Sri Lanka PDPA and eSignatures: What Your Business Must Know
Every time a document is sent for electronic signature in Sri Lanka, personal data is collected. Under the Personal Data Protection Act No. 9 of 2022, that creates obligations most businesses have not thought about yet.

Every time you send a document for electronic signature, something happens that most businesses do not think about: personal data is collected.
The signer's name, email address, IP address, device information, and the precise timestamp of every action they take: all of it is captured as part of the signing workflow. Under Sri Lanka's Personal Data Protection Act No. 9 of 2022, that data collection is not incidental. It is regulated. And the obligations it creates apply to your business regardless of which eSignature platform you use.
This article covers what the PDPA actually requires, where enforcement currently stands, how cross-border data transfers work under the law, and what the smartest Sri Lankan businesses are doing right now to stay ahead of full enforcement.
What is the PDPA and where does it stand in 2026?
The Personal Data Protection Act No. 9 of 2022 was enacted by the Parliament of Sri Lanka on 19 March 2022. It is Sri Lanka's first comprehensive data protection legislation and is modelled closely on the European Union's General Data Protection Regulation (GDPR), while incorporating elements tailored to Sri Lanka's digital economy context.
The Act was subsequently amended by the Personal Data Protection (Amendment) Act No. 22 of 2025, gazetted on 31 October 2025.
What has already come into force
Parts V and VI of the PDPA, establishing the Data Protection Authority (DPA) and setting out its functions, became operative in July and December 2023 respectively. The DPA has been set up and is operational under the Ministry of Digital Economy.
What is still pending
The substantive provisions of the PDPA (Part I definitions and scope, Part II data subject rights, Part III obligations of controllers and processors, and Part VII penalties) have not yet been given a fixed commencement date. The 2025 Amendment Act removed the previously set grace period deadlines and provides that these parts will come into force on a date the Minister appoints by Gazette Order. As of May 2026, no such date has been announced.
This does not mean the PDPA is irrelevant to your business today. It means that now, while enforcement is not yet active, is the right time to build compliant workflows. Businesses that wait until a commencement date is announced will have very little time to adapt.
Why eSignatures create PDPA obligations
The PDPA defines personal data broadly: any information that relates to an identified or identifiable natural person. When your business sends a contract for electronic signature, the signing platform collects the following data about every signer:
- Full name and email address: provided at the point of sending
- IP address: captured at the moment of signing
- Device and browser information: logged automatically
- Geolocation data: derived from the IP address
- Timestamp of every action: document opened, reviewed, signed
- Authentication records: OTP verification, email confirmation
Every one of these data points falls within the PDPA's definition of personal data. Collecting them constitutes processing under the Act.
This means that as the business sending the document, you are acting as a data controller under the PDPA, the entity that determines the purposes and means of processing. The eSignature platform handling that data on your behalf is a data processor.
Both roles carry obligations under the Act.
The six lawful bases for processing
The PDPA does not permit personal data to be processed for any reason. Processing must be grounded in one of the lawful bases set out in Schedule I of the Act.
For an eSignature workflow, the most directly applicable bases are:
Performance of a contract: Processing is lawful where it is necessary for the performance of a contract to which the data subject is a party, or to take steps at the data subject's request prior to entering into a contract. When you send an employment contract, service agreement, or NDA for signature, this is the basis that applies. The signing workflow is necessary to form the contract.
Legitimate interests: Processing may be lawful where it is necessary for the legitimate interests of the controller, provided those interests are not overridden by the interests or rights of the data subject. This is a secondary basis and requires a genuine balancing assessment.
Consent: Processing is lawful where the data subject has given clear, informed, and freely given consent. For most commercial agreements, the contract performance basis is stronger and more appropriate than consent, because consent can be withdrawn at any time.
For most business eSignature workflows (employment agreements, client contracts, NDAs, service agreements), the contract performance basis is the appropriate lawful ground.
What controllers must do: key obligations
Once you are acting as a data controller in an eSignature workflow, the PDPA imposes several obligations.
Transparency
At the time of collecting personal data, controllers must provide data subjects with key information including: the identity of the controller, the purpose of processing, with whom the data may be shared, and information about any cross-border transfer. For a signing workflow, this is typically addressed through a privacy notice or disclosure shown to signers before they access the document.
Data minimisation
The PDPA requires that personal data collected is adequate, relevant, and limited to what is necessary for the purpose. An eSignature platform that captures an audit trail of IP address, timestamp, and device information is capturing data that is genuinely necessary for evidentiary purposes. That is proportionate. A platform that processes additional data beyond what the workflow requires (for advertising or profiling purposes) would not meet this standard.
Security
Controllers must implement appropriate technical and organisational measures to protect personal data against unauthorised access, disclosure, alteration, and destruction. Choosing an eSignature platform with encryption, access controls, and tamper-evident audit trails is part of meeting this obligation.
Data breach notification
Controllers are required to notify the Data Protection Authority and affected individuals in the event of a personal data breach. This obligation applies regardless of whether the breach occurred in your systems or in those of your data processor (the eSignature platform).
Data Protection Impact Assessments
For processing that is likely to result in high risk to the rights of data subjects, the PDPA requires a Data Protection Impact Assessment (DPIA). For standard commercial eSignature workflows, a DPIA is unlikely to be required. For high-volume, sensitive, or automated workflows (such as healthcare consent forms or financial services onboarding), the obligation is worth assessing.
The cross-border transfer question
This is where the PDPA has the most direct practical impact on businesses using cloud-based eSignature platforms.
Section 26 of the PDPA governs the transfer of personal data outside Sri Lanka. Under the Act, personal data may only be transferred to a third country if one of the following conditions is met:
- An adequacy decision has been made by the Minister designating that country as providing adequate protection
- The controller implements appropriate safeguards: binding and enforceable obligations on the recipient ensuring data subject rights are protected
- The data subject has given explicit consent to the transfer
- The transfer is necessary for the performance of a contract with the data subject
As of May 2026, no adequacy decisions have been issued by the Sri Lankan Minister. The Data Protection Authority has published draft cross-border transfer directives for stakeholder consultation, but these have not yet been finalised.
What this means practically: if your eSignature platform stores signing data (audit trails, signed documents, signer personal data) on servers outside Sri Lanka without appropriate contractual safeguards in place, you may be in a position that requires remediation once enforcement becomes active.
The 2025 Amendment introduced greater flexibility for cross-border flows, allowing organisations to make judgment-based decisions on where data is stored based on sensitivity and security classification. This is a more pragmatic approach than the original provisions and signals regulatory intent to facilitate rather than restrict digital business.
The data residency answer: why BYOS matters
The most practical response to the cross-border transfer question is keeping signing data in your own storage rather than the platform's cloud.
A bring-your-own-storage (BYOS) approach means that when documents are signed, the signed files and associated data are saved directly to your own Google Drive, OneDrive, or private cloud, not to the eSignature platform's servers. The platform facilitates the workflow; your infrastructure holds the data.
This approach:
- Eliminates the cross-border transfer concern because the data never leaves your designated storage
- Keeps your signed documents under your own access controls and retention policies
- Simplifies compliance with any future PDPA data residency requirements
- Addresses the transparency obligation because you have full visibility of what is stored and where
For Sri Lankan businesses in financial services, healthcare, legal, or any sector handling sensitive personal data, BYOS is the cleanest path to PDPA alignment, regardless of when full enforcement is activated.
Penalties: what the law provides
The PDPA empowers the Data Protection Authority to impose administrative penalties for non-compliance:
- For a first instance of non-compliance: up to LKR 10 million
- For subsequent non-compliance: an additional penalty of twice the amount imposed for the previous violation
Factors the Authority considers when determining penalties include the nature and duration of the violation, the number of data subjects affected, and any steps taken to mitigate the impact.
To put this in context: while LKR 10 million is significant in the Sri Lankan regulatory landscape, it is considerably lower than equivalent penalties under the GDPR (which can reach 4% of global annual turnover). This reflects the PDPA's calibration to Sri Lanka's economic context and business environment.
Enforcement timing note: As of May 2026, the penalty provisions have not yet come into force. They will become operative on the commencement date appointed by the Minister. Given the direction of travel (the DPA is staffing up, key regulations are being consulted on, and the 2025 Amendment removed the fixed grace periods), businesses should treat enforcement as a near-term reality rather than a distant prospect.
What this means for your eSignature workflow today
If your business uses electronic signatures in Sri Lanka, here is the practical position in May 2026:
The law is enacted, the Authority exists, and enforcement is coming. The substantive provisions of the PDPA are not yet active, but the DPA is operational and building its enforcement capacity. Waiting for a commencement date to be announced before acting is a poor strategy.
Your eSignature platform is a data processor: check what they do with signer data. Under the PDPA, you as the data controller are responsible for ensuring your processors comply with the Act's obligations. Review your platform's data processing practices, where data is stored, and what contractual protections are in place.
The contract performance basis is your lawful ground for most commercial signing. You do not need separate consent for processing the personal data of someone signing a contract with you. The contract itself is the lawful basis.
Cross-border transfers need attention. If your platform stores data outside Sri Lanka and no adequacy framework is in place, you need either appropriate contractual safeguards or a platform that keeps data in your own storage.
Build transparency into your signing process. Before a signer accesses your document, they should see a clear notice about what data is collected and how it is used. Most eSignature platforms can accommodate this in the invitation message or through a linked privacy notice.
Frequently asked questions
Does the PDPA apply to eSignatures in Sri Lanka?
Yes. When you collect personal data as part of an eSignature workflow (names, email addresses, IP addresses, timestamps), you are processing personal data under the PDPA. The Act applies to all processing carried out within Sri Lanka and by entities offering services to Sri Lankan residents.
Is the PDPA currently being enforced?
The Data Protection Authority is operational, but the substantive provisions including penalties have not yet been given a commencement date under the 2025 Amendment Act. Full enforcement is expected once the DPA completes its institutional setup. The direction of travel is clear: preparation now is the right approach.
What lawful basis applies to eSignature data collection?
For most commercial agreements, the lawful basis is performance of a contract: the signing workflow is necessary to form the agreement. Consent is generally not the appropriate basis for commercial contract signing because it can be withdrawn at any time.
Can I transfer signed documents and signer data outside Sri Lanka?
Yes, subject to conditions. Cross-border transfers are permitted where appropriate safeguards are in place, where the transfer is necessary for a contract, or where the data subject has given explicit consent. The cleanest approach is using a platform with BYOS: keeping data in your own storage removes the transfer question entirely.
What should I look for in an eSignature platform from a PDPA perspective?
Look for: clear disclosure of where signer data is stored, the option to keep documents in your own cloud storage (BYOS), a tamper-evident audit trail, data breach notification procedures, and a data processing agreement that defines the processor's obligations under the PDPA.
Sources
- Personal Data Protection Act No. 9 of 2022 (Parliament of Sri Lanka)
- Personal Data Protection (Amendment) Act No. 22 of 2025 (DLA Piper Data Protection Laws of the World)
- Data Protection Authority of Sri Lanka
- Personal Data Protection Act No. 9 of 2022, Schedule I (Parliament of Sri Lanka)
- DLA Piper Data Protection Laws of the World: Sri Lanka
- Personal Data Protection Act No. 9 of 2022, Section 26
- DLA Piper: Transfer of Personal Data in Sri Lanka
- Biometric Update: PDPA Amendment Act 2025
- Personal Data Protection Act No. 9 of 2022, Part VII
- Groundviews: Sri Lanka's Digital Law and Privacy Landscape, April 2026
This article is for general informational purposes and does not constitute legal advice. The PDPA implementation timeline is subject to change by Gazette notification. For specific legal advice on PDPA compliance for your business, consult a qualified Sri Lankan attorney.
Put the ideas into practice
Build a faster signature workflow with Zined
Use automated sends, reusable templates, AI-assisted reviews, and enterprise-ready controls to move agreements forward without adding friction for signers.
Keep reading
Related articles

Is an Electronic Signature Legally Valid in Sri Lanka?
Electronic signatures have been legally valid in Sri Lanka since 2006. But the law makes a distinction that most businesses miss and getting it wrong can leave your contracts unenforceable. Here is what you actually need to know.

eSignatures for Sri Lanka BPOs: How to Send Contracts to International Clients the Right Way
Sri Lanka's BPO sector serves clients in the EU, US, and Australia who expect GDPR-compliant digital workflows. Here is how to build a signing process that meets international standards, handles high document volumes, and answers the data compliance questions your clients are already asking.

eSignatures for HR in Sri Lanka: What You Can Digitise and What Still Needs Wet Ink
Most HR content about digital signing says go fully paperless. In Sri Lanka, that is not entirely true. This guide covers exactly what HR teams can digitise today, what the Labour Department still requires in hardcopy, and how to build a compliant hybrid workflow.