Okay, so, welcome. The topic today that we wanted to address jointly is how do you respect privacy across jurisdictional boundaries in the area of digital credentials? The context within which we want to talk about this issue is credentials that already are being used across jurisdictional boundaries.
Today, in the physical world. For example, driver licenses and passports. These physical credentials are used worldwide already. In practice, they're shown to a relying party and the protection you have for the use to which the data is put depends on local law.
Now, as we move from physical credentials to digital credentials, digital credential solutions provide us with new features such as selective release and verifiable authenticity of the actual data. And so the question arises, when it comes to privacy of the data that you release, can we do better in the digital world that we are doing in the physical world?
And if so, how do we do that? The challenge is that your local protections don't apply. If you live in EU and you go visit another country and you rent a vehicle there and the rental agency doesn't normally advertise or market to European residents, you may not be covered by GDPR. So your local protections that you enjoy in your normal state where you reside may not apply when you cross jurisdictional boundaries. When you do cross jurisdictional boundaries, you typically don't know what does apply there.
So just knowing that your home protections don't apply doesn't tell you what does apply where you are sharing your credential. Yet you still want the service. And if I can't get my service using my digital credential, I'm going to go ahead and share my physical credential with potential negative effects. So that's a challenge we're trying to address. And when we look at solutions, they typically are two extremes. Someone can decide for the holder of a digital credential if releasing the information, if releasing a document is acceptable or not. So that's the one extreme.
The holder may be denied the service and may default to a physical document, which as I mentioned, could have negative effects. The other extreme is where the holder is on the holder's own. So no guidance, nothing. The holder decides if a transaction should go ahead and as a result may be surprised by what happens to the data that has been shared. Our thinking is that there is a solution that is sort of in between.
In this solution, you have the wallet that takes in trust signals and those trust signals could be many things such as relying party information, location, website, the data requested, et cetera. That gets fed into a decision model, a guidance model that has conditions and policies in it. And then the important part is that gets converted into guidance for the holder. So the holder receives the guidance and based on the guidance, the holder can then decide how to move forward. So it's not someone deciding on behalf of the holder, but the holder does have guidance to go ahead.
This model, this logical model has its own challenges. Who compiles the model? Is it the issuer? Is it the wallet provider? What sits inside the model? How is the model expressed? Is it in a contract, written contract that the issuer has with the wallet provider or is it in a electronic format where an issuer at provisioning time can tell the wallet, this is the model that you need to use? So those are questions, but the more challenging challenge, if I can put it that way, I think is how the guidance is surfaced to the holder. How do you do that in a way that the holder understands?
How do you do it in a simple enough way that doesn't take away from the complex issue that it really is? Also taking into account that different types of users may have different ways of surfacing the information. If the holder is busy with an online transaction, the way in which the information gets presented or the guidance gets presented could be different from the way the guidance is presented in an in-person situation where you're standing in a queue where the holder does not have time to read any funny stuff where time is of the essence.
So it is a real challenge in surfacing the guidance to the holder. So nevertheless, even though this is a challenging model, we as Anva have been participating in the Cantera work and we believe that the output of the Cantera work can provide a very strong trust signal into this process. And as a very pragmatic input, we believe it could help guide to a large extent what type of guidance could be provided to a holder. And the next part of the presentation is all about Cantera, so I'll hand it over. Thank you.
I'm gonna have to move because I don't wanna sit here and turn around and look at the screen, but I'll never be able to keep track. So I see, yes. So I'm gonna stand up here where I can actually see the slides a little better. And I thank you all for coming. Just a couple of clarifications. If there are any French speakers in the room, my name is actually pronounced Chopard. It is a French name. I am based in Washington, DC. The nonprofits that I have worked with for the last many years are actually national and international. Some of you may know the Cantera Initiative.
In fact, some of my staff is here that is based in the UK. And I just wanna give, in case you don't know who we are and why we might be partnering with Lofi and others, just a brief description is, so the Cantera Initiative is a nonprofit. It is international. We have offices in the US and in the UK, but we also have staff here in the EU. So we're kind of all over the place. We're very virtual. But I think the unique thing about us is that we have members. And at the same time, we're a little schizophrenic because we do certifications.
For those of you who may have heard John Pert speak yesterday, who's from the United Kingdom DSIT, which is Department of Science, Innovation and Technology, we are the only currently accredited certification body for the DIATF. And so we very much do that. And I find myself as I'm looking at this, thinking in terms of audits and certifications and standards and things. But also we do the same thing in the US for the NIST digital identity standards that are based there. And then we do a variety of other things, which is not really relevant to today.
But I think the significance is really the work that has come out of these work groups, which is where we see member and experts involved. Privacy Enhancing Mobile Credentials, we call it the PEMC for short. But it's very focused, obviously, on this type of work. And what we've been able to do and what the group has done, I can't really take credit for it, is really come up with what are some best practices, which I think Wafi has really done a good job of setting you up for what it is we're trying to address, how can we address it?
And this group of which he's been a very key part of has really documented some important requirements. And I wanna just kind of go through some of that information for you today. So as I mentioned, Kintara is a global nonprofit. We're dedicated to trustworthy digital identity and personal data. We are known for incubating standards and feeding that into ISO and other organizations for trust frameworks and really focusing on good practices or best practices. Those are some of our acknowledgments.
The work group itself was formed to try to define what that good practice for privacy in mobile identity credentials might look like. And they've really focused, as Wafi pointed out, on in-person or hybrid type transactions. And they've published a couple of different reports. And I wanna talk to you a little bit about what is in the most recent document that they did publish. So it provides sort of the scope, the intended audience, the ecosystem, if you will, which I'm gonna talk about in a minute, for the context of these principles.
It then really works through a lot of requirements that really are best practices. And that ends up being 39 requirements, which we're not gonna have time to talk about today. But that is really distilled into 11 principles around fair information practices. And I do wanna give you the highlights of those. It includes an appendix in this report that kind of takes this information and actually provides diagrams and flowcharts so that you look at these principles and you see how are they actually done in practice. What's it look like in the real world?
So the appendix is really useful for understanding that process. And then a glossary, just to make sure that everybody's on the same page when we use certain terms, which we're not always. So let me just start the report itself, which, by the way, is on the Kintara website. And I don't know that I put it in here, a link. I'm just realizing that. But kintarainitiative.org, the full report's there. It takes the mobile credential ecosystem and looks at the actors in that. So there's these five sort of roles, if you will, the issuer, the holder, the verifier, the provider, and the vendor.
And when we talk about these next sort of 11 privacy principles, they apply to some of these actors very specifically and others not so much. And then there are some principles that really should apply to everyone in the ecosystem. It might be implemented in a slightly different way depending on what your role is, but it's important to understand the different parts of the system as a whole. So I said there's 39 requirements that they came up with. I'm not a member of the group, I will admit. I'm the CEO, I'm the director. And I appreciate the opportunity to talk about this.
But I really think it's a wonderful mixture of all the actors that we just described really coming together at the table to talk about what these privacy principles are. So these are the 11 that it really can be distilled down into. I would like to talk about each of them a little bit so that you understand sort of what my little bullet points here really mean. But the other thing I think that's important is that when you look at this, these 11 principles are really relevant and I think important to organizations who wanna do the right thing anyway, right?
People who want to do a good job, who want to be privacy enhancing and still deliver a service. But I think the thing that we really should be thinking about in the long term is that these are often implicit. When I go through this, you're gonna say some of this is just common sense. But I think where we need to move is to a place where we're being more deliberate. If you're a vendor here, I would encourage you to be deliberate about addressing each one of these, to be explicit and not have it just be implicitly part of what you do.
I think in our marketing of a lot of this work, it's really about educating and educating every component of the system so that we're all on the same page and we're all actually being intentional, intentional, I can't talk, about each of these things. Okay, so let me break it down a little bit. So that first principle, consent and choice, it's really encouraging organizations to only process personal information with the consent and choice of the individual.
And what this principle is about really is trying to make sure that you have active holder engagement, that the individual, again, this isn't tacit, but that it's actually explicit. And one of the things also, I should just say this now that is overarching, all of these principles, this work group and the experts at the table all agreed, all of these should be in place by default. So after every one of these, you should think in your mind by default, this should exist.
And we don't always think about that in that way because many of this, like I said, is often implied and we aren't deliberate about it. But what this group came up with is saying, all of this should exist by default. The second one, principle, purpose, legitimacy and specification, that you should inform the holder of the verifier's purposes and should publicly state what those purposes are for collection.
And again, that it actually be legitimate and specific. The third principle, collection limitation, that's really recommending that organizations limit the information they collect from or about an individual for sort of the minimum amount that's necessary for whatever the specified purpose is.
Again, collection minimization by default. The fourth principle on data minimization, which I know we've talked about in other contexts as well, the importance of limiting the personal information that's processed by a process or a system to minimize the necessary data by default. The fifth principle, the use, retention and disclosure, limiting that, meaning that an organization would limit use, retention and disclosure of personal information.
So, retaining information only with consent, declaring what that retention period is, verifying verifiers would limit the holder information that they are processing and that all of those kinds of limitations would be by default. Number six, accuracy and quality for a specific purpose, implementing accuracy controls. The seventh principle, openness and transparency of access, providing provider transparency, allowing the holders to exercise some of their own rights about the data that is collected and shared, and making those policies clear and easily accessible.
The eighth principle on individual participation and access, allowing accessible credentials, allowing access by the holders from the verifiers. The ninth principle on accountability, being deliberate in accountability, actually designating an accountable person, responsible sort of for the accountability of the whole system. Information security, again, making sure that information security and management systems are in place, ensuring confidentiality, integrity, and availability. Might include encrypted channels, secure storage, security measures by default.
And then the 11th principle on privacy compliance, really making sure that they not only meet the regulatory and policy-based privacy or protection obligations, but also looking at conducting privacy assessments, implementing those privacy policies by default. And here's a summary of those principles by the actors. Specifically here, the issuers, the verifiers, and the providers or vendors.
Some of our key takeaways are that trust is socio-technical, privacy by default, as I mentioned before, looking at those 11 principles and being deliberate and explicit, and that putting the holder in control is really central to all of these good practices. And with that, I will turn it over to Lofi. So the takeaway is that getting certified as a verifier against the privacy requirements is not geographically bound. Any relying party can get certified. So it works across borders.
And we believe that that certification as an input, as a trust signal to a wallet is a very pragmatic way that covers a lot of the questions that a relying party, that a holder might have about a particular relying party. We don't try to boil the ocean. We think this is a workable approach to help safeguard sharing data across jurisdictional boundaries. Thank you. So is there any questions?
Yes, one question. I'm Natsuki Mura, the editor of ISO 29100. Looking at the principles, it looks exactly the same as the 29100 privacy principles. So I wanted to understand what's the delta? It's a very good question. The PMC requirements explicitly are based on the ISO requirements. I would say they're applied to a digital credential environment.
Okay, well, thank you very much. So in the interest of time, I would like you all to thank the presenters for this very interesting insight into the Contara Initiative and how you've been using this for American motor vehicle licenses. Thank you. Thank you. Thank you.