Transparency Stack

The Transparency Stack

No single standard covers transparency from start to finish. The Transparency Stack puts the existing standards in order and adds the operational layer.

What it is

A map of the standards

Engineers can point to the layer of the internet where something happens. Privacy has had no such map.

The Transparency Stack is that map for transparency. It shows which standard does which job, from privacy principles, through notice and consent, to the records that show what took place.

Read: The Transparency Stack, and where it sits on the OSI model

The layers

What each layer does.

  1. ISO/IEC 29100: privacy principles

    Sets the principles that everything else rests on, including openness, transparency and notice.

  2. ISO/IEC 29184: notice and consent

    Sets the controls for how a privacy notice is presented and how consent is asked for.

  3. ISO/IEC TS 27560:2023: consent records and receipts

    Sets the information structure for recording consent and giving the individual a receipt.

  4. ANCR extension to ISO/IEC TS 27560:2023

    Adds the Controller Identification Record, the versioned Notice Record, the Notice Receipt and the Notice Event Log. The receipt is anonymous by default and binds the disclosure event to the accountable controller and the applicable notice version.

  5. ITCoP and Convention 108+: the operational layer

    Sets out how an organization puts these into practice and keeps them current.

The records

Records you can inspect

Controller ID Record

The Controller Identification Record is published before any personal data is exchanged. It says who the controller is and how to reach them.

Notice Record

The notice itself, kept by version, so anyone can check exactly what was shown.

Notice Receipt

Evidence, held by the individual, that the notice was given. Available without being required to identify yourself.

Notice Event Log

A running record of each notice event over the life of the relationship.

Contact us

Talk to TCIEG

TCIEG welcomes discussion with regulators, standards participants, civil society, technology providers, legal experts, privacy engineers and implementation practitioners working toward interoperable Operational Transparency standards.

Contact us