පරිගණක අපරාධ හා දත්ත ආරක්ෂණ නීතිය Cyber Crime & Data Protection Law

ශ්‍රී ලංකාවේ පරිගණක අපරාධ පනත, පුද්ගලික දත්ත ආරක්ෂණ පනත සහ ගුරුවරුන් සඳහා ප්‍රායෝගික මාර්ගෝපදේශය A practical guide to the Computer Crimes Act, Personal Data Protection Act, and Online Safety Act for Sri Lankan teachers and administrators

පරිගණක අපරාධ පනත අංක 24, 2007 Computer Crimes Act No. 24 of 2007

අනුමැතියක් නොමැතිව වෙනත් කෙනෙකුගේ පරිගණකයට, උපාංගයකට හෝ ඒවායේ ඇති තොරතුරුවලට ඇතුළුවීම මෙම පනතින් වරදක් ලෙස සැලකේ. අනුමැතියෙන් තොරව හිතාමතා ප්‍රවේශ වීම දඬුවම් ලැබිය හැකි වරදකි.

Unauthorised access to another person's computer, device, or the information stored on it is an offence under this Act. Intentionally accessing without authorisation is punishable by law.

වරදවල්

Offences

දඬුවම්

Penalties

වරදOffence දඩයFine සිර දඬුවමImprisonment
සරල අනවසර ප්‍රවේශයSimple Unauthorised Access LKR 100,000 වසර 5ක් දක්වාUp to 5 years
අපරාධ අභිප්‍රාය සහිත ප්‍රවේශයAccess with Intent LKR 200,000 වසර 5ක් දක්වාUp to 5 years
⚠️ නවීන අවශ්‍යතා ⚠️ Modernisation Needed AI තාක්ෂණයෙන් සිදුවන අපරාධ සහ ක්‍රිප්ටෝ මුදල් වංචා වැනි නවීන තර්ජනවලට මුහුණදීමට මෙම පනත සංශෝධනය කිරීමට අවශ්‍ය බව පිළිගැනේ. There is consensus that the Act needs amendment to address modern threats like AI-driven crimes and cryptocurrency fraud.

පුද්ගලික දත්ත ආරක්ෂණ පනත අංක 9, 2022 Personal Data Protection Act No. 9 of 2022

මෙම පනත පුද්ගලික දත්ත සැකසීමට අදාළ වන අතර දත්ත හිමියන්ට ප්‍රවේශ වීමේ, නිවැරදි කිරීමේ, මැකීමේ සහ සැකසීමට විරුද්ධ වීමේ අයිතිවාසිකම් ලබා දෙයි.

This Act governs the processing of personal data and grants data subjects rights to access, rectify, erase, and object to the processing of their data.

දත්ත හිමියන්ගේ අයිතිවාසිකම්

Data Subject Rights

💰 දඬුවම් 💰 Penalties අනුකූල නොවීමකට රුපියල් මිලියන 10ක් දක්වා විධිමත් දඬුවම්. නැවත වරදක් සිදු කළහොත් මුල් මුදල මෙන් දෙගුණයක් අය කළ හැක. Up to LKR 10 million per non-compliance. Repeat offences can attract an additional penalty of twice the original amount.
📅 ක්‍රියාත්මක වීම පිළිබඳ යාවත්කාලීනය 📅 Enforcement Update දඬුවම් පැනවීමට අදාළ කොටස (VII කොටස) 2026 ජනවාරි 1 වන විට තවමත් ක්‍රියාත්මක නොවූ අතර, එම නිසා දත්ත ආරක්ෂණ අධිකාරියට දඩ නියම කළ නොහැකි විය. The section concerning administrative penalties (Part VII) was not yet in operation as of January 1, 2026, so the Data Protection Authority could not impose fines at that time.

සටහන: මෙම පනත බොහෝවිට ආයතන සහ දත්ත පාලකයන් (data controllers) ඉලක්ක කරයි. පෞද්ගලික හා ගෘහස්ථ භාවිතයන්ට ඇති බලපෑම පිළිබඳව තවදුරටත් පරීක්ෂා කිරීම අවශ්‍යයි.

Note: This Act mainly targets organisations and data controllers. Its impact on purely personal or household use requires further verification.

අන්තර්ජාල ආරක්ෂණ පනත අංක 9, 2024 Online Safety Act No. 9 of 2024

සමාජ මාධ්‍ය භාවිතයට අදාළව නව වරද කිහිපයක් මෙම පනතින් හඳුන්වා දෙයි. "තහනම් ප්‍රකාශ" සන්නිවේදනය කිරීම මෙහි ප්‍රධාන වශයෙන් තහනම් කෙරේ.

This Act introduces several new offences relevant to social media use. It primarily prohibits the communication of certain "prohibited statements" online.

වරදOffence දඩයFine සිර දඬුවමImprisonment
ද්වේෂය ඇති කිරීමPromoting Ill-Will LKR 500,000 වසර 5ක් දක්වාUp to 5 years
පෞද්ගලික තොරතුරු ප්‍රකාශයෙන් හිංසාවHarassment via Private Info LKR 500,000 වසර 5ක් දක්වාUp to 5 years
අන්තර්ජාල වංචාවOnline Cheating LKR 700,000 වසර 7ක් දක්වාUp to 7 years

ගුරුවරුන්ට ප්‍රායෝගිකව Practical Guide for Teachers

✅ අවසර ලැබූ ක්‍රියාකාරකම්

✅ Permitted Actions

❌ වරදක් විය හැකි ක්‍රියාකාරකම්

❌ Potentially Unlawful Actions

📜 අධ්‍යාපන අමාත්‍යාංශයේ 2024 චක්‍රලේඛය — ප්‍රධාන නිර්දේශ

📜 Ministry of Education Circular (Nov 2024) — Key Directives

💡 මතක තබා ගන්න 💡 Remember ඔබ සාමාජිකයෙකු වන සමූහයක පණිවිඩ කියවීම වරදක් නොවේ. ගැටලුව ඇති වන්නේ අවසරයකින් තොරව අනුන්ගේ දුරකථනයට/ගිණුමට ඇතුළු වීමෙනි. Reading messages in a group you belong to is not an offence. The problem arises when you access someone else's phone or account without consent.