ISO/IEC 29184:2020 Information technology — Online privacy notices and consent (Japanese title: Online Privacy Notices and Consent1). I received an International Standards Development Award for my work as the international editor (Project Leader) of this standard. It originated as the Japanese Ministry of Economy, Trade and Industry’s “Guidelines on Notice and Consent.” We brought the guidelines to ISO/IEC JTC 1, incorporated extensive feedback from organizations including the French data protection authority CNIL, and developed them into an international standard. I believe the standard has significant value in ensuring privacy transparency.

Why Privacy Transparency Matters Now

Our lives are more digital than ever. Home broadband and internet access have become commonplace, while devices such as smartphones and smartwatches routinely collect data about our activities. At the same time, the technologies used to process these vast amounts of data have advanced dramatically.

These technological advances have undoubtedly brought tremendous benefits: more convenient lives, innovative business opportunities, compelling services, and experiences that are valuable to us. At the same time, however, they have also created new challenges.

Growing Consumer Awareness of Privacy

Consumers are now more sensitive to privacy than ever before. Many people have begun to question how online services collect and use their personal information.

What is the underlying cause of these questions and concerns? It is a lack of explanation. The reality is that many companies do not explain clearly enough how they process, store, and manage the personal information they collect.

2 Essential Measures Companies Must Take

To improve this situation, companies are primarily expected to do 2 things:

1. Provide Clear Information

When collecting personal information, companies must explain its intended uses and methods of processing in a clear and understandable way. Rather than presenting complex terms of service filled with technical jargon, it is important to provide information that ordinary people can read and understand.

2. Obtain Appropriate Consent

Companies must obtain users’ consent to the use of their personal information in a fair and transparent way. Crucially, users must be able to withdraw that consent at any time.

Fundamental Principles of Privacy Protection

These measures draw on the international standard ISO/IEC 29100. Of the 11 principles it establishes, they are based on the following 2:

  • Principle 1: Consent and Choice — Individuals can make choices about how their information is used.
  • Principle 7: Openness, Transparency and Notice — Companies disclose how they handle information.

A Standard That Applies to All Online Businesses

This standard applies to every online business that handles personal information. It covers not only large corporations, but also companies operating small web services and any organization that manages employees’ personal information.

Conclusion: Becoming a Trusted Company

Benefiting from digital technology while protecting individuals’ privacy is a challenge that modern companies cannot avoid. By maintaining appropriate transparency and obtaining users’ consent properly, however, companies can earn consumers’ trust and build sustainable businesses.

Privacy protection is more than regulatory compliance; it can be a source of competitive strength in its own right. Isn’t now the time to review your company’s approach to privacy?

Footnotes

  1. JIS X 9252 https://webdesk.jsa.or.jp/books/W11M0090/index/?bunsyo_id=JIS+X+9252%3A2023

Related posts