ISO 22307:2008
Financial services — Privacy impact assessment
Financial services — Privacy impact assessment
- Статус документа:
- Действующий
- Формат:
- Электронный (PDF)
- Количество страниц:
- 28
- Дата публикации:
- 16 апреля 2008 г.
- Издание:
- ISO IS 22307 edition 1 version 1
- ICS:
- 03.060
ISO 22307:2008 recognizes that a privacy impact assessment (PIA) is an important financial services and banking management tool to be used within an organization, or by “contracted” third parties, to identify and mitigate privacy issues and risks associated with processing consumer data using automated, networked information systems. ISO 22307:2008 describes the privacy impact assessment activity in general, defines the common and required components of a privacy impact assessment, regardless of business systems affecting financial institutions, and provides informative guidance to educate the reader on privacy impact assessments. A privacy compliance audit differs from a privacy impact assessment in that the compliance audit determines an institution's current level of compliance with the law and identifies steps to avoid future non-compliance with the law. While there are similarities between privacy impact assessments and privacy compliance audits in that they use some of the same skills and that they are tools used to avoid breaches of privacy, the primary concern of a compliance audit is simply to meet the requirements of the law, whereas a privacy impact assessment is intended to investigate further in order to identify ways to safeguard privacy optimally. ISO 22307:2008 recognizes that the choices of financial and banking system development and risk management procedures are business decisions and, as such, the business decision makers need to be informed in order to be able to make informed decisions for their financial institutions. ISO 22307:2008 provides a privacy impact assessment structure (common PIA components, definitions and informative annexes) for institutions handling financial information that wish to use a privacy impact assessment as a tool to plan for, and manage, privacy issues within business systems that they consider to be vulnerable.
Abstract
Overview
ISO 22307:2008 - "Financial services - Privacy impact assessment" defines a standardized approach for performing a Privacy Impact Assessment (PIA) in financial and banking environments. The standard describes the PIA activity, the common and required components of a PIA for proposed financial systems (PFS), and provides informative guidance to help organizations identify and mitigate privacy issues and risks associated with processing consumer data in automated, networked information systems.
Key topics and technical requirements
- PIA objectives: Ensure privacy is considered throughout the system life cycle, assign accountability, inform decision-makers about privacy implications and mitigation options, and reduce the need for costly post-implementation changes.
- Minimum PIA process elements: A valid PIA must include a PIA plan, an assessment, a PIA report, competent expertise, an appropriate degree of independence/public aspects, and documented use in PFS decision-making.
- PIA plan requirements: The plan must define scope, business objectives, privacy compliance objectives (at minimum aligned with OECD privacy principles), whether the PIA is preliminary, life‑cycle phase, assumptions, constraints and alternatives.
- Documented outputs: The PIA plan leads to a documented report that describes the PFS, identifies required expertise, establishes independence, maps how the report will feed into decisions, lists relevant laws/standards, and catalogs known privacy risks.
- PFS description & modeling: Required artifacts include business process and data flow diagrams, data models and information access models showing how personal information is collected, used, disclosed, retained and secured.
- Contextual references: ISO 22307:2008 references OECD Guidelines and cites industry frameworks and security standards (e.g., ISO 17799) as part of compliance and mitigation planning.
Applications and who uses it
- Primary users: Chief Privacy Officers (CPOs), privacy and compliance teams, risk managers, IT architects, core banking system developers, and external contractors/vendors.
- Practical uses:
- Assess privacy impact of a new product, service or system in banking and financial services.
- Inform procurement, system design and governance decisions with documented privacy risk analysis.
- Support cross‑border data flow risk assessment in global banking operations.
- Complement (but not replace) privacy compliance audits by offering a forward‑looking design and mitigation focus.
Related standards
- OECD Guidelines on the protection of privacy and transborder flows of personal data (normative reference)
- ISO 17799 (information security best practice referenced for security program alignment)
Keywords: ISO 22307:2008, privacy impact assessment, PIA, financial services, banking privacy, privacy risk, data protection, proposed financial system, PIA plan, PIA report.
Технические детали
- Технический комитет
- ISO/TC 68/SC 9 - Information exchange for financial services
- SKU
- ISO 22307:2008
Похожие стандарты
Другие стандарты ISO
ISO 8212:1986
ОтменёнSoaps and detergents — Techniques of sampling during manufacture
Overview Standard Reference: ISO 8212:1986 Title: Soaps and detergents - Techniques of sampling during manufacture ISO 8212:1986 defines standardized techniques for taking representative samples of s…
ISO 20662:2020
ДействующийShips and marine technology — Hopper dredger supervisory and control systems
Overview ISO 20662:2020 - Ships and marine technology: Hopper dredger supervisory and control systems (HD‑SCS) - specifies the components, structure, general requirements, and functional requirements…
ISO 3021:2023
ДействующийAdventure tourism — Hiking and trekking activities — Requirements and recommendations
Overview ISO 3021:2023 - Adventure tourism: Hiking and trekking activities - Requirements and recommendations defines safety-focused requirements and recommendations for hiking and trekking offered a…
ISO 3826-2:2008
ДействующийPlastics collapsible containers for human blood and blood components — Part 2: Graphical symbols for use on l…
Overview ISO 3826-2:2008 - "Plastics collapsible containers for human blood and blood components - Part 2: Graphical symbols for use on labels and instruction leaflets" defines a system of internatio…
ISO/IEC 24730-1:2014
ДействующийInformation technology — Real-time locating systems (RTLS) — Part 1: Application programming interface (API)
Overview ISO/IEC 24730-1:2014 specifies the Application Programming Interface (API) for Real‑Time Locating Systems (RTLS). The standard defines a minimal, interoperable boundary that lets application…
ISO 8668-5:1992
ДействующийAircraft — Terminal junction systems — Part 5: Detail specification for type 3 system
Overview - ISO 8668-5:1992 (Aircraft terminal junction systems, Type 3) ISO 8668-5:1992 defines the detail specification for Type 3 Terminal Junction Systems (TJS) used in aircraft electrical install…
ISO 7574-3:1985
ДействующийAcoustics — Statistical methods for determining and verifying stated noise emission values of machinery and e…
Overview ISO 7574-3:1985 is part of the ISO 7574 series on acoustics and provides a simple (transition) statistical method for determining and verifying stated noise emission values for batches (lots…
ISO 15638-15:2014
ДействующийIntelligent transport systems — Framework for cooperative telematics applications for regulated vehicles (TAR…
Overview - ISO 15638-15:2014 (Vehicle location monitoring, TARV) ISO 15638-15:2014 is part of the ISO 15638 suite for Intelligent Transport Systems (ITS) and defines the framework and data specificat…