ISO/IEC 15944-17:2024
Information technology — Business operational view — Part 17: Fundamental principles and rules governing Privacy-by-Design (PbD) requirements in an EDI and collaboration space context
Information technology — Business operational view — Part 17: Fundamental principles and rules governing Privacy-by-Design (PbD) requirements in an EDI and collaboration space context
- Статус документа:
- Действующий
- Формат:
- Электронный (PDF)
- Количество страниц:
- 63
- Дата публикации:
- 9 апреля 2024 г.
- Издание:
- ISO/IEC IS 15944 edition 1 version 1
- ICS:
- 35.240.63
This document: a) focuses on PbD aspects of privacy protection requirements as external constraints on any type of Person, (e.g. organization or public administration) involved in any kind of business transaction among such Persons which involves the electronic data interchange (EDI) of any personal information; b) establishes a fundamental set of privacy principles known as Privacy by Design and assumptions based on primary sources; c) integrates existing normative elements in support of PbD as are already identified in ISO/IEC 14662 and ISO/IEC 15944-1, ISO/IEC 15944-5, ISO/IEC 15944-8, ISO 15944-12; d) provides overarching operational ‘best practice’ statements for associated (and not necessarily automated) processes, procedures, practices and governance requirements that need to act in support of implementing and enforcing technical mechanisms that support PbD in Open-edi transaction and collaboration space environments; e) focuses on PbD related aspects of the life cycle management of and accountability for the personal information, i.e. the contents of SPIs (and their SRIs) related to the business transaction interchanged via EDI as information bundles and their associated semantic components among the parties to a business transaction. This document focuses on the BOV aspects of a business transaction and does not concern itself with the technical mechanisms needed to implement the FSV aspects of the business requirements of the FSV including the specification of requirements of an FSV nature which include security techniques and services, communication protocols, etc.). The FSV includes any existing standard (or standards development of an FSV nature), which has been ratified by existing ISO, IEC, UN/ECE and/or ITU standards. This document does not specify the technical mechanisms, i.e. FSV which are required to support BOV-identified requirements. Detailed exclusions to the scope of this document are provided in Annex D.
Abstract
Overview
ISO/IEC 15944-17:2024 - Information technology - Business operational view - Part 17 - sets out fundamental principles and rules governing Privacy-by-Design (PbD) in the context of electronic data interchange (EDI) and collaboration space environments. This first-edition standard focuses on PbD as an external constraint on any Person (organization or public administration) engaged in EDI transactions that include personal information. It defines privacy principles, life‑cycle management expectations, tagging/labelling of personal information bundles (SPIs/SRIs), and operational best practices at the Business Operational View (BOV) level. Importantly, ISO/IEC 15944-17:2024 addresses business and governance requirements and explicitly does not specify the technical mechanisms (Functional Service View, FSV) needed to implement those requirements.
Key topics and requirements
- Privacy-by-Design principles: formalizes PbD concepts (proactive, default privacy, embedded privacy, full functionality, end-to-end safeguards, transparency, user‑centricity) and maps them to privacy protection principles.
- Privacy protection principles (PPP): consolidates primary legal/regulatory sources into an eleven‑point PPP framework applicable to EDI exchanges.
- Tagging and labelling: requirements for identifying and tagging sets of personal information (SPIs) and their semantic components (SRIs) to support policy enforcement and interoperability.
- Information Life Cycle Management (ILCM): rules to ensure personal information remains “under the control of” the organization across the full life cycle (cradle-to-grave) with clear accountability obligations.
- Collaboration space governance: operational best practices for processes, procedures and governance needed to support PbD in multi‑party EDI and collaboration environments.
- Conformance and scope: guidance on conformance statements and mapping to Open‑edi reference model constraints; Annex D lists detailed exclusions to scope.
Applications and who should use it
Practical uses include embedding privacy requirements early in business modelling, defining operational policies for cross‑organizational EDI, and creating interoperable metadata and tagging schemes for personal data. Typical users:
- Privacy engineers and Data Protection Officers (DPOs)
- Enterprise architects and EDI solution designers
- Compliance, legal and governance teams
- Standards developers and implementers integrating BOV requirements with technical FSV standards
- Public administrations and vendors operating collaboration spaces
Related standards
ISO/IEC 15944-17:2024 is intended for use with:
- ISO/IEC 14662 (Open‑edi Reference Model)
- Other parts of the ISO/IEC 15944 series (e.g., -1, -4, -5, -8, -12) The document maps PbD/BOV requirements to existing normative elements without prescribing technical protocols or security mechanisms (FSV), allowing organizations to apply jurisdictional privacy obligations within EDI and collaboration spaces.
Технические детали
- Технический комитет
- ISO/IEC JTC 1/SC 32 - Data management and interchange
- SKU
- ISO/IEC 15944-17:2024
Похожие стандарты
Упомянутые в описании и другие стандарты ISO
BS ISO/IEC 14662:2010
ДействующийInformation technology. Open-edi reference model.
ISO/IEC 15944-21:2023
ДействующийInformation technology — Business operational view — Part 21: Guidance on the application of the Open-edi bus…
Overview ISO/IEC 15944-21:2023 provides business-operational guidance for implementing an Open-edi Distributed Business Transaction Repository (OeDBTR). Building on the Open-edi Business Transaction…
ISO 8212:1986
ОтменёнSoaps and detergents — Techniques of sampling during manufacture
Overview Standard Reference: ISO 8212:1986 Title: Soaps and detergents - Techniques of sampling during manufacture ISO 8212:1986 defines standardized techniques for taking representative samples of s…
ISO 20662:2020
ДействующийShips and marine technology — Hopper dredger supervisory and control systems
Overview ISO 20662:2020 - Ships and marine technology: Hopper dredger supervisory and control systems (HD‑SCS) - specifies the components, structure, general requirements, and functional requirements…
ISO 3021:2023
ДействующийAdventure tourism — Hiking and trekking activities — Requirements and recommendations
Overview ISO 3021:2023 - Adventure tourism: Hiking and trekking activities - Requirements and recommendations defines safety-focused requirements and recommendations for hiking and trekking offered a…
ISO 3826-2:2008
ДействующийPlastics collapsible containers for human blood and blood components — Part 2: Graphical symbols for use on l…
Overview ISO 3826-2:2008 - "Plastics collapsible containers for human blood and blood components - Part 2: Graphical symbols for use on labels and instruction leaflets" defines a system of internatio…
ISO/IEC 24730-1:2014
ДействующийInformation technology — Real-time locating systems (RTLS) — Part 1: Application programming interface (API)
Overview ISO/IEC 24730-1:2014 specifies the Application Programming Interface (API) for Real‑Time Locating Systems (RTLS). The standard defines a minimal, interoperable boundary that lets application…
ISO 8668-5:1992
ДействующийAircraft — Terminal junction systems — Part 5: Detail specification for type 3 system
Overview - ISO 8668-5:1992 (Aircraft terminal junction systems, Type 3) ISO 8668-5:1992 defines the detail specification for Type 3 Terminal Junction Systems (TJS) used in aircraft electrical install…