What is ISO/IEC 15944-12 about?
ISO/IEC 15944-12 provides a method for identifying, in Open-edi modeling technologies and development of scenarios, the additional requirements in business operational view (BOV) specifications for identifying the additional external constraints to be applied to recorded information in business transactions relating to personal information of an individual, as required by legal and regulatory requirements of applicable jurisdictional domains.
ISO/IEC 15944-12 integrates existing normative elements in support of privacy and data protection requirements as are already identified in ISO/IEC 14662 and ISO/IEC 15944-1, ISO/IEC 15944-2, ISO/IEC 15944-4, ISO/IEC 15944-5, ISO/IEC 15944-8, ISO/IEC 15944-9, and ISO/IEC 15944-10.
ISO/IEC 15944-12 provides overarching, operational ‘best practice’ statements for associated (and not necessarily automated) processes, procedures, practices and governance requirements that act in support of implementing and enforcing technical mechanisms which support the privacy/data protection requirements necessary for implementation in Open-edi transaction environments.
ISO/IEC 15944-12 focuses on the life cycle management of personal information i.e., the contents of SPIs (and their SRIs) related to the business transaction interchanged via EDI as information bundles and their associated semantic components among the parties to a business transaction.
NOTE: - Privacy protection requirements (PPR) on information life cycle management (ILCM) and EDI of personal information as stated in this document serve as a minimum set of ILCM policy and operational requirements for all recorded information pertaining to a business transaction in particular, as well as ILCM implementation in any organization in general.
Who is ISO/IEC 15944-12 for?
ISO/IEC 15944-12 on Business operational view Part 12: Privacy protection requirements (PPR) on information life cycle management (ILCM) and EDI of personal information (PI) is useful for:
- Managers of private and public sector organizations
- IT systems and records/information management system professionals
- Privacy protection officers (PPOs) and other personnel in organizations, including those responsible for risk management
- Legal professionals and others within an organization responsible for information law compliance by the organization
Why should you use ISO/IEC 15944-12?
Modelling business transactions using scenarios and scenario components includes specifying the applicable constraints on the data content using explicitly stated rules.
Jurisdictional domains are the primary source of external constraints on business transactions
The focus of ISO/IEC 15944-12 is on any kind of recorded information concerning identifiable living individuals as buyers in a business transaction or whose personal information is used in a business transaction or any type of commitment exchange.
ISO/IEC 15944-12 describes the added business semantic descriptive techniques needed to support information life cycle management (ILCM) aspects as part of privacy protection requirements when modelling business transactions using the external constraints of jurisdictional domains.
ILCM aspects are central to the ability to ensure that privacy protection requirements (PPR) are passed on and supported among all the parties to a business transaction using EDI.
ISO/IEC 15944-12 applies to any organization which receives, creates, process, maintains, communicates, etc. personal information (PI) and, in particular, to those who receive, create, capture, maintain, use, store or dispose of sets of recorded information (SRIs) electronically. This document applies to private and public sector activities of Persons irrespective of whether such activities are undertaken on a for-profit or not-for-profit basis.
ISO/IEC 15944-12 is intended for use by those organizations to which privacy protection requirements apply and who therefore need to ensure that the recorded information (electronic records and transactions) in their IT Systems is trustworthy, reliable, and recognized as authentic.