The Data Protection Authority has released a new circular to guide government institutions through implementation of amended personal data protection laws, with core provisions set to take effect on 1 January 2027.
Sri Lanka's Data Protection Authority has issued Personal Data Protection Circular No. 01/2026, replacing an earlier version from September 2024. The new circular provides implementation guidance to public sector entities including government ministries, departments, local authorities, and state-owned corporations as they prepare for the Personal Data Protection Act No. 9 of 2022, as amended by Act No. 22 of 2025.
Following a presidential order issued on 22 July 2026, critical sections of the law are scheduled to become operational on 1 January 2027. Specifically, Sections 2 and 3, along with Parts I and III governing personal data processing and the roles of data controllers and processors, will come into force on that date. These provisions establish the foundational legal framework that public authorities must follow when handling personal data.
The circular outlines a series of preparatory steps institutions should undertake during the transition period. These include establishing governance structures, appointing Data Protection Officers where necessary, developing Data Protection Management Programmes, conducting audits and gap assessments, and performing data protection impact assessments. Public sector organisations are also encouraged to review and strengthen their existing policies, enhance staff training, and build institutional capacity for compliance.
The Authority has urged all public sector institutions to begin implementation activities promptly to ensure readiness before the deadline. The Data Protection Authority indicated it will issue additional implementing rules, regulations, directives and guidelines to support effective execution of Sri Lanka's data protection framework across the public sector.









