E-Privacy

Available (13)

Showing 1 - 12 per page



Requirements on processing PII using blockchain and distributed ledger technology (prEN 18379)

This document establishes general principles for and methods of processing personal identifiable information (PII) in BC/DLT systems and provides requirements and recommendations derived from legal requirements and recommendations in the GDPR. The document clarifies relevant terms for both technical as well as legal experts. It establishes a methodological framework that helps identifying types of PII as well as mapping legal principles of the GDPR to technical measures available to improve data protection or mitigate the risk of processing PII in BC/DLT-systems. This document is aimed towards establishing a high level of privacy in BC/DLT-systems. This document is applicable to all BC/DLT-systems.

Biometric System-on-Card Part 3: : Logical information interchange mechanism (ISO/IEC 17839-3:2026)

This document specifies:

  • logical data structures for a Biometric System-on-Card (BSoC);
  • enrolment procedures; and
  • usage of commands and data structures defined in other International Standards for BSoC.

This document does not define requirements for:

  • commands and data structures that apply to devices external to a BSoC;
  • commands and data structures that apply to logical interfaces inside a BSoC.

EUDI Wallet Held Assets Access Control, Operation and Management (prCEN/TS 18297)

This document specifies the functionality of the Wallet Unit for Access Control to Wallet Held Assets (WHAs) i.e. personal data relating to the Wallet User and stored in the Wallet Unit. It defines the Wallet Access Control decision Engine (WACE) and the corresponding functional requirements, resulting in recommendations to the user on decision to be made. This document aims at: 1) describing and specifying an Access Control Model supporting access control to the various possible operations on WHA(s); 2) providing the definitions and classification of the various types of data and metadata, and supporting access control to the various possible operations on WHA(s) ; 3) describing and specifying a W ACE controlling the access to the various possible operations on WHA(s) and the notification returned by the Wallet Access Control Decision Engine to a Wallet Unit; 4) identifying requirements applicable to the Wallet Access Control Decision Engine; This document also: 

  • identifies technical specifications and standards that can be used to support the concepts described herein;
  • specifies additional requirements for the use of the identified specifications to meet the above objectives; 
  • provides the missing technical specifications needed to meet the above objectives where needed; 
  • provides examples and use cases; The Access Control Model and Wallet Access Control Decision Engine defined in this document aim to comply with the regulator requirements regarding access control. 

    The following areas are out of the scope of this document: 1) content and encoding of the policies assigned for the disclosure of WHA(s), 2) implementation choice and encoding of Wallet Held Access Control Metadata; 3) encoding of electronic attestation(s) of attributes which are in the remit of ETSI/TC ESI.

Matthieu Grall

Country
France
Fellow's country
Open Call
Organisation type
Organization
Independent expert
Portrait Picture
Matthieu
Proposal Title
EU Aligned Contributions to SC27 and SC42 on Security, Privacy and Trustworthy AI
Standards Development Organisation
Topic
Artificial Intelligence
StandICT.eu Year
2029
Year

Mathy Vanhoef

Description of Activities

This fellowship supported my work in updating to the IEEE 802.11 standard to prevent a recently discovered security weakness. This weakness is related to mesh networks, where, without extra defenses, an adversary could inject arbitrary packets into protected mesh networks. We designed a defense to mitigate this challenging gap. Unique about our created defense is that it is fully backward compatible, meaning each individual mesh client can independently enable this defense. As a proof-of-concept, we also implemented this defense in the Linux kernel to demonstrate practicality and confirm it prevents attacks.
 

Country
Belgium
Fellow's country
Impact on SMEs (9th Open Call)
During the fellowship, I have been in contact with LANCOM, a European company providing Wi-Fi equipment, on improving the security of their devices, inspired by our research and contributions to the IEEE 802.11 standards. This allows European SMEs to take a leadership position on ensuring security and privacy in IEEE 802.11 equipment and networks.
Impact on society (9th Open Call)
Privacy and security are core human rights in our eyes, and our standardization improvements support this societal right. More broadly, these contributions help us as a European player to influence the IEEE 802.11 standard with these values. The security improvements are also created with sustainability in mind, as their overhead is designed to be minimal and practically negligible, and is designed to be backward compatible to reduce e-waste.

Open Call
Organisation type
Organization
Universiteit Leuven
Portrait Picture
Mathy Vanhoef
Proposal Title (9th Open Call)
Security and Privacy Enhancements for IEEE 802.11
Standards Development Organisation
Topic
Cybersecurity
StandICT.eu Year
2026
2029
Year
Topic (9th Open Call)

Jan Schallaböck

Description of Activities

This fellowship targets consumer-centric privacy by design in international standards work. Moreover, the Specific priorities, gaps and challenges identified are: 

  • Consumer trust and privacy gaps: Fragmented practice and fast-moving online services erode user trust; legal principles (e.g., privacy by design, accountability) are not consistently translated into usable, testable requirements. 
  • Stakeholder involvement: Consumer organisations and SMEs face high barriers to engage in lengthy, technical processes; national mirrors vary widely in how consumer voices are integrated. 
  • Skills & usability deficits: Lack of shared patterns (consent, transparency UX, data control) and uneven digital skills hinder meaningful participation and compliant implementations. 
  • Landscape fragmentation: Overlapping activities across SDOs make it hard for newcomers to find entry points, slowing delivery on e-privacy, safety, and transparency outcomes. 

How the fellowship addressed these

This fellowship supports my engagement as the chair of Chair of  ISO/IEC JTC 1/SC 44. The group’s Strategic Business Plan (SBP) aims to respond the the challenges identified above in the following manners: 

  • Th TC establishes an inclusive, modular work approach that supplements ISO 31700-1 with smaller, technology-/sector-specific deliverables—lowering thresholds for participation and speeding time-to-impact on safety, transparency, and e-privacy. 
  • Low-threshold stakeholder mechanisms: Communications/outreach plan and light-touch consultation formats to systematically bring in consumer groups and civil society, aligned with ISO/COPOLCO and relevant liaisons. 
  • SME: A stepwise, outcome-oriented approach envisaged in the SBP to accommodate different maturity levels and resource constraints, easing adoption by SMEs. 
  • Early scoping of verticals: Following the September 2025 SC 44 meetings in Kunming, first preliminary work is being initiated with additional verticals to follow.
Country
Germany
Impact on SMEs (9th Open Call)
European stakeholders—including consumer protection agencies, privacy NGOs, and SMEs—benefit from standards that operationalise the GDPR’s intentions while ensuring international interoperability. Yet their effective participation requires active facilitation, particularly in new structures such as SC 44, which currently lack established consumer consultation mechanisms.
The fellowship addressed this through structured moderation, bilateral liaison efforts (e.g. SC 27, SC 37, SC 42, OECD, TACD), and the development of participation tools that lower the threshold for stakeholder input. In the long term, systematic integration of consumer needs into technical standardisation will create both societal and economic value—opening opportunities for European SMEs and civil-society actors to co-shape usable, rights-based privacy-by-design standards.
Impact on society (9th Open Call)
The focused standards have several key societal impact:
Consumer trust and transparency: By developing modular, user-centric privacy standards (ISO 31700 family), the work enables individuals to better understand, control, and contest how their personal data are used across digital services.
Fairness and due process: Standardising transparency and accountability mechanisms strengthens procedural safeguards for consumers and ensures consistent respect for rights across jurisdictions.
Inclusion and accessibility: SC 44’s stakeholder model - outlined in the Strategic Business Plan - lowers participation barriers for consumer groups, NGOs, and SMEs, thus widening representation in global ICT standardisation.
Digital skills and awareness: Reusable guidance and patterns developed under SC 44 support capacity-building for both implementers and end-users, contributing to digital-skills and literacy objectives in the EU.
Socio-economic resilience: By reducing compliance costs and promoting interoperable privacy solutions, the standards ecosystem strengthens the competitiveness of European SMEs while reinforcing consumer rights and social trust online.
In sum, the fellowship advances a human-centred digital transformation, where privacy, transparency, and usability become intrinsic features of technology design—helping to operationalise European values of trust, accountability, and fairness in the global digital economy.
Open Call
Organisation type
Organization
iRights.Law RAe
Portrait Picture
Jan Schallaböck
Proposal Title (9th Open Call)
Strategic Business Plan: ISO/IEC JTC 1/SC 44 Consumer Protection in the Field of Privacy by Design
Role in SDO
Standards Development Organisation
StandICT.eu Year
2026
Topic (9th Open Call)

Robin Renwick

Description of Activities

The fellowship tackles the lack of international, or European, standard or technical specification that focuses explicitly on privacy and data protection capabilities of DLT systems. With this regards, ISO TS 24946 “Requirements and guidance for improving, preserving, and 
assessing the privacy capability of DLT systems” has now reached CD stage (July 2025) and will endeavour to move through this process and be completed in 2026. This process requires continued support from experts to ensure delivery, as scheduled. In this sense, the priority of this activity focuses  at the European level, CEN/CENELEC  JTC 19/WG3 to produce a European standard on PII protection within DLT which is strongly influenced by ‘DIN Spec 4997 - Privacy by Blockchain Design’ and the aforementioned ISO TS 24946. This European specification will seek to harmonise the GDPR and recent EDPB guidance to produce a technical specification intended for the European DLT ecosystem. 
This European specification will provide much needed clarity for the DLT ecosystem as regards data protection and privacy capabilities, affordances, and assessment. Further harmonisation between the international specification at ISO and the European standard will support interoperability, and ensure that privacy and data protection capabilities are harmonised globally. The main challenges concerns exacting requirements from regulations such as Article 76(3) of MiCAR, as well as Article 79(1) of the European AMLR will require navigation. Standards 
require alignment and compatibility with those legal texts, as well as corresponding regulations regarding personal data, data markets, and trust services (e.g., GDPR, Data Act, eIDAS2). Ensuring there are no gaps between regulatory texts and the proposed European standards will be a primary focus. Also, it must be ensured that there are no substantial gaps between international specifications and European standards will be the second focus. Standards alignment between ISO and CEN/CENELEC is viewed as a key outcome to benefit the global DLT ecosystem, and one that requires strong consensus building, given slightly different international privacy perspectives and preferences.

Country
Ireland
Open Call Topics
Open Call
Organisation type
Organization
Trilateral Research
Portrait Picture
Robin Renwick
Proposal Title (8th Open Call)
Harmonisation of ISO TS 24946 and CEN/CLC/ JTC19 WG3
Standards Development Organisation
Topic
E-privacy
StandICT.eu Year
2026
Topic (8th Open Call)

Matthieu Briottet

Description of Activities

The expected impact of the project is to provide stakeholders with a certification as defined in article 42 of the GDPR, thus improving trust between actors in a context of PII processing.

Fellow's country
Open Call Topics
Open Call
Organisation type
Organization
IT Consultant, TRAX
Portrait Picture
Briottet
Proposal Title (3rd Open Call)
Build certification scheme for En17926 (refining ISO27701 in EU context) complying with art 42 GDPR
Standards Development Organisation
StandICT.eu Year
2026
Year
Topic (3rd Open Call)

Julien Bringer

Description of Activities

I estimate that digital identities, and the way to ensure appropriate levels of assurance and handling of corresponding credentials, are key for the digital society.

Country
France
Fellow's country
Open Call Topics
Impact on SMEs (9th Open Call)
Blockchain and Distributed Ledger technologies are developed directly in a global environment and thus the activity impacts EU and SMEs in EU, as for the way EU specificities and regulations (e.g. GDPR, eIDAS, NIS, MiCA) considered as early as possible. Also many SMEs in EU are positioned around security of web 3.0 applications and on decentralized identity and future standards on this matter would be key for procurement.
Impact on society (5th Open Call)
Toward the development of EU-friendly solutions for biometrics-based services, employing strong privacy enhancing technologies, thus going further contractual/organisational requirements, to ensure privacy and security by design. Promoting the use of the newest privacy enhancing technologies is in particular very important (biometric technologies are more and more seen as a way to fight against authentication/identification threats in our digital lives) as sharing or leaking biometric information without appropriate protection can be very critical.
Organisation type
Organization
CEO - Kallistech
Portrait Picture
Bringer
Proposal Title (1st Open Call)
Towards standards convergence for digital identity wallets
Security and privacy of biometrics for remote authentication
Proposal Title (3rd Open Call)
Strengthening security and privacy of biometrics applications through standards
Towards standards convergence for digital identity
Proposal Title (5th Open Call)
Strengthening security and privacy of biometrics applications through standards
Proposal Title (9th Open Call)
Global blockchain and DLT standards on Security, Privacy and Identity
Role in SDO
Standards Development Organisation
Topic
Electronic Identification
StandICT.eu Year
2026
2029
Year
Topic (1st Open Call)
Topic (3rd Open Call)
Topic (5th Open Call)