AI Regulation Tracker / Commencement order
Sri Lanka Just Put a Date on the Part of Its Data Law That Reaches Profiling
Gazette Extraordinary 2498/16 appoints January 1, 2027 for Section 2, Section 3, Part I and Part III of the Personal Data Protection Act. That package carries the extraterritorial scope clause and the impact assessment duty for profiling.
Bottom line. An Order made by President Anura Kumara Dissanayake under Section 1(3) of the Personal Data Protection Act, read with Article 44(3) of the Constitution, and published in Gazette Extraordinary No. 2498/16 on July 22, 2026, appoints January 1, 2027 as the date Section 2, Section 3, Part I and Part III of the Act come into operation.
Who this affects. Controllers and processors caught by Section 2(1), which the Order expressly commences. That includes entities with no Sri Lankan establishment which offer goods or services to data subjects in Sri Lanka, or which specifically monitor their behaviour including profiling.
Effective date. January 1, 2027 for the named provisions. The Order names neither Part II, on rights of data subjects, nor Part VII, on penalties.
What changed. The Personal Data Protection (Amendment) Act No. 22 of 2025 substituted Section 1(3) and repealed the Act's earlier fixed deadlines. The substituted Section 1(3) lets the remaining provisions come into operation on dates appointed by Order in the Gazette, and this Order appoints January 1, 2027 for the named provisions.
Anthony's analysis. The interesting part is which provisions were chosen. Section 24's impact assessment duty and Section 12's management programme sit inside the commenced Parts, so the obligations that bite on profiling and monitoring switch on while the penalties Part does not.
Primary sources. Gazette Extraordinary No. 2498/16 and the Act.
Key facts
- Jurisdiction
- Sri Lanka
- Instrument
- Order under Section 1(3), Personal Data Protection Act No. 9 of 2022
- Published
- Gazette Extraordinary No. 2498/16, July 22, 2026 (Order dated Colombo, July 13, 2026)
- Made by
- President Anura Kumara Dissanayake, under Section 1(3) read with Article 44(3) of the Constitution
- Commences
- Section 2, Section 3, Part I and Part III, on January 1, 2027
- Not named in the Order
- Part II (rights of data subjects) and Part VII (penalties)
- Enabling power
- Section 1(3) as substituted by the Personal Data Protection (Amendment) Act No. 22 of 2025
- Enabling instrument
- Gazette Extraordinary No. 2498/16, L.D.B. 3/2023
Regulatory briefing
- Instrument
- Order under subsection (3) of Section 1 of the Personal Data Protection Act, No. 9 of 2022 (L.D.B. 3/2023)
- Authority
- President Anura Kumara Dissanayake, under Section 1(3) read with Article 44(3) of the Constitution
- Jurisdiction
- Sri Lanka, with extraterritorial reach under Section 2(1)
- Status
- The Order is in force. The provisions it appoints take effect January 1, 2027
- Bindingness
- Binding law
- Effective date
- January 1, 2027 for Section 2, Section 3, Part I and Part III
- Primary source
- Gazette Extraordinary No. 2498/16, July 22, 2026
What the Order actually does
It is one paragraph, and it is worth reading in full because the list of provisions is the whole story:
BY virtue of the powers vested in me by Sub-section (3) of Section 1 of the Personal Data Protection Act, No. 9 of 2022, read with paragraph (3) of Article 44 of the Constitution of the Democratic Socialist Republic of Sri Lanka, I, President Anura Kumara Dissanayake, do by this Order, appoint January 01st, 2027 as the date on which the provisions of Section 2, Section 3, Part I (Processing of Personnel Data) and part III (Controllers and Processors) of the aforesaid Act shall come into operation.Gazette Extraordinary No. 2498/16, July 22, 2026. The spelling of Personnel and the lower-case part III appear thus in the original; the Act's own Part I heading reads Processing of Personal Data
Four things are named. Section 2, which sets the Act's application and its reach beyond Sri Lanka. Section 3. Part I, on processing. Part III, on controllers and processors. Two significant things are not named: Part II, which carries the rights of data subjects, and Part VII, which carries penalties.
I want to be careful about what that silence means. The Order does not say those Parts are delayed or abandoned. It simply does not appoint a date for them, and no commencement date for either appears in the national sources reviewed as of August 3, 2026. A separate Order could appoint one at any time.
Why the commencement power looks like this
The Act was passed in 2022 with fixed statutory deadlines built into Section 1. Those are gone. The Personal Data Protection (Amendment) Act No. 22 of 2025 repealed subsections (4) and (5) and substituted a new Section 1(3) providing that the rest of the Act comes into operation on such date or dates as the Minister may appoint by Order published in the Gazette.
So Sri Lanka replaced a legislated timetable with an appointed one. For anyone tracking the jurisdiction, that is the mechanism to watch: commencement now arrives by gazette Order, in whatever slices are appointed, rather than on a date you can read off the statute.
The provisions that matter for AI work
Two duties inside the commenced Parts are the reason this belongs on an AI regulation tracker at all.
Section 12(1) requires a controller to implement a Data Protection Management Programme. That is a governance obligation rather than a technical one, and it is the sort of thing that gets documented late and badly. Note that the 2025 Amendment repealed Section 12(2), so read the current text rather than the 2022 print.
Section 24 is the sharper one. It requires a data protection impact assessment before processing where that processing involves, in the Act's words, a systematic and extensive evaluation of personal data or special categories of personal data including profiling, or a systematic monitoring of publicly accessible areas or telecommunication networks. If you run scoring, segmentation, behavioural analytics or any model that evaluates people at scale, that language is aimed at you, and the assessment has to happen before the processing.
Neither provision mentions artificial intelligence. Sri Lanka has no AI-specific statute. But an assessment duty triggered by systematic evaluation and profiling is, in practice, an AI governance duty for most firms that have one.
Whether this reaches a US company
Often, yes, and that is the part most readers will underestimate. Section 2 is one of the provisions this Order commences, and Section 2(1) is where the extraterritorial hooks live.
Section 2(1)(b)(iii) reaches a controller or processor that offers goods or services to data subjects in Sri Lanka, including offerings specifically targeted at them. Section 2(1)(b)(iv) reaches one that specifically monitors the behaviour of data subjects in Sri Lanka, including profiling with the intention of making decisions about that behaviour, so far as the behaviour takes place in Sri Lanka.
Read those together and the exposed population is wider than firms with a Colombo office. A US company running ad targeting or behavioural analytics that reaches Sri Lankan users can be in scope with no local establishment at all. So can a business with delivery or BPO operations processing personal data there.
The practical work between now and January is unglamorous and takes longer than people expect. Establish whether Section 2(1) catches you. If it does, identify the processing that trips Section 24 and get the assessments done before the date rather than after, because the duty is expressly a pre-processing one. Stand up the Section 12 programme. And do not let the absent penalties Part become the reason nobody funds the work, because the obligations commence whether or not the sanctions Part follows them.
| Provision | Subject | Named in this Order? |
|---|---|---|
| Section 2 | Application, including extraterritorial reach | Yes, from January 1, 2027 |
| Section 3 | As enacted | Yes, from January 1, 2027 |
| Part I | Processing of personal data | Yes, from January 1, 2027 |
| Part III | Controllers and processors | Yes, from January 1, 2027 |
| Part II | Rights of data subjects | Not named in this Order |
| Part VII | Penalties | Not named in this Order |
Sri Lanka has fixed January 1, 2027 for Section 2, Section 3, Part I and Part III of the Personal Data Protection Act. The commenced package carries both the extraterritorial application clause and the Section 24 duty to run an impact assessment before systematic evaluation or profiling, so firms with no Sri Lankan establishment can be caught. Part II rights and Part VII penalties are not named in this Order. Check Section 2(1) exposure now, and complete Section 24 assessments before the date, not after.
- Primary source
- Gazette of the Democratic Socialist Republic of Sri Lanka, Extraordinary No. 2498/16, July 22, 2026 (Order dated Colombo, July 13, 2026, L.D.B. 3/2023), and the Personal Data Protection Act, No. 9 of 2022 for Sections 2, 12 and 24 and the Part headings.
- Corroborating
- Personal Data Protection (Amendment) Act, No. 22 of 2025, which substituted Section 1(3) and repealed the former subsections (4) and (5).
- How to verify
- Open the gazette PDF and read the single operative paragraph: it names Section 2, Section 3, Part I and Part III and appoints January 1, 2027. Then open the Act and read Section 2(1)(b)(iii) and (iv) for the extraterritorial hooks and Section 24(1) for the pre-processing assessment trigger.
Last verified: August 3, 2026 against the primary sources listed above.
Frequently asked
What did Sri Lanka commence on July 22, 2026?
Nothing commenced on that date. The Order published in Gazette Extraordinary No. 2498/16 on July 22, 2026, and dated July 13, 2026, appoints January 1, 2027 as the date on which Section 2, Section 3, Part I and Part III of the Personal Data Protection Act No. 9 of 2022 come into operation.
Is the whole Personal Data Protection Act in force from January 2027?
No. This Order names only Section 2, Section 3, Part I and Part III. Part II, on rights of data subjects, and Part VII, on penalties, are not named in it, and no commencement date for either appears in the national sources reviewed as of August 3, 2026. A further Order could appoint one.
Does this apply to a company with no presence in Sri Lanka?
It can. Section 2, which the Order commences, extends the Act to controllers and processors that offer goods or services to data subjects in Sri Lanka, and to those that specifically monitor the behaviour of data subjects in Sri Lanka including profiling intended to inform decisions about that behaviour, so far as the behaviour takes place there. No local establishment is required.
Is this an AI law?
No. Sri Lanka has no AI-specific statute, and the Act does not mention artificial intelligence. It matters for AI work because Section 24 requires an impact assessment before processing that involves systematic and extensive evaluation of personal data including profiling, or systematic monitoring of publicly accessible areas or telecommunication networks, and Section 12 requires a data protection management programme. Both sit in the Parts this Order commences.