Overview
ISO/IEC TS 27570:2021 - Privacy protection - Privacy guidelines for smart cities is a Technical Specification (first edition, 2021) that provides actionable guidance on protecting privacy across smart city ecosystems. Published by ISO/IEC JTC 1/SC 27, the document takes a multiple-agency and citizen-centric viewpoint and explains how standards can be used at both global and organizational levels to benefit citizens. It is applicable to all organization types and sizes - public bodies, private companies, supply‑chain partners and not‑for‑profits operating in smart city environments.
Key topics and technical focus
The specification focuses on practical privacy guidance rather than prescriptive technical controls. Major topics include:
- Ecosystem privacy planning (recommendations R6.1–R6.4) - establishing an ecosystem privacy plan and governance approach for multi‑stakeholder smart city services.
- Governance and roles - coordination across agencies, accountability, and privacy management activities integrated with the smart city ICT reference framework (see ISO/IEC 30145 series).
- Supply chain and vendor management - guidance for third‑party contracts, procurement and supply‑chain privacy risk controls.
- Data management - lifecycle guidance for personal data, retention, sharing and data minimization in IoT, cloud and big‑data contexts.
- Privacy risk management & engineering - recommended processes for assessing privacy risks and embedding privacy-by-design into systems and services.
- Processes and work products - governance, data management, risk management, engineering and citizen engagement processes (recommendations R8.2–R8.6) and examples of outputs.
- Practical annexes - example ecosystem privacy plan (Annex A) and an informative note on use of video cameras in smart cities (Annex B).
Keywords naturally addressed: privacy guidelines, smart cities, privacy protection, privacy management, data management, privacy engineering, IoT, cloud, big data, citizen engagement.
Applications and practical value
ISO/IEC TS 27570:2021 helps organizations:
- Design and coordinate multi‑agency privacy strategies for city services (transport, utilities, health, surveillance).
- Apply privacy-by-design in IoT deployments, cloud platforms and analytics while managing citizen data responsibly.
- Harmonize privacy governance across suppliers and public–private partnerships.
- Prepare ecosystem-level privacy plans, privacy impact assessments, consent mechanisms and citizen engagement initiatives.
Who should use this standard
- City authorities and municipal IT/program managers
- Privacy officers, compliance and legal teams
- System integrators, IoT/cloud service providers and vendors
- Urban planners, consultants and civil society groups involved in smart city projects
Related standards
- ISO/IEC 30145 series (smart city ICT reference framework)
- General privacy, IT governance, IoT, cloud and big‑data standards referenced for detailed controls and methods
ISO/IEC TS 27570:2021 is a practical roadmap for embedding robust, ecosystem‑level privacy protection into modern smart city initiatives while keeping citizens’ rights and multi‑stakeholder coordination central.