BS ISO/IEC 29184:2020
$167.15
Information technology. Online privacy notices and consent
Published By | Publication Date | Number of Pages |
BSI | 2020 | 34 |
This document specifies controls which shape the content and the structure of online privacy notices as well as the process of asking for consent to collect and process personally identifiable information (PII) from PII principals.
This document is applicable in any online context where a PII controller or any other entity processing PII informs PII principals of processing.
PDF Catalog
PDF Pages | PDF Title |
---|---|
2 | undefined |
7 | Foreword |
8 | Introduction |
9 | 1 Scope 2 Normative references 3 Terms and definitions |
10 | 4 Symbols and abbreviated terms 5 General requirements and recommendations 5.1 Overall objective 5.2 Notice 5.2.1 General 5.2.2 Providing notice obligation |
11 | 5.2.3 Appropriate expression 5.2.4 Multi-lingual notice 5.2.5 Appropriate timing |
12 | 5.2.6 Appropriate locations 5.2.7 Appropriate form |
13 | 5.2.8 Ongoing reference 5.2.9 Accessibility 5.3 Contents of notice 5.3.1 General 5.3.2 Purpose description |
14 | 5.3.3 Presentation of purpose description 5.3.4 Identification of the PII controller 5.3.5 PII collection |
15 | 5.3.6 Collection method 5.3.7 Timing and location of the PII collection |
16 | 5.3.8 Method of use 5.3.9 Geo-location of, and legal jurisdiction over, stored PII 5.3.10 Third-party transfer |
17 | 5.3.11 Retention period 5.3.12 Participation of PII principal 5.3.13 Inquiry and complaint |
18 | 5.3.14 Information about accessing the choices made for consent 5.3.15 Basis for processing 5.3.16 Risks |
19 | 5.4 Consent 5.4.1 General 5.4.2 Identification of whether consent is appropriate 5.4.3 Informed and freely given consent |
20 | 5.4.4 Providing the information about which account the PII principal is using 5.4.5 Independence from other consent |
21 | 5.4.6 Separate consent to necessary and optional elements of PII 5.4.7 Frequency 5.4.8 Timeliness 5.5 Change of conditions 5.5.1 General |
22 | 5.5.2 Renewing notice 5.5.3 Renewing consent |
24 | Annex A (informative) User interface example for obtaining the consent of a PII principal on PCs and smartphones |
30 | Annex B (informative) Example of a consent receipt or consent record (NOTE in 5.4.3) |
33 | Bibliography |