Why this directory exists
Rights language becomes more durable when systems can implement data minimization, unlinkability, strong authentication, private transport, and secure group communication as technical properties rather than promises alone.
Verified starting points
RFC 9458 · Oblivious HTTP
Forwards encrypted HTTP messages so an origin cannot directly link requests to the client.
Review record
- Reviewed
- 2026-09-03
- Next review
- 2027-03-03
- State
- reviewed_primary
Observed: The RFC Editor page was retrieved and identifies RFC 9458 as an IETF Proposed Standard describing Oblivious HTTP.
Limit: Standards status and scope are recorded from the primary standards-body locator. This does not prove adoption, implementation quality, conformance, or suitability for a specific deployment.
Report basis: Cognitive Liberty Privacy Directory.md#technical-standards-ecosystem-fifty-definitive-specifications
RFC 9576 · Privacy Pass Architecture
Architecture for authorization based on privacy-preserving authentication mechanisms.
Review record
- Reviewed
- 2026-09-03
- Next review
- 2027-03-03
- State
- reviewed_primary
Observed: The RFC Editor page was retrieved and identifies RFC 9576 as an informational IETF document describing the Privacy Pass architecture.
Limit: Standards status and scope are recorded from the primary standards-body locator. This does not prove adoption, implementation quality, conformance, or suitability for a specific deployment.
Report basis: Cognitive Liberty Privacy Directory.md#technical-standards-ecosystem-fifty-definitive-specifications
RFC 7258 · Pervasive Monitoring Is an Attack
Engineering guidance treating pervasive monitoring as an attack to be mitigated in protocol design.
Review record
- Reviewed
- 2026-09-03
- Next review
- 2027-03-03
- State
- reviewed_primary
Observed: The RFC Editor primary page was retrieved. This record describes the document’s standards role, not any deployment claim.
Limit: Standards status and scope are recorded from the primary standards-body locator. This does not prove adoption, implementation quality, conformance, or suitability for a specific deployment.
Report basis: Cognitive Liberty Privacy Directory.md#technical-standards-ecosystem-fifty-definitive-specifications
RFC 8890 · The Internet is for End Users
Guidance that protocol and standards decisions should prioritize the interests of end users.
Review record
- Reviewed
- 2026-09-03
- Next review
- 2027-03-03
- State
- reviewed_primary
Observed: The RFC Editor primary page was retrieved. Its relevance is the end-user-centered design principle cited in the supplied privacy research.
Limit: Standards status and scope are recorded from the primary standards-body locator. This does not prove adoption, implementation quality, conformance, or suitability for a specific deployment.
Report basis: Cognitive Liberty Privacy Directory.md#technical-standards-ecosystem-fifty-definitive-specifications
RFC 9420 · Messaging Layer Security
Efficient asynchronous group key establishment with forward secrecy and post-compromise security.
Review record
- Reviewed
- 2026-09-03
- Next review
- 2027-03-03
- State
- reviewed_primary
Observed: The RFC Editor page was retrieved and identifies RFC 9420 as an IETF Proposed Standard for group key establishment.
Limit: Standards status and scope are recorded from the primary standards-body locator. This does not prove adoption, implementation quality, conformance, or suitability for a specific deployment.
Report basis: Cognitive Liberty Privacy Directory.md#technical-standards-ecosystem-fifty-definitive-specifications
RFC 9230 · Oblivious DNS over HTTPS
Separates client identity from DNS query content through oblivious relay architecture.
Review record
- Reviewed
- 2026-09-03
- Next review
- 2027-03-03
- State
- reviewed_primary_limited
Observed: The RFC Editor resource resolved during the review sequence, though a follow-up retrieval was rate-limited; status is therefore recorded as primary locator confirmed with limited re-open evidence.
Limit: Standards status and scope are recorded from the primary standards-body locator. This does not prove adoption, implementation quality, conformance, or suitability for a specific deployment.
Report basis: Cognitive Liberty Privacy Directory.md#technical-standards-ecosystem-fifty-definitive-specifications
W3C Verifiable Credentials Data Model 2.0
Extensible data model for tamper-evident, machine-verifiable credentials with explicit privacy considerations.
Review record
- Reviewed
- 2026-09-03
- Next review
- 2027-03-03
- State
- reviewed_primary
Observed: The W3C Recommendation was retrieved and confirms its 15 May 2025 Recommendation status, privacy considerations, data minimization, and zero-knowledge proof examples.
Limit: Standards status and scope are recorded from the primary standards-body locator. This does not prove adoption, implementation quality, conformance, or suitability for a specific deployment.
Report basis: Cognitive Liberty Privacy Directory.md#technical-standards-ecosystem-fifty-definitive-specifications
W3C Web Authentication Level 3
Public-key credential API for strong, origin-bound authentication without shared-password reuse.
Review record
- Reviewed
- 2026-09-03
- Next review
- 2027-03-03
- State
- reviewed_primary
Observed: The current W3C Recommendation was retrieved and confirms Level 3 Recommendation status dated 25 August 2026.
Limit: Standards status and scope are recorded from the primary standards-body locator. This does not prove adoption, implementation quality, conformance, or suitability for a specific deployment.
Report basis: Cognitive Liberty Privacy Directory.md#technical-standards-ecosystem-fifty-definitive-specifications
NIST Privacy Framework
Voluntary tool for identifying and managing privacy risk while developing products and services.
Review record
- Reviewed
- 2026-09-03
- Next review
- 2027-03-03
- State
- reviewed_primary
Observed: The current NIST Privacy Framework page was retrieved. It describes the framework as voluntary and shows the Privacy Framework 1.1 Initial Public Draft programme state.
Limit: Standards status and scope are recorded from the primary standards-body locator. This does not prove adoption, implementation quality, conformance, or suitability for a specific deployment.
Report basis: Cognitive Liberty Privacy Directory.md#technical-standards-ecosystem-fifty-definitive-specifications
NIST SP 800-63-4 · Digital Identity Guidelines
Technical guidelines for identity proofing, authentication, federation, and related assertions.
Review record
- Reviewed
- 2026-09-03
- Next review
- 2027-03-03
- State
- reviewed_primary
Observed: The NIST final publication page was retrieved and confirms publication in July 2025 and supersession of SP 800-63-3.
Limit: Standards status and scope are recorded from the primary standards-body locator. This does not prove adoption, implementation quality, conformance, or suitability for a specific deployment.
Report basis: Cognitive Liberty Privacy Directory.md#technical-standards-ecosystem-fifty-definitive-specifications
A directory is only useful if it can admit uncertainty and age.
Every stable record has a review date, next-review date, source basis, verification state, and limitation. A stale or unreachable resource should be marked accordingly in a future release rather than silently retained as current.