Standard · ISO/IEC TS 27560:2023 · Edition 1 · revision underway

ISO/IEC TS 27560 Consent Record Information Structure

Maintained by ISO/IEC JTC 1/SC 27

What it helps you do

ISO/IEC 27560 supports an interoperable, open, and extensible information structure for consent records and receipts, including exchange and lifecycle management of consent for processing personally identifiable information.

  • Clinical
  • Cross-cutting
PlanAcquireHarmonizeExchangeLearn + reuse

01

Where it fits and where it does not

Use these four checks before committing implementation time.

Use it when
Systems that must record what a person consented to, provide a receipt, exchange consent information, and manage changes or withdrawal over time.
Limits
A conforming record does not prove that consent was informed, freely given, current, or the correct lawful basis; jurisdictional and ethical requirements remain controlling, and the standard is being revised.
Best for
Clinical and Cross-cutting teams working across Plan → Acquire → Exchange → Learn + reuse.
Maturity
ScalingUsable now, but adoption or tooling is still developing. Pilot the exact stack first.

02

See it in the workflow

This view shows the input, the change the standard introduces, and the resulting output.

  1. InputWhat starts

    Clinical and Cross-cutting source data, metadata, and local mappings

  2. ISO/IEC 27560What changes

    Use ISO/IEC 27560 as a pinned standard across Plan → Acquire → Exchange → Learn + reuse

  3. OutputWhat becomes possible

    A handoff the next system or team can validate against the same release

Readiness gateA conforming record does not prove that consent was informed, freely given, current, or the correct lawful basis; jurisdictional and ethical requirements remain controlling, and the standard is being revised.

03

A concrete example

Create a versioned consent record at capture, issue the related receipt, bind purposes, data categories, parties, processing, and lifecycle status to stable identifiers, and propagate withdrawal or supersession to downstream controls.

Why it matters: Supports automated consent-state and permitted-processing checks, but an agent cannot infer legal validity, contextual integrity, or acceptable secondary use from structure alone.

04

What it fits with

Complements DPV privacy concepts, ODRL policies, DUO data-use conditions, and domain records by supplying the consent-record structure those artifacts do not define.

05

Implementation starter

Start with one bounded handoff. Pin, test, and review it before scaling.

  1. Define one handoff, its accountable owner, and the decision ISO/IEC 27560 must support.

  2. Pin the exact version and companion artifacts: ISO/IEC TS 27560:2023 · Edition 1 · revision underway.

  3. Map one representative input to the required standard artifacts.

  4. Test the result against the canonical source and record every exception.

  5. Preserve the source data, mappings, and review evidence before scaling.

06

Test the main limitation

Risk

A conforming record does not prove that consent was informed, freely given, current, or the correct lawful basis; jurisdictional and ethical requirements remain controlling, and the standard is being revised.

Test

Run one representative end-to-end pilot and record exactly where ISO/IEC 27560 loses context, needs an extension, or depends on another standard.

Risk

Machine-readable output may still be unfit for analysis or ML.

Test

Test the output for missing context, provenance, terminology alignment, time leakage, and the intended downstream decision. Supports automated consent-state and permitted-processing checks, but an agent cannot infer legal validity, contextual integrity, or acceptable secondary use from structure alone.

07

Official resources

Specifications, diagrams, examples, and guides from the organizations that maintain them.

  • Primary sourceISO/IEC TS 27560:2023 · Edition 1 · revision underway

    ISO/IEC TS 27560:2023

    Official publisher or steward guidance for this standard profile.

    Publisher
    ISO/IEC JTC 1/SC 27
    Open official source

Next action

Put this profile in context

Compare its role with adjacent standards or place it inside an end-to-end data pathway before choosing an implementation.