Transparency Performance Indicators: Benchmarking Age Assurance

ISO/IEC 27566-2 benchmarks age assurance for accuracy but not transparency. The Kantara ANCR Working Group's TPI scores transparency and consent performance, for physical and digital age checks alike.

Share
Transparency Performance Indicators: Benchmarking Age Assurance

The ANCR Working Group's Transparency Performance Indicators turn transparency from an assertion into a score, and they apply to age assurance in both physical and digital contexts.

Age assurance is being standardised internationally. ISO/IEC 27566-2 is the benchmarking part: it exists to let age assurance systems be measured and compared. It benchmarks accuracy, coverage, and robustness. What it does not yet measure is the property that decides whether an age assurance system is lawful and trustworthy: is it transparent, and can it obtain and demonstrate valid consent? You cannot benchmark what you cannot measure.

📊
Transparency you can score. The ANCR Transparency Performance Indicators turn transparency and consent into a measurable number, for physical and digital age assurance alike. Read the TPI recommendation →

The ANCR Working Group has published the tool that measures it.

What TPI 's are

In August 2025 the Kantara Initiative's Anchored Notice and Consent Receipts (ANCR) Working Group published the Transparency Performance Indicators Recommendation, "Transparency Performance Indicators: PII Controller Identification for Valid Consent." It builds on the Working Group's core lineage: the Consent Receipt, carried into ISO/IEC 29184:2020 Annex B, standardised as ISO/IEC TS 27560:2023, and extended by the ANCR Notice Receipt Extension.

TPI measures two things. First, Controller Identification: is the entity processing the data identified, resolvable, and inspectable before anything is asked of the individual? Second, a four-index transparency measurement, each scored from 0 to 100, with a pass mark at 70:

  • Notice Adequacy: is a notice presented, at the right time and place?
  • Notice Content: does it carry what the law requires (controller, purposes, rights, contact, cross-border scope)?
  • Rights Access: can the individual reach and exercise their rights from the notice?
  • Accountability: is there durable, inspectable evidence that disclosure happened?

The output is a transparency and consent performance score for a controller. Evidence-based, not asserted.

Why it fits physical and digital age assurance

Age assurance does not only happen online. It happens at a door, at a till, at a border, on a device, and through third-party providers the individual never sees. Each shares a controller who must be identified and a notice that must be given before the individual is measured, scanned, estimated, or inferred.

Because TPI measures controller identification and notice performance rather than a channel or a technology, one scale scores a physical check and a digital one alike. A store scanning an ID, an app estimating age from a selfie, and a platform inferring age from behaviour can each be benchmarked for transparency and consent performance against the same measure. That portability is precisely what a benchmarking standard needs.

How it applies to the benchmark

Where age assurance processes personal data, the transparency record can be structured with ISO/IEC TS 27560:2023 and the ANCR Notice Receipt Extension, and its performance scored with TPI. The extension defines the notice and consent record; TPI scores how well a system produces it. This gives a benchmarking standard such as ISO/IEC 27566-2 a transparency and consent performance dimension alongside the accuracy measures.

It is being taken up in exactly that setting. National body comments on the WD 27566-2 draft reference the ANCR extension to TS 27560 as the record structure for auditable notice in age assurance, the substrate TPI is designed to measure.

Crucially, TPI and the extension do not force identification. Evidence of disclosure can be produced without an account or a personal identifier, so a system can score full marks on Accountability while holding no more data than necessary.

Reference implementation

The pattern runs in production. A live reference implementation at globalprivacyrights.org serves a Controller Identification Record, a versioned notice, and an append-only Notice Event Log, publicly resolvable and machine-readable, with no login and no identification required. It is a controller measured in the open, on the indicators TPI defines.

The point

A benchmark that scores how accurately a system estimates age, but not whether it identified who was collecting the data or recorded that a notice was given, measures the wrong thing first. Transparency and consent performance can be scored today, across physical and digital age assurance, with published and freely available standards from the ANCR Working Group.

References

  • ANCR Transparency Performance Indicators Recommendation ("PII Controller Identification for Valid Consent"), Kantara Initiative ANCR WG, August 2025. kantarainitiative.org
  • ANCR Notice Receipt Extension to ISO/IEC TS 27560:2023, Kantara ANCR WG. kantarainitiative.github.io/ancr-wg
  • Joint statement on a common international approach to age assurance, six data protection and privacy authorities including the Office of the Privacy Commissioner of Canada, September 2024. priv.gc.ca
  • Open letter on age verification, cryptography and security researchers, February 2026. csa-scientist-open-letter.org

Posted for the Kantara Initiative ANCR Working Group. Mark Lizar, ANCR-WG contributor and editor of the Consent Notice Receipt for Digital Consent.