FB pixel

Sri Lanka nods Personal Data Protection Act amendments

Categories Biometrics News  |  ID for All
Sri Lanka nods Personal Data Protection Act amendments
 

The amendments to Sri Lanka’s Personal Data Protection Act (PDPA) mark a major step towards establishing a world-class, innovation-friendly regulatory environment for personal data protection, Dr. Hans Wijayasuriya, chief adviser to the President on Digital Economy, said.

“In particular, the amendments allow for greater flexibility in cross-border data flows, empowering institutions to make judgment-based decisions on where and how data is stored and processed. For example, organizations can now choose between resident, sovereign or public cloud facilities based on the sensitivity and security classification of data,” Dr. Wijayasuriya told Biometric Update.

This means that public and private sector data controllers can make case-specific choices with respect to storage and computing, balancing data sensitivity, storage and computing costs, and access to AI capabilities. Specifically on AI, the revised PDPA clarifies the permissible use of cloud platforms for processing, strengthens constitutional rights to challenge bias or discrimination, and defines procedures for seeking remedies against automated decision-making, he clarified.

Other notable enhancements include provisions for the Regulator to issue sector-specific guidelines, define timelines for responding to subject requests, and adopt a phased implementation approach to enhance the operational efficacy of the Data Protection Authority (DPA).

Following final approval of the PDPA as amended, the immediate priority is to establish the DPA as a fully-fledged regulator with expert skills across data stewardship and governance, policy, regulation, and enforcement, Dr Wijayasuriya said. An announcement will be made shortly, seeking applications for a Director General and Senior Management team.

The law will become fully operational once the DPA is staffed and functional. As seen in jurisdictions such as the EU, Malaysia, Singapore, and the Philippines, PDPA frameworks evolve.

Alongside building awareness and compliance in the private sector, the Government of Sri Lanka is committed to ensuring that Ministries, Departments, and Local Authorities are equipped with the necessary capacity and training to implement privacy and data protection measures in full compliance with the PDPA.

The PDPA is South Asia’s first comprehensive data protection legislation designed to safeguard citizens’ data rights and foster digital economy growth.

Addressing the issue of security, Dr. Wijayasuriya noted that fundamental security and control measures come first and that this can be subject to a proportionate assessment of risk and granular data in use.

DPA Acting Director General Waruna Sri Dhanapala explained that for government sector personnel data management, cross-border data flows will have some sort of freedom. “With this Act, there will be more choices for public sector personnel data controllers to procure cost-effective technological solutions.”

Related Posts

Article Topics

 |   |   |   |   |   | 

Latest Biometrics News

 

AI deepfakes push biometric industry toward measurable assurance

The rise of AI-generated deepfakes and injection attacks is reshaping how organizations evaluate biometric security systems, pushing the industry toward…

 

Security, ruggedness key for reliable biometric physical access control tools

A recent webinar from Biometric Update and Goode Intelligence opens up the hood on the 2026 Biometric Physical Access Control…

 

Trident pivots to multi‑vertical holding company focused on sovereign digital infrastructure

Trident Digital Tech Holdings Ltd. is overhauling its corporate structure to strengthen focus on its offerings for national digital economies….

 

South Africa Home Affairs seeks $828M budget for digital ID, biometric visa projects

South Africa’s Department of Home Affairs has tabled a budget of 13.8 billion Rand (about US$828 million) in parliament for…

 

NIST biometric age estimation update show demographic, accuracy gains

Demographic disparities and mean error rates are falling among the newest age estimation and verification algorithms submitted to the U.S.’…

 

Identity verification becomes core compliance infrastructure across regulated sectors

Identity verification is increasingly becoming embedded operational infrastructure across regulated industries as tighter AML, KYC and fraud-prevention requirements push organizations…

Comments

Leave a Reply

This site uses Akismet to reduce spam. Learn how your comment data is processed.

Biometric Market Analysis and Buyer's Guides

DIGITAL ID for ALL NEWS

Featured Company

ID for ALL FEATURE REPORTS

BIOMETRICS WHITE PAPERS

BIOMETRICS EVENTS

EXPLAINING BIOMETRICS