A call for a digital transparency standard

Digital borders are operational reality, but notice is still a local, narrative artifact. Why cross-border accountability needs a machine-readable, inspectable transparency standard.

Share
A call for a digital transparency standard

By Mark Lizar — Interoperability Expert Group (225IEG) / Global Privacy Rights / 0PN Transparency Lab

Digital borders are now operational reality. Data flows, AI mediated services, and digital identification systems routinely cross jurisdictions. Yet “notice” is still treated as a local, narrative artifact. That mismatch is now a material governance risk.

The practical requirement is simple: an individual, an agent, or a regulator must be able to discover who is accountable, what is being done, and under what authority, before identification is demanded or data is collected. If that information cannot be discovered and inspected reliably, the notice record is not testable. If it is not testable, it cannot support accountable cross border processing.

Proportionate machine-readable rights access

What should be normative first is not a fixed rights list imposed on every jurisdiction. It is the requirement that rights information access be machine readable and proportionate: disclosed in a form a person or an agent can inspect, and scaled to the processing at hand.

This is the minimum that makes the notice record testable. It is the property that ISO/IEC 29184 Online privacy notices and consent standard defines for standard notice presentation, but does not make operational for record exchange. Which is why the consent notice receipt extension of 27560 TS, posted at Kantara, supplies that operational layer by making rights access inspectable and machine actionable in the notice record itself.

Why “operational transparency” has to come before “authority by default”

Many systems now operate as authority by default. They act first, collect first, infer first, and only later offer explanations and controls. That is not a stable model for the digital commons, because it makes oversight reactive and it makes meaningful choice impossible in practice, it makes the internet unfair and harmful.

A transparency by default Internet governance model reverses the sequence:

  1. Controller identification is disclosed first.
  2. Purpose, justification, and scope are disclosed in a structured form.
  3. Rights access information is disclosed in a machine readable way, proportionate to the processing context.
  4. Only then can authorization, objection, withdrawal, or other lawful processing controls be exercised with evidence. This is not “more compliance.” It is the minimum architecture for auditable accountability at scale.

A safe construction method: each decision carries an operational principle

A normative rights table can be safe and inclusive only when it is paired with the discipline that governs its use. This extension, contributed as a 26689 work item under ISO / IEC governance, and is predicated on a simple code of practice pattern: each normative decision in the specification is matched by one operational principle in the Transparency Code of Practice.

The specification stays testable. The Code of Practice carries the judgment, set through processes which provide for inclusive and informed consensus.

Two worked examples show how this avoids the usual failure modes:

  • Principle 1: proportionality to technology. Transparency and controls scale up with the identification and inference power of the technology in use, notably digital identification and AI. The greater the capability, the more specific the disclosure and the stronger the practical controls.
  • Principle 2: transparent limitation. Where a right is scaled down, the limitation is itself disclosed, bounded, and auditable. A derogation carries a triad: the limitation considerations that justify it, the safeguards that bound it, and the derivative rights controls the individual retains.
    • A derogation transforms a right into a derivative control under safeguards. It does not delete it.
    • Principle 2 answers the common objection that jurisdictions differ. They do. The point is that difference must be declared and audited, not borders crossed silently. A derogation reference mechanism makes variation inspectable. It is how a normative rights annex can remain both testable and inclusive.

Co-Regulated Id and discovery: search and listings

A major governance gap is that discovery infrastructure has become de facto regulation infrastructure.

Search engines, app stores, ad tech directories, and data broker listings shape what is discoverable about accountability. They determine whether an individual can locate a real controller, a real rights access point, or even a stable notice statement.

Without a machine readable transparency standard, discovery remains dominated by ad-governed marketing pages, inconsistent registries, and non interoperable “about” pages that cannot be validated or personally compared at scale.

The UK ICO registry as a missed, and still plausible, commons foundation

The UK ICO register was a plausible foundation for a common public accountability index. It could have evolved into a global “company search engine” for the digital commons. A place where controllers are discoverable, where notice endpoints are stable, and where rights access points are locatable.

Even now, the underlying idea remains sound. If we want cross border enforceability, we need a shared common data controller discovery surface that can be indexed, validated, and referenced in machine readable notice.

Updated finally 18 years later with an AI Controller registry, Aug 2nd, 2026.

Why this mitigates risk, not just satisfies process

Transparency, in the standards sense, is disclosure that is informed and that enables informed engagement. A controller that publishes a controller identification record, a versioned notice, and a proportionate machine readable rights context has created an inspectable transparency schema.

That schema is what makes accountability operational:

  • An assertion of compliance cannot transfer liability, because there is nothing to inspect.
  • Inspectable evidence of disclosure, proportionate to the technology, with rights and derivative controls that remain exercisable, can.
  • Proportionate machine readable rights access is therefore not a compliance burden. It is the mechanism by which a controller mitigates risk and, where lawful, enables responsible reliance on evidence rather than assertion.

A practical call

If we care about cross border data flows, AI governance, and fair digital identification systems, we need a digital transparency policy standard that harmonises notice so as to be operable, discoverable, testable, and machine readable transparency.

That starts with one common point of consensus, the normative requirement that makes the internet inclusive, that can survive jurisdictional diversity:

proportionate machine readable rights transparency and access.