š Sri Lanka Data Protection Compliance Framework Effective 1 Jan. 2027
⢠Core Timeline & Mandate: Key provisions of the Personal Data Protection Act, No. 9 of 2022 will officially become operational on 1 January 2027, as appointed via Extraordinary Gazette No. 2498/16. ⢠Key Operational Areas: ⢠Scope & Legality: Section 2 (scope), Section 3 (relation to written law), and Part I (lawful/transparent data processing) take effect. ⢠Corporate Obligations: Part III introduces requirements for designating Data Protection Officers (DPOs), reporting personal data breaches, and performing Data Protection Impact Assessments. ⢠Cross-Border & Vendor Governance: Framework establishes strict controller-processor contractual rules and oversight on cross-border data transfers affecting sectors handling user data. ⢠Transition Guidance: The Data Protection Authority of Sri Lanka (DPA) urges entities to utilize the remaining transition window to review governance, update contracts, and strengthen safeguards ahead of the 2027 deadline.