GDPR) and reflected in modern data protection frameworks worldwide.

What does the DPIA test examine?

First, it requires a clear description of the processing activity. This includes what data is collected, for what purpose, who is affected, how long the data is kept, and who can access it.

Second, it asks whether the processing is likely to result in high risk. High risk commonly arises in situations such as large-scale data processing, use of new technologies, profiling, automated decision-making, biometric or health data use, employee monitoring, or processing data of vulnerable individuals.

Third, the DPIA test evaluates necessity and proportionality. The organisation must show that the processing is genuinely needed and that the same objective cannot be achieved in a less intrusive way.

Finally, it requires identification of risk mitigation measures. These may include encryption, access controls, reduced retention periods, human oversight, and clear mechanisms for exercising data subject rights.

If significant risk remains even after safeguards, the organisation must consult the data protection authority before proceeding.

Why the DPIA test matters

A proper DPIA demonstrates accountability. Regulators often focus not only on whether harm occurred, but on whether risks were assessed and addressed in advance. In enforcement actions, failure to conduct a DPIA is frequently treated as a serious compliance failure.

In simple terms

A DPIA test forces organisations to think about data protection risks before harm happens, not after.

© Sri Lanka Data Protection Watch (SLDPW)

22/01/2026

Digital marketing is powerful, but it comes with responsibility. Every click, form, and ad campaign involves personal data. Names, emails, locations, browsing behaviour, and preferences are not just marketing assets.

They are part of someone’s private life. Responsible digital marketing means:
• Collecting only what is truly necessary
• Being clear about why data is collected
• Using data lawfully, fairly, and transparently
• Protecting customer information from misuse or breaches
• Respecting consent and the right to opt out

Trust is the real currency of the digital economy. Brands that respect personal data do not just comply with the law. They build credibility, loyalty, and long-term value. Smart marketing respects privacy. Ethical growth depends on it.













Address

Korathota North
Kaduwela
10640

Opening Hours

Monday 09:00 - 17:00
Tuesday 09:00 - 17:00
Wednesday 09:00 - 17:00
Thursday 09:00 - 17:00
Friday 09:00 - 17:00

Website

Alerts

Be the first to know and let us send you an email when Sri Lanka Data Protection Watch posts news and promotions. Your email address will not be used for any other purpose, and you can unsubscribe at any time.

Shortcuts

Share

Category