Skip to content
ADR-0024Architecture decisionAcceptedversion 1.0.02 October 2026

Context ​

Today's doğrulayıcı (verifier)Gösterilen belgeyi denetleyen taraf: imza, belge verenin güven listesindeki kaydı, durum ve politika. Relying party diye de anılır. entry carries only:

  • client_id,
  • legal name,
  • access certificate fingerprint,
  • usage scopes (purpose + requested claims).

The EU gap analysis (2026-09-29) found this incomplete. In the EU every verifier reports a common data set to the national registrar (CIR 2025/848 Annex I; TS6 v1.2.2). The wallet must show a link to the privacy policy on the consent screen (RPA_10). The user's erasure request (TS7) and complaint to the data protection authority (TS8) also rely on the contact details in this entry.

Project management approved collecting in Tamga the same information that is collected in the EU.

Decision ​

K1 — Verifier entry: the EU common data set ​

The relying_parties[] entry in the güven listesi (trust list)Bir ülkenin kök sertifikalarını, belge verenlerini ve kayıtlı relying party'lerini taşıyan imzalı liste. Bugün Tamga'da güven bu listelere dayanır; ortak defter sonra gelir. carries the following fields. The names correspond to the TS5 WalletRelyingParty class.

TS6FieldTamgaMandatory
1Legal namelegal_nameyes
2Trade name (shown to the user)trade_nameyes
3, 6Official identifieridentifiers[] ({scheme, value}; Türkiye: TR-VKN tax number, TR-MERSIS; country-prefixed)yes
4Addresspostal_addressyes
5Websiteinfo_urino
7Contactcontact {support_uri, email, phone}; at least one, support_uri recommendedyes
8Service descriptionservice_description (multilingual)yes
9Requested datascopes[].vct + scopes[].claims (exists today)yes
10Purposescopes[].purpose + purpose_localized (exists today)yes
—Privacy policy (for each use)scopes[].privacy_policy_uriyes
11Public-sector bodyis_public_sector_bodyyes
12–13Entitlement typeentitlements[] (service_provider, non_q_eaa_provider, pub_eaa_provider, …; mapped to ETSI TS 119 475 URIs)yes
14–16Intermediary relationshipuses_intermediaries[] (RP) / served_relying_parties[] (intermediary); ADR-0017conditional
—Data protection authoritysupervisory_authority {name, country, email / phone / form_uri}; Türkiye: the KVKK Authorityyes

K2 — Issuers carry the same identity and contact fields ​

The issuers[] entry carries: trade_name, identifiers[], postal_address, info_uri, contact, supervisory_authority. For an belge veren (issuer)Belgeyi imzalayıp veren kurum: üniversite, meslek kuruluşu, kamu kurumu ya da şirket., entitlements is written automatically: class EAA → non_q_eaa_provider, PUB → pub_eaa_provider. These fields are the source of the address and contact information in ETSI TS 119 602 (LoTE (List of Trusted Entities)ETSI TS 119 602 liste biçimi; Tamga listelerinin LoTE görünümünü yayınlar ve dış LoTE listelerini okuyabilir.) lists.

K3 — Wallet ​

  • The consent screen shows the trade name, the purpose and the privacy policy link (RPA_06, RPA_10).
  • The contact and data protection authority details in the entry feed the erasure request (TS7) and complaint (TS8) flows.

K4 — Personal data ​

The trust list is public. Verifier and issuer entries are therefore only for organisations (legal persons). Registering a natural person as a verifier is not supported in the pilot. Contact details are organisational (support page, organisational e-mail/phone); no personal names are written.

K5 — Transition ​

  • The new fields are added to the list format as optional; existing entries do not break.
  • The publisher requires the mandatory K1/K2 fields for every new or updated entry. All entries are completed before the pilot.
  • The registration certificate (WRPRC (Wallet-Relying Party Registration Certificate)Relying party'nin hangi alanları neden isteyebileceğini bildiren kayıt sertifikası., verifier_info) and the registration API (TS5) are the next step.

Options considered ​

OptionResultWhy
Today's narrow entryrejectedNo privacy policy, contact or data protection authority; RPA_10, TS7 and TS8 cannot be met
EU field names verbatim (camelCase)rejectedTamga lists use snake_case; the TS5 mapping is documented in a table, and EU names are used on export
The EU data set, with Tamga namesacceptedSame content; LoTE and, later, TS5 API export through the mapping

Invariants ​

CodeRule
RPR1Every new or updated verifier entry carries a privacy policy link for each usage scope and at least one contact channel.
RPR2Verifier and issuer entries are only for organisations; an entry contains no personal name or personal contact details.
RPR3Every verifier entry names the competent data protection authority and how to reach it.

Consequences ​

  • @tamga-network/trust schema: new fields (optional). Trust publisher: mandatory-field check for new/updated entries.
  • apps/trust-publisher/registry: existing entries (the Tamga verification service, institutions) are completed. The institutions' official details are obtained from the institutions.
  • Wallet consent screen: trade name + privacy policy link.
  • LoTE (SPEC-ID-0002 §8.1.1): issuer address and contact from these fields.
  • The participation rules of SPEC-TRUST-0001 and FW-TF-0001 are updated.

Status ​

Accepted — 2026-09-29. With project management approval. DECISIONS: D-REG-1. Implementation queued.