DPDP Act VS DPDP vs Sri Lanka PDPA
Comparison of India’s DPDP Act and Sri Lanka’s PDPA. Highlights differences in legal bases, data portability, and physical record scope. See what to fix.
Discuss this page with an LLM
What This Means In Practice
Use this table to brief your legal, product and marketing teams.
| Question | DPDP Direction | DPDP vs Sri Lanka PDPA Direction | Practical Impact |
|---|---|---|---|
| Can we process by default? | Often consent-first | Often depends on a different legal model | India flows may need earlier consent design. |
| Is a global privacy model enough? | No | Not always | Global privacy work does not map one-to-one to DPDP. |
| Are children protected differently? | Under 18 | Check local age thresholds | Indian child-user products need stricter review. |
| Is breach risk enough to trigger work? | Yes | Yes | Security, response and evidence matter in both systems. |
Three Questions To Ask Internally
- Are we copying a non-India privacy model into an Indian product?
- Do our consent flows work for Indian users?
- Which global privacy controls can be reused, and which must be redesigned for DPDP?
If you operate across India and another market, do not assume one privacy program covers both. Use the stricter flow where user trust and evidence matter most.
Want all of this handled, end to end? Sanctum is the all-in-one DPDP compliance programme behind this site: legal position, data map, gap analysis, implementation, tooling, training, readiness opinion, and breach cover under one accountable owner. How all-in-one DPDP compliance works or see the Sanctum programme.
Differences in Legal Grounds
India’s DPDP Act limits data processing to consent or specific “legitimate uses” such as medical emergencies, employment, or state functions. Sri Lanka’s PDPA follows a model similar to the EU GDPR, offering six distinct legal bases. This includes “legitimate interests” pursued by the controller or a third party. Businesses operating in both countries must recognize that processing activities allowed under legitimate interest in Sri Lanka may require explicit consent from users in India.
Data Portability and Subject Rights
Sri Lanka’s PDPA grants individuals the right to data portability, allowing users to request their data in a structured, machine-readable format to move to another provider. The Indian DPDP Act does not include a right to data portability. Companies managing data in both jurisdictions must implement technical export tools for their Sri Lankan operations that are not legally mandated for their Indian user base.
Material and Operational Scope
The PDPA applies to personal data processed within Sri Lanka, regardless of whether the data is digital or part of a manual filing system. India’s DPDP Act excludes non-digital data that remains in physical paper format. Additionally, the PDPA requires every controller to nominate a Data Protection Officer if they meet specific volume or risk thresholds. India restricts the mandatory DPO requirement to companies classified as Significant Data Fiduciaries by the central government.
Comparison Table
| Feature | DPDP Act 2023 (India) | PDPA No. 9 of 2022 (Sri Lanka) |
|---|---|---|
| Material Scope | Digital personal data only | Digital and manual filing systems |
| Legal Basis | Consent or Certain Legitimate Uses | 6 bases including Legitimate Interest |
| Data Portability | Not provided | Explicitly granted to subjects |
| Minors | Individuals under 18 | Individuals under 18 |
| DPO Requirement | Only for Significant Data Fiduciaries | Mandatory for public bodies and large processors |
| Cross-border | Restricted via government blacklist | Allowed via adequacy or approved clauses |
| Enforcement | Data Protection Board of India | Data Protection Authority of Sri Lanka |
This week
Review your internal data processing logs to identify any operations currently justified under “legitimate interests” for your Sri Lankan entity and determine if those same operations require a fresh consent notice under the Indian DPDP Act’s narrower “legitimate uses.”
FAQ
Q: Does the DPDP Act cover physical paper files like the PDPA? A: No. The DPDP Act only applies to personal data in digital form or data digitized after collection. Sri Lanka’s PDPA applies to both digital data and data contained in manual filing systems.
Q: Is a Data Protection Officer mandatory for all companies in both regions? A: No. In India, only Significant Data Fiduciaries must appoint a DPO. In Sri Lanka, all public bodies and any private entity processing high volumes of data or specific risk categories must appoint a DPO.
Q: How do cross-border transfer rules differ between India and Sri Lanka? A: India uses a blacklist model where the government can restrict transfers to specific countries. Sri Lanka uses a model where the Data Protection Authority issues adequacy decisions or approves specific contract clauses for transfers.
Confused by the differences?
Dual compliance is tricky. Our experts can help you navigate both DPDP vs Sri Lanka PDPA and DPDP requirements.
Book Strategy Call