The 2026 Sri Lanka Police app: Another compliance failure?

By Dr Sanjana Hattotuwa

In early 2025, Sri Lanka Police launched eTraffic under the government’s ‘Clean Sri Lanka’ programme. It skipped Google’s Play Store entirely, required sideloading from a Vercel website, sought background location, camera and storage access, and carried a tragi-comically weak privacy policy. That same week, hackers had seized the Police’s own social media accounts. I critiqued it on launch day. Two days later, when confronted with questions posed by journalists who had read my article, the then Police Media Spokesman insisted there was “only a connection through an account”, revealing how little to nothing the institution understood about data security, and the right to privacy.

News reports now indicate the Police launched the eponymous ‘Sri Lanka Police’, built by Vampior Designs (Private) Limited, with an SOS button, reporting to specialised units, and a chatbot.

I examined version 1.0.11, the Google Play release, using a copy of the installation file (i.e., the APK) whose digital signature confirms it as Google’s own build. Though I did not install or run the app, I deconstructed it, and read what it contains – permissions, web addresses, labels buried in its code, certificates etc, and also checked where its servers sit. I then compared the findings with the app’s Google Play data safety declaration and the developer’s own privacy policy.

For starters, this app is far better built than eTraffic, and carries no advertising, analytics or social media trackers, encrypts everything in transit, locks login credentials in the phone’s secure storage, offers a fingerprint lock, and detects tampered phones and faked GPS to deter hoax alerts.

Nothing in the app’s code suggests it reads SMS messages, contacts or call logs, captures the screen, or listens in the background. Generally competent coding, however, is not the end of it.

Sri Lanka’s Police have given citizens no reason to trust them offline or online with anything, and especially personally identifiable information (PII) like NIC details. Independent scrutiny of apps launched by Police only ever occur after their public release, which is to get things completely backwards. E-government, and digitalisation should not ask citizens to blindly accept or install official apps especially given decades-old, significant, and enduring trust deficits in large sections of our society around anything to do with the state’s involvement in personal lives, and information.

This app, albeit to a somewhat lesser degree than the one in 2025, is a case study in the general lack of any rights respecting guardrails, and compliance testing in what the government rolls-out – which is a significant, and growing issue I’ve written about at length.

As flagged in some news reports, registration for this app asks for your national identity card (NIC) number and photographs of both sides of the card. Foreign nationals hand over passport numbers and photos. Children without an NIC register through a parent or guardian, whose NIC number and card photos the app also takes. The code includes a feature that detects NIC details in photos. An SOS alert feature can add voice recordings, photographs and a GPS trail. Vampior’s privacy policy names none of this, listing name, email and phone number before relying on a catch-all for “other information that you voluntarily provide”. There is nothing voluntary about a registration screen that will not proceed without submitting both sides of one’s NIC. The Play Store declaration lists name, address, phone number, and approximate location. No mention of identity numbers, document images, voice recordings or precise location (when activated, which is thus a feature in the app).

Tellingly, PII submitted through the app, as well as SOS location streams, complaints and chatbot conversations do not travel to police.lk but to appv2.vampior.com, the developer’s own domain, sitting behind Cloudflare, a US company routing traffic through servers worldwide. There may be good reasons for this, but there’s zero documentation around where the data ends up, why those choices were made, or whether it stays in Sri Lanka. Google handles all the notifications, maps and embedded videos. Yet the app promises that Police “will not share your location or any details with third parties”, which is, prima facie, a claim its own architecture contradicts. Google lets developers exclude service providers when declaring sharing, so the Play Store’s “no data shared” label isn’t very helpful. At launch, Police mentioned only an unnamed private partner, leaving it to our imagination as to who this could be.

The SOS button is, in practice, a live tracker, since pressing and holding it sends precise GPS coordinates to the server every two seconds while the alert stays active, including with the screen off, which background location access permits. This obviously has its uses, and is only activated on-demand. That said, the privacy policy and in-app notice speak only of location-based features and location during SOS. Neither tells users that SOS means continuous tracking, feeding a server that also keeps an SOS history. What may save a life will likely generate official plaudits, but from a rights, and privacy-first perspective, citizens deserve to know how long the server keeps their movement records.

The ‘Interactive AI Police Assistant’ chatbot is also rather problematic. The About screen describes it as: “Smart conversational bot offering instant legal guidance, complaint tracking, and station locations.” The app promotes it as offering instant legal guidance, complaint tracking and station locations, yet the app itself contains no AI code. Every message, along with the conversation so far, goes to the developer’s own servers at appv2.vampior.com. When you are logged in to the app, each request carries tokens that tie the chat to your NIC-based account. The app does not reveal what AI model is used for inference (i.e., to answer queries). It could be a developer hosted AI model or relay content, and commentary to a foreign AI company such as OpenAI or a Chinese variant in mainland China. Users simply have no idea, and given how the chatbot is presented, including for ‘legal guidance’ (which I didn’t test), this is potentially a nightmare for end-user privacy. To wit, the respective privacy policies do not mention chatbot transcripts, and nothing discloses how long Vampior keeps them or how anyone can delete them.

The app stores a registered user’s actual password on the phone, albeit in encrypted form. Bizarrely, however, there’s leftover developer logging left in the app (which is very sloppy) that writes registration details, and one-time passcode responses into system logs that diagnostic reports or rooted handsets have a very high likelihood of exposing. In other words, the PII stored on the phone isn’t as secure as it should be. Vampior’s verified servers can also potentially block access, force updates (which may introduce new features, and substantially change the way the app works), and restrict SOS to certain areas. Who potentially decides which parts of the country get an SOS button, and why is this an architectural consideration?

Whether any of this is lawful can be established by mapping the app’s features, and failings against Gazette of 22 July 2026, which brings sections 2 and 3, and Parts I and III, of the Personal Data Protection Act (PDPA) by 1 January 2027 (Part II’s rights and Part VII’s penalties still await an implementation date, which is its own story). From January, Schedule V obliges controllers to tell people who the controller is, what data they collect, who receives it, whether it leaves the country and how long they keep it. The app and its policies fall way short on each count. Nobody can say whether Police, Vampior or both act as controller, which leaves duty, disclosure and redress unattached to anyone. Section 7 demands proportionate collection, yet registration takes an NIC number and both sides of the card. Children’s data, and photographs that may reveal ethnicity, fall into special categories under Schedule II’s stricter conditions. Section 20 requires a government department to publish a Data Protection Officer’s contact details. I found none. The 2022 text kept public authorities’ data in Sri Lanka by default, though the 2025 amendment scrapped it, barring transfers abroad only for categories the Minister prescribes. Other transfers need compliance with the Act’s core duties or an exception such as informed, explicit consent, but the Police app’s silence on server location(s) makes neither verifiable. On current evidence, at the time of writing, the ‘Sri Lanka Police’ app would emphatically not meet the PDPA’s transparency, minimisation and accountability requirements on 1 January 2027 – which in turn suggests the Police have no clue about compliance, why it is not something optional even today or how it can be engineered in their digitalised service delivery.

None of this inspires any confidence in precisely what’s sorely lacking in Sri Lanka, and the Police rightly seek to establish – a general public that trusts the institution, and uses what it puts out to strengthen public safety, and security. Beyond any one app, the greater tragedy may well be in the near impossibility to find anyone within the institution who appreciates this fully.

 

The post The 2026 Sri Lanka Police app: Another compliance failure? appeared first on Newswire.

Comments (0)
Add Comment