Overview
ISO/IEC TS 27560:2023 - "Privacy technologies - Consent record information structure" defines an interoperable, open and extensible information structure for recording personally identifiable information (PII) principals’ consent to PII processing. The technical specification standardizes both the consent record (the controller’s recordkeeping artifact) and the consent receipt (an acknowledgement or artefact provided to the PII principal). Its aims are to support provision of a consent record to individuals, enable exchange of consent information between systems, and manage the life cycle of recorded consent. It is the first edition (2023) and builds on ISO/IEC 29184.
Key topics and technical requirements
- Consent record vs. consent receipt: formal definitions and intended roles - records are for controller recordkeeping; receipts are for PII principals and references to records.
- Interoperable data structure: an extensible information model that includes sections such as record header, PII processing, PII information, party identification, and event history.
- Recordkeeping controls: requirements and recommendations for how PII controllers must structure, store and maintain consent records and receipts.
- Consent lifecycle management: guidance for recording events (granting, withdrawal, modification) and timestamps to support lifecycle workflows.
- Formats and examples: informative Annexes provide example encodings (JSON), lifecycle examples, performance/efficiency considerations, and mapping to ISO/IEC 29184.
- Security & integrity: informative guidance on protecting consent records and receipts (see Annex E), including integrity considerations for exchanges.
- Scope limits: the standard specifies structure and content but does not mandate a specific exchange protocol.
- Terminology & consent types: aligns with ISO/IEC 29100 and ISO/IEC 29184 for consent definitions and types (explicit, implied, etc.).
Practical applications and target users
Who uses ISO/IEC TS 27560:2023:
- Privacy engineers and system architects designing consent management systems and privacy dashboards.
- Software developers and vendors of consent management platforms (CMPs) implementing consent receipts and records (JSON examples provided).
- Data Protection Officers (DPOs), compliance and legal teams establishing auditable, standardised consent recordkeeping for regulatory compliance.
- Organizations and controllers seeking interoperable mechanisms to exchange consent metadata across services and third parties.
- Regulators and auditors evaluating consent lifecycle evidence.
Typical applications:
- Issuing machine-readable consent receipts to data subjects.
- Centralized consent repositories for audit and compliance.
- Cross-system consent portability and synchronization.
- Supporting data subject requests and dispute resolution with authoritative consent records.
Related standards
- ISO/IEC 29184 (Online privacy notices and consent) - complements and maps to ISO/IEC TS 27560 (see Annex H).
- ISO/IEC 29100 (Privacy framework) - source terminology and principles.
Keywords: ISO/IEC TS 27560:2023, consent record, consent receipt, consent management, PII, privacy technologies, interoperability, JSON, data protection, lifecycle, recordkeeping.