Co-regulated Identity

Identity belongs to the person.

Identity is what a person owns. Identification is what organizations and tracking systems do to that person.

The problem

Who is identified first

In person, you can see who you are dealing with before you hand anything over. Online the order is reversed. The individual is identified and verified first, and often never learns which organizations did the identifying.

What co-regulated means

Two sets of rules

Every digital interaction runs under two sets of rules at once: the organization's own rules, and the public rules of treaty, law and standards.

Co-regulated identity puts the public rules into records that the individual, the organization and the regulator can all inspect. The controller, the processor, the individual and the regulator each have a defined role in one shared framework that can be audited.

The individual manages their identity. The controller is accountable for identification. People give consent, and systems set permissions.

The specification

The ANCR extension

The work is specified in the ANCR (Anchored Notice and Consent Receipt) extension to ISO/IEC TS 27560:2023, developed in the Kantara Initiative ANCR Working Group. Release 1, a v1.0 Release Candidate dated 7 September 2026, is under Working Group review.

It defines four records: the Controller Identification Record, the Notice Record, the Notice Receipt and the Notice Event Log.

Release 1 defines eight conformance criteria in clause 5.1: sequence, minimum notice disclosure, anonymity by default, public rule reference, evidence, reciprocal and proportionate disclosure, non-exclusion, and authorization state. Assessment is by inspection of the artefact each criterion names.

The ANCR extension, current release and participation routes, at Kantara

See how these records fit in the Transparency Stack

Take part

Join the work

The ANCR extension is developed in the Kantara Initiative ANCR Working Group, which is open to participants through Kantara. Contact us if you would like an introduction to that work.

Contact us

Talk to TCIEG

TCIEG welcomes discussion with regulators, standards participants, civil society, technology providers, legal experts, privacy engineers and implementation practitioners working toward interoperable Operational Transparency standards.

Contact us