Overview
ISO/TR 31700-2:2023 is a technical report that provides illustrative use cases and associated analysis to help implement and interpret the requirements in ISO 31700-1 (Privacy by design for consumer goods and services). The document targets engineers and practitioners involved in the development, deployment and operation of digitally enabled consumer goods and services. It uses a use‑case template (based on IEC 62559-2) and presents sample scenarios-notably on-line retailing, a fitness company and smart locks-to clarify practical privacy‑by‑design challenges and lifecycle decisions.
Key topics and technical requirements
- Privacy by design across the PII lifecycle: guidance on integrating privacy from initial design through operation, updates and end‑of‑life / retirement of personally identifiable information (PII).
- Illustrative use‑case analysis: step‑by‑step scenarios that map interactions between consumers, products and ecosystem actors to privacy requirements.
- ISO 31700-1 requirements explained: structured coverage of the main requirement categories - general, consumer communication, risk management, develop/deploy/operate privacy controls, and end of PII lifecycle.
- Viewpoints for analysis: consumer product, engineering framework and ecosystem viewpoints to ensure multi‑stakeholder perspectives.
- Risk management & consumer communication: example approaches for privacy risk assessments, breach communications and responding to consumer inquiries.
- Mapping to privacy engineering concepts: relationships to privacy protection goals (Unlinkability, Transparency, Intervenability), NIST Privacy Framework functions (Identify, Govern, Control, Communicate, Protect) and engineering objectives (Predictability, Manageability, Disassociability).
- Use‑case templates: practical format (based on IEC 62559-2) to capture sequence of interactions, roles, risks and required controls.
Practical applications
ISO/TR 31700-2 is practical for:
- Translating ISO 31700-1 requirements into real world product scenarios
- Designing privacy controls for connected consumer devices and services
- Preparing privacy risk assessments, consumer-facing communications and end‑of‑life PII handling plans
- Training multidisciplinary teams on privacy‑by‑design decision points using concrete examples
Common application areas include: e‑commerce platforms, health & fitness apps and devices, smart home products (e.g., smart locks), IoT device manufacturers, and consumer service providers.
Who should use this standard
- Privacy engineers and architects
- Product and firmware developers
- System integrators and solution designers
- Compliance, legal and product managers
- Security and risk teams working on consumer-facing products
Related standards
- ISO 31700-1 - high‑level requirements for privacy by design in consumer goods and services
- IEC 62559-2 - use‑case template methodology (basis for the TR’s templates)
- NIST Privacy Framework - referenced for mapping functions and engineering objectives
Keywords: ISO/TR 31700-2:2023, privacy by design, consumer goods, use cases, PII lifecycle, privacy engineering, ISO 31700-1, NIST Privacy Framework, smart locks, online retailing, fitness apps.