ISO/IEC 15944-8:2012
Information technology — Business operational view — Part 8: Identification of privacy protection requirements as external constraints on business transactions
Information technology — Business operational view — Part 8: Identification of privacy protection requirements as external constraints on business transactions
- Статус документа:
- Отменён
- Формат:
- Электронный (PDF)
- Количество страниц:
- 221
- Дата публикации:
- 29 марта 2012 г.
- Издание:
- ISO/IEC IS 15944 edition 1 version 1
- ICS:
- 35.240.60
ISO/IEC 15944-8:2012 has been developed to support modelling generic international requirements for identifying and providing privacy protection of personal information throughout any kind of information and communications technology (ICT) based business transaction where the individual has the role of a buyer. It provides users and designers with a methodology and tools addressing requirements imposed by jurisdictional domains. ISO/IEC 15944-8:2012 takes the "business operational view" (BOV) aspects developed in ISO/IEC 14662, together with, in particular, ISO/IEC 15944-1 and ISO/IEC 15944-5 as well as many other international references. ISO/IEC 15944 models the requirements of jurisdictional domains as external constraints upon the creation, use, interchange, and information life-cycle management of data. ISO/IEC 15944-8:2012 addresses the wider context of the public policy requirements of jurisdictional domains controlling the use of personal information (PI). These include regulations for consumer protection, privacy protection, individual accessibility, etc. ISO/IEC 15944-8:2012 identifies and expands upon eleven generic, primitive, international principles that have been associated with privacy protection by international, regional, and UN member states' requirements. It models them with respect to the "collaboration space" of a business transaction and commitment exchange involving an individual acting in the role of a "buyer". It provides principles and rules governing the establishment, management and use of identifiers of that individual, including the use of legally recognized names (LRNs), recognized individual identity (rii), and methods of non-identification such as the use of anonymization and pseudonymization of personal information. ISO/IEC 15944-8:2012 also sets out principles governing information life-cycle management (ILCM) as well as the rules and associated coded domains for obtaining informed consent for collection, specifying state changes, records retention, record deletion and related matters in support of privacy protection requirements.
Abstract
Overview
ISO/IEC 15944-8:2012 - Information technology - Business operational view - Part 8 - defines a methodology for identifying privacy protection requirements as external constraints on ICT-based business transactions where an individual acts as a buyer. Built on the Business Operational View (BOV) and Open-edi concepts, the standard models jurisdictional public-policy constraints (privacy, consumer protection, accessibility, human rights) as requirements that affect creation, use, interchange and life-cycle management of personal information (PI). It explicitly identifies eleven generic international privacy principles and provides templates, rules and coded domains to support consistent privacy design and compliance.
Key topics and technical requirements
- Eleven fundamental privacy principles (e.g., preventing harm, accountability, purpose limitation, informed consent, data minimization, retention limits, accuracy, safeguards, openness, access, complaint/challenge) and their application to business transactions.
- Collaboration space modelling for Open-edi scenarios - buyer, seller and regulator roles - to map where privacy constraints apply in transaction lifecycles.
- Identifiers and identity rules: principles for establishing, managing and using identifiers, legally recognized names (LRNs), recognized individual identity (rii), and registration authority (RA) considerations.
- Non‑identification methods: rules governing anonymization and pseudonymization of personal information in transactions.
- Information Life‑Cycle Management (ILCM): integrated principles for state changes, records retention, deletion and time/date referencing to meet jurisdictional privacy rules.
- Data tagging/labelling and coded domains for specifying permitted state changes and retention policies that enforce privacy constraints.
- Templates and conformance: scenario templates for specifying privacy requirements in Open-edi use cases and conformance statements for implementers.
Practical applications and users
ISO/IEC 15944-8:2012 is intended for:
- Privacy architects and data protection officers designing compliant data flows across jurisdictions.
- Business analysts and e‑commerce solution designers mapping privacy constraints into transaction models (Open-edi/BOV).
- System integrators and software vendors implementing identifier, consent and retention controls in ICT systems.
- Regulators and policy makers aligning public policy requirements with technical transaction models.
- Compliance teams and auditors using templates and conformance guidance to verify that transaction processes meet jurisdictional privacy requirements.
Practical uses include designing privacy-aware e‑commerce workflows, specifying PI tagging and retention policies, defining consent mechanisms, and modeling cross-border data restrictions.
Related standards
- ISO/IEC 15944‑1 and ISO/IEC 15944‑5 (related parts of the multipart eBusiness standard)
- ISO/IEC 14662 (Open‑edi Reference Model) These form the BOV/Open‑edi foundation on which 15944‑8 models privacy as external constraints.
Keywords: ISO/IEC 15944-8:2012, privacy protection, business transactions, jurisdictional domains, information life‑cycle management, anonymization, pseudonymization, informed consent, identifiers, Open-edi, Business Operational View (BOV).
Технические детали
- Технический комитет
- ISO/IEC JTC 1/SC 32 - Data management and interchange
- SKU
- ISO/IEC 15944-8:2012
Похожие стандарты
Стандарты, упомянутые в описании