AI in HR: The Data Privacy Question Sri Lanka Isn't Asking

Quick answer: AI in HR is being adopted across Sri Lanka faster than most companies can govern it. The risk isn't the technology itself, it's that most AI recruitment tools process candidate and employee data on servers outside Sri Lanka, which triggers obligations under the Personal Data Protection Act (PDPA) that almost nobody is checking. Before approving any AI HR tool, ask where the data goes, who is accountable for it, and whether an on-device alternative removes the question entirely.
Scroll through LinkedIn this month and you will see it everywhere: AI-powered screening, AI-written job ads, AI chatbots running the first round of interviews, AI recruitment tools scoring candidates before a human ever reads a CV. The pitch from every vendor sounds the same. Let AI handle the busywork so your HR team can focus on people.
It is a good pitch. It is also missing the one question every Sri Lankan HR leader should ask before adopting any of it: where does the CV, the salary history, the NIC number, the performance review actually go once it is uploaded?
Most of the local conversation about AI in HR is about efficiency. Almost none of it is about who is holding the data, and what happens to it next.
What happens to employee data when you feed it into an AI tool?
When a recruiter feeds a candidate's CV into a free AI screening tool, or pastes an employee's performance review into a chatbot to help draft feedback, that data usually leaves Sri Lanka entirely. It gets processed on servers the company does not control, under a privacy policy nobody read, sometimes to help train a model that is not theirs.
The candidate never agreed to that. Neither did the employee whose salary and health information ended up inside a prompt.
This is not a hypothetical risk. It is the default behavior of most consumer-facing AI tools, and it is exactly the kind of data processing Sri Lanka's own data protection law was written to catch.
What does the PDPA actually require from HR teams?
The Personal Data Protection Act No. 9 of 2022 (PDPA) treats CVs, National ID numbers, salary details, medical records, and performance data as personal data, some of it sensitive personal data, from the moment it is collected. In practice, that means four things for any HR team using AI:
- A lawful basis is required to process the data. "The AI tool needed it to work" is not one.
- Cross-border transfers need a safeguard. If a tool sends candidate data to a server outside Sri Lanka, that is a cross-border transfer, and the Act sets specific conditions for when it is allowed.
- The company is the data controller, not the vendor. If a free browser extension leaks a candidate's CV, the company that used it carries the liability, not the tool that leaked it.
- Data minimization still applies. If a screening tool does not need a candidate's home address or marital status to shortlist them, it should not have access to it.
Most HR teams adopting AI tools today have never put these questions to their IT or legal team. The tool looked useful, it was free or cheap to try, and it got rolled out before anyone asked where the data lands.
The Personal Data Protection Act No. 9 of 2022 (PDPA) treats CVs, National ID numbers, salary details, medical records, and performance data as personal data from the moment it's collected, medical records (and any CV content touching health, religion, or similar) also qualify as a "special category" of personal data, which the Act subjects to a stricter processing standard. One caveat worth flagging up front: the sections below aren't in force yet. They were due to commence in March 2025, that date was withdrawn days before taking effect, and a July 2026 gazette has now set January 1, 2027 as the new start date. Treat this as what's coming, not what's enforceable today — and build the runway accordingly. In practice, that means four things for any HR team using AI:
- A lawful basis is required to process the data. "The AI tool needed it to work" is not one on its own — the closest fit is "legitimate interests," and that requires actually documenting a balancing test against the candidate's interests, not just asserting necessity.
- Cross-border transfers need a safeguard. If a tool sends candidate data to a server outside Sri Lanka, that is a cross-border transfer, and the Act sets specific conditions — an adequacy decision, prescribed safeguards, or one of a short list of exceptions — for when it's allowed.
- The company is the data controller and carries liability regardless of what a vendor does. If a free browser extension leaks a candidate's CV, the company is on the hook as controller either way — and if that vendor used the data beyond the company's instructions (say, to train its own models), the vendor can become separately liable too, not instead.
- Data minimization still applies. If a screening tool does not need a candidate's home address or marital status to shortlist them, it should not have access to it.
What should HR ask an AI vendor before approving any tool?
You do not need to be a compliance specialist to do this well. Before the next AI recruitment tool gets approved, put three questions to the vendor in writing:
- Where is the data processed, and does it leave Sri Lanka? If it does, under what legal safeguard?
- Is our data used to train your model, or any other customer's model? Get this in writing, not a verbal assurance on a sales call.
- What happens to the data after the hiring decision is made? Is it deleted, and on what schedule?
If a vendor cannot answer these clearly and in writing, that is the answer.
Why does AI hiring bias matter alongside data privacy?
Data privacy and AI hiring bias are often treated as separate issues, but they come from the same root cause: nobody can see what the model is actually doing with the data it holds. A widely cited example is Amazon's abandoned recruiting tool, which learned from a decade of male-dominated resumes and began downgrading CVs that contained the word "women's." The company could not fully explain the pattern until it had already shaped years of hiring recommendations.
The lesson for Sri Lankan HR teams is not to fear AI hiring tools. It is to demand transparency about both what data a tool touches and how it reaches its recommendations, before either becomes a problem you discover after the fact.
Does cloud-based AI create more PDPA exposure than on-device AI?
Most AI hiring tools getting attention right now are cloud-first. Candidate data flows to a server, gets processed, and a score or recommendation comes back. That architecture is convenient, and it is also the exact model that creates PDPA exposure, because the data has to leave the company's control to get any value from the tool.
There is a different way to build this. Run the AI on the device itself, so candidate CVs and profile data never leave the recruiter's laptop or phone in the first place. No cloud upload, no server logs holding a candidate's personal details, no cross-border transfer question to even ask, because there is no transfer.
This is the architecture behind EdgeTal, an on-device AI recruiting assistant built specifically around this idea: privacy by architecture rather than privacy by policy. It processes CVs and candidate profiles locally using on-device AI, so the compliance question that trips up cloud-based tools does not arise in the first place. It is a genuinely different answer to the question this article is raising, not a compliance checkbox bolted onto a cloud product after the fact.
What does responsible AI in HR actually look like?
Efficiency is not the same as responsibility. A tool that screens two hundred CVs in ten seconds is not doing an HR function any favors if it does so by quietly shipping sensitive personal data to a server with no accountability trail back to the business.
Before the next AI adoption conversation, the question worth putting on the table is not how much time a tool will save. It is who is legally responsible when the data ends up somewhere it should not, and whether the company can even answer that question today.
Frequently asked questions
Does Sri Lanka's PDPA apply to HR and recruitment data?
Yes. The PDPA covers any personal data collected and processed by an organization operating in Sri Lanka, including CVs, employee records, salary details, and performance data, regardless of whether the processing is done manually or through an AI tool.
Is using ChatGPT or similar tools for HR tasks a PDPA risk?
It can be. Pasting candidate or employee personal data into a general-purpose AI chatbot typically sends that data to servers outside Sri Lanka without a documented lawful basis or transfer safeguard, which is the kind of processing the PDPA regulates.
Who is liable if an AI HR tool leaks candidate data?
The company using the tool, not the vendor. Under the PDPA, the organization that collects and processes the data is the data controller and carries primary accountability, even when a third-party tool caused the leak.
What is on-device AI and how does it help with HR data privacy?
On-device AI runs the model directly on a laptop or phone instead of sending data to a cloud server. Because candidate and employee data never leaves the device, there is no cross-border transfer to justify and no third-party server holding sensitive records.
Do free AI recruitment tools carry more risk than paid ones?
Not inherently, but free tools are less likely to publish clear data processing terms, and some use uploaded data to train their models by default. Always confirm data handling terms in writing regardless of price.
What should be in an AI vendor's data processing agreement?
At minimum: where data is processed and stored, whether it is used for model training, how long it is retained, how it is deleted, and what happens in the event of a breach. If a vendor cannot provide this in writing, treat that as a red flag.
Does the PDPA apply to small and medium HR teams, not just large companies?
Yes. The PDPA applies based on what data is processed and where, not the size of the organization. Smaller HR teams are often more exposed because they adopt free or unvetted tools faster and have less legal review before rollout.
That is the part of "AI in HR" nobody is talking about yet in Sri Lanka. It is time we started.
About the author: Hasanthi Lakmali writes on HR, technology, and workplace practice in Sri Lanka, focused on how local HR teams adopt AI responsibly under Sri Lanka's Personal Data Protection Act. She shares more on this at aihr.lk, where she helps HR professionals learn to use AI responsibly.
Need help putting this into practice?
Knovik builds and ships the systems behind posts like this one, AI automation, web platforms, and search strategy, end to end.