Overview
ISO/IEC 29184:2020, titled Information technology - Online privacy notices and consent, defines controls for designing clear, timely online privacy notices and for obtaining demonstrable consent to collect and process personally identifiable information (PII). Applicable in any online context where a PII controller or other entity informs PII principals, the standard supports transparent, fair and revocable consent and implements privacy principles from ISO/IEC 29100 (Consent and Choice; Openness, Transparency and Notice).
Key Topics and Requirements
- Notice obligations and structure: Requirements for when notice must be provided, appropriate timing, locations and forms (including visual and audible notices) and ongoing references to prior notices.
- Clarity and accessibility: Notices must be concise, legible, in plain language, multilingual where appropriate, and accessible (e.g., screen reader support).
- Notice content elements: Mandatory information categories such as purpose descriptions, identification of the PII controller, types and methods of PII collection, timing/location of collection, intended uses, third‑party transfers, retention periods, jurisdiction/geo‑location of stored PII, risks, and complaint/contact channels.
- Consent controls: Conditions for when consent is appropriate; requirements for informed, freely given, specific and unambiguous (explicit/opt‑in) consent; separation of necessary vs optional PII; frequency and timeliness of consent requests; recordkeeping (consent receipts).
- Change management: Guidance on renewing notices and renewing consent when processing conditions change.
- Implementation evidence: Organizations must document applicability of each control, justifications if controls don’t apply, and methods for verifying implementation.
- Practical artifacts: Annexes provide a sample user interface for obtaining consent on PCs and smartphones (Annex A) and an example consent receipt or record (Annex B).
Applications
ISO/IEC 29184 is practical for any online service or product that collects PII:
- Websites, mobile apps, e‑commerce platforms, IoT services and cloud services
- Online recruitment/HR portals and customer support systems
- Systems that transfer PII to third parties or across jurisdictions
Use cases include designing privacy policies and consent flows, building consent management platforms (CMPs), and documenting compliance during audits.
Who should use this standard
- Privacy officers, data protection and legal teams
- Product managers, UX designers and front‑end developers implementing consent UIs
- Security architects and compliance/audit professionals
- PII controllers and processors seeking documented, demonstrable privacy practices
Related Standards