The Data Protection Authority (DPA) has issued a new directive requiring public institutions to strengthen safeguards governing the collection, use, storage, and transfer of personal information.
Personal Data Protection Circular No.01/2026, issued in August, establishes a compliance framework for the public sector under the Personal Data Protection Act (PDPA) No.9 of 2022, as amended by Act No.22 of 2025.
The circular, signed by DPA Chairman Rajeeva Bandaranaike, applies to ministries, Government departments, provincial administrations, commissions, district secretariats, public corporations, statutory bodies, and State-Owned Enterprises.
It replaces Personal Data Protection Circular No.01/2024 and directs public institutions to issue the necessary internal instructions immediately to begin compliance activities.
The legislation regulates the processing of information that can directly or indirectly identify an individual. Its protections apply to the personal data of both citizens and non-citizens.
A central requirement of the circular is the appointment of Data Protection Officers (DPOs). Under Section 20 of the act, every ministry and Government department processing personal data must designate an officer to oversee compliance and serve as its principal contact with the DPA.
Institutions must publish the contact details of their DPOs on their official websites and provide the officers’ names and contact information to the authority. They must also give the appointed officers sufficient resources and authority to implement effective data protection management programmes.
The amended legal framework allows the public sector to adopt a ‘cloud-first’ strategy and use global cloud infrastructure for data storage and processing.
Public institutions may also transfer personal data outside Sri Lanka, provided legally binding safeguards are in place to ensure that the information receives protection equivalent to that available domestically.
The authority has directed public institutions to conduct audits identifying the personal information they hold, its sources, and the purposes for which it is processed.
They must also assess gaps between their existing practices and the requirements of the law, introduce internal data-protection policies, and train employees on their legal responsibilities.
The DPA said that the act would be implemented in phases. Although the authority was established in 2023, it will begin investigating complaints and hearing appeals after the relevant provisions are brought into operation by the Minister of Technology.