All reports

KYE Governed Research Rail · Bulletin · Edition 2026-06

The noyb question: proving rights, consent and contestability at execution time — June 2026

seriesRoadmap to AI Governance formatBulletin sectorcross-sector audienceLegal Counsel cadenceMonthly Free edition

Ed25519-sealed · fingerprint 6d2213f91e1f2dd9 · verify it yourself ↓

KYE Protocol governs actions and authorities, not outcomes, diagnoses, or results. This report synthesises public sources under the evidence / no-hallucination gate — every claim below is pinned to a cited source.

Executive tear-sheet

Digital-rights enforcement has moved from "do you have a privacy policy?" to "prove what happened" — and most organisations cannot answer at execution time. Reporting on publicly available sources, not legal advice: the European NGO noyb enforces data-protection rights through strategic litigation and complaints, pressing organisations to demonstrate compliance rather than assert it. This brief relays that enforcement posture and, separately and clearly labelled, shows how KYE Protocol™ lets a responsible organisation answer the "show us the evidence" question — for consent, authority and contestability — at the moment an AI system acts, using machinery KYE Protocol™ already ships. It is not legal advice.

Key findings

  • Enforcement-side vs execution-side. noyb asks, after the fact, were rights violated? The answerable counterpart is an execution-side question: was this action authorised, on what legal basis, with what data, and how could the person contest it — provably, at the time?
  • Policies are not evidence. A privacy notice, a logentry and a screenshot are weak answers to an enforcement request. A signed, replayable record of authority + legal basis + data source + human review + contestability path is a strong one.
  • The rights map to artefacts KYE Protocol™ already produces. Access (GDPR Art. 15) → DSAR Evidence Pack™; consent/legal basis → consent + data-use records; automated decisions (Art. 22) → an appeal/contestability record; objection (Art. 21) and rectification (16) → withdrawal/correction trails.
  • As AI personalises consequential decisions, the bar rises from "is there a policy?" to "prove who authorised it, what data was used, which rights applied, and how the person could contest it."

What noyb does, as reported

TL;DR According to noyb's own description of how it works, it advances data-protection rights through standard-setting cases and enforcement complaints — distinguishing precedent-setting litigation from routine enforcement.

According to noyb's own description of how it works, it advances data-protection rights through standard-setting cases and enforcement complaints — distinguishing precedent-setting litigation from routine enforcement. The practical effect on organisations is an evidentiary one: when a complaint lands, the controller must show, concretely, that the right authority, legal basis and controls applied. This brief relays that posture; it does not characterise any specific case and is not legal advice.

What KYE Protocol™ reads into it (interpretation, not advice)

TL;DR This section is KYE Protocol™'s interpretation, clearly separated from the reported facts above, and is not legal advice.

This section is KYE Protocol™'s interpretation, clearly separated from the reported facts above, and is not legal advice. The enforcement question — show us the evidence — is an authority-and-evidence question, which is what KYE Protocol™ records at execution time. The artefacts already exist; this is positioning, not new product:

  • "Who/what processed the data, for what purpose, on what basis?" → the <a href="/data-governance.html">Data Governance Pack</a> records data-use, data-asset and per-access evidence; consent is a signed acceptance record.
  • "Was a human required, and did the person get to contest it?" → an appeal/contestability record captures the review and the contest path (the Art. 22 answer).
  • "Was the right withdrawn or the data corrected?" → withdrawal and correction are first-class states in the agent-memory authority record.
  • "Can you reconstruct it later, against an enforcement request?" → every record is sealed into a <a href="/evidence-pack.html">Evidence Pack™</a> and is Replay-Proof™ — verifiable from published keys alone, not a screenshot.

One boundary KYE Protocol™ states plainly: it proves contestability and lawful basis — who acted, on what authority, with what data, and how the person could object — not an explanation of a model's internal reasoning (a self-narrated rationale is not evidence). KYE Protocol™ is the execution-side record a responsible organisation holds before enforcement becomes necessary; whether and how any of this applies to a given organisation is a matter for that organisation's own legal advisers.

Claims → sources — every claim mapped to a pinned source

This is the claims→source map: no claim ships without a cited, pinned public source (evidence gate). Each numbered claim below is pinned into this edition's sealed evidence pack kye:evidence-pack:research:noyb-rights-evidence:2026-06.

  1. noyb (None of Your Business), the European digital-rights NGO founded by Max Schrems, enforces data-protection rights through strategic litigation, standard-setting cases and complaints — pressing organisations to demonstrate, not merely assert, that they complied. https://noyb.eu/en/project/how-we-worknoyb — European Center for Digital Rights. Cited as a digital-rights enforcement actor, not as a statement of law. (retrieved 2026-06-14T00:00:00Z)
  2. The GDPR gives data subjects enforceable rights — access (Article 15), rectification (16), objection (21) and the right not to be subject to a solely-automated decision with legal or similarly significant effect (22) — exercisable against the controller. https://eur-lex.europa.eu/eli/reg/2016/679/ojOfficial Journal of the European Union (Regulation (EU) 2016/679, GDPR) (retrieved 2026-06-14T00:00:00Z)

Replay-verifiable

This edition is sealed and Ed25519-signed over the published keys. Any reader can confirm the seal offline — no KYE service required.

Signature algorithm
EdDSA
Key id
kye:key:self-audit-fixture-2026-06
Seal fingerprint
6d2213f91e1f2dd9 (sha256 of the signature, first 16 hex)
Published keys (JWKS)
/trust/self-audit-jwks.json
Report envelope
kye:research-report:noyb-rights-evidence-2026-06 · schema kye.research_report.v1

Verify it yourself: fetch the published JWKS, recompute the Ed25519 signature over this edition's canonicalised envelope (minus seal) bound to the body hash, and confirm it matches the key id above — from public keys alone, no KYE service in the loop.

How verification works