ETSI - TR 103 591
SmartM2M; Privacy study report; Standards Landscape and best practices
| Organization: | ETSI |
| Publication Date: | 1 October 2019 |
| Status: | active |
| Page Count: | 37 |
scope:
Context of the present document
In order to provide a global and coherent view of all the topics addressed, a common approach has been outlined across the Technical Reports concerned (see below) with the objective to ensure that the particularities of the IoT systems are properly addressed and that the overall results are coherent and complementary.
In this context, the present document has been built with this common approach also applied in all of the other documents listed below:
• ETSI TR 103 533 [i.2]
• ETSI TR 103 534 (part 1 and 2) [i.28]
• ETSI TR 103 535 [i.33]
• ETSI TR 103 536 [i.34]
• ETSI TR 103 537 [i.35]
• ETSI TR 103 591 (the present document)
Scope of the present document
The present document elaborates on how to ensure effective protection of individuals' privacy in the IoT environment. It acknowledges the challenges for privacy and data protection and stresses the necessity for a human centred approach.
To this end, the present document will:
• highlight the role of social values in the design of IoT systems;
• discuss the role of standards under the GDPR and the proposed ePrivacy Regulation;
• outline the role of the individual, also, through a set of use cases drawn from an ongoing EU project and further adapted for the needs of the present document;
• produce an overview of the main privacy and data protection challenges emerging in the IoT environment;
• review the privacy standardization gaps identified in ETSI TR 103 376 [i.1] and how some of these gaps have been resolved since the completion of the work if at all;
• illustrate current best practices across industrial and other organizations in the processing of personal information to meet, and in some cases exceed, the minimum requirements for compliance in view of maximizing the protection of personal information;
• point at the fundamental shifts taking place in relation to privacy under EU Law, including the shift from rulebased frameworks to principle-based frameworks, the necessity to go beyond mere compliance to meaningful accountability and the implementation of impact-based measures.
For reasons explained below under clause 7.3, the development of new standards falls outside the scope and the objectives of the present document.
Notably, the present document is addressed to the entire set of stakeholders with a role in the IoT environment and it complements ETSI TR 103 533 [i.2].
Document History