SIST EN ISO/IEC 29184:2023 PDF
Information technology - Online privacy notices and consent (ISO/IEC 29184:2020)
Information technology - Online privacy notices and consent (ISO/IEC 29184:2020)
- Статус документа:
- Действующий
- Формат:
- Электронный (PDF)
- Количество страниц:
- 34
- Дата публикации:
- 12 июня 2023 г.
- Издание:
- (ISO/IEC 29184:2020)
- ICS:
- 35.030
This document specifies controls which shape the content and the structure of online privacy notices as well as the process of asking for consent to collect and process personally identifiable information (PII) from PII principals. This document is applicable in any online context where a PII controller or any other entity processing PII informs PII principals of processing.
Abstract
Overview
SIST EN ISO/IEC 29184:2023 provides internationally recognized requirements for online privacy notices and the process of obtaining user consent in digital environments. Developed by the International Organization for Standardization (ISO) and the International Electrotechnical Commission (IEC), and adopted by the European Committee for Standardization (CEN), this standard addresses how personally identifiable information (PII) is communicated and managed when collected, processed, or used online.
The standard is applicable to any organization acting as a PII controller or involved in processing PII in an online context, whether commercial, governmental, or non-profit. The aim is to ensure individuals are clearly informed of data practices and meaningfully empowered to grant or withhold consent, in line with global privacy expectations and regulations.
Key Topics
SIST EN ISO/IEC 29184:2023 details important controls and guidelines relating to privacy communication and user consent:
-
Content and Structure of Online Privacy Notices
- Clear, concise, and easily accessible language
- Multi-lingual support for diverse user bases
- Notice provided at appropriate times and locations
- Layered or summarized notices for improved comprehension
- Accessibility features for users with disabilities
- Ongoing access to previous and current versions of privacy notices
-
Essential Elements in Privacy Notices
- Identification of the PII controller
- Description of the purpose(s) for data collection and use
- List of specific PII elements collected
- Methods of PII collection and information about third-party transfers
- Retention periods for stored data
- Risk assessments related to PII processing
- Mechanisms for user inquiries and complaints
-
Consent Management
- Consent must be informed, specific, freely given, and clear (opt-in)
- Differentiation between necessary and optional data collection
- Procedures for renewing notice and withdrawing consent
- Recordkeeping for consent, including timing and terms applicable at the point of consent
-
Change Management
- Requirements for updating affected individuals about changes in privacy practices or terms
- Processes for re-notification and re-consent where appropriate
Applications
SIST EN ISO/IEC 29184:2023 is valuable for all organizations that interact with users online and process their personal data. Key applications include:
- Websites, E-commerce, and Online Services: Ensuring that privacy practices are transparent and users can make informed choices about their data.
- Mobile Applications: Providing just-in-time notices and consent mechanisms that are accessible and clear on smartphones and tablets.
- Cloud Services and Digital Platforms: Facilitating compliance with privacy regulations when handling data across borders and via third parties.
- Governmental or Public Sector Services: Guaranteeing citizens are duly informed and empowered regarding data use in public digital services.
- Financial Services, Healthcare, and Education: Strengthening privacy management in sectors with heightened requirements for PII protection.
The standard reinforces trust, facilitates compliance with data protection laws (such as GDPR), and helps organizations build sustainable privacy programs.
Related Standards
Organizations may implement SIST EN ISO/IEC 29184:2023 in conjunction with other key privacy, security, and accessibility standards, including:
- ISO/IEC 29100: Privacy framework - foundational privacy principles and terminology.
- ISO/IEC 27001: Information security management systems.
- ISO/IEC 40500 (WCAG 2.0): Web content accessibility guidelines for making privacy notices usable to all.
- ISO/IEC 27701: Extension to ISO/IEC 27001 for privacy information management.
By adopting SIST EN ISO/IEC 29184:2023, organizations demonstrate a commitment to user privacy, regulatory alignment, and ethical data management in the digital age.
Технические детали
- Технический комитет
- ITC - Information technology
- SKU
- SIST EN ISO/IEC 29184:2023
Похожие стандарты
Стандарты, упомянутые в описании
SIST EN ISO/IEC 29100:2020
ДействующийInformation technology - Security techniques - Privacy framework (ISO/IEC 29100:2011, including Amd 1:2018)
Overview EN ISO/IEC 29100:2020 (ISO/IEC 29100:2011, including Amd 1:2018) defines a high-level privacy framework for the protection of personally identifiable information (PII) in information and com…
ISO/IEC 27001:2022/Amd 1:2024
ДействующийInformation security, cybersecurity and privacy protection — Information security management systems — Requir…
Overview ISO/IEC 27001:2022/Amd 1:2024 is the latest amendment to the internationally recognized ISO/IEC 27001 standard, which establishes requirements for information security management systems (IS…
BS ISO/IEC 40500:2025
Information technology — W3C Web Content Accessibility Guidelines (WCAG) 2.2
SIST EN ISO/IEC 27701:2025
ДействующийInformation security, cybersecurity and privacy protection - Privacy information management systems - Require…
Overview SIST EN ISO/IEC 27701:2025 - Information security, cybersecurity and privacy protection - Privacy information management systems (PIMS) - Requirements and guidance (ISO/IEC 27701:2025) - spe…