The title sounds rather grandiose, but of course there is no way I can produce a comprehensive list, so for now I will jot down whatever comes to mind as a starting point. If there are others, please feel free to keep adding them in the comments.

◎International Covenant on Civil and Political Rights and UN Human Rights Committee (ICCPR)

This Covenant states in Article 16, “Everyone shall have the right to recognition everywhere as a person before the law.” This “everywhere” should presumably be extended to apply to digital identity as well.

◎Privacy Guidelines

The OECD’s Guidelines on the Protection of Privacy and Transborder Flows of Personal Data set out guidelines concerning the free flow of personal data, both domestically and internationally, and restrictions on that flow.

◎Machine Readable Travel Document (MRTD)

When it comes to identity-document-type documents, Japan seems to use its own specifications, except for passports. The International Civil Aviation Organization (ICAO) defines visually and machine-readable travel documents, such as passports and visas. When considering such documents in Japan in the future, it may be worth considering the adoption of ICAO specifications.

◎ISO Standards

Efforts to conform to ISO will be important for international compatibility and as a basis for government procurement under the WTO.

  • ISO/IEC 29100 Privacy Framework (FDIS ballot)
  • ISO/IEC 29101 Privacy Reference Architecture (CD3 ballot)
  • ISO/IEC 29115 Entity Authentication Assurance Framework (CD3 ballot)
  • ISO/IEC 24760 A framework for identity management Part 1: Terminology and Concepts (FDIS ballot)
  • ISO/IEC 24760 A framework for identity management Part 2: Reference framework and requirements (WD1 comments)
  • ISO/IEC 24760 A framework for identity management Part 3: Practice (WD1 comments)
  • ISO/IEC 29146 A framework for access management (WD5 comments)
  • ISO/IEC 29190 Privacy Capability Assessment Model (WD2 comments)
  • ISO/IEC 29191 Requirements for partially anonymous, partially unlinkable authentication (CD2 ballot)

In addition, a related ITU-T standard that has not yet been brought to ISO is:

  • X.OITF Open Identity Trust Framework

It will likely be brought to ISO after it has undergone a certain degree of deliberation within ITU-T.

FIPPs: Fair Information Practice Principles

1. Transparency
2. Individual Participation
3. Purpose Specification
4. Data Minimization
5. Use Limitation
6. Data Quality and Integrity
7. Security
8. Accountability and Auditing

That will do for a start…

 

Related posts