Transparency Interoperability & Standards

Standards that work together.

The Transparency Stack connects four complementary standards so privacy principles, online notice and consent controls, structured records, and independently inspectable evidence can work as one operational sequence.

Where this sits

The standards lineage

Each standard has a distinct job. Together they move from shared privacy principles to the presentation of notice and consent, then to machine-readable records and receipts, and finally to evidence that identifies the accountable controller before the individual is asked to identify themselves.

  1. ISO/IEC 29100

    Privacy principles

  2. ISO/IEC 29184

    Notice and consent

  3. ISO/IEC TS 27560:2023

    Consent records and receipts

  4. Kantara ANCR

    Anchored notice and consent evidence

The Transparency Stack standards

Four standards, four necessary functions

These blocks describe the role of each standard in the Stack and provide authoritative sources for readers who want the published standard, implementation material, or active community work.

Foundation

ISO/IEC 29100:2024

Privacy framework. ISO/IEC 29100 establishes a common privacy vocabulary, identifies actors and their roles in processing personally identifiable information, describes privacy safeguarding requirements, and sets out privacy principles for information and communication technology systems.

Role in the Stack. It supplies the principles and conceptual foundation. Openness, transparency and notice begin here, alongside purpose legitimacy, consent and choice, collection limitation, data minimization, accountability, information security, and privacy compliance.

Why it matters. The later layers can be tested against a common privacy framework instead of treating notice or consent as an isolated interface event.

Presentation

ISO/IEC 29184:2020

Online privacy notices and consent. ISO/IEC 29184 specifies controls that shape the content and structure of online privacy notices and the process of asking individuals for consent to collect and process PII. ISO confirmed the 2020 edition as current in 2026.

Role in the Stack. It addresses what must be communicated and how the notice and consent interaction is presented online, including timing, accessibility, clarity, withdrawal, and the relationship between the notice and the requested choice.

Why it matters. A record cannot repair a notice that was unclear, late, or detached from the processing it described. This layer connects the privacy principles to the actual human interaction.

Record and receipt

ISO/IEC TS 27560:2023

Consent record information structure. The Technical Specification provides guidance for creating and maintaining machine-readable records about consent and for exchanging those records between parties as receipts.

Role in the Stack. It gives implementations a common information structure for the consent record and the person-facing receipt. The receipt makes evidence portable beyond a controller's internal database and supports consistent exchange between systems.

Why it matters. It changes consent from a local application state into structured information that can be retained, exchanged, compared, and audited. The published 2023 Technical Specification is the baseline used by the ANCR extension.

Anchored evidence

Kantara ANCR

Anchored Notice and Consent Receipt. The ANCR extension profiles ISO/IEC TS 27560:2023 for verifiable online notice evidence. It binds a notice receipt to a resolvable controller identity and a specific, versioned notice, while keeping the receipt anonymous by default.

Role in the Stack. ANCR adds the Controller Identification Record, Notice Record, Notice Receipt, and Notice Event Log needed to show who was accountable, what was presented, when it was presented, and how the notice or authorization state changed over time.

Why it matters. It provides the missing evidence layer. An individual, controller, auditor, or regulator can reconstruct a disclosure event without relying only on the controller's assertion and without requiring a personal identifier merely to obtain or verify the notice receipt.

Standards bodies

Where this work is carried

ISO/IEC JTC 1/SC 27/WG 5

Privacy standards, including online privacy notices and consent (ISO/IEC 29184) and the consent record information structure (ISO/IEC TS 27560:2023). PWI 26689, on notice and consent records, is registered here.

ISO/IEC JTC 1/SC 44

A preliminary work item on an Internet Transparency Code of Practice profile was established here by resolution on 3 September 2026 and assigned to WG 1.

Kantara ANCR WG

The Kantara Initiative ANCR Working Group, where the ANCR extension to ISO/IEC TS 27560:2023 is developed. Release 1 is under Working Group review.

Convention 108+

The modernised Council of Europe data protection convention. The Internet Transparency Code of Practice aligns with its transparency principles.

Interoperability

How the four standards work together

ISO/IEC 29100 defines the privacy principles. ISO/IEC 29184 carries those principles into the online notice and consent interaction. ISO/IEC TS 27560:2023 structures the consent record and receipt. Kantara ANCR anchors the record to a verifiable controller identity, an authoritative notice version, and lifecycle evidence.

The sequence is deliberate: identify the accountable controller, present the applicable notice, record the notice event, capture authorization where consent applies, and preserve evidence that can be independently inspected later.

Other protocols and vocabularies can connect at the appropriate layer. Privacy signals such as GPC and ADPC can express preferences; DPV can provide interoperable semantics; OAuth, OpenID Connect, SD-JWT and digital wallets can carry identity or authorization information. The Transparency Stack supplies the notice, accountability, and evidence context those technologies do not provide on their own.

Testing

Sandbox testing

TCIEG is preparing test material for the ANCR extension used together with ISO/IEC TS 27560:2023. The aim is audit trails that follow a standard and can be verified.

Contact us

Talk to TCIEG

TCIEG welcomes discussion with regulators, standards participants, civil society, technology providers, legal experts, privacy engineers and implementation practitioners working toward interoperable Operational Transparency standards.

Contact us