A matter in this discipline?
A partner in this practice will respond within one business day. The information you provide at intake is held in confidence.
Briefing · 10 minSri Lanka's Personal Data Protection Act is now fully in force, and the Data Protection Authority's early enforcement pattern gives in-house counsel a clear picture of what compliance requires in practice.
The Act's principal obligations will be familiar from other modern regimes: lawful bases for processing, purpose limitation, data-subject rights, breach notification, and — for controllers meeting the thresholds — the appointment of a data protection officer.
The provisions with the most operational bite are those on cross-border transfer. Transfers require an adequacy determination, appropriate safeguards, or a statutory derogation; groups that centralise HR or customer data abroad should map those flows and document the basis for each.
Processing agreements deserve early attention. Controllers remain responsible for their processors, and the Act expects that responsibility to be contracted for. Standard vendor terms drafted for other jurisdictions rarely satisfy the Sri Lankan provisions without amendment.
The firm's IT practice advises controllers and processors on PDPA compliance programmes, data-processing agreements, breach response, and dealings with the Authority.
Further briefings and notes from the firm’s lawyers.
All insights →
PublicationA collection of current laws and regulations frequently sought by the business community and civil society.
Briefing · 12 minHow the second edition of FIDIC's Red, Yellow, and Silver Books is landing in Sri Lankan procurement practice.
GuideA working guide for investors, developers, and entrepreneurs entering the Sri Lankan market.
A partner in this practice will respond within one business day. The information you provide at intake is held in confidence.