27/07/2026
𝗜𝘀 𝗬𝗼𝘂𝗿 𝗢𝗿𝗴𝗮𝗻𝗶𝘀𝗮𝘁𝗶𝗼𝗻 𝗥𝗲𝗮𝗱𝘆 𝗳𝗼𝗿 𝗣𝗗𝗣𝗔 𝗖𝗼𝗺𝗽𝗹𝗶𝗮𝗻𝗰𝗲 𝗯𝘆 𝟭𝘀𝘁 𝗝𝗮𝗻𝘂𝗮𝗿𝘆 𝟮𝟬𝟮𝟳?
Gazette Extraordinary No. 2498/16, published on 22nd July 2026, makes effective from January 1st 2027 the implementation of Sri Lanka’s Personal Data Protection Act, No. 9 of 2022 as amended ( PDPA) to be fully operational in scope, with the exception of only Part IV dealing with the ‘Use of Personal Data to Disseminate Solicited Messages’.
If your business processes data of employees, customers, suppliers, service providers, patients, students, job applicants or if you are a BPO provider of services such as payroll processing services, call center service or claim processing services the PDPA framework is likely to impose obligations on you.
Now is the time to ask the right questions:
1. Do we know what data is identified in law as ‘personal data’?
2. Does our organisation process ‘personal data’?
3. Are we ready to inform our data subjects what their rights are vis-à-vis our organisation?
4. Do we have appropriate policies and procedures for handling personal data?
5. Is personal data adequately protected from unauthorised access or disclosure?
6. Does the organisation need to appoint a Data Protection Officer (DPO)?
7. Have our employees been trained in their duties and responsibilities?
8. If a data breach occurred tomorrow, would we know what steps to take?
9. What is our liability for non-compliance with the PDPA?
Businesses that begin preparing today will be able to gain a competitive advantage by being better prepared to meet legal obligations, strengthening stakeholder confidence and minimising business and other risks.
Data protection is not an IT issue. It is a governance, legal and business imperative that deserves the attention of every BOD and of management at the highest levels.
At D. L. & F. De Saram, we will be sharing practical guidance over the coming months to help businesses understand the requirements and prepare for compliance readiness for 1st January 2027.