ISO/IEC 15944-12:2020
Information technology — Business operational view — Part 12: Privacy protection requirements (PPR) on information life cycle management (ILCM) and EDI of personal information (PI)
Information technology — Business operational view — Part 12: Privacy protection requirements (PPR) on information life cycle management (ILCM) and EDI of personal information (PI)
- Статус документа:
- Отменён
- Формат:
- Электронный (PDF)
- Количество страниц:
- 136
- Дата публикации:
- 25 мая 2020 г.
- Издание:
- ISO/IEC IS 15944 edition 1 version 1
- ICS:
- 35.240.63
This document: — provides method(s) for identifying, in Open-edi modelling technologies and development of scenarios, the additional requirements in business operational view (BOV) specifications for identifying the additional external constraints to be applied to recorded information in business transactions relating to personal information of an individual, as required by legal and regulatory requirements of applicable jurisdictional domains; — integrates existing normative elements in support of privacy and data protection requirements as are already identified in ISO/IEC 14662 and ISO/IEC 15944-1, ISO/IEC 15944-2, ISO/IEC 15944-4, ISO/IEC 15944-5, ISO/IEC 15944-8, ISO/IEC 15944-9, and ISO/IEC 15944-10; — provides overarching, operational ?best practice' statements for associated (and not necessarily automated) processes, procedures, practices and governance requirements that act in support of implementing and enforcing technical mechanisms which support the privacy/data protection requirements necessary for implementation in Open-edi transaction environments; — focuses on the life cycle management of personal information i.e., the contents of SPIs (and their SRIs) related to the business transaction interchanged via EDI as information bundles and their associated semantic components among the parties to a business transaction. NOTE Privacy protection requirements (PPR) on information life cycle management (ILCM) and EDI of personal information as stated in this document serve as a minimum set of ILCM policy and operational requirements for all recorded information pertaining to a business transaction in particular, as well as ILCM implementation in any organization in general. This document does not specify the technical mechanisms, i.e., functional support services (FSV) which are required to support BOV-identified requirements. Detailed exclusions to the scope of this document are provided in Annex H.
Abstract
Overview - ISO/IEC 15944-12:2020 (PPR on ILCM and EDI of PI)
ISO/IEC 15944-12:2020 defines privacy protection requirements (PPR) for the information life cycle management (ILCM) of personal information (PI) exchanged in business transactions, particularly those using Electronic Data Interchange (EDI) and Open-edi modelling technologies. The standard provides methods to identify additional external constraints (jurisdictional, legal and regulatory) that must be applied to recorded information in business transactions, integrates relevant normative elements from the ISO/IEC 15944 series and ISO/IEC 14662, and offers overarching operational best-practice statements to support implementation and governance.
Note: this part focuses on policy, governance and ILCM requirements and does not specify the technical functional support services (FSV) required to implement those mechanisms.
Key topics and technical requirements
- Fundamental privacy protection principles - a consolidated set of privacy principles (including 11 key principles) and links to consumer accessibility and protection.
- ILCM principles supporting PPR - requirements for compliance, purpose limitation, informed consent, control, retention limits, accuracy, integrity, safeguards, archiving and disposition/expungement.
- Tagging / labelling of data - rules for tagging Sets of Personal Information (SPIs) and Single Recorded Items (SRIs) to support policy enforcement and interoperability.
- Accountability and “under the control of” - governance and operational rules ensuring organizations retain control and responsibility for PI across its life cycle.
- Retention, state changes and disposition - specification of retention triggers, state-change types, record retention and disposal schedules (RRDS), and disposition/expungement rules.
- Data conversion, migration and synchronization - guidance on preserving ILCM constraints during data conversion and cross‑system synchronization.
- EDI-specific rules - requirements for EDI of PI between primary ILCM parties and agents, third parties and regulators.
- Conformance and annexed guidance - conformance statements and informative annexes (compliance decision trees, referential integrity, exclusions, and cross-references to other parts of the series).
Practical applications - who should use it
- Privacy officers, data protection officers and compliance teams developing ILCM policies that meet jurisdictional privacy laws.
- Enterprise architects, solution designers and system integrators implementing EDI/Open-edi business transactions that include PI.
- Business analysts and modelers using Open-edi scenarios to identify external constraints on data content.
- Auditors and regulators assessing conformity with privacy and ILCM governance practices.
- Third-party processors and agents who must align their handling of PI with primary ILCM requirements.
Related standards and references
- ISO/IEC 14662 (Open-edi reference model)
- Other parts of the ISO/IEC 15944 series (Parts 1, 2, 4, 5, 8, 9, 10)
- Annexes in ISO/IEC 15944-12 provide implementation guidance, exclusions (Annex H) and conformance criteria.
Keywords: ISO/IEC 15944-12, privacy protection, information life cycle management, ILCM, EDI, Open-edi, personal information, PPR, data retention, tagging, conformance.
Технические детали
- Технический комитет
- ISO/IEC JTC 1/SC 32 - Data management and interchange
- SKU
- ISO/IEC 15944-12:2020
Похожие стандарты
Стандарты, упомянутые в описании
ISO/IEC 15944-21:2023
ДействующийInformation technology — Business operational view — Part 21: Guidance on the application of the Open-edi bus…
Overview ISO/IEC 15944-21:2023 provides business-operational guidance for implementing an Open-edi Distributed Business Transaction Repository (OeDBTR). Building on the Open-edi Business Transaction…