PDPA and HR Records: What Sri Lankan Employers Owe
The Personal Data Protection Act covers employee and payroll records. What is in force since March 2025, and what it asks of Sri Lankan employers.

On this page
- What counts as personal data in your HR files
- Which parts of the Act apply to you now
- Your lawful basis: you already have one for payroll
- Biometric attendance: the higher bar
- Access control inside HR and payroll
- Retention and deletion after someone leaves
- What an employee can ask you for
- If you send data outside Sri Lanka
- Penalties
- Frequently asked questions
- Does the Personal Data Protection Act apply to a small business with five staff?
- Do I need an employee's consent to run payroll?
- Is fingerprint attendance data allowed under the Act?
- What happens if I keep old employee files too long?
- Where do I check for anything this page does not cover?
Employee and payroll records are personal data (information that can identify a person). The Personal Data Protection Act No. 9 of 2022 sets rules for using them. Parts of the Act are already in force. This page says which parts, and what they ask of you as an employer.
This is general information, not legal advice. For your own case, check the Data Protection Authority’s current notices.
What counts as personal data in your HR files
Name, NIC number, address, phone, bank account, salary and EPF number are personal data. So are attendance logs and appraisal notes. The Act’s definition of “financial data” names “data relating to remuneration” directly. Your payroll figures are personal data of each employee. They are not just your own business record.
Some employee data needs extra care. The Act calls this “special categories of personal data” (a list of sensitive types with a higher bar for using them). The list includes: racial or ethnic origin, political opinion, religion and genetic data. It also covers biometric data (fingerprint, face or iris data used to identify someone), health data, and data about a criminal case. A staff fingerprint attendance log falls on this list.
Which parts of the Act apply to you now
The Data Protection Authority’s own site sets out the operative dates, checked 20 September 2026:
| Part of the Act | What it covers | In force from |
|---|---|---|
| Part I | The controller’s core duties: purpose, accuracy, keeping data no longer than needed, security | 18 March 2025 |
| Part II | Employee (data subject) rights: access, withdrawing consent | 18 March 2025 |
| Part III | Duties on you as controller, and on any processor you use; breach reporting; sending data abroad | 18 March 2025 |
| Part VII | Penalties | 18 March 2025 |
| Parts V, VI, VIII, IX, X | The Authority itself, its powers and its fund | 1 December 2023 (part of Part V from July 2023, for Board appointments) |
| Part IV | Marketing messages by post, phone or email | Not yet in force |
Source: Data Protection Authority of Sri Lanka (dpa.gov.lk), checked 20 September 2026. For anything not settled here, check the Authority’s current notices.
Your lawful basis: you already have one for payroll
You need a lawful reason (the Act calls it a condition) before you process personal data (process means any use of it: collecting it, holding it, or looking it up, not just editing it). For ordinary HR and payroll records, two conditions usually apply. You do not need to ask the employee’s consent for either.
- The employment contract. Paying salary, tracking leave and running attendance are things you do to perform the contract.
- A legal obligation. The EPF Act, the ETF Act, the Inland Revenue Act and the Shop and Office Employees Act already make you keep and report these records. See the Shop and Office Employees Act guide for what it requires. Processing them to meet those duties is covered.
Consent is one of the Act’s conditions. You do not have to rely on it where the two above already apply.
Biometric attendance: the higher bar
Biometric data needs a condition from a separate list in the Act. Two usually fit an employer: the employee’s specific consent, or a condition for data needed “in the field of employment.” The Act does not spell out what safeguards a private employer must put in place. Ask the Authority if you are unsure. See biometric attendance and the law in Sri Lanka for how the devices themselves work, and Can You Deduct Salary for Late Attendance in SL? for how the same fingerprint log feeds payroll.
Access control inside HR and payroll
The Act asks you to keep personal data secure, using measures such as access controls. Limit who can open salary records, NIC copies and biometric logs. Usually that means payroll and a manager, not every supervisor. Employee Records: What to Keep and for How Long covers what to file and for how long.
Retention and deletion after someone leaves
The Act says you may keep identifiable personal data only as long as you need it. Keep it only for the purpose you collected it for. The Act does not set a fixed number of years for payroll or EPF/ETF records. Ask the Authority or the Labour Department for the retention period that applies to your records. Do not keep old fingerprint templates or NIC scans past the point you need them. Check Staff Turnover and Absenteeism: How to Calculate for tracking who has left.
What an employee can ask you for
Since 18 March 2025, an employee can:
- Ask, in writing, whether you hold their personal data, and see it.
- Withdraw consent at any time, where consent was the basis you used.
Answer a written request. If you are unsure what a request covers, ask the Authority rather than guessing.
If you send data outside Sri Lanka
Your payroll or HR system may store data on a server abroad. The Act sets conditions before you can do that. The first route is a country the Minister has approved. Otherwise you must meet the Act’s own conditions, such as the employee’s explicit informed consent. This applies whether the host is a payroll bureau or a cloud system.
Penalties
The Authority can fine a controller or processor for a failure to follow one of its directives. The fine can reach LKR 10,000,000 for each failure. A repeat failure after a previous penalty doubles that amount. You can appeal to the Court of Appeal within 21 working days of the notice.
Do this automatically in Humanised. Humanised hosts employer data on Microsoft Azure in Singapore. Access to the employee management system is controlled by user role.
This is general payroll guidance. Every case is different. For your own case, speak to a payroll practitioner or a lawyer.
Frequently asked questions
Does the Personal Data Protection Act apply to a small business with five staff?
Yes. The Act sets no size threshold for ordinary employers. Any size business that processes personal data must follow Parts I, II, III and VII. These have been in force since 18 March 2025.
Do I need an employee’s consent to run payroll?
No, not usually. Paying salary performs the employment contract. Reporting to EPF, ETF and the IRD meets a legal obligation. Both are lawful grounds on their own.
Is fingerprint attendance data allowed under the Act?
Biometric data needs its own lawful ground. One example is the employee’s specific consent. Another is a condition tied to employment. The Act gives no step-by-step procedure for employers. Check with the Data Protection Authority for anything not covered here.
What happens if I keep old employee files too long?
The Act says not to keep identifiable personal data longer than you need. Keep it only as long as your purpose for collecting it lasts. Delete or anonymise records once no legal duty still needs them.
Where do I check for anything this page does not cover?
The Data Protection Authority (dpa.gov.lk) publishes its own notices and guidance.
Was this article helpful?
Your feedback helps us improve these guides.