Privacy Policy

E-Law Chambers – Law Firm Registration No. W/T/2/2397 Website: www.elawchambers.comLast updated: 24 September 2026

This Privacy Policy governs the collection, use, disclosure, transfer, retention, storage and protection of Personal Data by E-Law Chambers, Law Firm Registration No. W/T/2/2397 (hereinafter referred to as "We," "Us," "Our," or "ELC"). It applies to all individuals and entities ("you," "your") who access our website, www.elawchambers.com (the "Website"), who use our client portal (the "Customer Portal"), or who otherwise share Information with us, including clients, prospective clients, beneficial owners, authorised representatives, staff members and job applicants.

For the avoidance of doubt, this Privacy Policy forms part of the Terms of Use of this Website and the Customer Portal and should be read in conjunction with them.

At ELC, we value your privacy and are dedicated to ensuring the protection and responsible handling of your Personal Data in compliance with all applicable laws. Your privacy is protected, and your Personal Data is processed only as described in this Policy.

1. Definitions

For the purposes of this Privacy Policy:

"Consent" means any freely given, specific, informed and unambiguous indication, by way of a written declaration or an affirmative action, signifying your agreement to the Processing of your Personal Data.

"PDPA" means the Personal Data Protection Act, No. 9 of 2022 of Sri Lanka.

"FTRA" means the Financial Transactions Reporting Act, No. 6 of 2006 of Sri Lanka, together with all rules, regulations, directions and guidelines issued under it, including the Customer Due Diligence requirements applicable to Designated Non-Finance Businesses and Professions.

"AML/CFT Laws" means the FTRA, the Prevention of Money Laundering Act, No. 5 of 2006, the Convention on the Suppression of Financing of Terrorism Act, No. 25 of 2005, and any related laws, regulations, rules and directions, each as amended from time to time.

"CDD" means Customer Due Diligence, being the identification and verification of clients, their beneficial owners and persons acting on their behalf, understanding the purpose and nature of the business relationship, and ongoing monitoring, as required under the AML/CFT Laws.

"FIU" means the Financial Intelligence Unit of the Central Bank of Sri Lanka, or any successor authority.

"Customer Portal" means the secure online portal made available by ELC to clients for submitting documents and information, completing onboarding and CDD requirements, communicating with us and accessing matter-related information.

"Processing" means any operation performed on Personal Data, including collection, storage, preservation, alteration, retrieval, disclosure, transmission, making available, erasure, destruction, consultation, alignment, combination, or the carrying out of logical or arithmetical operations.

"Personal Data" means any information that can identify you directly or indirectly, by reference to: (a) an identifier such as a name, an identification number, financial data, location data or an online identifier; or (b) one or more factors specific to the physical, physiological, economic, cultural or social identity of that individual or natural person.

"Special Categories" means Personal Data revealing racial or ethnic origin, political opinions, religious or philosophical beliefs, genetic data, biometric data processed for the purpose of uniquely identifying a natural person, data concerning health or a natural person's sex life or sexual orientation, Personal Data relating to offences, criminal proceedings and convictions, or Personal Data relating to a child.

Other defined terms used herein have the meanings given in this Privacy Policy or, in their absence, in the PDPA.

2. Personal Data collected by ELC

The Personal Data we collect may include (but is not limited to):

  • your name, gender and contact particulars, including telephone number(s), residential/mailing address(es) and e-mail address(es);
  • information from identification documents, such as NIC, passport and driving licence numbers, together with details of visas and permits, including employment passes, work permits and residency status, and biometric data where required;
  • CDD and KYC information, including proof of identity and address, date and place of birth, nationality, occupation, source of funds and source of wealth, the purpose and

intended nature of the business relationship, information on politically exposed person (PEP) status, and sanctions and adverse-media screening results;

  • beneficial ownership and corporate information, including details of directors, shareholders, secretaries, ultimate beneficial owners, persons exercising control and authorised signatories of entities that instruct us;
  • transaction information, including details of transactions and funds handled or facilitated by us on your behalf, relevant bank and payment particulars, and the parties involved;
  • financial information, including bank account details, salaries, bonuses and fees;
  • professional background information, including employment and training history and academic and professional qualifications;
  • name and contact details of an individual's next-of-kin;
  • Customer Portal information, including login credentials, user identifiers, documents and files uploaded, messages, activity and audit logs, and account settings;
  • information collected during your use of the Website, including device identifiers, IP addresses, browser types, pages viewed, operating systems, and the timing, frequency and pattern of visits and interactions;
  • Special Categories of Personal Data, which may include information about your health, race, ethnicity, religious beliefs or criminal records, where relevant to a matter or required by law;
  • legal and compliance information, including case details, legal documents and any other information necessary for the provision of legal services;
  • information we receive from third parties, such as public registers and records, screening providers and social media platforms; and
  • any other information that may be construed as "Personal Data" under the PDPA and is collected through our interactions and operations.

3. How ELC collects your Personal Data

We may collect your Personal Data through various channels, including:

  • Personal Data that you provide directly to us when you engage our legal or other professional services, register for or use the Customer Portal, complete onboarding or CDD forms, fill out forms, contact us, or otherwise communicate with us, whether through the Website, e-mail, correspondence, telephone or in person;
  • Personal Data automatically collected when you visit our Website or use the Customer Portal, through cookies, web beacons and similar technology;
  • Personal Data received through referrals or references from business partners or other third parties, including other law firms and professional service providers;
  • Personal Data received when you participate in or attend events hosted or organised by ELC;
  • Personal Data obtained from third parties such as public registers, the Registrar of Companies, screening and verification providers, social media platforms and other service providers, where you have made that information available or where it is provided to us in the course of our services;
  • Personal Data collected in the course of providing legal services, including from documents, communications and other sources relevant to your matter, and data shared with us by other parties involved;
  • when we communicate with other legal entities, government bodies, regulators, financial institutions or third-party service providers in relation to your matter;
  • when you provide Personal Data as part of an employment application or in connection with the provision of goods or services; and
  • when you submit Personal Data to ELC for any other purpose related to ELC's business operations.

4. How ELC Processes your Personal Data

We will Process Personal Data only to the extent necessary and proportionate to achieve the specific purposes set out below:

  1. Provision of legal and professional services, including legal advice, company secretarial services, representation in legal proceedings, preparation of legal documents and all related activities as instructed by you;
  2. Client onboarding and Customer Portal services, including account creation, authentication, secure document exchange and communication;
  3. Compliance with the AML/CFT Laws, including:
  • conducting CDD, enhanced due diligence and ongoing monitoring;
  • identifying and verifying clients, beneficial owners and persons acting on behalf of clients;
  • screening against sanctions lists, PEP lists and other risk databases;
  • risk-assessing clients, matters and transactions;
  • maintaining records as required by law;
  • detecting and reporting suspicious transactions and any other reports required to be made to the FIU or other competent authorities; and
  • responding to lawful requests and directions of the FIU, supervisory bodies and law enforcement;
  1. client relationship management, including communication, billing and updates on your matters;
  2. compliance with other legal, regulatory and professional obligations, including conflict checks;
  3. supporting ELC's internal operations, including audits, quality control and data analysis;
  4. ensuring the security of our Website, Customer Portal, premises and information systems, including preventing fraud, unauthorised access or other malicious activity;
  5. managing relationships with employees, consultants and vendors, including recruitment and contract management; and
  6. pursuing other Legitimate Interests (as defined below).

5. Financial Transactions Reporting Act, CDD and AML

compliance ELC is a law firm that, when carrying out certain activities for clients, is subject to obligations under the FTRA and the other AML/CFT Laws. You acknowledge and agree that:

  1. CDD is mandatory. We are required by law to identify and verify the identity of our clients, their beneficial owners and persons acting on their behalf before, and in some cases during, the course of a business relationship. We may be unable to act for you, or may be required to cease acting, if you do not provide the information and documents we request.
  2. Ongoing monitoring. We may review client information and transactions throughout the relationship to ensure they are consistent with our knowledge of you, your business and your risk profile, and we may request updated information and documents at any time.
  3. Reporting. Where required by the AML/CFT Laws, we may report suspicious transactions and other information to the FIU or another competent authority. We are prohibited by law from informing you or any other person that such a report has been made or is being considered ("tipping off").
  4. Processing without Consent. Processing for AML/CFT compliance is carried out to comply with a legal obligation. It therefore does not depend on your Consent, and withdrawal of Consent will not prevent us from Processing, retaining or disclosing Personal Data as required by law.
  5. Record retention. We will retain CDD records, transaction records and related correspondence for the minimum periods required by the AML/CFT Laws (currently not less than six (6) years, or such longer period as may be required by law or by a competent authority), even after the business relationship has ended.
  6. Restrictions on your rights. To the extent permitted by the PDPA and the AML/CFT Laws, we may refuse or limit requests for access, erasure or restriction of Personal Data where compliance would breach our legal obligations, prejudice an investigation, or constitute tipping off.
  7. Professional privilege. Nothing in this Policy waives legal professional privilege or the duty of confidentiality that we owe to clients. We will disclose privileged information only where the law requires or expressly permits us to do so, and only to the extent required.

6. Customer Portal

If you use the Customer Portal:

  • you are responsible for keeping your login credentials confidential and for all activity under your account. You must notify us immediately of any unauthorised use;
  • documents and information you upload are used to provide our services, to carry out CDD and to meet our legal obligations;
  • we log activity on the Customer Portal (for example, log-ins, uploads and downloads) for security, audit and compliance purposes;
  • we apply access controls so that only authorised personnel with a need to know can view your information;
  • where you submit information about other individuals (for example, directors, shareholders, beneficial owners or next-of-kin), you confirm that you are authorised to provide it and that you have informed them that their Personal Data will be processed in accordance with this Policy; and
  • we may suspend or restrict your access where we suspect misuse, a security risk, or a breach of our terms or of the law.

7. Legal basis for Processing Personal Data

In accordance with the PDPA, we rely on the following grounds for Processing your Personal Data:

  • (a) you have given Consent;
  • (b) the Processing is necessary to fulfil a contract to which you are a party, or to take steps at your request before entering into a contract;
  • (c) the Processing is necessary to address an emergency that poses a threat to the life, health or safety of you or another individual;
  • (d) the Processing is necessary to comply with a legal obligation to which ELC is subject, including obligations under the FTRA and other AML/CFT Laws;
  • (e) the Processing is necessary to perform a task carried out in the public interest or to exercise powers, functions or duties assigned to ELC under applicable laws, including government-issued circulars, directives or codes; or
  • (f) the Processing is necessary to achieve the "Legitimate Interests" of ELC or a third party, unless overridden by the interests of a data subject which require the protection of personal data (in particular where the data subject is a child).

As per Schedule I of the PDPA, "Legitimate Interest" includes:

  • Processing in scenarios where you are a client or are providing services to ELC;
  • where you can reasonably be deemed to expect, at the time and in the context of collection, that your Personal Data may be Processed for that purpose;
  • where Processing is strictly necessary for the purpose of preventing fraud; and
  • Processing to the extent strictly necessary and proportionate for ensuring network and information security.

Although your express Consent is a primary basis for Processing, there are situations where we may lawfully Process your Personal Data without it, including where Processing is necessary to comply with legal obligations (including AML/CFT obligations), fulfil contractual requirements, or pursue Legitimate Interests. Even if you withdraw your Consent, it may still be lawful for us to continue Processing where one or more of the other legal grounds applies.

8. How ELC protects your Personal Data

We are committed to upholding your rights and ensuring the integrity and confidentiality of your Personal Data by implementing physical, electronic and managerial measures to protect it from unauthorised access, disclosure, alteration or destruction. These include:

  • education and training for relevant staff on privacy, confidentiality and AML/CFT obligations;
  • administrative and technical controls restricting access to Personal Data on a need-to-know basis;
  • technological security measures such as firewalls, encryption, secure authentication and antivirus software;
  • access logging and audit trails on the Customer Portal;
  • physical security measures, including controlled access to our premises; and
  • limiting the collection and retention of Personal Data to what is necessary and proportionate for the purposes in this Policy.

While we implement reasonable security measures, no method of internet transmission or electronic storage is completely secure. We cannot guarantee absolute security of data sent to or from us over the internet, and by providing us with your Personal Data you acknowledge and accept these risks. In the event of a personal data breach, we will notify the Data Protection Authority and affected individuals where required by the PDPA.

9. Sharing your Personal Data

We may disclose or share the Personal Data we collect in the following circumstances:

9.1 Within ELC. Access is restricted to those within ELC who need it to fulfil the purposes in this Policy, on a need-to-know basis. All personnel are required to handle Personal Data confidentially and in accordance with our security protocols.

9.2 Third parties. We may share Personal Data (wherever located) with third parties only for purposes consistent with this Policy. These may include affiliated entities, persons connected with the provision of legal or professional services to you (including transactional or dispute counterparties and their advisers), the Registrar of Companies and other government registries, banks and financial institutions, identity verification and screening providers, IT service providers, cloud and data storage providers, data processors and payment processors.

9.3 Mandatory disclosures. We may disclose information where required by law or necessary to comply with a court order, judicial or governmental warrant, or to cooperate with law enforcement or other government agencies. This includes disclosures and reports to the FIU, the Central Bank of Sri Lanka, supervisory authorities and law enforcement under the AML/CFT Laws, which may be made without notice to you where the law so requires.

9.4 Transfers outside Sri Lanka. Personal Data in our possession may be transferred to other countries for any of the purposes in this Policy, including where our service providers or cloud infrastructure are located abroad. Such countries may have differing laws on confidentiality, and information may become subject to disclosure requirements in those countries. When we, or our permitted third parties, transfer information outside Sri Lanka, we or they will impose contractual or other safeguards on recipients to protect it to the standard required under Sri Lankan law, and will comply with the cross-border transfer requirements of the PDPA.

We do not sell your Personal Data.

10. Cookies and tracking technology

Our Website and Customer Portal use cookies and similar technology to improve your experience, analyse usage and manage site performance. Cookies are small data files placed on your device to recognise it, remember your preferences and improve functionality.

The types of cookies we use are:

  • Strictly Necessary Cookies: essential for core functions such as secure log-in, session management and site navigation. Without them, certain features (including the Customer Portal) may not operate correctly.
  • Performance Cookies: gather data on how you interact with our site, such as which pages are most visited, to help us enhance performance and user experience.
  • Functionality Cookies: remember your preferences and settings, such as language, to offer a more customised experience.

Managing cookies. You can control cookies through your browser settings. Most browsers allow you to refuse or delete cookies; however, disabling cookies may affect your ability to use certain features. A notification banner on our Website gives you the option to manage your cookie consent.

From time to time, our pages may include third-party tools and widgets which may place cookies on your device, subject to your browser settings and cookie preferences. Cookies do not give us your e-mail address or personally identify you. In our analytics we may collect identifiers such as IP addresses, but solely to determine the number of unique visitors and not to identify individual users.

11. Your rights and choices

Under the PDPA, you have certain rights regarding your Personal Data, including:

  • Right to request access: to the Personal Data we hold about you and how it is being used;
  • Right of withdrawal: to withdraw your Consent at any time by written request. Withdrawal does not affect the lawfulness of Processing before withdrawal, or our right to Process without Consent under applicable law;
  • Right to request rectification or completion: where the Personal Data we hold is inaccurate or incomplete;
  • Right to request erasure: in certain circumstances, such as when the data is no longer necessary for its original purpose or you withdraw Consent and no other legal basis applies;
  • Right to refrain from further Processing: where Processing is based on the grounds in items (e) or (f) of Schedule I or item (f) of Schedule II of the PDPA;
  • Right to review a decision based solely on automated processing: where it has a significant or continuing impact on your rights or freedoms; and
  • Right of appeal: to the Data Protection Authority of Sri Lanka if we refuse to act on your request for access, rectification or erasure.

Limits on these rights. As explained in Section 5, these rights are subject to our obligations under the AML/CFT Laws and other applicable law, including retention requirements, the prohibition on tipping off, and legal professional privilege. Where we cannot fully comply with a request, we will tell you, to the extent the law allows, and will explain your right of appeal.

To exercise your rights, contact our Data Protection Officer using the details in Section 16.

ELC will take reasonable steps to ensure that the Personal Data we process is accurate and up to date. However, we will not be liable for any issues arising from our services if the Personal Data you provide is incomplete or inaccurate, or if you do not inform us of relevant changes in a timely manner.

12. Data retention

We retain your Personal Data only for as long as reasonably necessary to fulfil the purposes in this Policy or as required by law. In particular:

  • AML/CFT records (CDD documents, beneficial ownership information, transaction records and related correspondence) are retained for the period required by the AML/CFT Laws, currently not less than six (6) years, or longer if required by law or a competent authority;
  • client files and legal records are retained for the period required by professional rules, limitation periods and our legal obligations; and
  • Customer Portal data and logs are retained for as long as your account is active and thereafter for the periods above.

When Personal Data is no longer required, we will securely delete, anonymise or pseudonymise it.

13. Links to other websites

This Website may contain links to third-party websites that we do not own or control. We are not responsible for their privacy practices, content or activities. This Privacy Policy does not apply to such sites. By accessing third-party links you acknowledge and agree that we are not liable for any loss or damage arising from your use of them.

14. Changes to this Privacy Policy

ELC may modify or update this Privacy Policy at any time. Changes take effect immediately upon posting on our Website. Where a change materially affects your rights or obligations, we will make reasonable efforts to notify you, and where a change requires your renewed Consent, we may ask you to review and accept the updated terms.

15. Governing law and jurisdiction

This Privacy Policy, and any dispute or claim arising out of or in connection with it, is governed by and construed in accordance with the laws of the Democratic Socialist Republic of Sri Lanka.

Any legal action or proceeding arising out of or related to this Privacy Policy shall be brought exclusively in the courts of Sri Lanka. By agreeing to this Privacy Policy, you consent to the jurisdiction of, and venue in, such courts and waive any objection to such jurisdiction or venue.

16. Data Protection Officer and contact

ELC has appointed a Data Protection Officer (DPO) to oversee compliance with the PDPA and to address any concerns or questions about the Processing of your Personal Data. If you have any questions, concerns or requests relating to your Personal Data, your rights or this Privacy Policy, you may contact our DPO:

Name: The Data Protection Officer Firm: E-Law Chambers (Law Firm Registration No. W/T/2/2397) Address: No. 104, Royal Pearl Garden, A.S.P. Liyanage Mawatha, Wattala, Sri Lanka E-mail: dpo@elawchambers.com Telephone: 011 2 930 929 Website: www.elawchambers.com