Last updated 8 October 2026
From 1 January 2027, the core duties of Sri Lanka’s Personal Data Protection Act (PDPA) apply to any business that collects personal data, and your website is usually where most of it is collected. Contact forms, booking engines, WhatsApp buttons, chatbots, analytics and newsletter sign-ups all handle personal data, so each one needs a legal basis, a clear privacy notice and proper security before that date.
The start date comes from Gazette Extraordinary No. 2498/16, published on 22 July 2026. It brings Section 2, Section 3, Part I (processing of personal data) and Part III (controllers and processors) of the Personal Data Protection Act, No. 9 of 2022 into operation on that day.
This guide explains what actually starts in January, what doesn’t yet, and the 12 changes most Sri Lankan business websites will need. It’s written for owners, marketers and IT teams, not lawyers, and it links to the official source for every point.
What the PDPA is, and what actually starts on 1 January 2027
The PDPA is Sri Lanka’s first comprehensive data protection law. It was passed in March 2022 as Act No. 9 of 2022, amended by the Personal Data Protection (Amendment) Act, No. 22 of 2025, and is enforced by the Data Protection Authority of Sri Lanka (DPA).
The 2025 amendment scrapped the fixed grace periods in the original Act. Instead, each part now starts on a date the Minister sets by Gazette order. That’s why the law has come into force in stages:
| Date | What happened | Source |
|---|---|---|
| 1 January 2027 | Section 2 (scope), Section 3, Part I (processing of personal data) and Part III (controllers and processors) come into operation | Gazette 2498/16 |
| 22 July 2026 | Gazette 2498/16 published, setting the 1 January 2027 date (order signed 13 July 2026) | Gazette 2498/16 |
| 31 October 2025 | Amendment Act No. 22 of 2025 published, removing the fixed grace periods and changing several duties | Act No. 22 of 2025 |
| 2023 | Provisions setting up the Data Protection Authority (Parts V, VI, VIII, IX and X) brought into operation | DPA |
| March 2022 | PDPA, Act No. 9 of 2022, passed | Act No. 9 of 2022 |
What starts on 1 January 2027
- Part I, processing of personal data (sections 4 to 12). The rules on how you collect and use data: a lawful basis for every use, purpose limitation, security, transparency, and a documented Data Protection Management Programme.
- Part III, controllers and processors (sections 20 to 26). Data Protection Officers, contracts with service providers, breach notification, data protection impact assessments and transfers outside Sri Lanka.
The DPA has described these provisions as the core compliance framework for controllers and processors, and has urged businesses to review their policies, contracts and security before the date (Daily FT).
What doesn’t have a start date yet
Gazette 2498/16 does not bring these parts into operation. Each needs a further Gazette order:
- Part II, rights of data subjects (sections 13 to 19): access, correction, erasure, withdrawing consent and objecting.
- Part IV, solicited messages (section 27): consent and opt-out rules for marketing messages.
- Part VII, penalties (sections 38 to 40): administrative fines of up to LKR 10 million.
Don’t read this as “rights and fines can wait”. Part I, which does start in January, already requires your privacy notice to tell people about their rights. It also requires your management programme to make those rights easy to exercise. A website built for the full Act now won’t need rebuilding when the remaining parts are switched on.
Does the PDPA apply to your business?
If your website collects personal data from people in Sri Lanka, almost certainly yes. Under section 2 of the Act, it applies when processing happens wholly or partly in Sri Lanka, or when the controller or processor is:
- domiciled or resident in Sri Lanka;
- incorporated or established under Sri Lankan law; or
- offering goods or services to, or monitoring the behaviour of, people in Sri Lanka, even from overseas.
That last point catches foreign hotel groups, e-commerce stores and SaaS companies selling into Sri Lanka. Company size doesn’t matter. The only exclusions are purely personal or household use and data that isn’t personal.
“Personal data” is broader than most people expect. It means any information that can identify a person directly or indirectly. On a website, that covers names, email addresses and phone numbers, but it can also cover IP addresses, device IDs, location data and the identifiers that analytics and advertising tools use.
Three roles matter:
- Controller: you, if you decide why and how the data is used.
- Processor: a provider that handles data on your behalf, such as your hosting company, email platform, CRM or chatbot vendor.
- Data subject: the person the data is about, such as a customer, guest, student or job applicant.
The PDPA website checklist: 12 changes to make before 1 January 2027
Start by listing every point where your site collects data: forms, bookings, checkouts, chat widgets, newsletter pop-ups, job applications, analytics and ad pixels. Then work through these 12 points.
1. Rewrite your privacy notice to the PDPA standard
Section 11 requires you to give people the information listed in Schedule V of the Act, in writing or electronically, in a “concise, transparent, intelligible and easily accessible” form. A copied GDPR template or a two-line policy won’t cover it. Your notice must state:
- who you are and how to contact you, plus your Data Protection Officer’s contact details;
- why you collect each type of data, and the legal basis for each purpose;
- the categories of data you collect;
- that people can withdraw consent, and how;
- who you share data with, and whether it is sent outside Sri Lanka;
- how long you keep it, or how you decide;
- people’s rights, how to use them, and their right to complain to the DPA;
- whether giving the data is required, and what happens if they don’t; and
- any automated decision-making or profiling, with meaningful information about how it works.
Link the notice from your footer and from every form.
2. Give every form and tool a lawful basis
Under section 5 and Schedule I, every use of personal data needs one of six bases: consent, contract, legal obligation, emergency, public interest, or legitimate interests. For example:
- Quote request or booking form: usually contract, because the person asked you to take steps.
- Newsletter: consent.
- Fraud prevention or basic site security logs: often legitimate interests, provided they don’t override the person’s rights, especially a child’s.
Record your choice for each purpose. It feeds straight into your privacy notice and your management programme (point 12).
3. Collect consent properly
The Act defines consent as a “freely given, specific, informed and unambiguous indication” of agreement, given by written declaration or affirmative action (section 56). On a website, that means:
- no pre-ticked boxes;
- a separate tick box for marketing, not bundled into “I accept the terms”;
- consent that is as easy to withdraw as it was to give; and
- a record of who consented, when, and to what wording.
4. Decide how you handle cookies, analytics and pixels
The PDPA has no cookie-specific rule. However, analytics and advertising tools that identify or track individual visitors process personal data, so they need a lawful basis like everything else. If you rely on consent, use a banner that offers a genuine “Reject” option and loads non-essential tags only after acceptance. If you rely on legitimate interests for basic analytics, document why, minimise the data, and explain it in your privacy notice.
5. Collect only what you need
Part I requires data to be collected for “specified, explicit and legitimate” purposes (section 6), and to be adequate, relevant and limited to those purposes. Audit your forms. If a contact form asks for a NIC number, date of birth or home address “just in case”, remove the field.
6. Put contracts in place with your processors
Section 21 says controllers may only use processors that provide appropriate technical and organisational safeguards. The processing must be governed by a contract that sets out its subject matter, duration, nature, purpose, the types of data and the categories of people involved. Check the data processing terms for your hosting, form plugins, email marketing tool, CRM, payment gateway, booking engine and chatbot provider. If any of these AI tools store chat transcripts, they belong on this list too (see our post on website chatbots).
7. Check where your data is stored
Most Sri Lankan websites send data abroad, through overseas hosting, Google Workspace, cloud CRMs or international booking engines (common on hotel and villa websites). Section 26, as replaced by the 2025 amendment, allows transfers outside Sri Lanka if you comply with the Act’s obligations and adopt an instrument the DPA specifies in a directive. Exceptions include explicit informed consent and transfers necessary for a contract. The DPA’s draft directive on cross-border instruments is still a consultation draft, so for now map every transfer and keep the provider’s contract terms on file.
8. Harden your website’s security
Section 10 requires “appropriate technical and organisational measures” such as encryption, pseudonymisation, anonymisation and access controls. For a website, the practical baseline is:
- HTTPS everywhere and a valid SSL certificate;
- updated CMS, plugins and themes, and unused plugins removed;
- strong admin passwords, two-factor authentication and role-based access;
- form submissions not left sitting unencrypted in email inboxes or plugin databases; and
- regular, tested backups.
WordPress sites are a frequent target, so start there (read our WordPress security guide). If you’d rather hand it over, our website development team can do it for you.
9. Prepare a breach response plan
Section 23 requires controllers to notify the DPA of personal data breaches in the form and timeframe set by rules. The DPA’s draft breach notification rules propose:
- notifying the Authority within 72 hours of becoming aware, unless the breach is unlikely to create risk;
- notifying affected people at the same time where the risk is high; and
- keeping a written record of every breach, confirmed or suspected.
The rules are still a draft, but 72 hours is short. Decide now who investigates, who decides, and who contacts the DPA.
10. Check whether you need a Data Protection Officer
Under section 20, you must appoint a Data Protection Officer (DPO) if you’re a public authority, or if your core activities involve regular and systematic monitoring of people, large-scale processing of special categories of data, or processing that risks harm to people’s rights. The DPA’s draft DPO regulations list scale factors such as processing data on 25,000 or more people. The 2025 amendment confirms a DPO can be an outside provider. If you appoint one, publish their contact details on your website and give them to the DPA.
This matters most in sectors that handle sensitive data, including insurance and finance, healthcare and education.
11. Take extra care with children’s and sensitive data
The Act treats data about a child (anyone under 16) as a special category, alongside health, biometric, genetic, religious, political and similar data. Special categories need stronger justification, and consent for a child must come from a parent or guardian. Schools, tuition providers and education websites with enrolment or inquiry forms should review these first.
12. Document it all in a Data Protection Management Programme
Section 12 requires a Data Protection Management Programme: internal controls and records that show you comply. For a website, keep:
- a register of what data each form and tool collects, why, its lawful basis, where it’s stored and how long you keep it;
- your processor contracts;
- your consent records;
- your security measures;
- your breach log; and
- a process for handling complaints and data requests.
Where processing involves systematic profiling or monitoring, section 24 also requires a data protection impact assessment before you start, kept ready to give the DPA on request.
What are the penalties under Sri Lanka’s PDPA?
The PDPA’s fines are tied to the DPA’s directives. If the DPA finds you are not complying, it can direct you to take specific steps. Under section 38 (Part VII), failing to follow a directive can bring an administrative penalty of up to LKR 10 million for each non-compliance, and twice the previous amount for each repeat. When setting the amount, section 39 lets the DPA consider:
- how serious the breach was and how long it lasted;
- what you did to limit the damage;
- how well you cooperated; and
- whether you had broken the rules before.
Two caveats keep this accurate:
- Part VII had no start date as of October 2026. Gazette 2498/16 brings Parts I and III into operation, but not the penalty provisions.
- The cost isn’t only fines. Once Part I applies, non-compliance can lead to DPA inquiries and directives, contract problems with clients who must vet their suppliers, and lost customer trust if a breach becomes public.
The businesses that prepare now are the ones that won’t be scrambling when the remaining parts are switched on.
A 12-week PDPA plan for your website
With about 12 weeks until 1 January 2027, this order gets the highest-risk work done first.
October: find out what you collect
- List every form, plugin, chat widget, pixel and integration on your site, and what personal data each one collects.
- Note where each one stores data and which provider is involved, including whether it’s outside Sri Lanka.
- Decide whether you need a DPO, and who owns PDPA compliance internally.
November: fix the website
- Remove form fields you don’t need.
- Add proper consent tick boxes, and a cookie banner if you rely on consent for analytics or ads.
- Publish the rewritten privacy notice and link it from every form.
- Patch, harden and back up the site; switch on two-factor authentication for every admin.
December: paperwork and processes
- Collect data processing terms from every provider.
- Write a one-page breach response plan with named people and the DPA’s contact route.
- Set up a simple process for data requests (an email address and a log), ready for when Part II starts.
- Put it all into your Data Protection Management Programme file.
- Book a review for when the DPA finalises its draft rules or sets start dates for Parts II, IV and VII.
Sri Lanka PDPA: frequently asked questions
When does Sri Lanka’s PDPA come into force?
The core compliance provisions start on 1 January 2027. Gazette Extraordinary No. 2498/16 brings Section 2, Section 3, Part I and Part III into operation on that date. Parts II (data subject rights), IV (marketing messages) and VII (penalties) need separate Gazette orders, which hadn’t been issued as of October 2026.
Does the PDPA apply to small businesses?
Yes. The Act has no size threshold. If you process personal data in Sri Lanka, are based in Sri Lanka, or offer goods or services to people in Sri Lanka, it applies to you. Some duties, such as appointing a DPO, only apply above certain risk or scale levels.
Does the PDPA apply to companies outside Sri Lanka?
Yes, if they offer goods or services to people in Sri Lanka or monitor their behaviour (section 2). Foreign hotel groups, online stores and software companies with Sri Lankan customers are covered.
Do I need a cookie banner under the PDPA?
The PDPA has no cookie-specific rule. But analytics and advertising tools that track individual visitors process personal data and need a lawful basis. If that basis is consent, a banner with a real “Reject” option is the practical way to collect it.
Can I still host my website outside Sri Lanka?
Yes. Section 26, as amended in 2025, allows transfers outside Sri Lanka when you comply with the Act and use a safeguard the DPA specifies, or when an exception applies, such as explicit consent or necessity for a contract. The DPA’s directive on those safeguards was still a draft as of October 2026.
What are the fines under the PDPA?
Up to LKR 10 million for each failure to comply with a DPA directive, and twice the previous amount for repeat failures (section 38). The penalty provisions in Part VII had not been given a start date as of October 2026.
How fast must I report a data breach?
The DPA’s draft rules propose notifying the Authority within 72 hours of becoming aware of a breach, and notifying affected people at the same time where the risk is high. The rules were still a draft as of October 2026.
Is the PDPA the same as the GDPR?
No, though it’s similar in structure. Key differences: the PDPA defines a child as under 16, sets its own response period for data requests (one month, extendable to three), and its cross-border rules rely on instruments specified by Sri Lanka’s DPA rather than EU adequacy decisions. A GDPR-compliant site is a good starting point, but it still needs a Sri Lanka review.
Get a free PDPA website check
Most of the work in this checklist happens on your website: forms, consent, tracking, hosting and security. Microweb Global builds and maintains websites for Sri Lankan businesses. We can audit your site against these 12 points and fix what’s missing before 1 January 2027.
Book a free PDPA website check →
This article is general information about the Personal Data Protection Act, No. 9 of 2022, as amended, and reflects official sources available on 8 October 2026. It is not legal advice. Several DPA rules referred to here are still drafts and may change. Speak to a qualified lawyer about your organisation’s specific obligations.
Sources
- Personal Data Protection Act, No. 9 of 2022, Data Protection Authority of Sri Lanka
- Personal Data Protection (Amendment) Act, No. 22 of 2025, Data Protection Authority of Sri Lanka
- Gazette Extraordinary No. 2498/16, 22 July 2026
- DPA downloads: Acts, Gazettes, circulars and draft rules
- Draft Rules on Personal Data Breach Notifications, DPA, October 2024
- Draft Regulations on the Appointment of the Data Protection Officer, DPA, October 2024
- Draft Directive on Instruments for Processing Personal Data Outside Sri Lanka, DPA, October 2024
- Data protection compliance regime takes effect on 1 Jan. 2027, Daily FT, 10 August 2026