šŸ“ˆ Sri Lanka Data Protection Compliance Framework Effective 1 Jan. 2027

Source

• Core Timeline & Mandate: Key provisions of the Personal Data Protection Act, No. 9 of 2022 will officially become operational on 1 January 2027, as appointed via Extraordinary Gazette No. 2498/16. • Key Operational Areas: • Scope & Legality: Section 2 (scope), Section 3 (relation to written law), and Part I (lawful/transparent data processing) take effect. • Corporate Obligations: Part III introduces requirements for designating Data Protection Officers (DPOs), reporting personal data breaches, and performing Data Protection Impact Assessments. • Cross-Border & Vendor Governance: Framework establishes strict controller-processor contractual rules and oversight on cross-border data transfers affecting sectors handling user data. • Transition Guidance: The Data Protection Authority of Sri Lanka (DPA) urges entities to utilize the remaining transition window to review governance, update contracts, and strengthen safeguards ahead of the 2027 deadline.

Listen to this article

Duration: 1:07