Versions Compared

Key

  • This line was added.
  • This line was removed.
  • Formatting was changed.

...

  • The (surveillance) privacy controller credential is the digital version of an organization's privacy and surveillance notice and related default identification.
  • Rather than analogue identification - company identity, company address, company phone number, the controller credential contains the digital version of this information and privacy contract point for exercising data control for privacy rights
    • The point where a valid state of consent can be assured with a proof of notice and a record of consent.
  • The aim of this specification is to implement related standards and specification for different measure of privacy assurance in accordance with the principles of operational privacy.
  • At its core, the privacy controller credential is a security and rights record and that among things can be used for Non-Interdependent indepent access to rights and controls in context of decentralized use of identifiers.

Introduction

In privacy regulations globally the notice and notification requirements in legislation are the most consistent across jurisdictions. In all regulations the identity of the PII Controller is required to be provided to the person before, at the time, or as soon as possible, when processing personal information. 

This specification uses ISO/IEC standard semantics to generate a controller notice of controller receipt for each digital identifier based relationship, and in order to doing so implement privacy rights to control the use of the personal information related to the digital identifier relates too. (s). 


This specification also addresses security as a part of privacy (there won't be any "considerations" at the end). Current security approaches tend to look at privacy risk less wholistically. This specification addresses this key, no pun, security challenge - effectively KYC Key Security Challenge - KYC addressed enhanced with a new authorization flow called that that reflects - KYB - Know your business  .  

  • Verifying people for service use has been the main security approach 
  • Altenrative approach is to verfify their privacy controller credential and use privacy law for defining purpose specific services - 
  • Using standards fromework (ISO) with ANCR Receipt and the W3C Vocabulary for Notice and Notifications text (which fills the receipt fields) 

...