Versions Compared

Key

  • This line was added.
  • This line was removed.
  • Formatting was changed.

...

This section describes the creation and use of an the ISO/IEC 29100 Privacy Framework for processing (personal) data and to illustrate the use of ISO/IEC 29184 controls to assess performance of this record. The associated notice controller credential and its associated record is regulated with international privacy laws, principals and standards, As a result of the record’s basis on the ISO /IEC 29100 Security and Privacy Framework privacy and security frameworks, the record and associated data fields provide a globally binding and standardized governance framework for creating records. Importantly it provides the transparency legally required for trustworthy ‘consented data access’, for adequate data transfers internationally; and can also provide an opportunity to implement a low-cost digital (twin) record and receipt mechanism. The use of the associated notices, receipts and records dramatically improve the security of personal data control, significantly increasing transparency and as a result greatly improves the scale and effectiveness of cyber physical security and digital privacy.

...

TP1 requires monitoring the technical end point to monitor see if PII is captured in relation to when a notice is provided. Measuring This measures the notice regulatory performance . against legal and human usability requirements.

TPI: 2 PII Controller: Required PII Controller Data Transparency

...

Anchor
_Toc114372114
_Toc114372114
Anchor
_Toc114373615
_Toc114373615
Anchor
_Toc114373712
_Toc114373712
Anchor
_Toc114397916
_Toc114397916
Anchor
_Toc114372115
_Toc114372115
Anchor
_Toc114373616
_Toc114373616
Anchor
_Toc114373713
_Toc114373713
Anchor
_Toc114397917
_Toc114397917
Anchor
_Toc114497434
_Toc114497434
Transparency Accessibility Rating description table 2

https://openconsent.sharepoint.com/:w:/r/sites/AdvCIS-OPN-Operaqtions/_layouts/15/Doc.aspx?sourcedoc=%7Ba8cc43d2-7e99-4d1b-bdca-c51c2de48e38%7D&action=edit&wdPreviousSession=42c9c346-a1ef-485a-9caf-9c58f7cc796e

Rating

Description

Instruction

+1

Controller identity is embedded as a credential linked to authoritative registries.

PII Controller credential is displayed, using a standard format with machine readable language and linked, for example, in an http header in a browser

0

PII Controller Identity prominently displayed on first view – prior to processing first page of viewing, the assessment question would be

PII Controller Identity or credential is provided in first notice

-1

Privacy signal Is not first presented – but is linked and one click and screen away

The Controller Identity, or screen with the Controller Identity is one screen and click away. For example, the privacy policy link in the footer of a webpage

- 3

Identity or credential is two or more screens of view away

PII Controller Identity is not accessible enough to be considered ‘provided’

...