4

Risk Register

Every privacy risk raised across the platform, in one place, with inherent and residual levels. Risks arrive here automatically from assessments, detections and the modules that raised them.

Open risks
15
Critical residual
3
Accepted
3

Requires periodic re-endorsement

Associated ceiling
₹1600 Cr

Sum of statutory ceilings, not a prediction

Likelihood × impact

Open risks at residual level.

RareUnlikelyPossibleLikelyAlmost certain
Severe12
Major1131
Moderate13
Minor2
Negligible

Rows are impact (severe at the top), columns are likelihood.

Highest residual risk

What to work on next, in order.

18 risks

RSK-2026-0310
Unlawful processing by the AI assistant
Personal data including children's records is indexed and retrievable with no declared purpose or lawful ground.
aiCriticalCritical₹200 CropenDr. Kavya Menon
RSK-2026-0311
Processor contracts without prescribed safeguards
Eight processors handle citizen data under contracts that do not carry the Rule 6 security provisions.
third partyCriticalHigh₹250 CracceptedFarhan Ahmed
RSK-2026-0312
Plaintext identifiers in legacy databases
Identifier and financial columns are unencrypted at rest in three production systems.
securityHighHigh₹250 CracceptedNaveen Kulkarni
RSK-2026-0313
Children's data processed without verifiable parental consent
Scholarship processing relies on a self-declared guardian name.
childrenCriticalCritical₹200 CrmitigatingArjun Malhotra
RSK-2026-0314
Consent withdrawal not reaching downstream systems
Two systems continue to hold and use data after withdrawal.
consentCriticalHigh₹50 CrmitigatingVikram Saxena
RSK-2026-0315
Cross-border processing without a current assessment
Grievance and skill development data sits outside India with expired or absent agreements.
cross borderCriticalHigh₹50 CrmitigatingAnanya Reddy
RSK-2026-0316
Retention overrun in the analytics lake
Identifiable extracts persist far past their stated retention.
retentionHighMedium₹50 CropenArjun Malhotra
RSK-2026-0317
Unscanned legacy archive
8.6 TB of offline archive has never been inventoried.
governanceHighMedium₹50 CropenDr. Kavya Menon
RSK-2026-0318
Shadow AI exfiltration
Staff paste citizen data into consumer AI services outside the department boundary.
aiCriticalHigh₹250 CrmitigatingImran Sethi
RSK-2026-0319
Grievance response period exceeded
11% of grievances closed beyond the published 90-day period.
rightsHighMedium₹50 CropenHarpreet Kaur
RSK-2026-0320
DPIA cadence lapsed
As an SDF, the annual DPIA requirement has not been met.
governanceCriticalCritical₹150 CropenVikram Saxena
RSK-2026-0321
Privileged standing access to health data
Administrators hold standing access to diagnosis columns with no break-glass requirement.
securityHighHigh₹250 CropenRohit Verma
RSK-2026-0322
Uncertified entitlements past due
46 access grants across nine repositories remain uncertified.
securityHighMedium₹50 CracceptedFarhan Ahmed
RSK-2026-0323
Untested backup for a tier-1 health system
No restore test in 14 months.
securityMediumLow₹250 CrmitigatingSunita Khanna
RSK-2026-0324
Purpose drift in the data lake
Elements collected for scheme delivery are consumed by undeclared analytics purposes.
governanceHighMedium₹50 CrmitigatingFarhan Ahmed
RSK-2026-0325
Notice readability above target
Three service notices are written above the readability grade the Rules contemplate.
consentMediumLowmitigatingRohit Verma
RSK-2026-0326
Nomination right not exercisable online
Section 14 nominations require contacting the department.
rightsMediumLowmitigatingNaveen Kulkarni
RSK-2026-0327
Connector outage on a cross-border source
Discovery has had no visibility of the skill development platform for 11 days.
governanceMediumMediummitigatingNaveen Kulkarni