Nov 16, 2021 in Interoperability by DIACC

Request for Comment and IPR Review: PCTF Verified Person and Privacy Candidates for Final Recommendations V1.1

Notice of Intent: DIACC is collaborating to develop and publish the Verified Person and Privacy components of the Pan-Canadian Trust Framework (PCTF) to set a baseline of public and private sector interoperability of identity services and solutions. During this public review period, DIACC is looking for community feedback to ensure that the conformance criteria in each component is clear and auditable.

Document Status: These review documents have been developed by members of the DIACC’s Trust Framework Expert Committee (TFEC) Verified Person and Privacy Design Teams who operate under the DIACC controlling policies and consist of representatives from both the private and public sectors. These documents have been approved by the TFEC as candidates for Final Recommendation V1.1.

Summary:

The intent of the PCTF Verified Person component is to define a set of processes used to establish that a natural person is real, unique, and identifiable. This is a key ingredient in ensuring a digital representation of a person is properly created, used exclusively by that same person, and can be relied on to receive valued services and to carry out transactions with trust and confidence.

The PCTF Privacy component is concerned with the handling of personal data for digital identity purposes. The objective of this component is to ensure the ongoing integrity of the privacy processes, policies, and controls of organizations in a Digital Identity Ecosystem by means of standardized conformance criteria used for assessment and certification against the PCTF.

To learn more about the Pan-Canadian vision and benefits-for-all value proposition please review the Pan-Canadian Trust Framework Overview.

Invitation:

  • All interested parties are invited to comment.

Period:

  • Opens: November 16, 2021 at 23:59 PST | Closes: December 17, 2021 at 23:59 PST

When reviewing these components Conformance Criteria, please consider the following and note that responses to this question are non-binding and serve to improve the PCTF.

  1. Would you consider the Conformance Criteria as auditable or not? That is, could you objectively evaluate if an organization was compliant with that criteria and what evidence would be used to justify that?

Review Documents: PCTF Verified Person

Supporting Documents: PCTF Verified Person

Review Documents: PCTF Privacy

Supporting Documents: PCTF Privacy

Intellectual Property Rights:

Comments must be received within the 30-day comment period noted above. All comments are subject to the DIACC contributor agreement; by submitting a comment you agree to be bound by the terms and conditions therein. DIACC Members are also subject to the Intellectual Property Rights Policy. Any notice of an intent not to license under either the Contributor Agreement and/or the Intellectual Property Rights Policy with respect to the review documents or any comments must be made at the Contributor’s and/or Member’s earliest opportunity, and in any event, within the 30-day comment period. IPR claims may be sent to review@diacc.ca. Please include “IPR Claim” as the subject.

Process:

  • All comments are subject to the DIACC contributor agreement.
  • Submit comments using the provided DIACC Comment Submission Spreadsheet.
  • Reference the draft and corresponding line number for each comment submitted.
  • Email completed DIACC Comment Submission Spreadsheet to review@diacc.ca.
  • Questions may be sent to review@diacc.ca.

Value to Canadians:

The PCTF Verified Person and Privacy Components will provide value to all Canadians, businesses, and governments by setting a baseline of business, legal, and technical interoperability. The DIACC’s mandate is to collaboratively develop and deliver resources to help Canadian’s to digitally transact with security, privacy, and convenience. The PCTF is one such resource and guides digital identity ecosystem interoperability by putting policy, standards, and technology into practice aligning with defined levels of assurance. The DIACC is a not-for-profit coalition of members from the public and private sector who are making a significant and sustained investment in accelerating Canada’s Identity Ecosystem.

Context:

The purpose of this review is to ensure transparency in the development and diversity of a truly Pan-Canadian, and international, input. In alignment with our Principles for an Identity Ecosystem, processes to respect and enhance privacy are being prioritized through every step of the PCTF development process.

DIACC expects to modify and improve these candidates for Final Recommendation based upon public comments. Comments made during the review will be considered for incorporation into the next iteration and DIACC will prepare a Disposition of Comments to provide transparency with regard to how each comment was handled.