Controller first
The individual can see who is asking, and under what authority, before anything about them is collected.
Consent that can be shown to have happened.
The problem
In many online services the individual is identified before the controller is disclosed, before the purpose is stated, and before the legal basis can be checked.
A click recorded at that point is a system permission. It is weak evidence that a person understood and agreed.
What it takes
The individual can see who is asking, and under what authority, before anything about them is collected.
The exact version of the notice that was shown can be checked later.
The person keeps their own evidence of what they agreed to, and does not have to identify themselves to get it.
Later changes, including withdrawal, are recorded so the current state can be shown at any time.
From claim to evidence
REALconsent is TCIEG's public framework for explaining and testing whether an online consent interaction produces evidence of informed, specific, freely given, and withdrawable human choice. It separates the person's consent statement from the permissions a system manages after that statement.
The framework follows the Transparency Stack: ISO/IEC 29100 supplies the privacy principles; ISO/IEC 29184 addresses the notice and consent interaction; ISO/IEC TS 27560:2023 structures the consent record and receipt; and the Kantara ANCR extension anchors that evidence to the controller, notice version, presentation event, and later lifecycle changes.
TCIEG is developing the assessment method, implementation guidance, and participation model. Until those elements are formally published, REALconsent should be understood as a framework under development, not a certification or conformity mark.
Contact us
TCIEG welcomes discussion with regulators, standards participants, civil society, technology providers, legal experts, privacy engineers and implementation practitioners working toward interoperable Operational Transparency standards.