Discuss this page with an LLM

What This Means In Practice

Use this table to brief your legal, product and marketing teams.

Question DPDP Direction DPDP vs Sri Lanka PDPA Direction Practical Impact
Can we process by default? Often consent-first Often depends on a different legal model India flows may need earlier consent design.
Is a global privacy model enough? No Not always Global privacy work does not map one-to-one to DPDP.
Are children protected differently? Under 18 Check local age thresholds Indian child-user products need stricter review.
Is breach risk enough to trigger work? Yes Yes Security, response and evidence matter in both systems.

Three Questions To Ask Internally

  1. Are we copying a non-India privacy model into an Indian product?
  2. Do our consent flows work for Indian users?
  3. Which global privacy controls can be reused, and which must be redesigned for DPDP?

If you operate across India and another market, do not assume one privacy program covers both. Use the stricter flow where user trust and evidence matter most.

Want all of this handled, end to end? Sanctum is the all-in-one DPDP compliance programme behind this site: legal position, data map, gap analysis, implementation, tooling, training, readiness opinion, and breach cover under one accountable owner. How all-in-one DPDP compliance works or see the Sanctum programme.

India’s DPDP Act limits data processing to consent or specific “legitimate uses” such as medical emergencies, employment, or state functions. Sri Lanka’s PDPA follows a model similar to the EU GDPR, offering six distinct legal bases. This includes “legitimate interests” pursued by the controller or a third party. Businesses operating in both countries must recognize that processing activities allowed under legitimate interest in Sri Lanka may require explicit consent from users in India.

Data Portability and Subject Rights

Sri Lanka’s PDPA grants individuals the right to data portability, allowing users to request their data in a structured, machine-readable format to move to another provider. The Indian DPDP Act does not include a right to data portability. Companies managing data in both jurisdictions must implement technical export tools for their Sri Lankan operations that are not legally mandated for their Indian user base.

Material and Operational Scope

The PDPA applies to personal data processed within Sri Lanka, regardless of whether the data is digital or part of a manual filing system. India’s DPDP Act excludes non-digital data that remains in physical paper format. Additionally, the PDPA requires every controller to nominate a Data Protection Officer if they meet specific volume or risk thresholds. India restricts the mandatory DPO requirement to companies classified as Significant Data Fiduciaries by the central government.

Comparison Table

FeatureDPDP Act 2023 (India)PDPA No. 9 of 2022 (Sri Lanka)
Material ScopeDigital personal data onlyDigital and manual filing systems
Legal BasisConsent or Certain Legitimate Uses6 bases including Legitimate Interest
Data PortabilityNot providedExplicitly granted to subjects
MinorsIndividuals under 18Individuals under 18
DPO RequirementOnly for Significant Data FiduciariesMandatory for public bodies and large processors
Cross-borderRestricted via government blacklistAllowed via adequacy or approved clauses
EnforcementData Protection Board of IndiaData Protection Authority of Sri Lanka

This week

Review your internal data processing logs to identify any operations currently justified under “legitimate interests” for your Sri Lankan entity and determine if those same operations require a fresh consent notice under the Indian DPDP Act’s narrower “legitimate uses.”

FAQ

Q: Does the DPDP Act cover physical paper files like the PDPA? A: No. The DPDP Act only applies to personal data in digital form or data digitized after collection. Sri Lanka’s PDPA applies to both digital data and data contained in manual filing systems.

Q: Is a Data Protection Officer mandatory for all companies in both regions? A: No. In India, only Significant Data Fiduciaries must appoint a DPO. In Sri Lanka, all public bodies and any private entity processing high volumes of data or specific risk categories must appoint a DPO.

Q: How do cross-border transfer rules differ between India and Sri Lanka? A: India uses a blacklist model where the government can restrict transfers to specific countries. Sri Lanka uses a model where the Data Protection Authority issues adequacy decisions or approves specific contract clauses for transfers.

Confused by the differences?

Dual compliance is tricky. Our experts can help you navigate both DPDP vs Sri Lanka PDPA and DPDP requirements.

Book Strategy Call
Book clarity call