A statement from Global Privacy Rights

Operational Transparency Assurance

How Global Privacy Rights Controls give regulators inspectable, bilateral transparency and derivative rights controls, demonstrated through age assurance.

In one paragraph

Transparency today is asserted, not inspectable. Privacy policies and practice statements are narrative text that a regulator can only audit after the fact, by hand, one complaint at a time. Global Privacy Rights demonstrates a different model: operational transparency assurance, where the authority conditions for processing are made externally inspectable, before identification, in a machine-readable form. This converts transparency from a claim into standing evidence, and it gives regulators supervisory capacity they do not have today.

The problem

Transparency is asserted, not operational

A privacy notice is meant to disclose who is processing personal data, for what purposes, under what authority, and with what rights. In practice it is narrative text on a page. It cannot be verified after the event, it cannot be compared across controllers, and it cannot be read by a machine. A regulator wanting to know whether a controller gave lawful notice, under which version, at what time, must ask, wait, and rely on the controller's own internal logs.

That is a regulatory capacity gap. Oversight scales with staff and complaints, not with the market it supervises. The signal a regulator needs, a standing and inspectable statement of who is processing and under what authority, does not exist.

The model

Operational transparency assurance

Global Privacy Rights runs the alternative. Under Transparency by Default, the authority conditions for processing are externally inspectable before any individual is identified. Three artefacts carry it:

  • The Controller Identification Record (CIR): who the controller is, its legal basis, its rights access point, and its purposes, publicly resolvable before anything is asked of the individual.
  • The versioned notice: the exact notice in force, hash-linked to the CIR, so the disclosure at any past moment can be recovered.
  • The Notice Event Log (NEL): an append-only, timestamped record of disclosure events, publicly readable.

These are assured at levels. First-Factor Notice (1FN) is anonymous disclosure: CIR plus versioned notice plus evidence that disclosure happened, with no personal identifier. Second-Factor Notice (2FN) adds a consent statement returned by the individual, a consent receipt. Higher levels add countersignature and governed operation. Transparency is graded and evidenced, not claimed.

Capacity

How this gives regulators capacity

Because the records are public, resolvable, and machine-readable, a regulator, or an automated agent acting for one, can verify controller identity, legal basis, notice version, and disclosure events without a request, a login, or the controller's cooperation. Supervision moves from manual, per-complaint audit to standing, inspectable verification. A regulator can survey a whole sector's controllers against the same structure, flag those with no resolvable record, and check a specific disclosure against the notice that was in force. That is added regulatory capacity, delivered by design rather than by enforcement action.

Two-way

Bilateral transparency

Transparency in this model is two-way, not the one-way identification demand that dominates the internet today. The controller identifies itself, to the individual and to the regulator, before it requires the individual to identify. Where the controller countersigns the consent statement, the resulting receipt is bilateral: both parties are named, bound, and evidenced in the same record.

Across borders, a resolvable CIR and notice record let one jurisdiction's authority inspect another's controllers on a common structure. Bilateral and multilateral regulatory transparency of this kind is the practical basis for cooperation under instruments such as Convention 108+, turning cross-border oversight from correspondence into inspection.

Rights

Derivative rights controls

From the transparency record, rights become operational and proportionate to the technology. Rights controls are derived from an open digital code-of-practice profile, grounded in international law and standards and expressed in machine-readable form. The controls scale with the processing: the more surveillance, inference, or cross-border transfer a system performs, the more transparency it must show and the stronger the derivative rights controls that attach. Rights stop being paper entitlements a person must chase, and become inspectable, exercisable controls tied to the record and reachable from the notice.

Worked example

Age assurance

Age assurance is the sharpest test of this model, because it is being deployed under a child-safety mandate that makes identifying everyone feel responsible. As drafted, ISO/IEC 27566-2 benchmarks age assurance for accuracy but not for transparency or consent. Operational transparency assurance closes that gap. Before any face, identity document, or credential is requested, the individual and the regulator can see the controller, the authority, the purposes, and the rights. Disclosure is evidenced without an account or a personal identifier, so data minimisation and demonstrable accountability hold at the same time. The ANCR Transparency Performance Indicators score the transparency and consent performance of a system, physical or digital, on a common scale.

This is what regulators have already called for. In September 2024 six privacy authorities, including Canada's Privacy Commissioner, required age assurance to be minimised, transparent, and demonstrable. In February 2026 security researchers warned that identification-first age verification builds surveillance infrastructure that harms the people it is meant to protect. Global Privacy Rights Controls satisfy the first and avoid the second: provable disclosure without identification, measured, and inspectable.

The ask

What we ask of regulators

  1. Recognise operational transparency, inspectable-before-identification and machine-readable, as the evidentiary standard for demonstrating compliance, in preference to narrative assertions.
  2. Use public transparency records as a supervisory input, so oversight scales with inspection rather than complaint volume.
  3. Support the standards that make this the norm: ISO/IEC TS 27560:2023, the ANCR Notice Receipt Extension, the ANCR Transparency Performance Indicators, and a Transparency Code of Practice.
Live

It is live

The Controller Identification Record, versioned notice, and Notice Event Log are serving now at globalprivacyrights.org, publicly resolvable and machine-readable. Transparency here is not described. It is running.

References
  • ANCR Transparency Performance Indicators Recommendation ("PII Controller Identification for Valid Consent"), Kantara Initiative ANCR WG, August 2025. kantarainitiative.org
  • ANCR Notice Receipt Extension to ISO/IEC TS 27560:2023, Kantara ANCR WG. kantarainitiative.github.io/ancr-wg
  • Joint statement on a common international approach to age assurance, six data protection and privacy authorities including the Office of the Privacy Commissioner of Canada, September 2024. priv.gc.ca
  • Open letter on age verification, cryptography and security researchers, February 2026. csa-scientist-open-letter.org

Mark Lizar, Global Privacy Rights / 0PN Transparency Lab / Interoperability Expert Group, Co-Founder and Advisor.