Personal Data Protection Act, breach notification duties
Personal Data Protection Act, No. 9 of 2022, as amended by Act No. 22 of 2025, s.23
A citation is an address, not a summary. The first part names the law; what follows narrows it to the exact section, article or paragraph.
What follows is LexLint's own research summary of this law, not legal advice.
In force since 18 March 2025.
A breach notification rule binding public and private bodies.
As of 29 August 2026.
What it requires
- An app that suffers a personal data breach in Sri Lanka, including one involving a biometric identifier, must notify the Data Protection Authority in the form, manner, and time a rule made under the Act determines; whether and when the affected individual must also be told is set by a rule not yet located.
What this law does
Drafted with AI from the cited sources under the direction of UnGovr staff. UnGovr holds editorial responsibility for this page.
Section 23(1) requires a controller to notify the Authority of a personal data breach, in the form, manner, and within the time rules made under the Act determine. Section 23(2) requires the Authority to set, by rule, the circumstances triggering notice to the Authority, the circumstances triggering notice to the affected data subject, and the form and content of the notification.
The duty to notify the Authority is itself currently in force; the threshold, timeline, and whether the affected individual must be told are deferred entirely to rules made under section 52, which are not located.
When LexLint raises it
crawls_webtrains_modelsdeploys_chatbotprocesses_biometricsprocesses_voice
Read the law
official statute text, Parliament of Sri Lanka
Every line above is drawn from the primary source linked here, read on the date shown. This is a research summary, not legal advice.