Law / Sri Lanka

Sri Lanka

9 of 10 named instruments researched to a stage, across three of the six areas of law we track: 8 in force and 1 enacted but not yet in force. As of 16 September 2026.

  1. AI law none researched
  2. Privacy law 6
  3. Scraping law 2
  4. Cybersecurity law none researched
  5. Age gating law none researched
  6. News aggregation law 1

in forceenacted but not yet in forceproposedrepealed, withdrawn or blocked

Drafted with AI from the cited sources under the direction of UnGovr staff. UnGovr holds editorial responsibility for this page.

Privacy law6 instruments, 6 in force

Research summary (165 words)

Sri Lanka's Personal Data Protection Act, No. 9 of 2022 (PDPA) was certified by the Speaker 19 March 2022 and amended by the Personal Data Protection (Amendment) Act, No. 22 of 2025, certified 30 October 2025.

Commencement is phased by Part: Part V (the Data Protection Authority itself) began operation in July 2023; Parts VI, VIII, IX and X on 1 December 2023; and Parts I, II, III and VII, the entire substantive core (processing of personal data, data-subject rights, controller/processor duties, and penalties), on 18 March 2025.

Only Part IV (unsolicited-message provisions) remains unstarted, and the 2025 Amendment Act removed the fixed outer deadline for it entirely, leaving its commencement open-ended and Minister-discretionary. So every lawful-basis, special-category, data-subject-rights, cross-border-transfer, breach-notification, and enforcement duty described here has been in force since 18 March 2025.

Biometric data is an express special category, defined technology-neutrally to reach a voice-derived identifier by its own terms even though its illustrative list names only facial images, fingerprint, and iris data.

Breach notification

Personal Data Protection Act, breach notification duties

Personal Data Protection Act, No. 9 of 2022, as amended by Act No. 22 of 2025, s.23official statute text, Parliament of Sri Lanka

In force since 18 March 2025. Binds public and private bodies.

What this law does

Section 23(1) requires a controller to notify the Authority of a personal data breach, in the form, manner, and within the time rules made under the Act determine. Section 23(2) requires the Authority to set, by rule, the circumstances triggering notice to the Authority, the circumstances triggering notice to the affected data subject, and the form and content of the notification.

The duty to notify the Authority is itself currently in force; the threshold, timeline, and whether the affected individual must be told are deferred entirely to rules made under section 52, which are not located.

What it requires

Comprehensive regime

Personal Data Protection Act, comprehensive regime and lawful basis

Personal Data Protection Act, No. 9 of 2022, as amended by Act No. 22 of 2025, Schedule I, ss.5, 18(1), 20-25official statute text, Parliament of Sri Lanka

In force since 18 March 2025. Binds public and private bodies.

What this law does

Lawful basis, referenced by s.5 against Schedule I, follows a General Data Protection Regulation (GDPR) Article 6 shape: consent, contract necessity, legal obligation, vital interests, a public-interest task, or legitimate interest subject to a balancing test. Controller and processor duties are allocated at ss.20-25, with processors bound by written instructions and sub-processor flow-down duties.

Section 18(1) gives every data subject the right to request review of a decision based solely on automated processing that has created or is likely to create an irreversible and continuous impact on their rights and freedoms, subject to listed exceptions (authorized by law, authorized by the Authority, based on consent, or contract necessity). In force since 18 March 2025.

What it requires

Cross border transfer

Personal Data Protection Act, cross-border transfer of personal data

Personal Data Protection Act, No. 9 of 2022, as amended by Act No. 22 of 2025, s.26official statute text, Parliament of Sri Lanka

In force since 18 March 2025. Binds public and private bodies.

What this law does

For a public authority, personal data shall be processed only in Sri Lanka and not in a third country, unless the Authority classifies categories permitted for third-country processing pursuant to a Ministerial adequacy decision, reviewed at least every two years (s.26(1)-(2)), a default-localization rule.

For a private controller or processor, transfer is permitted to a country covered by an adequacy decision, or elsewhere only with appropriate safeguards specified by the Authority (s.26(4)), or, absent both, only under listed derogations: explicit informed consent after risk disclosure, contract necessity, legal-claims necessity, public interest, or a life-or-safety emergency (s.26(5)).

What it requires

Data subject rights

Personal Data Protection Act, data subject rights

Personal Data Protection Act, No. 9 of 2022, as amended by Act No. 22 of 2025, ss.13-19official statute text, Parliament of Sri Lanka, as amended

In force since 18 March 2025. Binds public and private bodies.

What this law does

Data subjects have rights of access (s.13), withdrawal of consent and cessation of further processing (s.14), rectification and completion (s.15), erasure (s.16), and (s.18) review of a decision based solely on automated processing. Section 17, amended in 2025, requires the controller to respond in writing within one month of a written request under ss.13-16 or 18, extendable by up to two further months with notice given before the original month expires.

Section 19, also amended in 2025, gives a right of appeal to the Authority against a controller's refusal on any of these grounds, with the Authority empowered to determine lawfulness and to direct compensation under s.35(2)(c).

What it requires

Enforcement supervision

Personal Data Protection Act, Data Protection Authority and penalties

Personal Data Protection Act, No. 9 of 2022, as amended by Act No. 22 of 2025, ss.35, 38official statute text, Parliament of Sri Lanka

In force since 18 March 2025. Binds public and private bodies.

What this law does

The Data Protection Authority (Part V, operative since July 2023, with the Chairman and Board appointed October 2023) is a body corporate that may sue and be sued. Under section 35, on complaint or its own initiative, the Authority may investigate a controller or processor and, after a hearing, direct it to cease non-compliant processing, take corrective action, or pay compensation to an aggrieved person who has suffered harm, loss, or damage.

Failure to comply with a directive triggers a monetary penalty under section 38 of up to Rs 10,000,000 per non-compliance, doubling for each subsequent one, collected by the Authority (net of any compensation payable) and credited to the Consolidated Fund; unpaid penalties are recoverable via the Magistrate Court of Colombo.

No standalone civil right of action was found; the Authority's directive-and-compensation mechanism under section 35(2)(c) is the only individual remedy, and it is regulator-administered rather than a court claim the data subject brings directly. Sections 35 and 38 themselves entered into force 18 March 2025, alongside the rest of Parts I-III and VII.

What it requires

Sensitive categories

Personal Data Protection Act, special categories and biometric data

Personal Data Protection Act, No. 9 of 2022, as amended by Act No. 22 of 2025, s.56, Schedule IIofficial statute text, Parliament of Sri Lanka

In force since 18 March 2025. Binds public and private bodies.

What this law does

Biometric data is defined at s.56 as personal data resulting from specific technical processing relating to the physical, physiological or behavioral characteristics of a natural person, which allow or confirm unique identification, including facial images, dactyloscopic (fingerprint) data, or iris-related data. Biometric data used for unique identification is one of the enumerated special categories of personal data.

Schedule II conditions processing of a special category on the data subject's consent (or a parent or guardian's for a child) unless another written law prohibits it regardless of consent, employment or social-security or defined public-health necessity, emergency necessity, data manifestly made public by the data subject, legal-claims necessity, or public interest under a written law with safeguards.

The operative definition's technology-neutral "physical, physiological or behavioral characteristics" language reaches a voice-derived identifier on its own terms, though the illustrative list names only facial images, fingerprint, and iris data, not voice specifically.

What it requires

Scraping law2 instruments, 1 in force, 1 enacted but not yet in force

Research summary (243 words)

Sri Lanka has no scraping-specific statute, so general law governs each dimension separately.

The Computer Crime Act, No. 24 of 2007 criminalises unauthorised access, unauthorised modification, and dealing with unlawfully obtained data, with a bare "no lawful authority" test that carries no requirement of circumventing a security measure, so its reach over a public, unauthenticated page is broader on its face than a security-circumvention statute, though no reported Sri Lankan case has tested it against that fact pattern.

The Intellectual Property Act, No. 36 of 2003 gives Sri Lanka an American-style fair use defence (section 11), rather than a fair-dealing list, judged by the purpose and character of the use, the nature of the work, the amount used, and the effect on the work's market; the Act has no text-and-data-mining exception distinct from that general test.

A collection or compilation of data is protected under section 7 only where its selection, coordination, or arrangement is itself original, so Sri Lanka confers no sui generis database right for a compilation assembled through investment or effort alone. The Personal Data Protection Act, No. 9 of 2022, as amended, is researched under this corpus's privacy topic and reaches scraped personal data on the same terms described there.

No Sri Lankan statute or reported case addresses the legal weight of a robots.txt directive, an AI-training-specific rule, unfair competition or misappropriation doctrine distinct from these statutes, or the enforceability of a browsewrap or clickwrap term against a scraper.

Computer misuse

Computer Crime Act, unauthorised access, modification and dealing with unlawfully obtained data

Computer Crime Act, No. 24 of 2007, ss. 3-7Official Act text, Parliament of Sri Lanka, Internet Archive capture of the National ICT Agency's copy

archived copyRead from a public archive copy, not the publisher directly. The publisher does not serve this page to automated readers, so a direct fetch was not an option here; how we access sources. Archived February 9, 2026. Publisher's page: https://www.icta.lk/icta-assets/uploads/2016/03/ComputerCrimesActNo24of2007.pdf

Commencement not set. Binds public and private bodies.

What this law does

Section 3 makes it an offence to intentionally secure access to a computer or to information held in it, knowing or having reason to believe there is no lawful authority for that access; section 4 raises the same conduct to a second offence where it is done with intent to commit a further offence.

Neither section requires infringing a security measure or defeating any technical control, so the provision's reach over a public, unauthenticated page turns entirely on whether the accessor had lawful authority, a question no reported Sri Lankan decision has tested against a scraping fact pattern. Section 5 separately criminalises causing a computer to perform a function that the person knows or has reason to believe will result in unauthorised modification or damage.

Section 6 criminalises intentionally causing danger or imminent danger to national security, the national economy, or public order. Section 7 criminalises buying, receiving, retaining, selling, downloading, uploading, copying or otherwise dealing with information known or believed to have been obtained from a computer without lawful authority by another person.

The Act's own section 1 defers its commencement to a date the Minister appoints by Gazette Order; no notice of that Order has been located, only the deferral mechanism itself.

What it requires

Copyright and text and data mining (TDM)

Intellectual Property Act, fair use and compilations of data

Intellectual Property Act, No. 36 of 2003, ss. 7, 8(c), 11Official Act text, National Intellectual Property Office of Sri Lanka

In force. Binds public and private bodies.

What this law does

Section 11(1)-(2) gives Sri Lanka an American-style fair use defence: the fair use of a work for purposes such as criticism, comment, news reporting, teaching, scholarship or research is not an infringement, judged by the purpose and character of the use (including whether it is commercial), the nature of the work, the amount and substantiality of the portion used, and the effect on the potential market for or value of the work.

The Act has no text-and-data-mining exception distinct from this general fair use test, so training a model on scraped Sri Lankan-hosted text rests only on whether that training can be characterised as fair use under these four factors, a question no reported Sri Lankan decision has answered. Section 8(c) excludes "news of the day" from copyright protection altogether.

Section 7(1)(b) protects a collection of works or a collection of mere data (a database), in machine-readable or other form, as a work only where the collection is original by reason of the selection, coordination, or arrangement of its contents; the underlying data itself is not protected, and Sri Lanka confers no sui generis database right of the kind that protects a compilation assembled through investment or effort alone regardless of originality. Section 1 of the Act carries no commencement clause of its own, and none has been located elsewhere in the Act.

What it requires

News aggregation law1 instrument, 1 in force

Research summary (322 words)

Sri Lanka has no press-publisher neighbouring right and no mandatory platform-to-publisher bargaining code; the general copyright framework of the Intellectual Property Act, No. 36 of 2003 is the only law reaching an aggregator's reproduction of news content.

Section 12(3) permits, without the copyright owner's authorization, the reproduction of a short part of a published work in the form of a quotation, provided the reproduction is compatible with fair practice, does not exceed the extent justified by its purpose, and is accompanied by an indication of the source and the author's name.

Section 12(6)(b) separately permits, for the purpose of reporting current events, the reproduction and broadcasting or other communication to the public of short excerpts of a work seen or heard in the course of those events, to the extent justified by that purpose, and section 12(6)(a) permits a newspaper, periodical, broadcaster, or other communicator to reproduce an article on current economic, political or religious topics from another newspaper or periodical unless the owner has expressly reserved that right.

Section 8(c) separately excludes "news of the day" from copyright protection altogether, so the bare facts a wire report carries are never protected regardless of the quotation and current-events exceptions. No reported Sri Lankan decision applies any of these provisions to a systematic news aggregator as opposed to an individual quoting or excerpting a published work.

Neighbouring rights under the Act protect performers, producers of sound recordings, and broadcasting organisations, not print or online news publishers, so there is no publisher-side neighbouring right of the kind the European Union's Digital Single Market Directive Article 15 creates, and no statute or case law addresses whether a hyperlink is itself a communication to the public or whether framing or inline display changes the answer.

No hot-news or misappropriation doctrine distinct from ordinary copyright law exists, and the Act predates the concept of a machine-readable text-and-data-mining reservation, so no opt-out mechanism of that kind exists either.

Snippet reproduction

Intellectual Property Act, quotation and reporting of current events

Intellectual Property Act, No. 36 of 2003, ss. 8(c), 12(3), 12(6)Official Act text, National Intellectual Property Office of Sri Lanka

In force. Binds private bodies.

What this law does

Section 12(3) permits, without the copyright owner's authorization, the reproduction of a short part of a published work in the form of a quotation, provided the reproduction is compatible with fair practice, does not exceed the extent justified by its purpose, and is accompanied by an indication of the source and the author's name.

Section 12(6)(a) permits the reproduction, in a newspaper or periodical or by broadcast or other communication to the public, of an article on current economic, political or religious topics published in another newspaper or periodical, unless the copyright owner has expressly reserved that right on the copies or in connection with the broadcast.

Section 12(6)(b) permits, for the purpose of reporting current events, the reproduction and broadcasting or other communication to the public of short excerpts of a work seen or heard in the course of those events, to the extent justified by that purpose. Section 8(c) separately excludes "news of the day" from copyright protection altogether, so the underlying facts of a news report carry no protection independent of these exceptions.

None of these provisions carries a headline-length or short-extract cap distinct from the fair-practice and purpose-justified tests they state, and no reported Sri Lankan decision applies any of them to a systematic news aggregator rather than an individual quoting or excerpting a published work.

Note and primary source

This page covers the instruments LexLint has researched to a stage. Instruments named in the corpus but not yet researched are counted in the head and are not listed here. Every entry carries its own primary source on its note page. This is a research index, not legal advice.