ISO/IEC DIS 10267

Information technology — Data usage — Methods to quantify the amount of personal information in a dataset ISO/IEC DIS 10267

General information

40.60   Close of voting   Sep 3, 2026

ISO/IEC

ISO/IEC JTC 1/SC 27 Information security, cybersecurity and privacy protection

International Standard

35.030   IT Security

Scope

The purpose of this document is to provide guidance on the methods to quantify the amount of personal information and to help estimate how easy it might be to reidentify someone in a dataset subjected to de-identification when it contains information about the characteristics of, actions of, or relationships to, natural persons. This guidance can further help organisations make better decisions for privacy protection and for appropriate use, sharing and exchange of such data.
This document is a high level, principles-based advisory standard which sets out terms and concepts that can be referenced by organizations.
This document does not provide an estimate of how easy it is to identify someone where additional external data is accessible, nor does it provide a way to define whether data is PII or not.

Life cycle

NOW

IN_DEVELOPMENT
ISO/IEC DIS 10267
40.60 Close of voting
Sep 3, 2026




Access Genorma App Everywhere

Get fast and easy access to top European and International standards (EN, ISO, IEC) via your mobile phone, tablet or the web.