Christoph Runde
The fellowship tackles the lack of international, or European, standard or technical specification that focuses explicitly on privacy and data protection capabilities of DLT systems. With this regards, ISO TS 24946 “Requirements and guidance for improving, preserving, and
assessing the privacy capability of DLT systems” has now reached CD stage (July 2025) and will endeavour to move through this process and be completed in 2026. This process requires continued support from experts to ensure delivery, as scheduled. In this sense, the priority of this activity focuses at the European level, CEN/CENELEC JTC 19/WG3 to produce a European standard on PII protection within DLT which is strongly influenced by ‘DIN Spec 4997 - Privacy by Blockchain Design’ and the aforementioned ISO TS 24946. This European specification will seek to harmonise the GDPR and recent EDPB guidance to produce a technical specification intended for the European DLT ecosystem.
This European specification will provide much needed clarity for the DLT ecosystem as regards data protection and privacy capabilities, affordances, and assessment. Further harmonisation between the international specification at ISO and the European standard will support interoperability, and ensure that privacy and data protection capabilities are harmonised globally. The main challenges concerns exacting requirements from regulations such as Article 76(3) of MiCAR, as well as Article 79(1) of the European AMLR will require navigation. Standards
require alignment and compatibility with those legal texts, as well as corresponding regulations regarding personal data, data markets, and trust services (e.g., GDPR, Data Act, eIDAS2). Ensuring there are no gaps between regulatory texts and the proposed European standards will be a primary focus. Also, it must be ensured that there are no substantial gaps between international specifications and European standards will be the second focus. Standards alignment between ISO and CEN/CENELEC is viewed as a key outcome to benefit the global DLT ecosystem, and one that requires strong consensus building, given slightly different international privacy perspectives and preferences.
This was a one-shot contribution to provide travel support for participation to the Internet Engineering Task Force (IETF), and specifically participation at the July 2025 plenary meeting in Madrid. I attended this meeting as an Internet Transport expert contributing work and progressing standards to support the evolution of the Internet and its support for enhanced resilience, authentication and privacy. An in-person attendance at the technical sessions also allowed me to progress the work for which I am an editor: Qlog draft-ietf-tsvwg-careful-resume-qlog, a transport specification based on the “qlog” specification being developed by the IETF QUIC; and a recent work item in the IETF Congestion Control working group, “Increase of the Congestion Window when the Sender Is Rate-Limited” (draft-ietf-ccwg-ratelimited-increase). In-person participation at this meeting is particularly important in my current role as an Area Director of the WIT Area, where I will help organise and oversee the meeting as a whole and specifically support the WIT area WG chairs in organising WG sessions and supporting cross area review of emerging specifications.
Regarding CEN/TC264/WG41, we are making hasty progress to a draft document early 2026 with the aim to issue a standard.
It aims to develop technical specifications and standards to efficiently manage terminology work ensuring seamless information exchange, minimizing misunderstandings, and enhancing both human-human and human-AI interactions.
In this fellowship, the main priority focuses on helping organisations to drive innovation and technological transformation using the Centre of Excellence (CoE) as the best management mechanism in a context of a shortage of professional profiles with expertise in Artificial Intelligence and other disruptive technologies.
The use of digital identity wallets is foreseen to be the best appropriate solution to support an age verification method, which uses the date of birth of the individual without disclosing it.
A strong priority for this work is to contribute to standards to enable consideration of the support for data management in the cloud. Data spaces can only be fully realised with the application of strong quality management controls through standardisation at multiple levels.
My contribution has a direct impact in 3GPP Release 19 specifications in the TR 23.946 CAPIF Guidelines.
The priority of my activity is the coordination of the 3GPP activities to update the ITU-R Recommendations on IMT-Advanced and IMT-2020.