India has entered a new phase of its technology story.
Every few decades, India changes the question it asks of technology.
In the nineteen nineties the question was whether the country could compete at all. A generation of engineers in Bangalore, Pune and Hyderabad answered it by quietly writing the software the rest of the world ran on. In the two thousands the question was whether ordinary Indians could afford to be connected, and mobile telephony answered so emphatically that a call from a village in Bihar became cheaper than almost anywhere on earth. In the decade that followed, the question was whether a billion people could be brought into the digital economy at once. India answered with a payments system now studied and copied across continents, and with mobile data so cheap it rewrote the household budget.
Each phase made the next one possible. And each left the same question politely unanswered.
Who, exactly, is looking after all that data?
India has now entered its fourth phase, and this one is not about speed or scale or cost. It is about trust. It began with a law, and it will be won or lost on whether anybody can build the machinery to keep that law honest.
On 13 November 2025 the government notified the Digital Personal Data Protection Rules, giving working shape to the Act passed two years earlier. Together they form India’s first complete privacy regime, and it is not a gentle document.
Companies must now say plainly what they are collecting and why. They must use it only for the reason they stated. They must delete it when that reason expires. If something goes wrong they must tell you, and tell the newly created Data Protection Board, with a full account inside 72 hours. Penalties climb to ₹250 crore per violation, and they are already live.
The rollout is deliberately staged, and India is standing in the middle of it right now. The Board came into being immediately. From 13 November 2026, a matter of months away, the country’s Consent Manager system opens for registration, creating an entirely new class of licensed intermediary whose sole job is to hold your permissions and honour them. By 13 May 2027 every remaining obligation becomes enforceable, and officials have already floated pulling that date forward.
So for the first time, an Indian citizen has a legal right to be forgotten by a company. The awkward part, the part that rarely makes the headlines, is that almost nobody has a reliable way of making it actually happen.
Think about the last time you installed an app. It asked for your contacts, or your location, or your photos, and you tapped Allow, because the alternative was not using the thing you had just downloaded. That single tap, made once and quite possibly years ago, is still working today. It has no expiry date. It does not know why it was granted. It has never been reviewed.
This is the uncomfortable truth beneath the new law. The devices we all carry were designed in an era that asked only one question, whether an app may have your data, and never the questions the law now insists upon: for what purpose, for how long, and can it be taken back. The law describes a conversation. Our phones and laptops can only manage a yes or a no.
Somebody has to build the missing piece. That is the space into which FaceOff has stepped.
FaceOff Security and Privacy OS is an Indian project with an ambitious pitch and, refreshingly, a fairly honest one. Its name carries the letters OS, but it does not ask you to throw away Windows or Android or whatever runs your phone today. It settles in alongside them, and takes charge of one specific thing: your personal information.
The idea is easier to grasp than the engineering behind it. At present, your data sits around your device like belongings scattered through an unlocked house, and every app you admit can help itself. FaceOff gathers those belongings into a single strongroom, locks it, and puts somebody on the door.
There are four moving parts, and each maps neatly onto something the law demands.
The first is the strongroom itself, where your information is scrambled into something meaningless to anyone without the key. The clever touch is where that key is kept: not in ordinary software, which can be broken into, but inside the small tamper resistant security chip already built into most modern phones and laptops. It is a safe within the safe, and even the device’s own system cannot open it.
The second is the gatekeeper. When an app wants your contacts it no longer simply takes them. It knocks, states its business, and waits. The gatekeeper checks who is asking, what they want, why they want it, and whether you ever agreed to any of this. If the answer is yes, the app receives a temporary pass that opens one drawer, for one stated reason, and then expires on its own.
The third is the rulebook, which is really the brain of the operation. It holds both the requirements of the law and your own personal preferences, and it is identical on every device you own. That last detail is the quiet secret of the whole design. Because the rules never change from one machine to another, only the way they are enforced does, FaceOff can behave consistently whether you are on a laptop in the office or a handset on a train.
The fourth is the ledger, which records every request, every approval and every refusal in a form that cannot be quietly altered afterwards. It is a visitors’ book that nobody can rewrite. When a regulator comes asking what happened, and under this law they will, the answer is already written down.
Picture something entirely mundane. A delivery app wants your address book so it can send the parcel to your sister.
Today it takes the lot: every name, number, birthday and email you have ever saved, and keeps them indefinitely on a server you will never see. Under FaceOff, it asks. The rulebook checks your permissions and replies with something far narrower. One name. One number. Hide the address. Five minutes, then it is gone. The app receives exactly that and nothing else. The ledger notes the whole exchange. The pass dies on schedule.
Change your mind next week and withdraw consent, and the system revokes anything still outstanding and schedules the rest for deletion. No emails to customer support. No form to fill in. It simply happens, because that is what the rulebook says must happen.
This is the shift, and it is worth pausing on. Privacy stops being a promise somebody makes to you in a document you did not read, and becomes a thing your device does on your behalf, quietly, every single day.
Any technology sold as a guardian of privacy deserves to be examined rather than applauded, so it is worth being clear about what FaceOff cannot do.
It cannot behave identically everywhere. Operating systems are like buildings with very different rules about what a security firm may install. On desktop machines, FaceOff can fit proper locks throughout. On Android its reach is narrower but still substantial. On the iPhone, the strictest building of all, Apple permits no outsider to install deep controls, so FaceOff can run its strongroom and watch what leaves the device, but it cannot patrol the entire phone. Anyone claiming otherwise is selling something.
The larger limit is more interesting. FaceOff governs your data while it sits on your device. The moment that five minute pass is redeemed and the information travels to a company’s servers, the gatekeeper is left standing at a door the data has already walked through. Nothing on your phone can force a distant computer in another city to delete anything.
What it can do is leave a receipt. Every grant carries a dated, unforgeable record of precisely what was permitted, for what purpose, and for how long. Misuse stops being your word against theirs and becomes a documented gap between what was allowed and what was kept. In a country that now has a Data Protection Board, an appeals route and penalties running to hundreds of crores, turning an argument into evidence is not a small achievement. It is simply a different achievement from the one the marketing might imply, and the project is stronger for saying so.
None of this is running at national scale today. FaceOff is an architecture and an argument rather than a finished product on a billion handsets, and the distance between an elegant design and a working national system is wide and littered with the wreckage of good intentions. It will need independent security certification, a genuine place in the Consent Manager ecosystem opening this November, and above all it will need to be quick enough and quiet enough that people leave it switched on.
But the timing is not accidental, and it is not trivial. A recent industry survey suggested that seven in ten Indian enterprises still have only a limited grasp of what the law requires of them. The deadline is May 2027 and may yet move closer. Somebody is going to have to build the plumbing of consent in this country, and it is a considerable thing that the attempt is being made here rather than imported later.
India spent thirty years learning to connect its people, and did it better and faster than almost anyone expected. The task of this decade is quieter and rather harder. It is to make all that connection safe, and to give an ordinary person a genuine say over the small, revealing, endlessly valuable trail of information they leave behind every day.
FaceOff is a wager that the answer belongs not in a distant data centre or a lengthy privacy policy, but right there in your hand, at the door of your own data, checking every visitor before it lets them in.