Overview
ISO/IEC TS 27564:2025 - "Privacy protection - Guidance on the use of models for privacy engineering" is a Technical Specification from ISO/IEC JTC 1/SC 27 (first edition, 2025). It provides practical guidance on using modelling and model‑based systems and software engineering (MBSSE) techniques to embed privacy into systems throughout their lifecycle. The document explains categories of privacy models, how modelling supports privacy engineering, model management concerns, and high‑level use cases (including privacy threat modelling and examples from ISO/IEC TR 31700‑2).
Key topics and technical guidance
- Model concepts and taxonomy
- Definitions of models, model patterns, model repositories and model kinds; models as digital artefacts and a Single Source of Truth (SSOT).
- MBSSE processes
- Guidance aligned to ISO/IEC/IEEE 24641: planning MBSSE, building models (produce, verify, validate, simulate) and supporting models (management, storage, reuse).
- Privacy modelling specifics
- Categories of privacy models of interest (system, ecosystem and engineering perspectives).
- Model representation, storage, reuse and repository practices.
- Intellectual property rights (IPR) considerations for models.
- Behavioural and policy interoperability using models.
- Engineering guidance
- Using models to engineer privacy capabilities, integrate system context, and address systems‑of‑systems (emergent risks).
- Profile‑based construction to align with horizontal standards (AI, IoT, safety, resilience).
- Practical examples
- High‑level use cases including privacy threat modelling and sample workflows (Annex A), and cross references to privacy impact assessments and data protection modelling frameworks.
Practical applications and users
Who benefits:
- Privacy engineers and system architects - to design privacy capabilities and model privacy requirements into architectures.
- Software engineers and model engineers - to create, validate and reuse privacy models within MBSSE toolchains.
- Data protection officers and compliance teams - to map regulatory obligations (e.g., DPIAs, GDPR/CPRA context) to engineering artefacts and demonstrate traceability.
- Tool vendors and repository managers - for implementing model storage, SSOT and interoperability features.
- Standards developers and auditors - for harmonising modelling practice across ecosystems.
Practical benefits:
- Consistency across lifecycle stages, improved interoperability between systems and supply‑chain partners, clearer traceability of privacy decisions and more effective identification and mitigation of privacy risks.
Related standards
- ISO/IEC/IEEE 24641 (MBSSE processes)
- ISO/IEC/IEEE 42010 (architecture descriptions)
- ISO/IEC TR 31700‑2 (use cases referenced)
- ISO/IEC 19763‑1 (model repositories and metadata)
- Cross‑cutting references: DPIA/data protection frameworks, AI and IoT related standards
Keywords: ISO/IEC TS 27564:2025, privacy engineering, privacy models, MBSSE, model‑based systems and software engineering, privacy threat modelling, SSOT, model repository, data protection.