By Roy Denish.
Sri Lanka Police app data practices raise concerns over NIC scans, GPS tracking, private servers, AI tools and data protection safeguards.
Beneath the sleek veneer of the Sri Lanka Police’s newly launched official mobile app lies an alarming disregard for constitutional rights, data protection, and transparency. Barely a year after the farcical debut of its amateurish, sideloaded eTraffic platform which collapsed under basic scrutiny while the institution’s own social media accounts were simultaneously hacked the police have returned with a technically polished successor built by private developer Vampior Designs. Yet better code does not excuse systemic accountability failures. By demanding mandatory National Identity Card scans, routing sensitive citizen data and continuous SOS GPS trails to private foreign servers, and embedding unverified AI chatbots without guardrails, the police are once again asking the public to surrender their most sensitive personal information on blind faith.
An examination of version 1.0.11 of the Google Play build reveals an application that, while structurally superior to its predecessor by omitting commercial trackers and securing login credentials locally, suffers from profound institutional blind spots. Independent scrutiny of state backed software continues to take place exclusively after public release, forcing citizens into a reactive position in which accountability is almost entirely absent. E-government digitalisation should never require a population with a decades old, well documented trust deficit regarding state surveillance to simply trust an opaque digital tool.
The application’s data collection practices actively contradict its own public safety promises. Registration is tightly gated behind the mandatory upload of photographs of both sides of an individual’s NIC, while foreign nationals are required to submit passport numbers and photographs, and parents must provide their own identity documents on behalf of children. Vampior’s privacy policy completely omits these mandatory document uploads, while the Google Play Store’s data safety declarations drastically underreport the scope of information being collected by failing to disclose document images, voice recordings, and precise location tracking.
Equally troubling is the complete lack of architectural transparency regarding where this data is sent. Personally identifiable information, SOS live tracking streams, complaints, and chatbot conversations bypass official state domains such as police.lk and are routed instead directly to appv2.vampior.com, which sits behind Cloudflare’s global network. Although the app claims that the police will never share location details with third parties, its infrastructure relies heavily on foreign services while leaving the identities of private data handlers shrouded in mystery.
The high-stakes features of the app amplify these risks:
The SOS Live-Tracker: Pressing and holding the SOS button converts the phone into a continuous tracking device, transmitting precise GPS coordinates every two seconds, even when the screen is off, through background location access. Neither the privacy policy nor the in-app notices inform users that this may create a persistent movement history on a developer-managed server.
The AI Assistant Chatbot: Billed as a smart tool for legal guidance and complaint tracking, the chatbot contains no local AI processing. Every conversation packet is bundled with user account tokens and sent to external servers, potentially exposing private legal queries to unverified foreign AI providers, including services such as OpenAI or Chinese-developed alternatives.
Developer Sloppiness: Leftover developer logging writes registration details and one-time passcodes directly into system logs, creating a serious vulnerability that could expose sensitive user credentials on rooted handsets or through diagnostic reports.
As Sri Lanka prepares for the enforcement of the Personal Data Protection Act (PDPA) by January 2027, this app appears to fall far short of its expected standards. The legislation requires clear identification of data controllers, strict data minimisation, designated Data Protection Officer contacts, and explicit transparency regarding cross-border data transfers. The police app provides none of these elements, leaving responsibility, compliance, and avenues for redress entirely unclear.
Ultimately, the release of this app exposes a glaring institutional dissonance: an enforcement agency tasked with upholding the rule of law appears to be bypassing legal compliance frameworks while treating citizens’ constitutional right to privacy as an afterthought. When state authorities outsource digital infrastructure to private vendors without rigorous oversight, mandatory data protection impact assessments, or transparent data localisation controls, they do not merely build a flawed app, they institutionalise surveillance by proxy.
Until the Sri Lanka Police internalise the reality that public trust cannot be coded by third party contractors or papered over with empty privacy disclaimers, every state backed digital initiative risks remaining a liability disguised as a public service.
