Standards explainer

What makes a consent receipt authoritative

A consent receipt is only worth something if it is authoritative: issued under a controller’s authority, bound to a notice you were given before you were identified, and tamper-evident. Here is what that means, and why a vocabulary alone cannot provide it.

The test

Three things have to be true

  1. Authority. It is issued under a named, resolvable controller who is accountable for it, not by whoever happened to keep the record.
  2. Notice-first. It is bound to a notice that was presented and resolvable before any identification was demanded, not reconstructed after tracking began.
  3. Tamper-evident. It is written to an append-only log and independently retainable, so its ordering and content cannot be quietly edited later.

Miss any one of these and you do not have an authoritative consent receipt. You have a record someone kept.

The distinction that matters

Describe is not authorize

A vocabulary can describe consent. The Data Privacy Vocabulary (DPV) can tag purposes, legal bases, and processing, and it can serialize them, including alongside ISO/IEC TS 27560. That is genuinely useful for interoperability.

But a vocabulary cannot supply authority. It has no controller identity, no notice-first binding, and no scoping of who may lawfully claim a legal basis, where, and under what oversight. So a DPV-serialized record is, at most, consent evidence. On its own it is not an authoritative consent receipt, and presenting it as one is how surveillance-by-default gets laundered into the appearance of consent.

In one line: DPV can say what a consent record contains. It cannot make that record authoritative. Authority comes from the controller, the notice, and the log, not from the vocabulary.

How we make it authoritative

Notice and Consent Receipt, here

At Global Privacy Rights the authority is explicit and inspectable, under ISO/IEC TS 27560:2023 and PWI 26689 (Notice and Consent Records):

Controller
did:web:globalprivacyrights.org, published as a Controller Identification Record (CIR) so anyone can see who is accountable before being identified.
Notice-first
The first-factor notice (1FN) is presented and resolvable before any identification is demanded. The receipt binds to the exact notice version shown.
Tamper-evident
Every notice event is written to an append-only Notice Event Log (NEL), so ordering and content are provable, not editable after the fact.
Standard
ISO/IEC TS 27560:2023 for the receipt structure; PWI 26689 for notice and consent records and the controller authority model.
Why it matters

For people

You can see who controls your data, and hold a receipt you can keep, not a claim you have to trust.

For controllers

Authority you can show beats compliance you assert. An authoritative receipt supports an enforcement decision.

For regulators

Notice-first ordering and a tamper-evident log make consent evidence strong enough to act on.

See it live

The petition issues a real one

Our Canada Day petition is also the first live instance of this: when you sign, you are shown a real notice, and signing mints a Notice and Consent Receipt bound to that notice. The petition dogfoods the standard it asks the world to adopt.

Sign the petition →

Inspect the records directly: CIR · NEL · your rights