IT Services

Sri Lanka PDPA Compliance Checklist for SMEs — 2026 Guide

Operational PDPA checklist for Sri Lankan SMEs after 18 March 2025 enforcement—roles, inventories, vendors, retention, and cloud ERP questions. Not legal advice.

Looking for AMC, outsourcing, cloud, or team support in Sri Lanka?

Browse Capricon IT services
By Manikya Searathna
Compliance officer reviewing a Sri Lanka PDPA checklist beside a laptop in an office

Sri Lankan SMEs that run cloud ERP, recruitment tools, chatbots, or customer databases need a practical PDPA operating checklist—not another summary of the statute. Enforcement of the Personal Data Protection Act, No. 9 of 2022 began on 18 March 2025 (date checked: August 2026).

Disclaimer: this article is operational guidance for business and IT teams. It is not legal advice. Have someone familiar with legal compliance review notices, contracts, and sector-specific duties before you treat any item as closed.

This checklist sits under Capricon’s pillar guide Digital Transformation in Sri Lanka. Related deep dives: WhatsApp/AI chatbots and customer data and cloud ERP data-protection checklist.

Official context

  • Official source: Personal Data Protection Act, No. 9 of 2022 (Parliament of Sri Lanka); Data Protection Authority guidance at dpa.gov.lk.
  • Date checked: August 2026.
  • Effective / enforcement stage: 18 March 2025.
  • Businesses affected: controllers and processors handling personal data—including SMEs using cloud software, CRM, HR/ATS, hospital systems, and messaging bots.
  • Required system changes (typical): role-based access, audit logs, retention/deletion workflows, vendor/processor documentation, minimised bot data, documented purposes.

SME PDPA operations checklist

1. Ownership and inventory

  • Name one accountable business owner for personal data (usually GM + IT/ops).
  • List every system that stores names, phones, NICs, emails, HR files, patient IDs, or payment references.
  • Note which vendor hosts each system (on-prem, Capricon cloud, other SaaS).
  • Flag spreadsheets and shared drives that still hold “shadow” customer or HR lists.

2. Purpose, minimisation, and notices

  • Write one sentence per dataset: why you collect it (billing, delivery, hiring, care).
  • Stop collecting fields nobody uses (extra NIC copies, open WhatsApp exports).
  • Align website, invoice, and chatbot privacy language with how you actually use data.
  • Route legal wording through counsel; keep IT focused on matching systems to that wording.

3. Access, roles, and logging

  • Remove shared “admin” passwords; use named users.
  • Separate cashier, accountant, HR, and owner roles in ERP/HMS/ATS.
  • Turn on audit logs for exports, role changes, and mass deletes where available.
  • Offboard leavers the same day—especially WhatsApp Business and cloud ERP admins.

4. Retention and deletion

  • Define how long you keep prospects, inactive customers, candidate CVs, and closed tickets.
  • Document tax/accounting retention separately from marketing lists.
  • Test one deletion or anonymisation path in a staging or low-risk dataset.
  • Stop indefinite “keep everything” WhatsApp chat backups on personal phones.

5. Vendors and processors

  • Ask where data is stored and who can access it.
  • Ask for breach-notification contacts and backup/restore SLAs.
  • Ask whether subprocessors (AI model hosts, SMS gateways) receive personal data.
  • Keep signed contracts and last questionnaire answers in one folder.
Printed PDPA checklist and laptop for SME compliance work
Treat PDPA as roles, inventory, vendors, and retention—not a one-time policy PDF.

Questions to ask your cloud and software provider

  1. Which personal-data categories does the product store by default?
  2. Can we configure retention and export restrictions by role?
  3. Where are primary and backup copies located?
  4. How are AI features prevented from sending sensitive fields to public tools?
  5. What is the incident-response contact path and typical notification timeline?

For hosting controls, see cloud hosting backups and monitoring and Capricon’s cloud hosting Sri Lanka service. For ERP as system of record, review Capricon Core and the ERP software Sri Lanka hub.

Revision history

  • 2026-08-06 — Initial Capricon operational checklist published (enforcement date 18 Mar 2025 cited).

Next step

If your biggest exposure sits in invoicing, multi-branch cash, or cloud ERP access, book Capricon’s cash & VAT readiness audit or contact Capricon for a systems-focused data-protection walkthrough. For how digitization phases fit together, return to the complete digital transformation guide. Retail proof pattern: multi-branch ERP case study.

Sources

Frequently asked questions

When did Sri Lanka’s PDPA enter enforcement?

The Personal Data Protection Act, No. 9 of 2022 entered its enforcement stage on 18 March 2025. Businesses should treat personal-data handling in ERP, HR, CRM, and chatbots as an operational control problem from that date onward.

Is this checklist legal advice?

No. Capricon publishes operational guidance for systems and processes. Have your lawyer or compliance adviser review policies, notices, and DPIA-style assessments for your sector.

Does cloud ERP create PDPA risk?

Cloud ERP processes personal data (customers, staff, sometimes patients or candidates). Risk is managed with roles, access logs, retention, processor contracts, and host-country/transfer clarity—not by avoiding cloud by default.

What should SMEs do in the next 30 days?

Name a data owner, list systems that hold personal data, tighten admin access, add a retention note, and send a short questionnaire to cloud/software vendors. Then schedule a legal review of your privacy notice.

Related Capricon solutions

Explore tools and services for it services

Related guides on this topic

Related Capricon product & services

Ready to take your business to the next level?

Your next big move starts here - take charge, scale up, and lead your business to success.