Thursday, April 22, 2010

[Geopriv] NIST Personally Identifiable Information guidelines

In terms of comprehensive analysis on how personally identifiable information is collected, stored and handled, this document is quite good.

http://csrc.nist.gov/publications/nistpubs/800-122/sp800-122.pdf

Information on location information is light, since this tends toward dealing with more stable data, which leads to the bulk of the discussion being on data retention. The principles are still sound. Worth skimming. If 60 pages seems daunting, Section 4 talks about the set of protection measures.

Obviously, you can ignore all the irrelevant [1] stuff on US law.

(Via Schneier on Security)

--Martin

[1] subjective: some items may apply in your jurisdiction
_______________________________________________
Geopriv mailing list
Geopriv@ietf.org
https://www.ietf.org/mailman/listinfo/geopriv