In an article published on 25 September 2026 in the DailyFT, LIRNEasia Chair Professor Rohan Samarajiva discusses the risks of the state holding large amounts of personally identifiable information (PII). He looks at the misuse of electoral-registry information during the July 1983 pogrom, which critics of public-service digitalisation, particularly the Sri Lanka Unique Identity (SLUDI), cite as a reason for extreme caution, if not halting such initiatives.
He argues that the 1983 attacks involved photocopied electoral registers, not digital systems. Therefore, the underlying risk, he explains, is not digitalisation itself. It is the scale of PII held by the state and the potential for it to be misused by insiders, such as government officials with access to the information, or outsiders who obtain copies.
Professor Samarajiva notes that digitalisation could amplify these risks by making information easier to access and transmit. However, this does not mean that digital identity initiatives should be abandoned. He highlights the challenge is to balance the state’s need to use PII to deliver public services and conduct elections with the need to protect that information from misuse. This requires digital systems with appropriate safeguards, supported by the necessary administrative and legal measures to minimise the risk of PII misuse.
“Digitalisation did not contribute to the abuses of Personally Identifiable Information (PII) in 1983. But will digitalisation not amplify the risks? Yes, it may, unless the proper design safeguards are built into the digitalised systems and are backed up by the appropriate administrative and legal changes, also described as analogue complements. Similarly, implementation of the proper digital elements and their analogue complements may reduce the risks of abuse.”
Read the full article in the Daily FT.
2026 සැප්තැම්බර් 25 වන දින The Leader පුවත්පතේ පළ වූ ලිපියක, ලර්න්ඒෂියා ආයතනයේ සභාපති මහාචාර්ය රොහාන් සමරජීව, රජය විසින් විශාල ප්රමාණයක පුද්ගලයන් හඳුනාගත හැකි තොරතුරු (Personally Identifiable Information, PII) රැස්කර තබා ගැනීමෙන් ඇති විය හැකි අවදානම් පිළිබඳව සාකච්ඡා කරයි. මෙම ලිපියේදී ඔහු රාජ්ය සේවා ඩිජිටල්කරණයට, විශේෂයෙන්ම ශ්රී ලංකා ඩිජිටල් හැඳුනුම්පත් ව්යාපෘතියට විරුද්ධ විවේචකයන් එවැනි ක්රියාදාම පිළිබඳව අතිශය ප්රවේශම් විය යුතු බවට හෝ එවැනි වැඩසටහන් නතර කළ යුතු බවට ඉදිරිපත් කරන එක් හේතුවක් වන 1983 ජූලි මාසයේ ඇති වූ වාර්ගික සංහාරයේදී ඡන්ද නාමලේඛන තොරතුරු අවභාවිත කිරීම පිළිබඳව විමසා බලයි.
1983 ප්රහාරවලදී භාවිත වූයේ ඩිජිටල් පද්ධති නොව, ඡන්ද නාමලේඛනවල ඡායා පිටපත් බව ඔහු පෙන්වා දෙයි. එබැවින්, මෙහි මූලික අවදානම ඩිජිටල්කරණය නොවන බව ඔහු පැහැදිලි කරයි. අවදානම පවතින්නේ රජය සතුව පුද්ගලයන් හඳුනාගත හැකි තොරතුරු විශාල පරිමාණයෙන් පැවතීම සහ එම තොරතුරු වෙත ප්රවේශය ඇති රාජ්ය නිලධාරීන් වැනි අභ්යන්තර පාර්ශ්වයන් හෝ එහි පිටපත් ලබාගන්නා බාහිර පාර්ශ්වයන් විසින් ඒවා අවභාවිත කිරීමට ඇති හැකියාව තුළ බව ඔහු පෙන්වා දෙයි.
ඩිජිටල්කරණය නිසා තොරතුරුවලට ප්රවේශය සහ හුවමාරුව පහසු වීමෙන් මෙම අවදානම් තවදුරටත් වැඩි වීමට ඉඩක් ඇති බව මහාචාර්ය සමරජීව සඳහන් කරයි. කෙසේ වෙතත්, මෙයින් අදහස් වන්නේ ඩිජිටල් හැඳුනුම්පත් වැනි ව්යාපෘති අත්හැරිය යුතු බව නොවේ. රාජ්ය සේවා සැපයීම සහ මැතිවරණ පැවැත්වීම සඳහා PII භාවිත කිරීමේ රජයේ අවශ්යතාව සහ එම තොරතුරු අවභාවිතයෙන් ආරක්ෂා කිරීමේ අවශ්යතාව අතර සමතුලිතතාවක් පවත්වා ගැනීම මෙහිදී අභියෝගය බව ඔහු අවධාරණය කරයි. මේ සඳහා නිසි ආරක්ෂණ ක්රමවේද සහිත ඩිජිටල් පද්ධති අවශ්ය වන අතර, එසේම ඒවාට සුදුසු පරිපාලනමය සහ නීතිමය ක්රියාමාර්ග මගින් ද සහාය දැක්විය යුතු බව ඔහු පෙන්වා දෙයි.
“1983දී පෞද්ගලික තොරතුරු අවභාවිත වීමට ඩිජිටල්කරණයේ බලපෑමක් නො තිබුණි. එහෙත්, ඩිජිටල්කරණය නිසා මෙවැනි අවදානම් තවත් වැඩි නොවේ ද? ඔව්, ඩිජිටල් පද්ධති සකස් කිරීමේදී නිසි ආරක්ෂක ක්රමවේද ඇතුළත් නො කළහොත් අවදානම වැඩි විය හැකිය. එසේම, ප්රතිසම අනුපූරක (analog complements) ලෙස ද හැඳින්වෙන සුදුසු පරිපාලනමය සහ නීතිමය වෙනස්කම් මගින් ඒවාට සහාය දැක්විය යුතුය. නිවැරදි ඩිජිටල් ආරක්ෂණ අංග සහ ඊට අවශ්ය නීතිමය සහාය නිසි ලෙස යෙදවුවහොත් තොරතුරු අවභාවිත වීමේ අවදානම බොහෝ දුරට අවම කළ හැකිය.”
The Leader පුවත්පතේ පළවූ මෙම සම්පූර්ණ ලිපිය කියවීමට මෙතැනින් පිවිසෙන්න.