Overview
ISO/IEC 27556:2022 - Information security, cybersecurity and privacy protection - User-centric privacy preferences management framework - defines a user-centric framework for handling personally identifiable information (PII) based on privacy preferences. The standard guides the design and implementation of ICT systems that respect PII principals’ choices, support privacy-by-design, and enable machine-readable privacy preference management without prescribing specific preference content or formats.
Key topics
- Actors and roles: clear definitions for PII principals (data subjects), PII controllers, PII processors, privacy preference administrators (PPA) and third parties.
- Framework components: components for data collection, data transformation, PII transfer control, PII recipients, and the privacy preference manager (PPM).
- Privacy preference manager (PPM): functional recommendations, life‑cycle management of privacy preferences, and monitoring capabilities to ensure processing aligns with expressed preferences.
- Privacy properties and techniques: concepts such as de-identification, re-identification, redaction, unlinkability, intervenability, and transparency.
- Governance: privacy impact assessment (PIA) guidance and operational considerations for integrating PPM into a privacy information management system.
- Scope limits: the document describes structure and components but does not specify the exact content or format of privacy preference information.
Requirements & recommendations
- Implement mechanisms that translate PII principals’ privacy preferences into actionable controls within ICT systems.
- Provide life-cycle management for preferences (creation, update, revocation, enforcement).
- Enable monitoring and transparency so stakeholders can understand and intervene in privacy-relevant processing.
- Consider privacy impact assessments and privacy-by-design when deploying PPM services or PII exchange platforms.
Practical applications & who should use this standard
ISO/IEC 27556:2022 is practical for:
- Privacy engineers and system architects designing consent and preference-aware systems.
- Product managers and vendors of consent management platforms or privacy preference management services.
- Organizations implementing PII exchange platforms that need to enforce user preferences across service providers.
- Data Protection Officers and compliance teams performing PIAs and governance of PII processing.
- Regulators and auditors evaluating transparency, intervenability, and preference enforcement.
Use cases include consent-driven data sharing, configurable privacy settings across services, and privacy-preserving data exchanges aligned with user choices.
Related standards
ISO/IEC 27556:2022 helps embed user-centric privacy preferences management, enabling systems to honor PII principals’ choices while improving transparency and control.