Chapter 3 · 5/5
Consent and control
Who asked for what and what was shared: the consent screen, the transaction log and the right to erasure (GDPR).
5 min
Every technique in this chapter serves one goal: information should never move without the person knowing and wanting it to. However good the technology, the final decision is the person's. This page covers where that decision is made: the consent screen, the transaction log and the right to erasure.
The consent screen: three questions
When a verifier asks for information, the wallet shows a screen before sending anything. It answers three questions:
- Who is asking? The verifier's name is read from its record in the network's trust list; a site cannot pick its own name. If the verifier acts for someone else, as an intermediary, both names are shown.
- What are they asking for? The credential and its fields are listed one by one. The person can switch off some fields or refuse altogether.
- Why? The purpose the verifier declared when it registered with the network is shown. A field outside that purpose is flagged separately.
Requested by
Example Concert Hall · registered in the trust list
Requested data
- Over 18
- Date of birthOutside purpose
Registered purpose
Age check for event entry
The wallet is the person's tool, not their gatekeeper. Sharing with an unregistered verifier, or beyond the purpose, is still possible, but only after a clear warning, knowingly.
The transaction log: who did I show what to?
The wallet records which fields of which credential were shown, when and to whom. This transaction logThe wallet's record of which information was shown to whom and when. stays on the phone; it never goes to Tamga or any other server. If the person wants, they can export it as a file encrypted with a password of their choosing, for example as evidence for a complaint. The export never happens on its own.
The right to erasure
KVKK and the GDPR give people the right to have their data deleted. In Tamga that right shows up in three places:
- Resetting the wallet: all data on the device, and the person's records in Tamga's services (the identity service and the wallet provider), are deleted.
- Deletion requests: from the wallet, the person can ask an institution they shared with to delete their data.
- Complaints: the wallet also shows how to complain to the data protection authority the verifier answers to.
Chapter summary
Privacy is not one feature but a layered design: first shrink what is needed (data minimisation), then open only that (selective disclosure), if possible prove without opening anything (zero-knowledge proofs), stop traces from joining up (unlinkability), and finally leave the decision to the person. The next chapter shows how these ideas became a legal and technical framework in Europe.
Summary
- The consent screen shows who is asking, for what and why; requests beyond the registered purpose are flagged.
- The transaction log lives only in the wallet; it leaves only in an encrypted file the person creates with their own password.
- The person deletes their records at Tamga by resetting the wallet and can send deletion requests to institutions from it.
Go deeper
Technical details and binding rules: