Tsaaro got CERT-IN Empanelled | MeitY has published the DPDP Rules, 2023.
Tsaaro got CERT-IN Empanelled | MeitY has published the DPDP Rules, 2023.
Tsaaro got CERT-IN Empanelled | MeitY has published the DPDP Rules, 2023.
Tsaaro got CERT-IN Empanelled | MeitY has published the DPDP Rules, 2023.
Back To Home
Research Team (Tsaaro)
ChatGPT, Reddit and Roblox Enter the EU’s Toughest DSA Tier

On 31 August 2026, the European Commission designated ChatGPT as a very large online search engine (VLOSE) and Reddit and Roblox as very large online platforms (VLOPs) under the Digital Services Act.
The designation applies because each service reported at least 45 million average monthly users in the European Union, the threshold at which the DSA’s enhanced obligations apply. The three services now have four months, until January 2027, to comply with the additional requirements that apply to the EU’s largest online services.
What Changes Now?
The DSA requires very large platforms and search engines to identify and assess systemic risks arising from their services. These include risks linked to illegal content, fundamental rights, public security, electoral processes, protection of minors and users’ physical and mental wellbeing. Once those risks are identified, companies are expected to put measures in place to reduce them.
The enhanced regime also brings a much more formal compliance structure. Very large services must maintain an internal compliance function, undergo independent audits at least once a year and provide information to the European Commission and national authorities for regulatory oversight. Vetted researchers may also obtain access to platform data where necessary to study systemic risks.
Transparency requirements become stronger as well. Depending on the service, this can include greater transparency around content moderation, advertising and recommender systems, along with options that are not based on user profiling.
Why ChatGPT’s Designation Matters
The most notable part of the announcement is the treatment of ChatGPT. The Commission has formally classified the service as an online search engine for DSA purposes, bringing it within the same enhanced supervisory regime that applies to other very large search services.
This means OpenAI’s compliance obligations in Europe will no longer be viewed only through AI-specific regulation. ChatGPT must also be assessed as a major digital intermediary whose design and operation can create systemic risks at scale.
Reddit and Roblox face a similar shift. Both services allow users to make third-party content available to the public, bringing them within the DSA’s online-platform framework. The Commission will now have direct supervisory powers over their compliance with the additional VLOP obligations.
For businesses operating large digital platforms, the message is clear: DSA compliance changes significantly once a service crosses the scale threshold. User numbers are no longer simply a growth metric. They can determine whether an organisation enters one of the EU’s most demanding digital regulatory regimes.
Source: https://ec.europa.eu/commission/presscorner/detail/en/ip_26_1772
https://www.reuters.com/world/chatgpt-reddit-roblox-adhere-eus-very-large-platform-rules-2026-08-31/
News of the Week
India Stalls Alipay+ and UPI Link Over Data and Security Concerns

India has reportedly stalled a proposal to connect Alipay+ with the Unified Payments Interface (UPI) for cross-border payments, with questions around customer data and national security forming part of the government's concerns.
The proposal was submitted in January 2026 by Alipay+, which is operated by Singapore-based Ant International. The first phase would have allowed Indian travellers to use UPI-linked payments at more than 150 million merchants across China, Hong Kong and other Asian markets. A later phase contemplated allowing international visitors to use Alipay+ in India.
Three sources familiar with the discussions claim that scrutiny centred on the company's Chinese links, the processing and storage of transaction data and the potential misuse of customer information. Law-enforcement agencies also reportedly raised concerns about data breaches, cyberfraud and money-laundering risks.
The development shows that cross-border payment integration is increasingly being assessed as more than a financial interoperability issue. Where payment systems create new flows of transaction and customer data across jurisdictions, data storage, access, cybersecurity and national-security questions can become central to whether the arrangement proceeds.
FBI Investigates Report of Massive Driver’s-Licence Data Exposure

The FBI is investigating reports that tens of millions of U.S. and Canadian driver's licences were being offered for sale through a dark-web service.
Cybersecurity journalist Brian Krebs first reported the service, called Nexus, after discovering it being promoted on a Russian cybercrime forum. Nexus claimed to possess more than 153 million driver's-licence records, together with millions of other identity and travel documents. Krebs said he tested records with nine individuals who confirmed that the documents were authentic.
If the scale is verified, the consequences could be serious. Driver's licences combine photographs, addresses, dates of birth and other information routinely used to verify identity. Unlike a password, much of this information cannot simply be changed after a breach.
The incident is also a reminder of the concentration risk created by identity-verification services. Businesses increasingly ask users to provide government identification for onboarding, age verification, fraud prevention and other checks. Where those documents are retained by a third-party verification provider, a compromise can expose highly sensitive identity data collected across many unrelated businesses.
For organisations relying on these vendors, security diligence should therefore include what documents are retained, for how long, whether full images are necessary and how quickly retained identity data can be deleted once verification is complete.
https://krebsonsecurity.com/2026/09/fbi-probes-service-selling-153m-drivers-licenses/
Florida Pulls Highway Licence-Plate Readers Over Surveillance Concerns

Florida has taken action against automated licence-plate recognition cameras on state highways following growing concerns about privacy and surveillance.
The Florida Department of Transportation announced that it would revoke existing permits and stop issuing new permits for automated licence-plate readers installed within its highway jurisdiction. The Department cited the rapid expansion of the technology, reported misuse, privacy concerns and wider surveillance concerns as reasons for the move.
The measure does not amount to a complete statewide ban on every licence-plate reader. It specifically affects installations by local police and other users within the rights-of-way controlled by Florida's state highway system.
Much of the debate has focused on cameras supplied by Flock Safety. Flock has a network of around 120,000 AI-powered cameras across 49 U.S. states, which automatically capture and process licence-plate information as vehicles pass. Law-enforcement agencies argue that the systems help identify suspects and solve crimes, while critics have raised concerns about misuse and the creation of large-scale vehicle-location databases.
Florida's action is significant because it shows privacy concerns moving beyond websites, apps and consumer databases into physical surveillance infrastructure. Technologies that continuously identify vehicles in public spaces may offer clear law-enforcement benefits, but their scale raises questions about retention, access, sharing and the ability to reconstruct an individual's movements.
For organisations developing or deploying surveillance technology, simply having a legitimate public-safety purpose may no longer be enough. Regulators and public authorities are increasingly asking how much information is collected, how long it remains available, who can search it and what controls prevent the system from being used for unrelated purposes.

