Operational Transparency

Transparency has to move earlier.

Notice and accountability must be knowable before identification, before inference, and before any cross-border transfer.

What it means

Visible when it matters

Operational transparency means an individual and a regulator can see who is accountable, what purpose is pursued, and under what authority, at the moment it matters.

A privacy statement read after the fact comes too late. By then the individual has often been identified, profiled and passed to other organizations.

Notice and accountability must be knowable before identification, before inference, and before cross-border transfer

Why now

Why the old model fails

Traditional privacy controls were built around a visible relationship: an individual is aware of the organization, receives a privacy statement, makes a choice, and then provides their information. Digital systems now work in a different order. Identification, analytics, AI processing, inference, and cross-border disclosure can begin before an individual understands who is accountable, what is being processed, or what authority is being claimed.

Early processing

Websites, apps, devices and sensors can begin collecting signals, assigning identifiers, or routing data before an individual logs in, conducts a transaction or knowingly begins a relationship.

Early identification

Digital systems can identify, profile, link or infer information about an individual before they have access to notice or consent mechanisms. Transparency must shift to prior to the moment of identification and inference.

Many actors involved

PII processing involves platforms, cloud services, analytics providers, AI systems, identity tools, SDKs, APIs and ad-tech services. A static notice does not show who is acting, their role or authority, or their responsibility as PII moves across the ecosystem.

Cross-border risk

International transfers expose individuals to different legal regimes, enforcement criteria, disclosure rules and surveillance risks. These conditions should be made known to the individual prior to any transfer.

In practice

What organizations do

  1. Publish a controller identification record

    Say who the controller is, and how to reach them, before any personal data is exchanged.

  2. Keep the notice by version

    Record each version of the notice so that anyone can check what was shown on a given day.

  3. Give a receipt without asking for identification

    The individual gets evidence that the notice was given, and does not have to say who they are to get it.

  4. Keep an event log

    Record each notice event so the history can be inspected later.

Contact us

Talk to TCIEG

TCIEG welcomes discussion with regulators, standards participants, civil society, technology providers, legal experts, privacy engineers and implementation practitioners working toward interoperable Operational Transparency standards.

Contact us