Overview - ISO/IEC 27559:2022 (Privacy enhancing data de-identification framework)
ISO/IEC 27559:2022 provides a practical framework for identifying and mitigating re-identification risks and managing risks across the lifecycle of de‑identified data. Applicable to all sizes and types of organizations (public, private, government, not‑for‑profit) acting as PII controllers or PII processors, the standard supports privacy‑enhancing use of personal data while maintaining oversight when data are reused, shared, or released. It guides organizations on assessing the environment, attacker capabilities, data properties and implementing governance to reduce identity disclosure.
Key topics and technical requirements
- Context assessment
- Threat modelling, assessment of adversary motives and capacity, and transparency/impact assessment for stakeholder engagement.
- Data assessment
- Characterization of data features: data principals, data types, attribute categories and dataset properties to inform de‑identification choices.
- Attack modelling
- Consideration of population vs. sample‑based attacks, maximum/average risk scenarios and selection of appropriate data privacy models.
- Identifiability assessment and mitigation
- Methods to quantify identifiability, adversarial testing, and iterative mitigation steps such as reconfiguring environments, transforming data (e.g., masking, aggregation, techniques described in ISO/IEC 20889), and re‑evaluation.
- De‑identification governance
- Roles and responsibilities, policies and procedures, disclosure management, stakeholder communication, monitoring after data release, and incident mitigation.
- Practical tools referenced
- Includes informative annexes (example identifiers, threshold benchmarks) to support implementation.
Applications - who uses ISO/IEC 27559 and why
- Data protection officers, privacy teams, and compliance managers use the framework to meet regulatory privacy expectations while enabling data use.
- Data custodians and security engineers apply threat and attack modelling guidance to design safe data sharing and access controls.
- Researchers and analytics teams adopt the framework to enable internal reuse or external sharing of datasets without compromising privacy.
- Cloud and third‑party processors use the standard to define responsibilities when de‑identification or oversight is outsourced.
Benefits include stronger data governance, reduced re‑identification risk, and clearer alignment with privacy law and corporate privacy policies.
Related standards
Keywords: data de‑identification, privacy enhancing, re‑identification risk, PII, de‑identified data, data governance, threat modelling, anonymization, pseudonymization, ISO/IEC 27559.