Saturday, September 12, 2026

The 2026 Sri Lanka Police app: Another compliance failure?

Sri Lanka's push toward digital governance has long been celebrated as a step in the right direction. However, a closer examination of the country's latest law enforcement technology initiative raises uncomfortable questions about accountability, transparency, and legal compliance. The 2026 Sri Lanka Police app, an extension of the earlier eTraffic platform launched in early 2025 under the government's ambitious 'Clean Sri Lanka' programme, appears to be repeating the same mistakes that plagued its predecessor. For a nation striving to modernize its public institutions, the pattern of compliance failures is becoming increasingly difficult to ignore.

The Origins of eTraffic and the Clean Sri Lanka Programme

When Sri Lanka Police introduced eTraffic in early 2025, it was positioned as a landmark achievement in the country's digital transformation journey. Operating under the broader umbrella of the 'Clean Sri Lanka' programme, the app was designed to streamline traffic enforcement, reduce corruption at the point of interaction between officers and citizens, and bring greater efficiency to road safety management. On paper, the goals were admirable. In practice, however, the implementation raised red flags almost immediately among digital rights advocates, legal experts, and civil society organizations who scrutinized the app's underlying framework.

Critics noted that the eTraffic app lacked adequate privacy disclosures, did not clearly articulate how user data would be stored or shared, and appeared to have bypassed standard regulatory review processes that are typically required for government-facing digital platforms. Despite these concerns, the app was rolled out broadly, setting a troubling precedent for what would follow in 2026.

What the 2026 Police App Gets Wrong

The 2026 iteration of the Sri Lanka Police app, analyzed by digital governance researcher Dr. Sanjana Hattotuwa, appears to carry forward many of the same structural and procedural deficiencies that defined its predecessor. According to the analysis, the app continues to fall short of basic compliance benchmarks that any government-operated digital tool should meet, particularly one that interacts directly with citizens and collects sensitive personal data.

Among the key concerns raised is the apparent absence of a comprehensive privacy policy that meets internationally recognized standards. Users of the app are asked to provide personal information and grant device permissions without being given adequate explanation of how that information will be used, who will have access to it, or how long it will be retained. In an era where data protection has become a cornerstone of responsible digital governance, this omission is not a minor oversight — it is a fundamental failure.

Furthermore, questions have been raised about whether the app underwent any form of independent security audit before being made available to the public. The lack of transparent documentation around the app's development, testing, and deployment process makes it difficult for independent observers to assess whether citizen data is being adequately protected against breaches or misuse.

A Pattern of Institutional Negligence

What makes the 2026 compliance concerns particularly alarming is that they do not exist in isolation. They represent part of a broader, recurring pattern in which Sri Lankan government institutions launch digital initiatives with great fanfare but without the necessary legal, ethical, and technical groundwork in place. The eTraffic app's shortcomings were publicly documented, debated, and criticized. Yet those criticisms appear to have gone largely unheeded when the 2026 Police app was developed and deployed.

This raises a fundamental question about institutional learning and accountability. If government agencies are not required to demonstrate compliance before launching public-facing digital tools, and if there are no meaningful consequences for failing to meet basic standards, the cycle of non-compliance will inevitably continue. Citizens bear the cost of this negligence, not the institutions responsible for it.

The Broader Implications for Digital Governance in Sri Lanka

Sri Lanka is not unique in grappling with the challenges of responsible digital governance. Governments around the world have struggled to keep pace with the rapid evolution of technology and its implications for privacy, security, and civil liberties. However, what distinguishes responsible governments from negligent ones is the willingness to establish robust regulatory frameworks, enforce them consistently, and hold institutions accountable when they fall short.

For Sri Lanka to realize its digital governance ambitions, it must move beyond treating compliance as an afterthought. Independent oversight bodies need to be empowered to review government apps before launch. Data protection legislation must be strengthened and enforced. Civil society voices that raise legitimate concerns must be taken seriously rather than dismissed.

Conclusion

The 2026 Sri Lanka Police app may be the latest chapter in a troubling story, but it does not have to be the final one. Sri Lanka has the talent, the institutional knowledge, and the civil society capacity to do better. What remains to be seen is whether those in positions of authority have the political will to demand accountability and enforce the standards that citizens deserve. Until that changes, compliance failures will remain not the exception, but the rule.