Co-regulated Identity
Identity belongs to the person.
Identity is what a person owns. Identification is what organizations and tracking systems do to that person.
The problem
Who is identified first
In person, you can see who you are dealing with before you hand anything over. Online the order is reversed. The individual is identified and verified first, and often never learns which organizations did the identifying.
What co-regulated means
Two sets of rules
Every digital interaction runs under two sets of rules at once: the organization's own rules, and the public rules of treaty, law and standards.
Co-regulated identity puts the public rules into records that the individual, the organization and the regulator can all inspect. The controller, the processor, the individual and the regulator each have a defined role in one shared framework that can be audited.
The individual manages their identity. The controller is accountable for identification. People give consent, and systems set permissions.
The specification
The ANCR extension
The work is specified in the ANCR (Anchored Notice and Consent Receipt) extension to ISO/IEC TS 27560:2023, developed in the Kantara Initiative ANCR Working Group. Release 1, a v1.0 Release Candidate dated 7 September 2026, is under Working Group review.
It defines four records: the Controller Identification Record, the Notice Record, the Notice Receipt and the Notice Event Log.
Release 1 defines eight conformance criteria in clause 5.1: sequence, minimum notice disclosure, anonymity by default, public rule reference, evidence, reciprocal and proportionate disclosure, non-exclusion, and authorization state. Assessment is by inspection of the artefact each criterion names.
The ANCR extension, current release and participation routes, at Kantara
Take part
Join the work
The ANCR extension is developed in the Kantara Initiative ANCR Working Group, which is open to participants through Kantara. Contact us if you would like an introduction to that work.
Contact us
Talk to TCIEG
TCIEG welcomes discussion with regulators, standards participants, civil society, technology providers, legal experts, privacy engineers and implementation practitioners working toward interoperable Operational Transparency standards.