Operational transparency before identification and before transfer

A public interoperability initiative for trust-capable digital transparency.

IEG supports the development of interoperable digital transparency practices aligned with global privacy rules and standards.

Public role

IEG is leading the way in Operational Transparency.

IEG's mission is to drive interoperability with existing standards for notice, choice and consent - and to develop new standards to address modern requirements for transparency, particulary for cross-border and AI/ML use cases. We focus on the semantic and technical interoperability problems that make transparency hard to implement across digital identity systems including consent records and privacy notices. Our work involves aligning with established transparency-related standards, including the privacy principles of ISO/IEC 29100, notice and consent mechanisms of ISO/IEC 29184, and consent record and receipt structures of ISO/IEC TS 27560:2023 - as well as identifying where new Operational Transparency mechanisms are needed.

IEG brings together expertise in consent and notice standards, privacy engineering and privacy operationalization standards, alongside more than twenty years of guiding companies, industries and regulators in defining privacy requirements related to transparency, accountability, controller identification, and data subject rights. Our experts have co-edited foundational global standards for operationalizing privacy and security controls in emerging technology, including AI/ML, pioneered early specifications that have shaped international standards for consent records, machine-readable privacy vocabularies, notice record structures, and transparency reporting, and actively participate as experts in ISO/IEC SC27 JTC1 WG5 and other national and international standards organizations.

Why now

Old data protection models no longer fit digital identification.

Traditional privacy controls were built around a visible relationship: an individual is aware of the organization, receives a privacy statement, makes a choice, and then provides their information. Digital systems now work in a different order. Identification, analytics, AI processing, inference, and cross-border disclosure can begin before an individual understands who is accountable, what is being processed, or what authority is being claimed.

Processing now starts before the relationship

Websites, apps, devices and sensors can begin collecting signals, assigning identifiers, or routing data before an individual logs in, conducts a transaction or knowingly begins a relationship.

Identification now occurs before awareness

Digital systems can identify, profile, link or infer information about a individual before they have access to notice or consent mechanisms. Transparency must shift to prior the moment of identification and inference.

Accountability is spread across multiple actors

PII processing involves platforms, cloud services, analytics providers, AI systems, identity tools, SDKs, APIs and ad-tech services. A static notice does not show who is acting, their role or authority, or their responsibility as PII moves across the ecosystem.

Cross-border movement raises stakes

International transfers expose individuals to different legal regimes, enforcement criteria, disclosure rules and surveillance risks. Thee conditions should be made known to the individual prior to any transfer.

Engage with Interoperability Expert Group

Driving Operational Transparency standards

IEG welcomes discussion with regulators, standards participants, civil society, technology providers, legal experts, privacy engineers and implementation practitioners working toward interoperable Operational Transparency standards.

Contact    IEG