specshop.dev / Journal / Industry take
Industry take 10 min read Updated

AI and the Personal Data Protection Act in Sri Lanka: what an AI agent may touch, and how we set it up

Sri Lanka's Personal Data Protection Act, No. 9 of 2022 covers AI agents that read customer data: the duties, the risks, and the LKR 10 million penalty.

Anudi Imesha
Customer Success Manager · specshop.dev

Sri Lanka’s Personal Data Protection Act, No. 9 of 2022 applies to an AI agent that reads customer data, because the Act regulates the processing of personal data and an agent reading an inbox is processing it, and the business that decided to run the agent is the controller who carries the obligations. Parts I, II, III and VII of the Act came into operation on 18 March 2025, and section 38 lets the Data Protection Authority require a penalty of up to LKR 10 million for each non-compliance, which is about US$30,418.

AI agent tasks sorted by risk under Sri Lanka’s Personal Data Protection Act, with the control applied to each
Figure 29. The Act applies to the agent. The obligations are yours. Source: Personal Data Protection Act No. 9 of 2022 · Data Protection Authority · not legal advice.

Every US dollar figure below converts at LKR 328.75, the Central Bank of Sri Lanka’s indicative USD/LKR spot rate for 10 September 2026. This is general information about a statute, not legal advice, and the sections are quoted so your lawyer can check them.

The question the auditor asked

Picture the finance director of a mid-sized distributor in Colombo 2, four hundred trade customers, an accounts team of six. She is invented. The conversation is not.

Her auditor noticed something during the management letter interview. The company runs an AI agent on the customer service inbox: it reads incoming email, pulls the matching account balance, and drafts a reply for an assistant to send. He asks one question. Is that lawful under the Act?

She has a demo, an invoice and no answer. Worse, nobody has written down what the agent may read.

The question is badly posed, which is the useful part. No AI agent is lawful or unlawful in itself. Section 5 attaches lawfulness to processing, and section 56 defines processing as “any operation performed on personal data including but not limited to collection, storage, preservation, alteration, retrieval, disclosure, transmission, making available, erasure, destruction of, consultation, alignment, combination”. Every one of those verbs describes something the agent does before breakfast, so the answer is never yes or no. It is a list of decisions somebody must record.

What the Act is, and when it took effect

The Personal Data Protection Act, No. 9 of 2022 was certified on 19 March 2022. Under section 2 it applies where processing “takes place wholly or partly within Sri Lanka”, and to any controller or processor incorporated here or offering goods or services here.

Commencement was staged. The Data Protection Authority records that Parts VI, VIII, IX and X came into operation on 1 December 2023, and Parts I, II, III and VII on 18 March 2025, with Part IV on solicited messages to follow. Parts I, II and III are the ones that matter to an agent: the controller’s obligations, the rights of data subjects, and the duties of processors.

The text moved again last year. The Personal Data Protection (Amendment) Act, No. 22 of 2025, certified on 30 October 2025, replaced the cross-border provision in section 26 outright, redefined “third country” as “any other territory or country other than Sri Lanka”, and gave a controller one month, extendable to three, to answer a request under section 17. Anyone quoting the 2022 adequacy regime is quoting a repealed section.

Three definitions in section 56 decide who is on the hook. “Personal data” is “any information that can identify a data subject directly or indirectly”, by name, identification number, financial data, location data or online identifier. A “controller” “determines the purposes and means of the processing”. A “processor” processes “on behalf of the controller”. Your business is the controller. Your vendor is normally the processor, and under section 22(2) a processor that ignores its written instructions, or decides purposes and means itself, “shall, for the purposes of this Act be deemed to be a controller”.

The obligations that bite when work is automated

Part I sets eight obligations. Automation sharpens four.

Lawfulness, section 5 and Schedule I. Processing is lawful if it meets a Schedule I condition: consent, necessity for a contract with the data subject, a legal obligation, an emergency, a public interest task, or the controller’s legitimate interests “except where such interests are overridden by the interests of the data subject”. Most drafting work in a trading business sits on contract or legitimate interest, and a consent you never collected is worse than a legitimate interest you wrote down and can defend.

Purpose, section 6. Data must be processed for a “specified”, “explicit” and “legitimate” purpose and “shall not be further processed in a manner which is incompatible with such purposes”. This is the one automation breaks: email addresses collected to service an order, fed to an agent writing marketing follow-ups, are a new purpose.

Minimisation, section 7. Data must be “adequate”, “relevant” and “proportionate” to the purpose. An agent given whole-database access because that was easier to configure fails this test on day one.

Retention, section 9. Data must be kept in identifiable form “only for such period as may be necessary”. Prompt logs, transcripts and vector stores are retention, whatever you call them.

The rest still apply: accuracy under section 8, integrity and confidentiality under section 10 “including encryption, pseudonymisation, anonymisation or access controls”, transparency in a “concise, transparent, intelligible and easily accessible form” under section 11, and accountability under section 12, which requires a Data Protection Management Programme of documented controls showing how sections 5 to 11 are met. That programme is what an auditor asks for. Section 20 adds a Data Protection Officer where core activities involve regular and systematic monitoring or special categories at scale, and section 24 an impact assessment before “a systematic and extensive evaluation of personal data or special categories of personal data including profiling”. Special categories, in section 56, run from ethnic origin and religious belief through biometric and health data to anything relating to a child, anyone under sixteen.

On automated decisions, Sri Lanka is narrower than Europe. Article 22 of the GDPR gives a right “not to be subject to a decision based solely on automated processing”. Section 18 here gives only a right to request a review of a decision “based solely on automated processing” that has created or is likely to create “an irreversible and continuous impact” on rights and freedoms. A human approval step keeps you out of that section, because the decision is then not solely automated.

Low, medium and high risk agent tasks

Our reading, not a regulator’s classification.

Agent taskPersonal data touchedRisk under the ActControl we apply
Drafting replies to customer emailName, email, order and balanceLow, on contract or legitimate interestNamed approver; data pulled per query, not bulk loaded
Chasing overdue invoicesContact and payment historyLow to medium, purpose close to the originalApproval on the first message to each debtor
Summarising a call or meetingWhatever was said, sometimes health detailMedium, special categories arrive uninvitedRetention window agreed in writing; transcripts deleted on schedule
Enriching a customer list from outside sourcesData the subject never gave youHigh, sections 6 and 7 engagedNot built without written legal sign-off
Scoring or ranking people, credit or hiringA profile built from many fieldsHigh, sections 24 and 18 in playA human decides every outcome
Health, religion, ethnicity or a childSpecial categories, section 56High, Schedule II appliesOut of scope unless counsel approves

How we configure an agent, and what that is not

This is policy and configuration, not a guarantee, and not a legal opinion.

specshop.dev is an AI consultancy and AI agency in Colombo, Sri Lanka, led by Janaka Ediriweera, Principal AI and Product Management Consultant. Four settings go into the specification before an agent runs, which is the argument we made in The Spec Was Always the Product.

Approval. A named person approves every draft before it leaves, and how often they approve untouched is an AI agent’s approval rate. The side effect here is legal: a decision with a human in it is not solely automated.

Minimisation. The agent gets the fields the task needs, retrieved per query. If a task does not need a national identity card number, that field is out of scope.

Retention. Logs and transcripts have a stated deletion window, agreed in writing, not left to a default.

Region of processing. We tell you where the model runs, because it depends on the provider you choose and some are not in Sri Lanka. Section 26 as replaced in 2025 permits cross-border flows where the controller ensures compliance with Part I, Part II and sections 20 to 25, using instruments the Authority may specify by directive. That is a question for your contract and your lawyer, and the answer belongs in writing rather than in a sales deck, as we said of patient data in AI for clinics in Sri Lanka.

The questions to ask any AI vendor

  • Which Schedule I ground does this processing sit on, and who wrote that down?
  • Are you a processor or a controller, and what are your written instructions under section 22?
  • Which country does the model run in, and which sub-processors see the data?
  • What is retained, where, and on what deletion schedule?
  • Will you erase or return our data when we leave, under section 22(1)(d)?

A vendor who answers all five has thought about it. One who says the platform is compliant has answered none of them, because compliance here belongs to the controller.

Not legal advice, and please take some

Everything above is general information taken from the Act and the commencement notice of the Data Protection Authority, Sri Lanka’s dedicated regulator. No article can tell you whether your processing is lawful. Take the sections to a Sri Lankan lawyer who practises in data protection, with your real data flows in front of them. Section 38 makes directors and officers personally liable unless they prove they exercised all due care.

What to do this week

Write one page before you buy anything. List every field the agent will read, and against each the purpose that data was collected for and the Schedule I ground you rely on. Write the deletion window. Name the approver.

Then take that page to your lawyer, and to your vendor, in that order. If you want the mapping done first, a workflow mapping sprint is US$2,300, about LKR 756,125, with a written report in 48 hours, credited in full against the recruitment fee if you hire within 30 days. An agent’s salary starts at US$1,225 a month, about LKR 402,700, and the terms sit on the page where you hire an AI agent. The first thirty-minute call with our AI consultancy in Sri Lanka is free, and includes “not yet” as an answer.

Questions people actually ask.

Does the Personal Data Protection Act apply to AI in Sri Lanka?

Yes, in the sense that it applies to the processing of personal data by whatever means, and an AI agent that reads, stores or transmits customer data is processing it under the definition in section 56. The Act does not have an AI chapter, so the obligations that apply are the ordinary ones in Part I, and they fall on your business as the controller rather than on the vendor or the model.

Can an AI agent read customer data under Sri Lankan law?

It can, provided the processing meets a condition in Schedule I, stays within the purpose specified when the data was collected under section 6, and is limited to data that is adequate, relevant and proportionate under section 7. In practice that means writing down the ground you rely on and the fields the agent may see before you switch it on, and having a Sri Lankan lawyer check both.

Where is the data stored when an AI agent processes it?

That depends entirely on which model provider you choose, and some of them process outside Sri Lanka, so the honest answer from any vendor is the name of the region rather than a reassurance. Section 26, as replaced by the Amendment Act of 2025, allows cross-border data flows where the controller or processor ensures compliance with Part I, Part II and sections 20 to 25 of the Act, using instruments the Authority may specify.

Do customers need to consent to AI replies?

Not necessarily, because consent is only one of the Schedule I grounds and most customer service work sits on the performance of a contract or on legitimate interests instead. What you do owe under section 11 is transparency, in a “concise, transparent, intelligible and easily accessible form”, so a privacy notice that never mentions automated drafting is the weak point rather than the missing consent form.

Who enforces data protection in Sri Lanka?

The Data Protection Authority, established under section 28 of the Act, with its board appointed in October 2023 and the main obligations in force from 18 March 2025. Under section 38 it may require a controller or processor who fails to comply with a directive to pay a penalty not exceeding rupees ten million for each non-compliance, doubled for repeat failures, with an appeal to the Court of Appeal.

Sources

  1. Personal Data Protection Act, No. 9 of 2022, Parliament of Sri Lanka — certified 19 March 2022; section 2 on application, including processing “wholly or partly within Sri Lanka” and the exclusion of “purely for personal, domestic or household purposes”; section 5 and Schedule I conditions for lawful processing; section 6 “specified”, “explicit” and “legitimate” purposes and no further incompatible processing; section 7 “adequate”, “relevant” and “proportionate”; section 8 accuracy; section 9 retention “only for such period as may be necessary”; section 10 integrity and confidentiality “including encryption, pseudonymisation, anonymisation or access controls”; section 11 “concise, transparent, intelligible and easily accessible form”; section 12 Data Protection Management Programme; section 18 review of decisions “based solely on automated processing” with “an irreversible and continuous impact”; section 20 Data Protection Officer triggers; section 22(1)(d) and 22(2) processor obligations and deeming; section 24 impact assessments for “a systematic and extensive evaluation of personal data or special categories of personal data including profiling”; section 28 establishment of the Authority; section 38(1) penalty “which shall not exceed a sum of rupees ten million for each non-compliance”, 38(2) doubling, 38(6) liability of directors and officers, 38(7) appeal to the Court of Appeal; section 56 definitions of “personal data”, “controller”, “processor”, “processing”, “child” and “special categories of personal data”; Schedules I and II. Fetched 10 September 2026.
  2. Personal Data Protection (Amendment) Act, No. 22 of 2025, documents.gov.lk — certified 30 October 2025; section 10 replacing section 26 of the principal enactment so that cross-border data flows are permitted “only where such controller or processor, ensures compliance with the provisions of Part I, Part II and sections 20, 21, 22, 23, 24 and 25”, with instruments specified by a directive under section 33(c) and the exceptions in the new section 26(3); section 4 amending section 17 to a response period of one month extendable by two; section 14(3) redefining “third country” as “any other territory or country other than Sri Lanka”; section 11 inserting section 51A on guidelines. Fetched 10 September 2026.
  3. Personal Data Protection Act dates of operation, Data Protection Authority of Sri Lanka — Part V brought into operation in July 2023 with the board announced in October 2023; “the provisions of Part VI, VIII, IX and X of the aforesaid Act shall come into operation” on 1 December 2023; “the provisions of part I, II, III and VII of the aforesaid Act shall come into operation” on 18 March 2025; Part IV on solicited messages to follow. Fetched 10 September 2026.
  4. Article 22, General Data Protection Regulation (EU) 2016/679 — Article 22(1), “The data subject shall have the right not to be subject to a decision based solely on automated processing, including profiling, which produces legal effects concerning him or her or similarly significantly affects him or her”, used only as a contrast with section 18 of the Sri Lankan Act. Fetched 10 September 2026.
  5. Daily Indicative USD/LKR Spot Exchange Rates, Central Bank of Sri Lanka, 2026 — the indicative rate of LKR 328.75 per US$1 on 10 September 2026, used for every conversion in this post.