Vol. XVI · No. 266Wednesday 23 September 2026World Edition
TheNewsRupt coat of arms crest

The NewsRupt

Reported

The Rise of the Personal Data Vault

A quiet industry is being built on a simple premise: your data should live somewhere you control, not in a hundred accounts you do not.

By The NewsRupt Desk·Kerala desk·Wednesday 23 September 2026·6 min read

Most people's digital lives are scattered across dozens of company databases. Purchase histories live with retailers, health records with insurers and apps, location trails with mapping services, messages with whatever platform each friendship happens to run on. The individual holds none of it directly. A small but growing group of companies, standards bodies and public projects is working on an alternative that sounds old-fashioned and may prove consequential: the personal data vault, a single store of your records that you own and grant access to, rather than the reverse.

The idea is not new — the MIT-founded Solid project has championed personal data pods since 2016, and health records systems in several countries have experimented with patient-held data for longer. What is new is the pressure pushing it toward the mainstream. Privacy laws in India, the EU and a widening list of US states have created a legal right to data portability that is mostly exercised through clunky, one-off exports. AI assistants have raised the stakes: a model that reads your calendar, mail and documents to help you is only as trustworthy as the place that data lives. And repeated breaches at companies holding centralised troves have made the case, expensively, that hoovering everything into one corporate silo concentrates risk for everyone except the person the data describes.

The emerging pattern looks like this: a vault holds signed records in standard formats — health, financial, identity, preferences — and exposes them through permissions the user grants and revokes. An assistant that needs your travel history asks the vault, not a stack of apps. A lender verifying income requests the documents it needs, sees them, and retains what the terms allow. The design goal is to turn data sharing from an ambient, all-or-nothing arrangement into a deliberate transaction with a receipt.

The hard problems are not storage, which is cheap, but three practical ones. First, incentives: companies that profit from holding data have little reason to hold less of it, so vaults must either be mandated by regulation, bundled into products users actually want, or run by parties — banks, health systems, governments — with a structural reason to be neutral custodians. Second, interoperability: a vault full of proprietary formats recreates the silo problem with extra steps, which is why the meaningful work is happening in standards like verifiable credentials and cross-industry data schemas, not in any single app. Third, liability: when a user-granted permission leads to harm — a fraudulent loan approved on vault-held documents — the allocation of responsibility is unsettled law almost everywhere.

India's account aggregator framework is the most consequential live experiment, because it is mandated and wired into the financial system rather than optional. Millions of users have already used it to share bank statements with lenders and advisors through consent artefacts that expire. Its lessons travel: consent flows must be genuinely readable, revocation must be instant, and the ecosystem needs enough participating institutions that the vault is useful on day one rather than a promise.

For the average reader, the practical effect over the next few years will likely arrive quietly, embedded in products — a loan approved in minutes because your bank statements arrived as verified data, a doctor's second opinion that already includes your history, an assistant configured to read your documents from a store you can empty. The dramatic version, a general-purpose vault replacing your scattered accounts, will take longer and may never fully arrive.

A limitation worth stating: adoption figures for personal data infrastructure come mostly from the operators and regulators themselves, and usage is far smaller than enrolment. The business models for neutral custodians remain unproven — a custodian that cannot make money may eventually monetise the very data it was trusted to protect. Interoperability standards are still moving targets.

The NewsRupt files this from the Kerala desk. Corrections and right of reply are handled under our published standards policy.

How we report

Every claim above is sourced to a document, a named person, or a record we hold. Where we could not verify a claim, we say so. Read our standards and corrections policy →