This document contains guidelines for developing and establishing policies and procedures for deletion of personally identifiable information (PII) in organizations by specifying:
—    a harmonized terminology for PII deletion;
—    an approach for defining deletion rules in an efficient way;
—    a description of required documentation;
—    a broad definition of roles, responsibilities and processes.
This document is intended to be used by organizations where PII is stored or processed.
This document does not address:
—    specific legal provision, as given by national law or specified in contracts;
—    specific deletion rules for particular clusters of PII that are defined by PII controllers for processing PII;
—    deletion mechanisms;
—    reliability, security and suitability of deletion mechanisms;
—    specific techniques for de-identification of data.

  • Standard
    34 pages
    English language
    e-Library read for
    1 day

This document contains guidelines for developing and establishing policies and procedures for deletion of personally identifiable information (PII) in organizations by specifying:
—    a harmonized terminology for PII deletion;
—    an approach for defining deletion rules in an efficient way;
—    a description of required documentation;
—    a broad definition of roles, responsibilities and processes.
This document is intended to be used by organizations where PII is stored or processed.
This document does not address:
—    specific legal provision, as given by national law or specified in contracts;
—    specific deletion rules for particular clusters of PII that are defined by PII controllers for processing PII;
—    deletion mechanisms;
—    reliability, security and suitability of deletion mechanisms;
—    specific techniques for de-identification of data.

  • Standard
    34 pages
    English language
    e-Library read for
    1 day

This Technical Report provides an overview of the current deployment of biometric systems within Europe. It addresses the challenges that are being faced, in order to detect the current needs for improving the specifications for the implementation and deployment of biometric systems. This Technical Report considers all kind of deployments, from border control to ad-hoc services. As most of the deployed systems are based on the use of fingerprints or face recognition, this Technical Report will focus on these two biometric modalities, from the system integrator and interoperability points of view.
Identity documents, in terms of production, structure, interoperability, etc., are out of the scope of this TR. The TR is focused on the performance at system level.
The current European legislative initiatives around this topic (e.g., Entry/Exit System, framework for interoperability between EU information systems, etc.) need a robust framework study about the availability of standard technologies to improve interoperability in biometric products around the European Union.
By showing these needs, a set of recommendations for future standardization works is provided.
From a methodological perspective, the report gathers information of different entities with this classification:
- Capture/enrolment of biometrics including the quality assurance and the generation of feature or biometric models from the images.
- Best practices and guidelines to use biometrics in Europe.
- Data Quality environment using biometrics in European networks.

  • Technical report
    33 pages
    English language
    e-Library read for
    1 day

This Technical Report provides an overview of the current deployment of biometric systems within Europe. It addresses the challenges that are being faced, in order to detect the current needs for improving the specifications for the implementation and deployment of biometric systems. This Technical Report considers all kind of deployments, from border control to ad-hoc services. As most of the deployed systems are based on the use of fingerprints or face recognition, this Technical Report will focus on these two biometric modalities, from the system integrator and interoperability points of view.
Identity documents, in terms of production, structure, interoperability, etc., are out of the scope of this TR. The TR is focused on the performance at system level.
The current European legislative initiatives around this topic (e.g., Entry/Exit System, framework for interoperability between EU information systems, etc.) need a robust framework study about the availability of standard technologies to improve interoperability in biometric products around the European Union.
By showing these needs, a set of recommendations for future standardization works is provided.
From a methodological perspective, the report gathers information of different entities with this classification:
- Capture/enrolment of biometrics including the quality assurance and the generation of feature or biometric models from the images.
- Best practices and guidelines to use biometrics in Europe.
- Data Quality environment using biometrics in European networks.

  • Technical report
    33 pages
    English language
    e-Library read for
    1 day

This document contains recommendations on how to integrate the principle of ‘data protection and privacy by design’ during the entire lifecycle of video-surveillance products and services, in order to achieve ‘data protection and privacy by default’.

  • Technical report
    15 pages
    English language
    e-Library read for
    1 day

This document contains recommendations on how to integrate the principle of ‘data protection and privacy by design’ during the entire lifecycle of video-surveillance products and services, in order to achieve ‘data protection and privacy by default’.

  • Technical report
    15 pages
    English language
    e-Library read for
    1 day

This document provides requirements for manufacturers and/or service providers to implement Data protection and Privacy by Design and by Default (DPbDD) early in their development of their products and services, i.e. before (or independently of) any specific application integration, to make sure that they are as privacy ready as possible. The document will be applicable to all business sectors, including the security industry.

  • Standard
    62 pages
    English language
    e-Library read for
    1 day

This document provides requirements for manufacturers and/or service providers to implement Data protection and Privacy by Design and by Default (DPbDD) early in their development of their products and services, i.e. before (or independently of) any specific application integration, to make sure that they are as privacy ready as possible. The document will be applicable to all business sectors, including the security industry.

  • Standard
    62 pages
    English language
    e-Library read for
    1 day

This document specifies refinements for an application of EN ISO/IEC 27701 in a European context.
This document is applicable to the same entities as is ISO/IEC 27701: all types and sizes of organizations, including public and private
companies, government entities and not-for-profit organizations, which are PII controllers and/or PII processors.
An organization can use this document for the implementation of the generic requirements and controls of EN ISO/IEC 27701
according to its context and its applicable obligations.
Certification criteria based on these refinements can provide a certification model under ISO/IEC 17065 for processing operations
performed within the scope of a privacy information management system according to EN ISO/IEC 27701, which can be combined
with certification requirements for EN ISO/IEC 27701 under ISO/IEC 17021.

  • Draft
    34 pages
    English language
    e-Library read for
    1 day

Article 20 GDPR and Article 4 and 5 the proposed FIDA Regulation require the data access and portability of customer data. To support this demand CEN/TC 445 will organise the standardisation project with its Working Group 1 in which the following European standardisation deliverable will be developed.
European Standard (EN) for the semantic specification of the interfaces
The scope of this EN for customer (natural or legal person) data access and portability in the insurance sector should be based on the insurance-specific part of the proposed FIDA Regulation and therefore should contain:
•   Semantic specifications for the processes to support the data access and portability. These specifications define on the business level the functions and the behaviour for the following process interfaces:
- Request of the customer to the data holder for an actual transfer of the customer data (Article 4 FIDA).
- Transfer of the requested customer data from the data holder to the requesting customer (Article 4 FIDA).
- Request of a data user to a data holder for an actual transfer of customer data under a permission of the customer (Article 5 FIDA).
- Transfer of the requested customer data from the data holder to the requesting data user (Article 5 FIDA).
•   Sematic specifications for the customer data to be transferred by the above processes. The scope of the customer data will be limited to the insurance-specific part of the FIDA proposal defined in the Article 2 (1) and Article 3 (3) of FIDA. These specifications define on the business level each element of the customer data with identification, name, precise definition, and value type (text, number, amount, quantity, percentage, date, etc.). The composition of these data elements forms a semantic data model for the insurance-specific customer data. The data model will consist of the following parts:
- General data of the policy holder (including address, contact details, profession, payment means, etc.).
- General data of the insurance policy (including policy number, insurance product and coverages, insured period, premium amounts, etc.).
- Data specific to the consumers’ insured assets which are collected for the purposes of a demands and needs test.
- Data depending on class of business, such as
- Motor insurance (details about vehicle, usage, drivers),
- Property insurance (details about building, household or other objects),
- Liability insurance (details about insured persons and their activities),
- Accident insurance (details about insured persons and their activities),
- Insurance-based investment products (details about insured persons and the savings, investments, pension rights, etc.).
The EN specifies the processes and the data model on the semantic level in a syntax-neutral format, independent from its representation in a concrete implementation syntax.

  • Draft
    288 pages
    English language
    e-Library read for
    1 day

This document is applicable to all rail vehicles including OTMs and Road-rail machines, which are operated on the heavy rail network with nominal track gauge 1 435 mm and nominal static vertical wheelset forces up to 350 kN.
This document may also be applicable (partly or in full) to:
—   rail systems with different track layout, e.g. urban rail systems and/or;
—   rail systems with other than 1 435 mm nominal track gauge and/or;
—   non-public rail networks and vehicles, e.g. mine rail systems.
NOTE   For rail systems other than 1 435 mm track gauge or urban rail systems, the related post processing, limit values and test conditions could be different. They are specified nationally or individually taking into account track design and operating conditions.
This document contains the common parts of the series of documents as well as the relationship to other standards, general requirements and handling of deviations from requirements. These specifications are necessary for the application of the other parts of this series of documents.

  • Draft
    22 pages
    English language
    e-Library read for
    1 day

Article 20 GDPR and Article 4 and 5 the proposed FIDA Regulation require the data access and portability of customer data. To support this demand CEN/TC 445 will organise the standardisation project with its Working Group 1 in which the following European standardisation deliverable will be developed.
European Standard (EN) for the semantic specification of the interfaces
The scope of this EN for customer (natural or legal person) data access and portability in the insurance sector should be based on the insurance-specific part of the proposed FIDA Regulation and therefore should contain:
•   Semantic specifications for the processes to support the data access and portability. These specifications define on the business level the functions and the behaviour for the following process interfaces:
- Request of the customer to the data holder for an actual transfer of the customer data (Article 4 FIDA).
- Transfer of the requested customer data from the data holder to the requesting customer (Article 4 FIDA).
- Request of a data user to a data holder for an actual transfer of customer data under a permission of the customer (Article 5 FIDA).
- Transfer of the requested customer data from the data holder to the requesting data user (Article 5 FIDA).
•   Sematic specifications for the customer data to be transferred by the above processes. The scope of the customer data will be limited to the insurance-specific part of the FIDA proposal defined in the Article 2 (1) and Article 3 (3) of FIDA. These specifications define on the business level each element of the customer data with identification, name, precise definition, and value type (text, number, amount, quantity, percentage, date, etc.). The composition of these data elements forms a semantic data model for the insurance-specific customer data. The data model will consist of the following parts:
- General data of the policy holder (including address, contact details, profession, payment means, etc.).
- General data of the insurance policy (including policy number, insurance product and coverages, insured period, premium amounts, etc.).
- Data specific to the consumers’ insured assets which are collected for the purposes of a demands and needs test.
- Data depending on class of business, such as
- Motor insurance (details about vehicle, usage, drivers),
- Property insurance (details about building, household or other objects),
- Liability insurance (details about insured persons and their activities),
- Accident insurance (details about insured persons and their activities),
- Insurance-based investment products (details about insured persons and the savings, investments, pension rights, etc.).
The EN specifies the processes and the data model on the semantic level in a syntax-neutral format, independent from its representation in a concrete implementation syntax.

  • Draft
    288 pages
    English language
    e-Library read for
    1 day

This document specifies refinements for an application of EN ISO/IEC 27701 in a European context.
This document is applicable to the same entities as is ISO/IEC 27701: all types and sizes of organizations, including public and private
companies, government entities and not-for-profit organizations, which are PII controllers and/or PII processors.
An organization can use this document for the implementation of the generic requirements and controls of EN ISO/IEC 27701
according to its context and its applicable obligations.
Certification criteria based on these refinements can provide a certification model under ISO/IEC 17065 for processing operations
performed within the scope of a privacy information management system according to EN ISO/IEC 27701, which can be combined
with certification requirements for EN ISO/IEC 27701 under ISO/IEC 17021.

  • Draft
    34 pages
    English language
    e-Library read for
    1 day

This document is applicable to all rail vehicles including OTMs and Road-rail machines, which are operated on the heavy rail network with nominal track gauge 1 435 mm and nominal static vertical wheelset forces up to 350 kN.
This document may also be applicable (partly or in full) to:
—   rail systems with different track layout, e.g. urban rail systems and/or;
—   rail systems with other than 1 435 mm nominal track gauge and/or;
—   non-public rail networks and vehicles, e.g. mine rail systems.
NOTE   For rail systems other than 1 435 mm track gauge or urban rail systems, the related post processing, limit values and test conditions could be different. They are specified nationally or individually taking into account track design and operating conditions.
This document contains the common parts of the series of documents as well as the relationship to other standards, general requirements and handling of deviations from requirements. These specifications are necessary for the application of the other parts of this series of documents.

  • Draft
    22 pages
    English language
    e-Library read for
    1 day

Frequently Asked Questions

An EU Regulation is a binding legislative act that must be applied in its entirety across the European Union. Unlike directives, regulations do not need to be transposed into national law and are directly applicable in all member states. Regulations are used when uniform application across all EU countries is essential.

Regulation 2016/679 covers "REGULATION (EU) 2016/679 OF THE EUROPEAN PARLIAMENT AND OF THE COUNCIL of 27 April 2016 on the protection of natural persons with regard to the processing of personal data and on the free movement of such data, and repealing Directive 95/46/EC (General Data Protection Regulation)". There are 14 standards associated with this regulation.

Harmonized standards under 2016/679 are European standards (ENs) developed by CEN, CENELEC, or ETSI in response to a mandate from the European Commission. When these standards are cited in the Official Journal of the European Union, products manufactured in conformity with them benefit from a presumption of conformity with the essential requirements of 2016/679, facilitating CE marking and free movement within the European Economic Area.

Loading...