About us
Where operational privacy meets operational transparency.
TCIEG works to make transparency operational, evidence-based and verifiable, before identification, processing, tracking or transfer where prior transparency or consent is required.
How TCIEG started
Twenty years apart, working on the same problem.
For twenty years two privacy experts ran parallel and disconnected efforts to put privacy controls in place across systems, so that individuals could consent freely and on an informed basis.
Mark Lizar was in Europe campaigning for awareness of Operational Transparency, a principle drawn from the 2007 International Security Trust and Privacy Alliance research Analysis of Privacy Principles: Making Privacy Operational. Michele Drgon was in the United States driving Operational Privacy frameworks with global clients, and working on the privacy engineering standards that design transparency and other privacy controls into technology, across AI, the internet of things and cloud computing.
They met in April 2026 in ISO/IEC JTC 1/SC 27/WG 5, Michele as a liaison expert from OASIS and Mark through the Canadian mirror committee, while contributing to the AI privacy protection guidance that became ISO/IEC FDIS 27091. Mark had been evangelising the work Michele co-edited almost two decades earlier.
Two complementary paths, better joined than apart. The Transparency and Consent Interoperability Expert Group followed.
Mission
Our mission.
TCIEG's mission is to make transparency operational, evidence-based and verifiable before identification, processing, tracking or transfer, where prior transparency or consent is required.
Make authority transparent at the point of engagement, make the claim of authority inspectable at the point of contact, and give the individual usable evidence of the interaction, so we can control our own data.
The work moves privacy from policies and controller-maintained assertions toward digital interactions that can be independently reconstructed and verified.
Consent
Real consent requires real evidence.
Consent is a human-defined choice. Permissions are system-managed. Those are not the same thing.
A system can record that a permission changed without proving that legally meaningful consent occurred. Evidence of consent should be able to show what the individual was told, who was requesting the authorisation, what purposes applied, which notice governed the interaction, what the individual authorised, and what happened when that authorisation was modified or withdrawn.
TCIEG promotes the Transparency Stack, a standards-based approach to creating that evidence. It builds on established privacy standards and emerging evidence structures, including ISO/IEC 29100, ISO/IEC 29184, ISO/IEC TS 27560:2023 and the Kantara Initiative's ANCR work. Together these support a progression from privacy principles and notice presentation to structured records, receipts, authorisation evidence and auditable lifecycle history, and an interoperable evidence layer that works across technologies, organisations, jurisdictions and use cases.
Operational transparency
Transparency as a system capability.
Privacy requirements become meaningful in digital systems when they operate at the point where the interaction occurs.
Before an organisation identifies an individual, requests personal information, initiates tracking, requests an age or identity attribute, or asks for authorisation, the organisation itself should be knowable. The applicable authority, purpose, notice and relevant conditions should be resolvable and inspectable. The evidence of that interaction should persist.
Operational transparency turns transparency from a webpage into a system capability. It makes it possible to reconstruct what governed a particular interaction, instead of depending on the organisation's own later account of what occurred.
Identification
Co-regulated digital identification.
Digital identity infrastructure has concentrated on establishing facts about the individual. There must also be a reciprocal side.
Before an individual is asked to prove who they are, disclose an attribute, demonstrate their age, present a credential or otherwise become identifiable, the organisation making the request should itself be identifiable and accountable. Its authority, purpose, applicable notice and conditions of interaction should be knowable first.
Public rules can establish what must be disclosed and evidenced. Standards can provide common structures. Industry can implement interoperable systems. Independent resolution and verification can make the resulting infrastructure inspectable. That is a path toward digital identification which protects the individual before identification occurs, rather than placing the entire burden of proof on the individual.
Regulators
Working with regulators.
TCIEG advances the case for verifiable transparency and consent evidence with regulators and policymakers, and the development of an Internet Transparency Code of Practice is the instrument that work is organised around.
Regulators face the same evidentiary problem repeatedly. After an interaction has occurred, how can anyone reliably determine what an individual actually saw, which notice applied, which organisation was acting, what authorisation was obtained, and whether later changes were honoured? Standardised evidence can materially improve regulatory capacity.
The work includes engagement with regulators, consultations, regulatory sandboxes, implementation initiatives and policy programmes. The long-term objective is straightforward: where organisations are required to demonstrate transparency or valid consent, standardised and reconstructable evidence should become part of how compliance is demonstrated.
Standards
Working with standards communities.
Standards are central to this mission. TCIEG supports the continued development, alignment, implementation and adoption of standards that make notice, consent, identification, authorisation and lifecycle evidence interoperable.
We do this work where it is decided. Mark Lizar is editor of the ISO/IEC preliminary work item on an Internet Transparency Code of Practice profile at ISO/IEC JTC 1/SC 44/WG 1, established by plenary resolution on 3 September 2026, and project editor of PWI 26689 on notice and consent records at ISO/IEC JTC 1/SC 27/WG 5. He edits the ANCR Extension to ISO/IEC TS 27560:2023 at the Kantara Initiative and sits on the Canadian mirror committee to SC 27/WG 5. Michele Drgon is co-editor of ISO/IEC 27561 and a liaison expert to ISO from OASIS.
We also identify where adoption is impeded by a lack of interoperable interfaces between technologies and platforms. AI, digital identity, age assurance, agents, wallets, consent management, privacy signals and cross-border data systems increasingly interact with one another. Their transparency and authorisation mechanisms cannot remain isolated indefinitely.
Partners
Working with pilot partners and sponsors.
Standards become meaningful when they can be demonstrated. TCIEG is seeking sponsors, implementation partners, technology providers, research partners, regulators and other organisations interested in building and testing reference implementations, demonstrations, regulatory pilots and sandbox projects.
These projects show how interoperable transparency evidence works in real systems, including consent, age assurance, digital identification, AI interactions and cross-border data exchange. Sponsors and partners help move the work from architecture into demonstrable infrastructure.
Contact us
Talk to TCIEG
TCIEG welcomes discussion with regulators, standards participants, civil society, technology providers, legal experts, privacy engineers and implementation practitioners working toward interoperable Operational Transparency standards.