Overview
ISO/IEC TR 27550:2019 - Information technology - Security techniques - Privacy engineering for system life cycle processes - is a technical report that provides privacy engineering guidelines to help organizations integrate modern privacy practices into system and software life cycles. It clarifies the relationship between privacy engineering and other engineering viewpoints (system engineering, security engineering, risk management) and describes privacy activities across life cycle processes such as knowledge management, risk management, requirements analysis, and architecture design. The report extends ISO/IEC/IEEE 15288 by adding privacy-specific guidance.
Key topics
- Privacy engineering integration with system and software life cycle processes (acquisition, design, implementation, operation).
- Privacy-by-design / data protection by design principles and how they map to engineering activities.
- Risk management for privacy: guidance on privacy risk models, methodologies and linkage to security risk practices.
- Requirements engineering: how to elicit, specify and validate privacy requirements for systems and software.
- Architecture and design considerations: privacy-aware architecture definition, data minimization and technical controls.
- Knowledge and stakeholder management: roles (PII controller, PII processor, PII principal), multidisciplinary interactions, and documentation.
- Privacy properties and objectives discussed include predictability, manageability, disassociability, intervenability, and classic protection goals like confidentiality, integrity and availability.
- Supporting material: informative annexes with objectives, practical guidance, catalogues of measures and sample risk models.
Practical applications and who uses it
ISO/IEC TR 27550:2019 is practical for organizations and teams that need to build privacy into systems and products:
- Systems engineers and software engineers integrating privacy requirements into designs and architectures.
- Security engineers and risk managers aligning privacy risk management with security risk processes.
- Privacy officers, product managers and operations teams defining policies, privacy impact assessments (PIAs) and operational controls.
- Suppliers and integrators who must specify privacy requirements in acquisition and supply processes.
Use cases include developing cloud services, IoT systems, health and transport applications, and any ICT system processing personally identifiable information (PII).
Related standards
Commonly used together with:
- ISO/IEC 29100, 29134, 29151, 27018, 27552 (privacy and PII guidance)
- ISO/IEC 27001, 27002, 27005, 27034 (security and risk management)
- ISO/IEC/IEEE 15288, 12207, 29148 (system/software life cycle and requirements)
- Influential methodologies: NIST privacy engineering publications, LINDDUN, OASIS PMRM
ISO/IEC TR 27550:2019 is a practical reference for embedding privacy-by-design into engineering workflows and aligning privacy controls with life cycle processes and organizational roles.