Before Identification: Ana Brian Nougreres on transparency as a human right
At CPDP 2026, the UN Special Rapporteur on the Right to Privacy made the case that accountability must be inspectable before identification is demanded.
At CPDP 2026 in Brussels, on the Council of Europe panel "Transparency by Default: An Internet Transparency Code of Practice" opened by Peter Kimpian, Ana Brian Nougrères delivered a keynote she titled "Before Identification." Speaking as the United Nations Special Rapporteur on the Right to Privacy, she made a case that is as much about human dignity as it is about data.
Her starting point was the disappearance of borders. We now operate, she said, "within a borderless digital ecosystem characterized by multi-party chains of controllers, processors, and AI service layers that span the globe." In that world, protections have not kept pace:
We see individuals and regulators frequently unable to determine, until long after the processing has begun, who is truly accountable for their data, what specific purpose is being pursued, or what legal authority is being relied upon.
The problem is timing
Her sharpest point was about the order of operations. A standard digital interaction, she noted, begins with a demand: "Identify yourself." A login, a biometric scan, the creation of a profile. The individual is asked to surrender their identity first, on "abstract promises that the backend processing is lawful and secure."
That inversion, she argued, is not a minor technical shortcoming:
The "trust us" posture currently adopted by many actors, where digital identification is demanded before accountability can even be inspected, is not only a technical risk; it is a human rights challenge.
Because the problem is structural, so is the fix. Rather than wait for a breach or a complaint, she called for a new standard that "specifies exactly what must be inspectable before identification is demanded and before any transfer occurs." The goal, in her words, is to "transition from a model of blind trust to one of verifiable accountability."
A legal cornerstone, then an operational one
Nougrères grounded the approach in the Council of Europe's modernised Convention 108+, which she described as "this exact legal cornerstone": the normative foundation that ensures the right to privacy is "not lost in translation or diluted as data crosses jurisdictional lines." Convention 108+, she said, gives the mandate "to rigorously define what must be inspectable before digital identification is demanded and before any cross-border transfer occurs."
But legal text, she was clear, "cannot execute code or parse data packets on its own." It needs technical translation. That is where the operational transparency code of practice comes in, grounded in Convention 108+ and operationalised through the ISO/IEC WG 5 standardisation work, through "evidence artefacts" that attach verifiable governance to a data flow and make oversight scalable.
From reactive to proactive
The payoff she described is a change in what regulators can do. Embedding transparency and governance up front "enables regulatory intervention to become proactive, instead of reactive," replacing after-the-fact investigation with evidence available at the point of processing.
She closed with a call to the field:
We must demand that digital systems are architected to prove their compliance and accountability at the very first point of interaction, not after the data is already flowing through opaque, multi-party chains.
And with a vision:
Let us commit to building a digital ecosystem where privacy is the default, where transparency is fully operationalized, and where human dignity remains the indisputable center of our shared digital future.
This is the case TCIEG exists to carry forward: transparency before identification, grounded in Convention 108+, made verifiable through the record structures that let a person and a regulator see who is accountable, for what purpose, and under what authority, before they are asked to identify themselves.
Ana Brian Nougrères delivered "Before Identification" as the UN Special Rapporteur on the Right to Privacy at CPDP 2026, Brussels, 20 May 2026. The keynote is published by the Council of Europe.