01
Where it fits and where it does not
Use these four checks before committing implementation time.
- Use it when
- Systems that must record what a person consented to, provide a receipt, exchange consent information, and manage changes or withdrawal over time.
- Limits
- A conforming record does not prove that consent was informed, freely given, current, or the correct lawful basis; jurisdictional and ethical requirements remain controlling, and the standard is being revised.
- Best for
- Clinical and Cross-cutting teams working across Plan → Acquire → Exchange → Learn + reuse.
- Maturity
- ScalingUsable now, but adoption or tooling is still developing. Pilot the exact stack first.
02
See it in the workflow
This view shows the input, the change the standard introduces, and the resulting output.
- InputWhat starts
Clinical and Cross-cutting source data, metadata, and local mappings
- ISO/IEC 27560What changes
Use ISO/IEC 27560 as a pinned standard across Plan → Acquire → Exchange → Learn + reuse
- OutputWhat becomes possible
A handoff the next system or team can validate against the same release
03
A concrete example
Create a versioned consent record at capture, issue the related receipt, bind purposes, data categories, parties, processing, and lifecycle status to stable identifiers, and propagate withdrawal or supersession to downstream controls.
Why it matters: Supports automated consent-state and permitted-processing checks, but an agent cannot infer legal validity, contextual integrity, or acceptable secondary use from structure alone.
04
What it fits with
Complements DPV privacy concepts, ODRL policies, DUO data-use conditions, and domain records by supplying the consent-record structure those artifacts do not define.
- Metadata vocabularyDPV
Both support Clinical and Cross-cutting work and meet around Plan, Acquire, Exchange, Learn + reuse. Compare their roles before treating them as interchangeable.
Explore relationship - FrameworkFAIR
Both support Cross-cutting work and meet around Plan, Acquire, Exchange, Learn + reuse. Compare their roles before treating them as interchangeable.
Explore relationship - FrameworkFAIR DMM
Both support Cross-cutting work and meet around Plan, Acquire, Exchange, Learn + reuse. Compare their roles before treating them as interchangeable.
Explore relationship - StandardISO/IEC 5259
Both support Cross-cutting work and meet around Plan, Acquire, Exchange, Learn + reuse. Compare their roles before treating them as interchangeable.
Explore relationship
05
Implementation starter
Start with one bounded handoff. Pin, test, and review it before scaling.
Define one handoff, its accountable owner, and the decision ISO/IEC 27560 must support.
Pin the exact version and companion artifacts: ISO/IEC TS 27560:2023 · Edition 1 · revision underway.
Map one representative input to the required standard artifacts.
Test the result against the canonical source and record every exception.
Preserve the source data, mappings, and review evidence before scaling.
06
Test the main limitation
A conforming record does not prove that consent was informed, freely given, current, or the correct lawful basis; jurisdictional and ethical requirements remain controlling, and the standard is being revised.
Run one representative end-to-end pilot and record exactly where ISO/IEC 27560 loses context, needs an extension, or depends on another standard.
Machine-readable output may still be unfit for analysis or ML.
Test the output for missing context, provenance, terminology alignment, time leakage, and the intended downstream decision. Supports automated consent-state and permitted-processing checks, but an agent cannot infer legal validity, contextual integrity, or acceptable secondary use from structure alone.
07
Official resources
Specifications, diagrams, examples, and guides from the organizations that maintain them.
ISO/IEC TS 27560:2023
Official publisher or steward guidance for this standard profile.
- Publisher
- ISO/IEC JTC 1/SC 27