Skip to main content
Ontriq Logo

Ontriq Insights · August 26, 2026

Sri Lanka's Personal Data Protection Act: A Guide for Employers

The Personal Data Protection Act changed how Sri Lankan employers can collect, store, and use candidate and employee data. Here is what it means for hiring, screening, and everyday HR work — in plain English.

Sri Lanka's Personal Data Protection Act (No. 9 of 2022) requires employers to collect candidate and employee data lawfully, for a specific purpose, with informed consent, and to store it securely for no longer than necessary. Background checks remain fully legal, but they must be run transparently and only after the candidate has given clear consent.

What the PDPA Is, in Plain English

The Personal Data Protection Act, No. 9 of 2022 — usually shortened to the PDPA — is Sri Lanka's first comprehensive data protection law. In simple terms, it sets rules for how organizations collect, use, store, share, and eventually delete personal data: any information that can identify a living person. A name, an NIC number, a home address, an employment history, a degree certificate, a reference letter — all of it counts.

For employers, the important shift is one of mindset. Candidate and employee data is no longer something a company simply owns because it happens to hold it. Under the PDPA, the organization is accountable for that data — for why it was collected, how it is protected, who can see it, and how long it is kept.

It is also worth knowing what the PDPA is not. Sri Lanka has no single, dedicated "background check law." Employee screening is lawful, and the PDPA is the primary legal framework that governs how it must be done. This guide explains the practical implications in general terms; for decisions specific to your organization, always consult qualified legal counsel.

Why the PDPA Matters for Hiring and Screening

Recruitment is one of the most data-intensive activities in any business. A single hiring round can generate hundreds of CVs, copies of NICs and passports, degree certificates, salary slips, referee contact details, and interview notes. Every one of those documents is personal data, and every step — collecting it, sharing it with a verification partner, storing it after the decision — falls under the PDPA.

None of this makes screening less necessary. An estimated 40–50% of resumes contain some inaccuracy or exaggeration, and a bad hire can cost up to 30% of the employee's first-year potential earnings. The question for Sri Lankan employers is not whether to verify candidates, but how to verify them in a way that respects the law. If you are new to the process itself, start with our guide on how to do background checks on employees in Sri Lanka and come back to this article for the compliance layer.

Core PDPA Principles Applied to Recruitment

The PDPA is built on a set of data protection principles. Here is what each one looks like when applied to hiring:

  • Consent. Candidates must agree before you process their personal data for screening. Consent has to be informed and specific — a vague line buried in an application form is risky practice.
  • Lawful and specific purpose. Data should be collected for a clearly stated reason, such as assessing suitability for a named role. You cannot quietly repurpose it later for marketing, profiling, or an unrelated decision.
  • Data minimization. Collect only what the role genuinely requires. An entry-level hire rarely justifies the same depth of data collection as a finance director.
  • Security safeguards. Personal data must be protected against loss, leaks, and unauthorized access — technically (encryption, access controls) and organizationally (who in HR can open the file).
  • Retention limits. Data should be kept only as long as it is needed for the purpose it was collected for, then securely deleted or anonymized.
  • Candidate rights. Individuals can ask what data you hold about them and request correction of inaccuracies. Your processes need a way to answer those requests.

A Practical PDPA Checklist for Employers

Use this as a starting point for reviewing your recruitment workflow. It is not exhaustive, but it covers the areas where most HR teams have gaps:

  1. Map the candidate data you collect at each hiring stage — application, interview, verification, offer — and record why each item is needed.
  2. Add a clear, standalone consent step before any background check begins, describing which checks will run and who will perform them.
  3. Update privacy notices in job advertisements and application forms so candidates know how their data will be used.
  4. Restrict access to candidate files to the people who actually need them, and stop circulating CVs and NIC copies over open email threads.
  5. Set retention periods for candidate data — including data on rejected applicants — and actually enforce the deletion dates.
  6. Vet any third party that touches candidate data, including verification providers, and put your expectations in writing.
  7. Create a simple procedure for handling a candidate's request to access or correct their data.
  8. Brief hiring managers, not just HR, on what they may and may not do with candidate information.

If you want the operational counterpart to this list — the documents and checks to complete before an offer goes out — see our pre-employment screening checklist for Sri Lankan employers.

What Candidate Consent Should Look Like in Screening

Consent is the foundation of compliant screening in Sri Lanka, so it deserves more than a checkbox. In a background verification context, good consent practice generally means:

  • Written and recorded. A signed form or a logged digital acceptance that you can produce later if asked.
  • Specific about the checks. The candidate should know whether you will verify employment history, education, criminal records, identity and address, references, or sanctions lists — not just that "checks may be conducted."
  • Clear about who is involved. Name the verification partner if one will process the candidate's data on your behalf.
  • Given before the checks start. Consent collected after the fact does not fix a check that was run without it.

Handled this way, consent is rarely a barrier. Candidates with accurate credentials have little reason to object, and a transparent process signals that your organization takes both integrity and privacy seriously.

Common PDPA Mistakes in Hiring

Most compliance failures in recruitment are not deliberate — they are old habits that predate the law. The patterns we see most often:

  • Keeping CVs forever. Folders of applications from years-old vacancies, held "just in case," with no retention policy and no deletion schedule.
  • Screening without consent. Calling previous employers or running checks before the candidate has agreed, or relying on assumed consent because the person applied for the job.
  • Emailing NIC copies unencrypted. Forwarding identity documents, certificates, and salary slips through open email chains where anyone copied can save them.
  • Using data for other purposes. Adding applicants to marketing lists, sharing candidate details with other companies, or reusing screening data for unrelated internal decisions.
  • Over-collecting. Demanding the same exhaustive document set from every candidate regardless of role, seniority, or actual risk.

Hiring Activity vs. What the PDPA Expects

The table below summarizes how the principles above map onto the everyday steps of a hiring process:

Hiring activityWhat the PDPA expects
Collecting CVs and application formsA clear purpose, a privacy notice explaining how data will be used, and only the fields the role requires
Running a background checkInformed, specific candidate consent obtained before any verification begins
Storing NIC copies and certificatesSecure storage with access controls — not shared drives or inboxes open to the whole team
Sharing data with a verification partnerA vetted provider, disclosure to the candidate, and written terms covering how the data is handled
Deciding not to hire a candidateFair use of the data collected, plus a route for the candidate to request access or correction
Holding data after the process endsA defined retention period, followed by secure deletion or anonymization

How a Compliant Verification Partner Shifts the Burden

You can build all of this in-house, but much of the operational risk sits in the verification step itself — collecting sensitive documents, contacting institutions, and moving data between parties. Working with a provider that offers PDPA-compliant background verification moves those high-risk mechanics into a controlled process.

At Ontriq, candidates upload their documents through a secure candidate document portal rather than email, consent is captured before checks begin, and every report passes dual-analyst quality control that sustains 98%+ report accuracy. HR teams follow progress through a real-time case tracking portal with a dedicated account manager, and complete multi-check cases are delivered within 7 working days. Checks that involve especially sensitive documents — such as identity and address verification, including physical field visits — are handled end to end, so NIC copies and utility bills never sit in an unprotected inbox.

The employer still owns the hiring decision and the consent relationship with the candidate. But the day-to-day handling of documents, institutional outreach, and data security moves to a partner whose entire process is built around doing it properly.

The Bottom Line for Sri Lankan Employers

The PDPA does not prohibit screening — it professionalizes it. Employers who collect only what they need, ask permission first, protect what they hold, and delete what they no longer require can verify candidates as thoroughly as ever. Treat this guide as a starting framework, take legal advice on the specifics, and put the consent and retention basics in place before your next hiring round rather than after.

If you would rather not carry the verification workload yourself, explore our background verification services in Sri Lanka or contact our team to talk through a screening process that fits both your roles and the PDPA.

Build A Verified, Trusted Workforce Today

Ensure workplace safety and reduce hiring risks with our comprehensive background verification services.