Controller ID Record
The Controller Identification Record is published before any personal data is exchanged. It says who the controller is and how to reach them.
Transparency Stack
No single standard covers transparency from start to finish. The Transparency Stack puts the existing standards in order and adds the operational layer.
What it is
Engineers can point to the layer of the internet where something happens. Privacy has had no such map.
The Transparency Stack is that map for transparency. It shows which standard does which job, from privacy principles, through notice and consent, to the records that show what took place.
Read: The Transparency Stack, and where it sits on the OSI model
The layers
Sets the principles that everything else rests on, including openness, transparency and notice.
Sets the controls for how a privacy notice is presented and how consent is asked for.
Sets the information structure for recording consent and giving the individual a receipt.
Adds the Controller Identification Record, the versioned Notice Record, the Notice Receipt and the Notice Event Log. The receipt is anonymous by default and binds the disclosure event to the accountable controller and the applicable notice version.
Sets out how an organization puts these into practice and keeps them current.
The records
The Controller Identification Record is published before any personal data is exchanged. It says who the controller is and how to reach them.
The notice itself, kept by version, so anyone can check exactly what was shown.
Evidence, held by the individual, that the notice was given. Available without being required to identify yourself.
A running record of each notice event over the life of the relationship.
Contact us
TCIEG welcomes discussion with regulators, standards participants, civil society, technology providers, legal experts, privacy engineers and implementation practitioners working toward interoperable Operational Transparency standards.