Overview
ISO/TR 12859:2009 - "Intelligent transport systems - System architecture - Privacy aspects in ITS standards and systems" is an ISO Technical Report that provides general guidelines for addressing data privacy and associated legislative requirements during the development and revision of Intelligent Transport Systems (ITS) standards and implementations. It is informative in nature and intended to help ITS standards developers, system architects and implementers embed privacy-by-design principles into ITS architecture and services.
Key topics and requirements
ISO/TR 12859:2009 focuses on high-level privacy principles and design guidance rather than prescriptive technical controls. Major topics include:
- Scope and definitions: clear terms (e.g., personal data, personal information controller, purpose specification, accountability).
- Privacy principles (presented as checklist-style recommendations):
- Collection limitation and use limitation
- Specified, explicit and legitimate purposes for data collection
- Data minimization (adequate, relevant and not excessive)
- Accuracy and data quality, retention limits (identification only as long as necessary)
- Individual participation (access and correction rights)
- Consent and disclosure restrictions
- Need-to-know access and role-based data access
- Openness and transparency about practices
- Security safeguards to prevent loss, unauthorized access, modification or disclosure
- Cumulative interpretation of multiple recommendations to resolve conflicts
- Privacy requires security: recommends alignment with recognized information security practices (references ISO/IEC 27000 series and ISO/IEC 27002) for processing, transmission and storage of ITS data.
- Context and legal alignment: guidance is mapped to international policy instruments (OECD Guidelines, APEC Privacy Framework) and, for EU users, Directive 95/46/EC.
- Supplementary materials: Annexes provide data privacy frameworks, examples of national implementations, cumulative interpretation examples, and a list of security-related international standards.
Applications and users
ISO/TR 12859:2009 is practical for:
- ITS standards developers and technical committees (e.g., ISO/TC 204)
- System architects and software/hardware vendors designing ITS components (e.g., traffic monitoring, floating car systems, probe data)
- Project managers, privacy officers and legal teams assessing legislative compliance during ITS system design
- Integrators and public agencies procuring ITS solutions who need a privacy design checklist
Use cases include architecture reviews, standards gap analysis, privacy impact assessments and early-stage requirement capture to ensure legal and ethical handling of ITS personal data.
Related standards and keywords
Related references include ISO 24100 (probe data guidance to be published), the ISO/IEC 27000 series for information security, OECD Guidelines, APEC Privacy Framework and Directive 95/46/EC.
Keywords: ISO/TR 12859:2009, intelligent transport systems, ITS privacy, data protection, system architecture, privacy-by-design, ITS standards, data privacy guidelines, ISO, ITS security.