🇱🇰 PDPA Act No. 9 of 2022 Aligned

PDPA Compliance & DLP Implementation for Sri Lanka

Practical, technology-led resources for Sri Lanka's Personal Data Protection Act (PDPA) No. 9 of 2022 — build your Data Protection Management Programme (DPMP) and deploy Data Loss Prevention (DLP). Free. Open-source. Community-driven.

5
Implementation Phases
100%
PDPA Compliant
Free
Open Source

Why OpenDLP-LK?

Everything you need to implement enterprise-grade Data Loss Prevention, tailored for Sri Lankan organizations and PDPA compliance.

Step-by-Step Roadmap

Comprehensive 5-phase implementation guide from planning to continuous monitoring. No guesswork—just follow the phases.

View Roadmap

PDPA & DPMP Aligned

Every resource mapped to Sri Lanka's Personal Data Protection Act No. 9 of 2022 — including the Data Protection Management Programme (DPMP) required under Section 12(2).

Learn More

Ready-to-Use Templates

Download policy templates, checklists, data patterns, and training materials. Customize and deploy instantly.

Browse Templates

Sri Lankan Context

NIC patterns, local banking formats, Sinhala/Tamil support, and PDPA-specific guidance. Built for LK enterprises.

View Patterns

Data Champions Program

Train department leaders to drive DLP adoption. Training materials, certification, and ongoing support included.

Start Training

Open Source & Free

MIT Licensed. Fork, customize, contribute. Join hundreds of security professionals building together.

View on GitHub

5-Phase Implementation

From planning to continuous monitoring in 6-12 months. Follow our proven framework.

1

Planning

Months 0-2

Learn More →
2

Discovery

Months 2-4

Learn More →
3

Policy

Months 4-6

Learn More →
4

Pilot

Months 6-9

Learn More →
5

Monitoring

Ongoing

Learn More →

Sri Lanka PDPA & the Data Protection Management Programme (DPMP)

Sri Lanka's Personal Data Protection Act, No. 9 of 2022 (PDPA) is moving toward full enforcement. Its core accountability instrument is the Data Protection Management Programme (DPMP), required of controllers under Section 12(2) of the Act.

What the PDPA Requires

The PDPA is Sri Lanka's first comprehensive data protection law, overseen by the Data Protection Authority of Sri Lanka. It obliges every controller and processor to protect personal data — NIC numbers, financial records, health data, contact details — with demonstrable organisational and technical safeguards.

  • Lawful, transparent processing of personal data
  • A Data Protection Management Programme under Section 12(2)
  • Data breach notification and incident response
  • Respecting data subject rights (access, rectification, erasure)
Full PDPA Requirements

Build Your DPMP with DLP

A DPMP is more than paperwork — it needs working technical controls. Data Loss Prevention (DLP) supplies them: automated discovery and classification of personal data, policy enforcement at endpoints, email and cloud, monitoring, and auditable incident reporting your DPMP can evidence.

  • Discover & classify Sri Lankan personal data (NIC, passport, bank formats)
  • Map DLP policies directly to PDPA sections
  • Ready-to-use DPMP policy templates and gap analysis
  • Continuous monitoring and compliance reporting
Start a PDPA Gap Analysis

PDPA, DPMP & DLP — Frequently Asked Questions

What is the PDPA in Sri Lanka?

The PDPA is Sri Lanka's Personal Data Protection Act, No. 9 of 2022 — the country's first comprehensive data protection law. It regulates how organisations (controllers and processors) collect, use, store and share personal data of individuals in Sri Lanka, and it is enforced by the Data Protection Authority of Sri Lanka as the Act moves toward full enforcement.

What is a Data Protection Management Programme (DPMP)?

A Data Protection Management Programme (DPMP) is the internal accountability framework that controllers must implement under Section 12(2) of Sri Lanka's PDPA. A DPMP documents your policies, procedures, records of processing, risk assessments, training, breach response and monitoring controls that demonstrate ongoing PDPA compliance. OpenDLP-LK provides free templates, checklists and a phased roadmap to build a technology-led DPMP.

What is DLP (Data Loss Prevention) and how does it support PDPA compliance?

Data Loss Prevention (DLP) is a set of tools and processes that detect and prevent unauthorised disclosure of sensitive data such as NIC numbers, bank account details and health records. DLP provides the technical safeguards a DPMP needs: data discovery and classification, policy enforcement, monitoring and incident reporting — turning PDPA obligations into enforceable, auditable controls.

Who must comply with Sri Lanka's PDPA and by when?

The PDPA applies to controllers and processors that process personal data in Sri Lanka, including public authorities, banks, telecoms, healthcare providers and businesses that offer goods or services to persons in Sri Lanka. The Act is being brought into force in stages, so organisations should establish their DPMP and technical controls such as DLP now, before enforcement and penalties apply.

How do I start a PDPA-compliant DLP implementation?

Follow OpenDLP-LK's free 5-phase roadmap: (1) Planning and governance, (2) Data discovery and classification, (3) Policy development mapped to PDPA sections, (4) Pilot deployment, and (5) Continuous monitoring. Each phase includes checklists, Sri Lankan data patterns (NIC, passport, bank formats) and templates you can adopt into your DPMP.

Ready to Protect Your Data?

Join organizations across Sri Lanka implementing world-class data protection.