How Global Privacy Rights Controls give regulators inspectable, bilateral transparency and derivative rights controls, demonstrated through age assurance.
Transparency today is asserted, not inspectable. Privacy policies and practice statements are narrative text that a regulator can only audit after the fact, by hand, one complaint at a time. Global Privacy Rights demonstrates a different model: operational transparency assurance, where the authority conditions for processing are made externally inspectable, before identification, in a machine-readable form. This converts transparency from a claim into standing evidence, and it gives regulators supervisory capacity they do not have today.
A privacy notice is meant to disclose who is processing personal data, for what purposes, under what authority, and with what rights. In practice it is narrative text on a page. It cannot be verified after the event, it cannot be compared across controllers, and it cannot be read by a machine. A regulator wanting to know whether a controller gave lawful notice, under which version, at what time, must ask, wait, and rely on the controller's own internal logs.
That is a regulatory capacity gap. Oversight scales with staff and complaints, not with the market it supervises. The signal a regulator needs, a standing and inspectable statement of who is processing and under what authority, does not exist.
Global Privacy Rights runs the alternative. Under Transparency by Default, the authority conditions for processing are externally inspectable before any individual is identified. Three artefacts carry it:
These are assured at levels. First-Factor Notice (1FN) is anonymous disclosure: CIR plus versioned notice plus evidence that disclosure happened, with no personal identifier. Second-Factor Notice (2FN) adds a consent statement returned by the individual, a consent receipt. Higher levels add countersignature and governed operation. Transparency is graded and evidenced, not claimed.
Because the records are public, resolvable, and machine-readable, a regulator, or an automated agent acting for one, can verify controller identity, legal basis, notice version, and disclosure events without a request, a login, or the controller's cooperation. Supervision moves from manual, per-complaint audit to standing, inspectable verification. A regulator can survey a whole sector's controllers against the same structure, flag those with no resolvable record, and check a specific disclosure against the notice that was in force. That is added regulatory capacity, delivered by design rather than by enforcement action.
Transparency in this model is two-way, not the one-way identification demand that dominates the internet today. The controller identifies itself, to the individual and to the regulator, before it requires the individual to identify. Where the controller countersigns the consent statement, the resulting receipt is bilateral: both parties are named, bound, and evidenced in the same record.
Across borders, a resolvable CIR and notice record let one jurisdiction's authority inspect another's controllers on a common structure. Bilateral and multilateral regulatory transparency of this kind is the practical basis for cooperation under instruments such as Convention 108+, turning cross-border oversight from correspondence into inspection.
From the transparency record, rights become operational and proportionate to the technology. Rights controls are derived from an open digital code-of-practice profile, grounded in international law and standards and expressed in machine-readable form. The controls scale with the processing: the more surveillance, inference, or cross-border transfer a system performs, the more transparency it must show and the stronger the derivative rights controls that attach. Rights stop being paper entitlements a person must chase, and become inspectable, exercisable controls tied to the record and reachable from the notice.
Age assurance is the sharpest test of this model, because it is being deployed under a child-safety mandate that makes identifying everyone feel responsible. As drafted, ISO/IEC 27566-2 benchmarks age assurance for accuracy but not for transparency or consent. Operational transparency assurance closes that gap. Before any face, identity document, or credential is requested, the individual and the regulator can see the controller, the authority, the purposes, and the rights. Disclosure is evidenced without an account or a personal identifier, so data minimisation and demonstrable accountability hold at the same time. The ANCR Transparency Performance Indicators score the transparency and consent performance of a system, physical or digital, on a common scale.
This is what regulators have already called for. In September 2024 six privacy authorities, including Canada's Privacy Commissioner, required age assurance to be minimised, transparent, and demonstrable. In February 2026 security researchers warned that identification-first age verification builds surveillance infrastructure that harms the people it is meant to protect. Global Privacy Rights Controls satisfy the first and avoid the second: provable disclosure without identification, measured, and inspectable.
The Controller Identification Record, versioned notice, and Notice Event Log are serving now at globalprivacyrights.org, publicly resolvable and machine-readable. Transparency here is not described. It is running.
Mark Lizar, Global Privacy Rights / 0PN Transparency Lab / Interoperability Expert Group, Co-Founder and Advisor.