错误:搜索内容不能为空,请输入英文关键词
错误:关键词超出字数限制,请精简
高级检索

Data Minimization Under Certain Standards

  • Kathrin Gardhouse

摘要

While privacy laws frequently require data minimization, they often fall short of providing actionable technical detail—especially in contexts where full anonymization is impractical or undesirable. To address this, several standards-setting organizations have developed frameworks that operationalize de-identification and other minimization practices. These standards fill crucial gaps by translating broad legal principles into concrete methodologies. In this chapter, we examine key standards that have emerged as influential in this space, including ISO/IEC 27559:2022, NISTIR 8053, NIST SP800-188, and the PCI DSS. These standards provide structured approaches to assessing re-identification risks, applying de-identification techniques, and embedding privacy governance into organizational practices.