Notice before identification: launching TCIEG
Notice before identification puts the sequence back — what must be inspectable before you are asked to identify, and why TCIEG is launching to standardise it.
Every digital interaction now begins with the same demand. Identify yourself. Log in, scan a face, create an account, accept the terms. Only afterwards, if at all, does a person learn who is accountable for what follows, what is being processed, on what authority, and where it travels.
Traditional privacy frameworks assume a visible relationship. Individuals know the company, read a privacy notice, make a choice and then hand over their personal data. Digital systems no longer work in that order: identification, profiling, inference, automated processing and cross-border disclosure begin before an individual has any idea who is accountable, what is being processed, or under what authority. The notice arrives after the fact, if it arrives at all.

Notice before identification puts the sequence back. It is one of the primary transparency principles that the Transparency and Consent Interoperability Expert Group (TCIEG.org) is driving through its transparency standardisation and interoperability initiatives. TCIEG is also championing the creation of an Internet Transparency Code of Practice (ITCoP).
Where the principle was introduced
This concept was introduced in May at CPDP 2026 in Brussels during the “Transparency by Default: An Internet Transparency Code of Practice” panel, organised by the Council of Europe. Peter Kimpian, Secretary to the Committee of the Council of Europe Privacy and Data Protection, moderated the panel which included Ana Brian Nougrères, UN Special Rapporteur on the Right to Privacy, Jan Schallaböck, Vice-Convenor, ISO/IEC JTC 1/SC 27/WG 5, Identity management and privacy technologies, Peter Kits, Partner, KPMG Tech Law & Privacy, and Mark Lizar, Co-founder of TCIEG.
Dr. Brian Nougrères presented the keynote and made the case that transparency is as much about human dignity as it is about data. Her starting point was the disappearance of borders. “We now operate”, she said, "within a borderless digital ecosystem characterized by multi-party chains of controllers, processors, and AI service layers that span the globe." In that world, protections have not kept pace. Individuals and regulators frequently cannot determine, until long after the processing has begun, who is truly accountable, what specific purpose is being pursued, or what legal authority is being relied upon.
The order of operations
Her sharpest point was about sequence. A standard digital interaction, she noted, begins with a demand: "Identify yourself." A login, a biometric scan, the creation of a profile. The individual is asked to submit to identification first, on "abstract promises that the backend processing is lawful and secure." That inversion, she argued, is not a minor technical shortcoming. The "trust us" posture currently adopted by many actors, where digital identification is demanded before accountability can even be inspected, is not only a technical risk. It is a human rights challenge. Because the problem is structural, so is the fix. Rather than wait for a breach or a complaint, she called for a new standard that "specifies exactly what must be inspectable before identification is demanded and before any transfer occurs." The goal, in her words, is to "transition from a model of blind trust to one of verifiable accountability."
From legal text to verifiable evidence
Dr. Brian Nougrères grounded the approach in the Council of Europe's modernised Convention 108+, which she described as "this exact legal cornerstone": the normative foundation that ensures the right to privacy is "not lost in translation or diluted as data crosses jurisdictional lines." Convention 108+, she said, gives the mandate "to rigorously define what must be inspectable before digital identification is demanded and before any cross-border transfer occurs." But legal text, she emphasised, "cannot execute code or parse data packets on its own." It needs technical translation. That is what the Internet Transparency Code of Practice is for. Grounded in Convention 108+ and operationalised through the ISO/IEC WG 5 standardisation work, it turns obligations into "evidence artefacts" that attach verifiable governance to a data flow and make oversight scalable.
The result is a change in what regulators can do. Standardised notice and consent records make transparency and governance obligations checkable online and up front, at the point of processing, rather than reconstructed afterwards. Technologies built this way, she said, "enable regulatory intervention to become proactive, instead of reactive."
She closed with a call to the global community of regulators, technologists, and civil society "to champion this operational transparency": "We must demand that digital systems are architected to prove their compliance and accountability at the very first point of interaction, not after the data is already flowing through opaque, multi-party chains." And with a vision: "Let us commit to building a digital ecosystem where privacy is the default, where transparency is fully operationalized, and where human dignity remains the indisputable center of our shared digital future."
This is why today we announce the launch of TCIEG.
The Transparency and Consent Interoperability Expert Group, champions of the global internet's adoption of common human rules for the Internet Transparency Code of Practice.
Finally, scaling human privacy and security online (rather than the other way around). Transparency by default turns transparency into a two-way street, so that a person and a regulator can see who is watching, for what purpose, and under what authority, before digital identification is demanded and before data crosses a border. It requires a co-regulated form of digital identification that can scale, grounded in Convention 108+ and carried into a standard internet protocol.
The work has three parts. First, a machine readable notice and consent receipt exchange. ISO/IEC TS 27560, the consent record information structure, was contributed from the Kantara Initiative Consent and Information Sharing Work Group. TCIEG works with the Kantara ANCR Work Group, which holds liaison to ISO/IEC JTC 1/SC 27/WG 5 and contributes the ANCR extension to TS 27560, for generating Digital Consent. This sets the rules for co-regulated implementations of digital identification, so that authoritative online records can be used to regulate sovereign digital identification technology online.
This way a notice presented online produces a record the individual can trust, issued from the controller's published information and without identifying the person who receives it. Second, a publicly accessible Controller Identification Record, so that the accountable party and its processing locations are known before anyone is identified or tracked. Third, the Internet Transparency Code of Practice, a global transparency policy profile that sets the rules we can all use online. It states the rule in one line: what is inspectable in person must be verifiable online, before identification is demanded and before any transfer occurs. That is what these standards make possible on networked devices, by default.

Transparency that cannot be checked is a promise. Online notice that produces a record is evidence, and that record holds the controller to account by default. That is the difference this era is built on.
Learn more
Sign up to the TCIEG Insights blog to follow the work as it develops
Contact: info@tcieg.org