Skip to content

Open questions and change log

Open means no production default is invented. The owner captures a primary source, assesses impact and moves the question through legal/technical review.

IDQuestionCurrent evidenceProduct postureReview trigger
OQ-001Is an official consolidated Rules text published?G.S.R. 846(E) + G.S.R. 892(E)apply the seven captured correctionsMeitY/Gazette consolidated text
OQ-002Have DPBI Chairperson/Members been appointed?6 May recruitment onlyestablishment yes; operational status openappointment notification
OQ-003Is DPBI Digital Office Portal live and documented?voluntary Aadhaar use approvedno API/availability claimofficial launch/manual
OQ-004What CM standards/assurance/application interfaces exist?Rule 4/First Schedule onlyadapter placeholder, readiness onlyBoard publication
OQ-005Have any CM registrations issued?none locatedno registered claimBoard register
OQ-006Which entities/classes are SDFs?no notification locatedcandidate onlyCentral Government notification
OQ-007Restricted countries / Rule 15 orders?none locatedempty signed policyGazette/order
OQ-008Rule 13(4) specified data/localisation?none locatedinactive policycommittee/Government specification
OQ-009Startup/class exemptions?statutory power onlyno automatic exemptionsection 17 notification
OQ-010Section 43A/SPDI transition detail?phased section 44provision-specific legal reviewcommencement/amendment source
  • consolidate RBI activity-specific payment, KYC, digital lending, AA and incident instruments for the pilot entity;
  • map SEBI later CSCRF implementation circulars by RE category;
  • verify current IRDAI master circular/consolidation and entity categories;
  • obtain central/state healthcare record, clinical trial, pharmacovigilance and device sources;
  • map labour/tax/benefit record sources by state/entity;
  • verify education board/university/state record and child-safety rules;
  • identify actual NCIIPC/protected-system scope for a design partner.
  • confirm customer/regulator APIs from current docs; never infer proprietary fields;
  • formalise connector capability manifest and sandbox choice;
  • decide supported Kubernetes/PostgreSQL/object/KMS matrix after prototypes;
  • benchmark subject HMAC/re-identification and consent scale assumptions;
  • select signed legal configuration format and offline revocation model;
  • validate Mermaid client-side rendering under strict CSP and print fallback.
  • created verified commencement cohorts from G.S.R. 843(E) and Rule 1 of G.S.R. 846(E);
  • captured G.S.R. 892(E) and incorporated all seven published Rules corrections;
  • recorded Board establishment, May recruitment and July Aadhaar use-case approval separately;
  • created initial legal status, source and control data;
  • specified product profiles, sectors, UX, architecture, APIs, connectors, security, operations, open-source strategy, GTM and MVP;
  • pinned Astro 7.1.6, Starlight 0.41.5, local Mermaid integration and validated schemas;
  • selected Apache-2.0/DCO recommendation;
  • retained official consolidation, Board operations and sector consolidation as explicit backlog.

Every entry records requester, source IDs, old/new status or interpretation, affected control/page/ template/API, customer migration, legal reviewer, activation date and release. Corrections do not erase prior research; the change log explains them.