Transparency by Default: introducing TCIEG and the Internet Transparency Code of Practice

At CPDP 2026 in Brussels, a Council of Europe panel introduced the Internet Transparency by Default Code of Practice. This is the effort we are taking forward.

Share

At the yearly CPDP Conference in Brussels on 20 May 2026, Peter Kimpian of the Council of Europe opened the panel "Transparency by Default: An Internet Transparency Code of Practice" and introduced, for the first time, the Internet Transparency by Default Code of Practice. He was joined on the panel by Ana Brian Nougrères, the United Nations Special Rapporteur on the Right to Privacy; Mark Lizar of Transparency Lab, Canada; Jan Schallaböck, convener-support to the ISO/IEC working group on privacy and identity management (JTC 1/SC 27/WG 5); and Peter Kits of KPMG.

The panel put a deceptively simple proposition on the table. In a digital world, accountability has to be inspectable before identification is demanded, and disclosure has to be evidenced before personal data crosses a border. That is not how the web works today. Identification, analytics, inference, and cross-border transfer routinely begin before a person can see who is accountable, for what purpose, under what authority.

Ana Brian Nougrères, in her keynote as United Nations Special Rapporteur on the Right to Privacy, named the stakes plainly:

The "trust us" posture currently adopted by many actors, where digital identification is demanded before accountability can even be inspected, is not only a technical risk; it is a human rights challenge.

This is the effort we are now taking forward, and the reason we have formed TCIEG, the Transparency and Consent Interoperability Expert Group.

What TCIEG is

TCIEG is an interoperability effort for verifiable internet transparency: notice, consent, and the records that prove them. Its mission is to support and facilitate the Council of Europe's Transparency Code of Practice, the operational layer that takes what Convention 108+ already requires and specifies it in terms a controller can implement and a regulator can verify.

The group did not appear from nowhere. It sits on two decades of work in notice and consent, from the Kantara Consent Receipt through ISO/IEC 29184 and ISO/IEC TS 27560:2023, and the ANCR Notice Receipt Extension that carries that lineage into cross-border and AI use. TCIEG's anchoring in the Council of Europe instruments is the completion of a design decision made years ago: build the receipt on the OECD principles that underpin Convention 108, so the record means the same thing across borders.

Why now

The old model assumed a visible relationship: a person sees an organisation, reads a notice, makes a choice, then hands over information. Digital systems have inverted that order.

  • Processing starts before the relationship. Sites, apps, and devices assign identifiers and route data before a person knowingly begins anything.
  • Identification happens before awareness. Systems profile and infer before a person reaches any notice or choice.
  • Accountability is spread across many actors: platforms, clouds, analytics, AI, SDKs, ad-tech. A static notice cannot show who is acting, in what role, or with what authority.
  • Cross-border movement raises the stakes, exposing people to different legal regimes and enforcement without their knowledge.

Transparency has to move to before the moment of identification. That is what "transparency by default" means, and it is what the Code of Practice specifies.

What we are doing

TCIEG supports the Internet Transparency Code of Practice with the Council of Europe, contributes to SC 44 and to ISO/IEC JTC 1/SC 27/WG 5, and is promoting the Kantara ANCR ISO/IEC TS 27560:2023 Notice Receipt Extension as the record structure that makes this verifiable. We are careful about our claims: TCIEG does not claim ISO or CoE endorsement, and the ANCR extension is a proposal in progress, not an adopted standard.

The proof of the idea is operational, not asserted. Our own site publishes a Transparency Policy that follows the Code rather than a privacy policy that asserts it, and a working first-notice reference implementation is in development.

Join the effort

TCIEG is open to regulators, standards participants, civil society, technology providers, legal experts, and privacy engineers working toward interoperable operational transparency. You can read more at tcieg.org and subscribe to follow the work.