PERSONAL DATA PROTECTION ACT COMPLIANCE
Last Updated: 21/09/2026
1. Purpose of This Statement
This statement describes how Kotipathi, operated by PikLig Developers ("we", "us", "our"), complies with the Personal Data Protection Act, No. 9 of 2022 of the Democratic Socialist Republic of Sri Lanka (the "PDPA" or "the Act"). It is a companion to our Privacy Policy and provides the Schedule V information required under Section 11 of the Act in a consolidated, accessible form.
The Act was certified on 19 March 2022. Parts I, II, III and VII (substantive obligations, data subject rights, and penalties) are being brought into force on a schedule determined by the Minister by Gazette. This statement will be updated as the enforcement timetable evolves and as rules, regulations, directives and guidelines are issued by the Data Protection Authority of Sri Lanka ("the Authority").
2. Controller Identity and Contact
- Controller: PikLig Developers (operator of Kotipathi)
- Website: www.kotipathi.lk
- Email (general): [email protected]
- Contact page: /contact
3. Data Protection Officer
Where designation or appointment of a Data Protection Officer (DPO) is required under Section 20 of the Act and any rules made thereunder, the DPO can be contacted at:
- Email: [email protected] (subject line: "DPO")
- Responsibilities: advising on data protection obligations, monitoring compliance, advising on data protection impact assessments, liaising with the Data Protection Authority of Sri Lanka, and serving as a point of contact for data subjects.
4. Lawful Basis for Processing (§5, Schedule I & II)
We do not collect directly identifying personal data from you (see Section 2.1 of our Privacy Policy). We do not ask for your name, email, phone number, address, NIC number, or any government-issued identification. Where personal data is processed incidentally (for example, an anonymous authentication identifier, cookies, or analytics signals), we rely on one or more of the following lawful bases under Schedule I of the Act:
- Legitimate interests — for delivering the lottery-results service, preventing fraud and abuse, protecting network and information security, and improving reliability; always balanced against your rights and freedoms (Schedule I(f), as clarified by item (h) of Schedule I).
- Consent — for non-essential processing such as analytics, advertising personalisation, and similar optional features (Schedule I(a), Schedule III). Consent is freely given and can be withdrawn at any time.
- Contract / pre-contract — to the extent the service you request constitutes a contractual relationship, to provide that service (Schedule I(b)).
- Legal obligation — where we must process data to comply with Sri Lankan law (Schedule I(c)).
We do not deliberately collect the special categories of personal data listed in Schedule II of the Act (data revealing racial or ethnic origin, political opinions, religious or philosophical beliefs, genetic data, biometric data for the purpose of uniquely identifying a natural person, data concerning health, sex life or sexual orientation, or personal data relating to offences, criminal proceedings, convictions, or to a child).
4A. No Feature Is Gated Behind Data Provision
Provision of personal data is voluntary and is not a requirement (whether statutory, contractual, or otherwise) for using the Services. You may use the lottery-results features, scan, search, history, and all other functionality without submitting any personal data, without creating an account, and without providing identifying information of any kind. If you decline cookies, decline analytics, decline advertising personalisation, or decline to contact us, we do not restrict, disable, or degrade any feature of the Services. This satisfies the information requirement in item (l) of Schedule V of the Act.
5. Your Rights as a Data Subject (Part II)
Under Part II of the Act, every data subject has the following rights, which we facilitate through our Data Subject Rights Request process:
- Right of access (§13) — confirmation of processing and a copy of your personal data together with the Schedule V information.
- Right to withdraw consent and right to object (§14) — at any time, for processing based on consent or on certain legitimate interests.
- Right to rectification or completion (§15) — correction of inaccurate or incomplete data.
- Right to erasure (§16) — deletion of personal data in the circumstances specified in the Act.
- Right regarding automated individual decision-making (§18) — you may request a review of decisions based solely on automated processing that have an irreversible and continuous impact on your rights and freedoms.
- Right of appeal (§19) — to the Data Protection Authority of Sri Lanka against our decisions on the rights above.
We respond to requests made under §§13–16 within 21 working days as required by §17 of the Act. If we refuse a request, we will inform you of the reasons (unless disclosure is prohibited by law) and of your right to appeal.
6. Transparency Information (§11 + Schedule V)
The full Schedule V information set is provided in our Privacy Policy. In summary, you will find there: our identity and contact details; DPO contact; the purposes and legal basis for processing; our legitimate interests where relied upon; the categories of personal data collected; the procedure to withdraw consent; recipients or third parties with whom data may be shared; information on any cross-border transfers; retention periods; the procedure for exercising data subject rights; the right to complain to the Data Protection Authority; whether data provision is a statutory or contractual requirement; and information about automated decision-making.
7. Cross-Border Data Flow (§26)
To deliver the service, certain personal data is processed outside Sri Lanka by trusted service providers. As of the date of this statement, this includes:
- Google Cloud (Firebase) — asia-south1 (Mumbai, India) for application hosting, authentication, callable functions, App Check, and performance monitoring.
- Google (multi-region) for Google Analytics, Google AdSense, and reCAPTCHA.
- Scanbot SDK (license validation) — barcode decoding is performed on-device; licence validation is contacted periodically.
Such transfers are carried out in reliance on one or more of the mechanisms envisaged in §26(3)–(5) of the Act and the related directives of the Authority, which may include: (a) an adequacy decision by the Minister, if and when made; (b) binding corporate rules, agreements, codes of conduct or certification schemes recognised by the Authority (including APEC Cross-Border Privacy Rules, Europrivacy, and EU/Switzerland/United Kingdom GDPR certifications); (c) a cross border processing impact assessment; or (d) your explicit consent after being informed of the absence of an adequacy decision or appropriate safeguards.
Where we rely on your explicit consent for a transfer, you will be informed of the possible risks and you may withdraw that consent at any time as described in Section 5 above.
8. Retention (§9)
Personal data is kept only for as long as necessary for the purposes for which it was collected, unless a longer period is required or permitted by law. In particular, analytics and diagnostic data are retained for limited periods set by the relevant processor, and locally cached data on your device is subject to a rolling retention window which you can reset at any time from within the application.
9. Security, Integrity and Confidentiality (§10)
We apply appropriate technical and organisational measures to protect personal data against unauthorised or unlawful processing and against loss, destruction or damage. These include HTTPS with strict transport security, Firebase App Check backed by reCAPTCHA v3, least-privilege access to backend services, encryption in transit, and provider-managed encryption at rest.
10. Personal Data Breach Notification (§23)
In the event of a personal data breach that is likely to result in a risk to the rights and freedoms of data subjects, we will notify the Data Protection Authority of Sri Lanka in the form, manner, and timing determined by the rules made under the Act. Where a breach is likely to result in a high risk to rights and freedoms, we will also notify affected data subjects without undue delay, using a means of communication reasonably calculated to reach those affected, together with guidance on mitigating steps that data subjects may take.
11. Accountability and Data Protection Management Programme (§12)
We are implementing a Data Protection Management Programme ("DPMP") in line with Section 12 of the Act and the guidelines issued by the Authority. This programme is designed to establish and maintain duly catalogued records of processing activities; to provide appropriate safeguards based on personal data protection impact assessments where required under §24; to integrate data protection into our governance structure; to provide a mechanism to receive complaints, conduct inquiries, and identify personal data breaches; and to facilitate the exercise of data subject rights under Part II.
12. Children
The service is not directed to children and lottery-related content is intended for persons of lawful age to participate in lotteries under the laws of Sri Lanka. Personal data relating to a child (a natural person below the age of sixteen years) is a special category under Schedule II of the Act. We do not knowingly collect such data; where consent is relied upon for a child, consent of the parent or legal guardian is required. If you believe a child has provided us with personal data, please contact us using the details above and we will take appropriate steps to remove it.
13. Right to Complain to the Data Protection Authority of Sri Lanka
Without prejudice to any other remedy, you have the right to lodge a complaint with the Data Protection Authority of Sri Lanka:
- Website: www.dpa.gov.lk
- Email: [email protected]
- Address: First Floor, Block 5, BMICH, Bauddhaloka Mawatha, Colombo 07, Sri Lanka.
14. Related Policies
- Privacy Policy — full Schedule V information set.
- Cookie Policy — categories of cookies and how to manage them.
- Data Subject Rights Request — how to exercise your §§13–16 rights.
- Terms of Service
Last updated: 21/09/2026