Scope
This document establishes high-level requirements for privacy by design to protect privacy throughout the lifecycle of a consumer product, including data processed by the consumer.
NOTE 1 This document does not contain specific requirements for all the privacy assurances and commitments that organizations can offer consumers.
NOTE 2 This document provides references in the bibliography to other existing authoritative standards, that provide more detailed requirements and guidance on privacy (e.g. identification of PII, PII access and privacy controls, consumer consent, notification of breach, secure disposal of PII, interactions with third party processors) for common functions within the organization (e.g. Corporate Governance; Data and Privacy Governance; IT Operations and IT Services Management; Security and Security Management; Data Management and Database Administration; Marketing, Product Management; Web and mobile application development, systems development; Systems administration, network administration).
NOTE 3 This document does not specify particular methodologies that an organization may adopt for the design and-implementation of privacy controls, nor the technology that may be used to operate such controls.
Comment on proposal
Required form fields are indicated by an asterisk (*) character.