Don't ask whether the ISO certificate is current.
Ask: which three controls did you sample last week with fresh evidence — access, logging, change — and what failed?
Zero failures for months usually means the sample is polite, not that the system is clean.
On-device processing shrinks the transfer surface.
It still doesn't prove consent withdrawal, erasure across local state and backups, or which telemetry still leaves the device — under pressure.
Privacy architecture isn't evidence architecture. Boards still need the receipts.
We announce our first personal agent, and it's important to understand how we got here.
Over the past 20 years India has transformed to become a digital-first society. The India Stack rails (AADHAR, UPI, Account Aggregator, ONDC, DIGI***) are prolific across India. Couple this with the ubiquitous availability (~data) and usage (~trust) on mobiles and this becomes even more potent.
The vast surface area of digital adoption in India, will lead to millions of personal agents.
It's inevitable.
A sovereign personal agent is thus an outcome in India. Not a starting point. If you permit some tech-speak, this is the Hybrid-LM architecture - where the personal data remains on the device and that same device is the compute.
This solves two of the biggest roadblocks of personal agents - privacy and compute. This massively scalable architecture is essentially Micro-LMs running on these billion mobile phones. And just like a typical data center these are always charged and available with idle compute time and capacity.
India already has 1B micro-data centers. Today.
And we have the tech where tokens are local. In fact, its our own benchmarks are crazy.
The India DPDP act comes into force on 13 November 2026. That is a critical tailwind for personal agents.
What needs more work is published guardrails, a registry, a tribunal and effective inclusion of the civil society (~open source).
We are here. It's already today.
With @jagsha97
Boards ask if the privacy policy covers deletion.
Sharper: pick one Principal who requested erasure in the last 90 days. Can you show systems, vendors, and backups where their data was removed — with timestamps?
If the answer is a policy paragraph, you have a notice, not an operation.
Most "incident ready" decks end at who to call.
Ask one harder question:
Can you produce, in under an hour, the systems that held the affected principals, the last backup that is clean, and who can authorize customer notice — without a war room?
If those three answers need a scramble, the tabletop was theatre.
Most "incident ready" decks end at who to call.
Ask one harder question:
Can you produce, in under an hour, the systems that held the affected principals, the last backup that is clean, and who can authorize customer notice — without a war room?
If those three answers need a scramble, the tabletop was theatre.
Masking on the public portal is not the control.
If a downstream app or vendor can reconstruct name, address, and chassis from the same plate, ask:
Who authorized that access path, what is rate-limited, what gets logged, and how fast can you revoke it?
If those four answers are not in one place, the Board is reviewing a screenshot, not a system.
₹2 buys a stranger's home address. We tested a Play Store app with 10M+ downloads selling VAHAN/eChallan data, one number plate gave us the owner's full name, father's name, permanent address, insurance policy, chassis and engine numbers, all of which Parivahan masks behind an OTP.
This isn't a hack. Researchers at Cyderes traced it to licensed API keys given to KYC companies, now resold on Telegram.
IFF has written to MoRTH, NIC & CERT-In demanding a forensic audit, and filed RTIs on 22 Sept. Found your own data on these apps or similar website? Write to [email protected]
"We host in India" is not a transfer answer.
If a support tool, CDN, or analytics vendor mirrors logs overseas, ask:
Where does a Principal's data actually move on a normal Tuesday — not in the architecture slide?
If nobody can draw that path from signup to support ticket, the Board is approving a hope.
Boards open Mondays asking if DPDP "is on track."
Sharper question after a weekend of product experiments:
Which new SaaS, plug-in, or AI tool touched personal data since Friday — and is it already on your processor list with a purpose, retention path, and kill switch?
If Legal finds out from the invoice, you don't have a processor register. You have a surprise.
@nixxin Useful regulatory question: not whether an agent is "autonomous", but what authority its harness + memory can exercise.
Can it buy, publish, message, or touch sensitive data without a human checkpoint?
Define those boundaries before scale turns an edge case into an incident.
An AI agent reaching for private encryption keys is a warning for boards.
"Approved use case" is not a security control.
Ask:
• What can it read?
• Where can it write?
• Can it be stopped?
• Who reviews the logs?
Fuzzy answers mean it is already in production.
@surispeakss The date on the slide is the easy part.
Harder: which systems today still run behavioural tracking or ads against an under-18 cohort, and who can pull the disablement evidence without a war-room?
Inventory that path now — consent UX alone won't save the Board pack.
Most Boards ask if you're "DPDP ready" on consent and breach.
If your product can touch anyone under 18, ask three sharper ones:
Can you show verifiable parental consent — not a checkbox a teenager clicked?
Are tracking, behavioural monitoring, and targeted ads actually off for that cohort?
Who owns age and parent verification when a freemium signup lands on a Saturday night?
If those answers live only in Legal's deck, you don't have evidence. You have a slide.
@cybersigmacs "Assessment-ready" for DPDP means more than a policy PDF.
If MeitY names you tomorrow, Rule 13 wants living control evidence — monitoring outputs, risk decisions, audit trails — not last year's ISMS binder. Pull one control's fresh receipts this week and see if the trail holds.
@Castellum_Labs A Rule 13 DPIA dies without this map.
Application → API → SaaS → third party → backup is exactly what assessors and the Board will ask for. If you only know where data sits, not where it moves next, you don't have impact assessment — you have an asset list.
@Apoorva161816 Useful correction on the penalty ladder.
The SDF tier only bites after naming — so the control work is preemptive: can you already produce a DPIA-grade data map and audit trail? Waiting for the gazette before building evidence is how Boards get surprised.
Seven weeks to Consent Manager is the headline. The quieter risk is operating without a constituted Board to interpret edge cases.
Document your interim choices now — notice language, children's data gates, CM handoff — so when the Board arrives you have a rationale trail, not a scramble.
@surispeakss Rule 13(3) is not an AI ethics essay.
If you get named, you must verify algorithmic software doesn't risk Principal rights — with evidence a Board can read. Inventory recommendation systems and ML models that touch personal data before the naming notice invents the deadline.
@surispeakss This is the Board slide most decks skip.
Naming under section 10 starts the Rule 13 clock — DPIA, independent audit, Board report — whether Legal has a binder or not. Ask now: who owns the first twelve-month evidence pack, and which systems already produce receipts?
Boards are counting down to 13 Nov Consent Manager.
Sharper question: if MeitY names you a Significant Data Fiduciary tomorrow, does Rule 13 already have somewhere to land?
DPIA every twelve months. Independent audit. Report of significant observations to the Board. The clock starts the day you're named — not the day you hire a consultant.
If you can't show a living data map and control evidence now, the gazette notice won't invent it.
@TheHackersNews the practical follow-through is separate validation for each affected surface, then a named owner for the patch and re-test. one ticket for two layers can hide an unverified assumption.