Part of the AI Regulation News hub.
Sri Lanka's Data Protection Authority has issued a circular to ministries, provincial councils and state-owned enterprises replacing its 2024 public sector circular and restating what the amended PDPA requires of them
The circular is administrative, not legislative. Its most consequential line is an admission: the enforcement dates that would make most of the Act operative are still expected rather than fixed.
Bottom line: An administrative circular from the Data Protection Authority to public sector heads. It creates no obligation on its own; the obligations sit in the Personal Data Protection Act No. 9 of 2022 as amended by Act No. 22 of 2025. It supersedes and replaces Circular No. 01/2024 with effect from its date of issue.
Who this affects: Secretaries to ministries, chief secretaries of provinces, heads of departments, district secretaries, chairpersons of commissions, public corporations and statutory institutions, and chairmen of government companies and state-owned enterprises, plus the data protection officers they appoint.
Issue date: 7 August 2026. It supersedes Circular No. 01/2024 dated 13 September 2024. No compliance deadline is stated, because the enforcement dates are not yet set.
What changed: It replaces the 2024 circular, folds in the 2025 amendments, and tells public authorities that the enforcement dates originally set for 18 March 2025 have been amended and that new phased dates are expected to be announced.
Analysis: The circular asks institutions to build a compliance programme against a statute whose operative provisions are not yet in force. The Authority states plainly that it would only investigate complaints and hear appeals once the relevant governing provisions are brought into operation. Preparation is being requested; enforcement is not yet available.
Primary sources: Personal Data Protection Circular No. 01/2026 (PDF, English) · Data Protection Authority of Sri Lanka
- Instrument (EN)
- Personal Data Protection Circular No. 01/2026, Application of PDPA in the Public Sector
- Authority
- Data Protection Authority of Sri Lanka, signed by Chairman Rajeeva Bandaranaike
- Jurisdiction
- Sri Lanka
- Status
- Issued; supersedes Circular No. 01/2024 dated 13 September 2024
- Bindingness
- Administrative circular. The binding instrument is the PDPA No. 9 of 2022 as amended by Act No. 22 of 2025, whose enforcement dates are still to be announced.
- Issue date / next deadline
- 7 August 2026. No deadline stated; phased commencement dates are expected.
- Underlying statute
- Personal Data Protection Act No. 9 of 2022, enacted 19 March 2022, as amended by Act No. 22 of 2025
- Primary source
- https://www.dpa.gov.lk/media/DPA_Circular_012026_E.pdf
What the circular is
It is a letter, six pages including an annexure, addressed to the top of the Sri Lankan public service and copied to the Secretary to the President, the Secretary to the Prime Minister, the Secretary to the Cabinet of Ministers and the Secretary General of Parliament.
Its function is to restate the Personal Data Protection Act as it now stands after the 2025 amendment and to tell public authorities what that means for them. It closes by superseding and replacing Circular No. 01/2024 with effect from the date of issue.
The Authority also asks recipients to pass instructions down: heads are told to inform all institutions under their purview to issue relevant directives to initiate compliance activities, with an illustration of what those might be in Annexure 1.
The commencement problem, stated in the document
Part V of the Act, which establishes the Authority itself, was brought into operation on 17 July 2023 by order gazetted as Extraordinary Gazette No. 2341/59 dated 21 July 2023, so that a chairman and board could be appointed in August 2023.
The rest is not settled. The circular records that the enforcement dates originally set for 18 March 2025 under Extraordinary Gazette No. 2366/08 of 8 January 2024 have been amended, and that the 2025 amendment now allows different sections and parts to be brought into operation in phases, including Parts 1, 2, 3 and 7 on penalties, and sections 2 and 3.
The Authority tells public authorities to take note of the new enforcement dates, which it says are expected to be announced soon. It adds a parenthetical note that it would only investigate complaints and hear appeals once the relevant governing provisions are in operation.
What the 2025 amendment changed, on the Authority's account
The circular lists the amendment's key features. Public and private sector bodies can adopt a cloud-first strategy. The data protection officer function can be outsourced. Commencement can be phased. A new Section 51A lets the Authority issue guidelines under Section 12(2), including sectoral guidelines. Response timelines for data subject rights requests are clearer.
The change with the sharpest edge for automated systems is to Section 18. On the Authority's account, review of automated decisions was extended to cover instances where such a decision affects rights protected under the Constitution, and it names equality and non-discrimination as examples.
The circular also states there should not be a fee for a data subject request, though fees may be levied in exceptional circumstances on criteria to be specified by rules.
Cross-border transfer was loosened and conditioned at once. The amendment gives a controller discretion to engage in cross-border transfers, which the Authority describes as putting public authorities and the private sector on equal footing for global cloud infrastructure, but it also requires controllers and processors engaged in such transfers to adopt binding and enforceable instruments under Section 26(2). A draft directive already published by the Authority recognises contractual clauses, codes of conduct, certifications and transfer impact assessments among those instruments.
The data protection officer obligation
Section 20 of the Act requires every ministry or government department processing personal data to appoint a data protection officer. The circular calls this an important governance requirement under Part III of the Act.
Public corporations and government owned companies are treated differently. The circular notes they are not caught by the criteria in Section 20(1)(a), but says an obligation may nevertheless arise under Section 20(1)(b) and regulations made under it, and encourages such institutions to assess their own processing and decide whether appointment is required.
Two publication steps are specified. The appointed officer's contact details are to be published on the institution's official website and made readily accessible to data subjects, and the name and contact details are to be communicated to the Authority in the manner it specifies.
The functions listed track Section 20(5): advising on compliance obligations, advising on data protection impact assessments where applicable, serving as the contact point with the Authority, and promoting awareness and training inside the institution.
What public authorities are told to start doing
Annexure 1 sets out six initial steps: awareness across staff, a governance structure with a data protection officer and internal steering committee, a personal data audit recording what data is held and where it came from, a gap assessment with a remediation plan, policy implementation covering rights requests, retention, privacy notices and consent management, and ongoing training and capacity building.
The circular points to material already on the Authority's website: a draft regulation on the form and manner of carrying out a data protection impact assessment for specified processing activities, and draft rules on data breach notification.
It also signals engagement rather than enforcement as the near-term posture. The Authority says it expects to maintain regular dialogue with sectoral regulators in finance and banking, insurance, health, telecommunications, civil registration and tourism, and that advisory committees are expected to be formed. Awareness and advanced certificate programmes are promised for heads of departments, legal officers, data protection officers and ICT and human resource officers.
What we did not verify
We opened and read the full English text of Circular No. 01/2026 at dpa.gov.lk, all six pages, including Annexure 1 and the signature block.
We did not open the Personal Data Protection Act No. 9 of 2022, the Amendment Act No. 22 of 2025, Extraordinary Gazette No. 2341/59, Extraordinary Gazette No. 2366/08, the superseded Circular No. 01/2024, the draft DPIA regulation, the draft breach notification rules, or the draft cross-border directive. Every description of those instruments here is the circular's own characterisation.
We will not claim that any part of the PDPA beyond Part V is currently in force, because the circular itself says the new phased enforcement dates are still expected. We also note that the PDF's document properties carry a Word file name describing a final draft dated 29 June 2026; the circular as issued is dated 7 August 2026 and signed, and we treat that date as the instrument's own. We cannot say whether a Sinhala or Tamil version differs.
Two things transfer beyond Sri Lanka. First, a superseding circular is worth reading against the one it replaces, because what a regulator chooses to restate tells you what it thinks was misunderstood. Second, the automated decision point is easy to miss in a public sector document: on the Authority's account, the review right in Section 18 now reaches decisions touching constitutional rights such as equality and non-discrimination, which is the provision an agency deploying algorithmic eligibility or scoring should be reading first. None of it is enforceable until commencement is gazetted.
Source File
https://www.dpa.gov.lk/media/DPA_Circular_012026_E.pdf
Open the circular PDF at dpa.gov.lk and confirm the date of 7 August 2026 and reference DPA/Legal/01/02, paragraph 2.2 on the amended enforcement dates and the note about investigating complaints only once provisions are in operation, paragraph 1.3 on the Section 18 automated decision change, and paragraph 4.11 superseding Circular No. 01/2024.
This Circular shall supersede and replace Personal Data Protection Circular No. 01/2024 dated 13th September 2024, with effect from the date of issuance of this Circular. ยท Data Protection Authority of Sri Lanka, Circular No. 01/2026, 7 August 2026
FAQ
Is the PDPA in force in Sri Lanka now?
Only in part. The circular records that Part V, establishing the Authority, came into operation on 17 July 2023. It states that the dates originally set for 18 March 2025 were amended and that new phased enforcement dates are expected to be announced.
Can the Authority act on a complaint today?
The circular says it would only investigate complaints, hear appeals and similar matters once the relevant governing provisions are brought into operation.
Do state-owned enterprises have to appoint a data protection officer?
The circular says they are not caught by the criteria in Section 20(1)(a), but an obligation may arise under Section 20(1)(b) and regulations made under it. It encourages them to assess their processing and determine whether appointment is required.
What does it say about automated decisions?
On the Authority's account, the 2025 amendment extended the Section 18 review of automated decisions to include instances where such a decision affects rights protected under the Constitution, such as equality and non-discrimination.
Related briefings
Sponsored Training
Practical AI training for regulated professionals, built around verification, documentation and a defensible process. See the courses.