Personal Data Protection Act 2022 · As enacted · Part III · Controllers and Processors
26. Cross-border data flow
Official English translation. Where it differs from the Sinhala or Tamil text, the Act itself says which text prevails.
Official translationFrom Department of Government Printing, unchanged
Where a public authority process personal data as a controller or processor, such personal data shall be processed only in Sri Lanka and shall not be processed in a third country, unless the Authority in consultation with, that controller or processor as the case may be and the relevant regulatory or statutory body, classifies the categories of personal data which may be permitted to be processed in a third country, prescribed by the Minister pursuant to an adequacy decision made under subsection (2).
For the purpose of making an “adequacy decision”, the Minister shall, in consultation with the Authority take into consideration the relevant written law and enforcement mechanisms relating to the protection of personal data in a third country and the application of the provisions of Part
I, Part II and sections 20, 21, 22, 23, 24 and 25 of Part III of this Act, and such other prescribed criteria relating to the processing of personal data, in a third country for the purpose of cross border data flow.
Any adequacy decision made by the Minister under this subsection shall–
be subject to periodic monitoring of the developments in a third country that may affect such decisions and the Minister may review such decision at least every two years; and
remain in force until amended or revoked by the
Minister in consultation with the authority.
A controller or processor other than a public authority may process personal data–
in a third country prescribed pursuant to an adequacy decision; or
in a country, not being a third country prescribed pursuant to an adequacy decision, only where such controller or processor as the case may be, ensures compliance with the respective obligations imposed under Part I, Part II and sections 20, 21, 22, 23, 24
and 25 of Part III of this Act.
For the purpose of ensuring compliance under paragraph (b) of subsection (3), a controller or processor shall adopt such instruments as may be specified by the
Authority to ensure binding and enforceable commitments of the recipient in the third country to ensure appropriate safeguards to the rights of the data subjects and remedies protected by this Act.
In the absence of any adequacy decision pursuant to subsection (2) or appropriate safeguards pursuant to subsecion (4), a controller or processor other than a public authority may process personal data outside Sri Lanka if–
the data subject has explicitly consented to the proposed processing of personal data outside Sri
Lanka, after having been informed of the possible risks of such processing for the data subject due to the absence of an adequacy decision and appropriate safeguards; or
the transfer is necessary for the performance of a contract between the data subject and the controller or the implementation of any pre contractual measures taken by the controller at the request of the data subject; or
the transfer is necessary for the establishment, exercise or defence of legal claims relating to the data subject; or
the transfer is necessary for reasons of public interest as defined in item (g) of Schedule I of this Act; or
the transfer is necessary to respond to an emergency that threatens the life, health, or safety of the data subject or another person and where the data subject or his legal guardian is physically or legally incapable of giving consent; or
such processing is permitted under any other conditions as may be prescribed under this Act.
Part IV
Use of Personal Data to Disseminate Solicited Messages
Part V
Data Protection Authority
Part VI
Director-General and the Staff of the Authority
Part VII
Penalties
Part VIII
Fund of the Authority
Part IX
Miscellaneous
Part X