Privacy Policy
Effective Date: 2 September 2026
Sri Lanka Computer Emergency Readiness Team | Coordination Centre (“Sri Lanka CERT”, “we”, “our” or “us”) respects the privacy of individuals who visit our website and use our online services.
This Privacy Policy explains how personal data and other information may be collected, used, protected and disclosed when you visit the Sri Lanka CERT website or interact with services available through it.
Sri Lanka CERT processes personal data in accordance with applicable Sri Lankan law, including the Personal Data Protection Act, No. 9 of 2022, as amended by the Personal Data Protection (Amendment) Act, No. 22 of 2025, where applicable.
1. Information We Collect
Information You Provide to Us
You may browse the Sri Lanka CERT website without providing your name, telephone number or email address.
However, personal data may be collected when you voluntarily submit information through a service available on this website. Depending on the service used, this may include:
- Your name;
- Email address;
- Telephone number;
- Organization or other information you choose to provide;
- The contents of messages or inquiries submitted to Sri Lanka CERT; and
- An email address submitted for a newsletter or security-information subscription.
Information requested through a website service will be limited to information reasonably required to provide the relevant service or respond to your request.
Cyber Security Incident Information
As part of its cyber security functions, Sri Lanka CERT receives and handles information relating to computer security incidents affecting individuals, organizations and digital infrastructure.
Incident information may contain personal data, technical information, indicators of compromise, system information, communications, evidence or other information necessary for incident handling, analysis and coordination.
Incident reports submitted through the official Incident Reporting Portal may also be subject to privacy and data-processing information provided through that system.
Technical and Security Information
When the website is accessed, Sri Lanka CERT's web infrastructure and associated security infrastructure may automatically process technical information necessary to operate, secure and troubleshoot the service.
Depending on the infrastructure involved, this may include:
- Network or source address information, including an IP address or proxy address;
- Date and time of a request;
- The requested page or resource;
- HTTP response status;
- The referring webpage, where provided by the browser;
- Browser and user-agent information; and
- Other technical information required for security monitoring, troubleshooting and service administration.
The web server hosting this website currently operates behind upstream security and proxy infrastructure. Accordingly, different components of the infrastructure may receive different connection information.
Web-server access and error logs on the current hosting server are rotated daily and are ordinarily retained for approximately 14 rotated days, in addition to the current active log. Security infrastructure outside the web server may be subject to separate operational and security-retention requirements.
2. How We Use Information
Information collected through this website may be used to:
- Operate, maintain and secure the website;
- Detect, investigate and respond to cyber security threats or misuse;
- Troubleshoot technical problems;
- Respond to inquiries and service requests;
- Provide requested Sri Lanka CERT services;
- Process newsletter or security-information subscriptions;
- Handle and coordinate cyber security incidents;
- Communicate with affected or relevant parties where required for incident handling;
- Maintain appropriate operational and security records;
- Comply with applicable legal and regulatory requirements; and
- Improve the reliability and security of our services.
Sri Lanka CERT does not sell personal data collected through this website.
3. Cookies and Browser Storage
Sri Lanka CERT has designed the current website to minimize unnecessary cookies and third-party tracking.
At the effective date of this Privacy Policy, ordinary browsing of the website does not use advertising or web-analytics cookies.
Language Preference
When you select a website language, your browser may store the selected language in local browser storage under a language-preference setting.
If you select Sinhala or Tamil, a functional
googtrans cookie is created so that the selected
translation can be applied. Google Translate is then loaded to
provide the requested translation.
Google Translate is not automatically contacted solely because a new visitor opens the website in English. Selecting English removes the translation cookie used by the website.
Local and Session Storage
The website may use browser local storage or session storage for limited functional purposes, including remembering a language selected by the visitor or maintaining temporary browser compatibility or interface state.
These mechanisms are not intended by Sri Lanka CERT for advertising profiling. Visitors may clear cookies, local storage and other site data using the controls provided by their web browser.
4. Third-Party Content and Services
Some website features use services operated by third parties. Sri Lanka CERT has configured certain third-party content so that it is not automatically loaded when the relevant page is opened.
Google Translate
Google Translate is loaded only after a visitor chooses a supported translated language such as Sinhala or Tamil. When Google Translate is activated, information such as the visitor's network address, browser information or other technical information may be transmitted to Google in accordance with Google's applicable terms and privacy practices.
YouTube
Videos displayed on the Media page use YouTube's privacy-enhanced domain and are configured to load only after the visitor chooses to load a video.
Once the visitor loads or interacts with YouTube content, information may be transmitted to YouTube or Google and cookies or similar browser technologies may be used in accordance with their policies.
Google Maps
Embedded Google Maps content is configured so that the map is loaded only after the visitor chooses to load it.
Once loaded, Google may receive technical information and may use cookies or similar technologies in accordance with its policies.
5. Disclosure and Incident Coordination
Sri Lanka CERT does not disclose personal data without an appropriate purpose or legal basis.
However, where necessary to provide cyber security incident handling and coordination services, relevant information may need to be shared with parties such as:
- The organization affected by an incident;
- Internet service providers;
- Hosting or technology providers;
- Other Computer Emergency Response Teams or Computer Security Incident Response Teams;
- Relevant overseas cyber security organizations;
- Organizations associated with suspected malicious infrastructure; or
- Competent public authorities where disclosure is required or permitted by law.
Where practicable and appropriate, information may be limited or sanitized to reduce unnecessary disclosure of information relating to the reporting party or affected organization.
Personal contact information of a person reporting an incident will not ordinarily be disclosed to unrelated third parties merely because an incident was reported.
6. Third-Party Websites
The Sri Lanka CERT website contains links to websites and services operated by government organizations, international organizations, private organizations, social-media platforms and other third parties.
When you follow a link to another website, that website is responsible for its own privacy, security, cookie and accessibility practices. Sri Lanka CERT does not control and is not responsible for the privacy practices or content of external websites.
7. Retention of Personal Data
Sri Lanka CERT retains personal data only for as long as reasonably necessary for the purpose for which it was collected, subject to applicable operational, evidentiary, legal, regulatory, cyber security and records-management requirements.
Different categories of information may therefore have different retention periods.
As described above, logs on the current website server are ordinarily maintained using approximately 14 daily rotated log files in addition to the current active log.
Incident records may need to be retained for longer periods where necessary for incident handling, evidence preservation, cyber security analysis, legal obligations or organizational records-management requirements.
8. Security of Personal Data
Sri Lanka CERT applies technical and organizational security measures intended to protect information under its control from unauthorized or accidental access, disclosure, alteration, loss, misuse or destruction.
These measures include controls relating to network security, endpoint security, access management, system hardening, monitoring and other cyber security safeguards where appropriate.
No Internet-based service can guarantee absolute security. Users should therefore take appropriate precautions when transmitting particularly sensitive information electronically.
Where secure or encrypted communication methods are made available by Sri Lanka CERT for sensitive incident or vulnerability information, users are encouraged to use those methods.
9. Your Data Protection Rights
Subject to the Personal Data Protection Act and any applicable conditions, limitations or exemptions, a data subject may have rights relating to personal data processed by Sri Lanka CERT, including the right to:
- Request access to personal data relating to them;
- Request correction or completion of inaccurate or incomplete personal data;
- Request erasure in circumstances provided by law;
- Withdraw consent where processing is based on consent;
- Object to or request that further processing cease in circumstances provided by law; and
- Exercise any other right available under applicable data-protection law.
A request may be subject to identity verification and any lawful restrictions applicable to the particular information or processing activity.
10. Contacting Sri Lanka CERT
Questions concerning this Privacy Policy or the processing of personal data through the Sri Lanka CERT website may be directed to Sri Lanka CERT using the official contact information published on this website.
Sri Lanka Computer Emergency Readiness Team | Coordination Centre
Room 4-112, BMICH
Bauddhaloka Mawatha
Colombo 07, Sri Lanka
Email: cert@cert.gov.lk
Telephone: +94 11 269 1692
Hotline: 101
Cyber security incidents should be submitted through the official Incident Reporting Portal where applicable.
11. Changes to This Privacy Policy
Sri Lanka CERT may update this Privacy Policy from time to time to reflect changes to website functionality, cyber security practices, legal requirements or data-processing activities.
The revised version will be published on this website with an updated effective date.