Skip to content

Sri Lanka’s iGaming regulation plan: Key insights from MoDE

Sudhanshu Ranjan
Written by Sudhanshu Ranjan

Sri Lanka is no longer observing the iGaming trend in silence. The nation formally established its Gambling Regulatory Authority (GRA) on the first day of SiGMA South Asia in December 2025. The GRA’s formation followed years of operating under laws that weren’t designed for the digital age, and officials revealed that between 60 to 70 percent of casino users in Sri Lanka played online, yet online casino operations remained unregistered and untaxed.

Chanaki Mallikarachchi, Director of Information and Communication Technology (ICT) at the Ministry of Digital Economy (MoDE) in Sri Lanka, was among those considering exactly what that foundation should look like. In an exclusive interview with SiGMA News, she set out a vision that was technical, thoughtful, and, at its core, deeply principled.

GRA regulates, MoDE enables

Mallikarachch was clear: MoDE was not a gambling regulator. She said, “The most important principle is institutional separation. GRA regulates, MoDE enables. That separation protects governance integrity.”

Practically speaking, MoDE’s role is to build the digital backbone: developing a regulatory technology stack, supervisory dashboards, and API-based exchanges with organisations like the Financial Intelligence Unit, Inland Revenue, and the Central Bank of Sri Lanka to licence application workflows and operator onboarding.

Experts stressed that to regulate online gambling effectively, the GRA needed to be technology-first, and that required a partner in digital infrastructure who understood what that meant in practice. Mallikarachchi’s ministry was positioning itself to be exactly that.

Mallikarachchi’s key message was that whatever was built for gaming should not be built in isolation. “Any infrastructure developed for this sector should be aligned with Sri Lanka’s broader digital public infrastructure agenda rather than being treated as a stand-alone gambling platform,” she noted.

Age checks need real teeth

Tourism-linked gaming brought about sensitive questions: how do you verify who someone is, how old they are, and where they come from, without creating a bureaucratic nightmare that drives users away entirely?

Mallikarachchi’s answer was direct. She explained, “Age assurance cannot be treated as a light-touch checkbox. It should involve strong identity proofing, age verification, repeat verification for higher-risk transactions, and operator accountability for failures.”

She argued these controls should nationally trust services, reusable across banking, government platforms, and other regulated private-sector use cases.

She added, “This is more consistent with Sri Lankan cultural sensitivities than creating a frictionless entertainment app experience.”

Data governance: Privacy first always

Digital gaming platforms gather a great deal of personal information, such as identity documents, financial transactions, location data, and behavioural patterns. That data turned into a liability and a regulatory risk in the absence of a clear governance plan.

Mallikarachchi was clear about where Sri Lanka should begin: with the Data Protection Authority (DPA) serving as the oversight agency and the Personal Data Protection Act (PDPA), No. 9 of 2022, as revised in 2025.

She emphasised, “Offshore hosting cannot be allowed to undermine regulatory visibility, lawful access, or data subject protection. The data governance model should be privacy-preserving, auditable, and regulator-accessible, rather than purely operator-driven.”

Sovereignty is non-negotiable

Sri Lanka’s integrated resort ambitions involved a complex web of private partners, foreign investors, and interconnected systems. According to 6Wresearch, Sri Lanka’s gambling market was valued at $293.93 million in 2020 and was projected to reach $410.04 million by 2026, reflecting a CAGR of 5.24 percent over the 2021–2026 forecast period. The commercial opportunity was real. So was the risk if the digital architecture was not designed properly from the start.

Mallikarachchi identified three non-negotiables in any PPP arrangement. The first is accountability and clarity. Contracts had to outline who was in charge of what, where data was kept, who could access it, and what documents the regulator could look at.

The second is security by design. Encryption in transit and at rest, zero-trust access controls, tamper-evident logging, penetration testing, and contractual rights for independent audit.

The third, and perhaps most politically charged, was data sovereignty. Sri Lankan authorities must have lawful visibility, enforceable access, and preservation of evidence.

“Sovereignty must mean legal control, recoverability, and inspectability.”

Chanaki Mallikarachchi, Director (ICT) at the Ministry of Digital Economy, Sri Lanka.

Mallikarachchi cautions that in a sector already bound by law to AML and CFT obligations, tax compliance, and foreign exchange rules, anything less would create a serious governance gap.

Build once, benefit everyone

The final and most forward-looking part of the conversation concerned what gaming infrastructure could do beyond gaming itself. Mallikarachchi’s argument was simple but important. If Sri Lanka were going to invest in building digital systems for a regulated gaming sector, those systems should not be siloed. They needed to be designed from the ground up as a national digital infrastructure.

“Government should require that any approved investment be built on a shared-infrastructure-first principle,” she stated. Systems created for gaming should also strengthen e-government, tourism, banking, licensing, and small business services across the economy, not just one regulated sector.

“Sri Lanka should not appear to be building digital infrastructure for gambling alone,” she explained. “It should be building trusted national digital capability that can support regulated sectors where permitted, while also improving public services, financial integrity, tourism systems, and business enablement.”

Sri Lanka’s digital ministries were under pressure to keep up with their regulators as the GRA went live and operator licensing was anticipated to take shape until 2026. Mallikarachchi’s message to the sector was clear: cybersecurity requirements, identity infrastructure, data governance regulations, and technical underpinnings were not an afterthought. Operators entering the market would be expected to build upon them rather than around them at the time they were being created.

Be part of the action! Join the world’s biggest iGaming community with SiGMA’s Top 10 News countdown. Subscribe HERE for weekly updates, insider insights, and exclusive subscriber-only offers.

This site is registered on wpml.org as a development site. Switch to a production site key to remove this banner.