If you have difficulty in submitting comments on draft standards you can use a commenting template and email it to admin.start@bsigroup.com. The commenting template can be found here.
This document specifies principles for privacy protection through pseudonymization services, aimed at safeguarding personal health information . It is applicable to organizations implementing pseudonymization processes or claiming trustworthiness in pseudonymization service operations. This document:
— defines foundational principles for pseudonymization
— aligns with updated regulations and standards, such as ISO/IEC 20889:2018 , ISO/IEC 27559:2022 , and other relevant documents, and methodologies for pseudonymization services
— provides guidance on practical application of pseudonymization , including examples of de-identification process, best practices and case studies
— defines important elements in the concept of pseudonymization, direct and indirect identifiability of personal information, and different types of data variables
— provides guidance on risk assessment for re-identification, and two distinct contexts of re-identification of pseudonymized information, and
— specifies various techniques designed to balance privacy protection with data utility to ensure that the data can be used for analytics, research, or operational needs without revealing personal identities.
Additionally, this document addresses new regulatory and ethical frameworks, such as the EU AI Act[1] , IEEE 7000 , and IEEE 7007 , as well as guidance on pseudonymization in AI, considering the impact of emerging technologies on privacy protection.
Required form fields are indicated by an asterisk (*) character.
You are now following this standard. Weekly digest emails will be sent to update you on the following activities:
You can manage your follow preferences from your Account. Please check your mailbox junk folder if you don't receive the weekly email.
You have successfully unsubscribed from weekly updates for this standard.
Comment by: