{"id":4326,"date":"2024-04-27T06:20:29","date_gmt":"2024-04-27T12:20:29","guid":{"rendered":"https:\/\/trustarc.com\/?post_type=regulations&#038;p=4326"},"modified":"2025-03-05T10:59:33","modified_gmt":"2025-03-05T16:59:33","slug":"iso-27550","status":"publish","type":"regulations","link":"https:\/\/trustarc.com\/regulations\/iso-27550\/","title":{"rendered":"ISO 27550 International Standard"},"content":{"rendered":"\t\t<section id=\"block_74071a0a99f518b020969e00fb3d2c06\" class=\"hero-section-colors text-center bg-navy-gradient\">\n\t\t\t<div class=\"container\">\n\t\t\t\t\t\t\t\t\t<span class=\"sub-title block font-bold \">Standard<\/span>\n\t\t\t\t\t\t\t\t\t\t<h1>ISO 27550 <\/h1>\n\t\t\t\t\t<p>The International Organization for Standardization (ISO) 27550, focuses on security techniques, establishes engineering guidelines designed to help entities to incorporate privacy engineering elements into various system lifecycle processes. <\/p>\n\t\t\t<\/div>\n\t\t<\/section>\n\t\t\n\n\t\t<section id=\"block_7e7ab393e253d5515387aa7f5f04e503\" class=\"columns-one text-left\" style=\"\">\n\t\t\t<div class=\"container\">\n\t\t\t\t\t\t\t\t\t<div class=\"text-holder\">\n\t\t\t\t\t\t<h2 style=\"text-align: center\">Who should use ISO 27550?<\/h2>\n<p style=\"text-align: center\">This voluntary international standard is directed towards engineers and practitioners involved in the development, implementation or operation of systems that need privacy consideration. Managers responsible for privacy, development, product management, marketing, and operations also find this standard beneficial.<\/p>\n\t\t\t\t\t<\/div>\n\t\t\t\t\t\t\t<\/div>\n\t\t<\/section>\n\t\t\n\n\t<section id=\"block_588c2cd59b1a1d31325c2f9f709ee822\" class=\"columns-two\" style=\"padding-bottom:0;\">\n\t\t<div class=\"container\">\n\t\t\t\t\t\t\t<div class=\"heading text-center max-width\">\n\t\t\t\t\t\t\t\t\t\t\t<h2>Key obligations of ISO 27550<\/h2>\n\t\t\t\t\t\t\t\t\t\t<\/div>\n\t\t\t\t\t\t<div class=\"col-wrap\">\n\t\t\t\t\t\t\t\t\t\t<div class=\"col\">\n\t\t\t\t\t\t\t<h4>Risk management processes<\/h4>\n<p>Conduct a risk management process to identify, assess, and remediate systematic risks throughout the entire lifecycle of a system product and\/or service. Perform supplementary analysis to identify risks associated with processing <a href=\"\/resource\/personally-identifiable-information\/\">PII<\/a> and system vulnerabilities, estimate risks&#8217; possibilities and consequences, and prioritize mitigating them.<\/p>\n\t\t\t\t\t\t<\/div>\n\t\t\t\t\t\t\t\t\t\t\t\t<div class=\"col\">\n\t\t\t\t\t\t\t<h4>Implementation of data management controls<\/h4>\n<p>Establish system infrastructures that enable granular control over PII to implement key privacy principles such as maintaining data quality and integrity, achieving data minimization, and implementing individuals&#8217; privacy preferences. Enable certain privileged stakeholders to administer changes to PII management and processing, ensuring fair treatment of individuals.<\/p>\n\t\t\t\t\t\t<\/div>\n\t\t\t\t\t\t\t\t\t<\/div>\n\t\t\t\t\t<\/div>\n\t<\/section>\n\t\n\n\t<section id=\"block_b36ca031084736ee3fc58582dd80b9e3\" class=\"columns-two\" style=\"padding-top:0;padding-bottom:0;\">\n\t\t<div class=\"container\">\n\t\t\t\t\t\t<div class=\"col-wrap\">\n\t\t\t\t\t\t\t\t\t\t<div class=\"col\">\n\t\t\t\t\t\t\t<h4>Safeguarding individual identities via disassociability<\/h4>\n<p>Disassociability actively conceals an individual&#8217;s identity and\/or activities from unnecessary exposure during processing or transactions involving PII. Achieve disassociability through deploying cryptographic techniques, including anonymity, de-identification, unlinkability, unobservability, and pseudonymity.<\/p>\n\t\t\t\t\t\t<\/div>\n\t\t\t\t\t\t\t\t\t\t\t\t<div class=\"col\">\n\t\t\t\t\t\t\t<h4>Transparency<\/h4>\n<p>Provide individuals with information regarding the entire system lifecycle that covers actual and planned processing activities, including: why PII is needed for processing, the purpose of processing, and whether PII will be disclosed to third-parties.<\/p>\n\t\t\t\t\t\t<\/div>\n\t\t\t\t\t\t\t\t\t<\/div>\n\t\t\t\t\t<\/div>\n\t<\/section>\n\t\n\n\t\t<section id=\"block_22ac11439b444ac48578dfe78a5cd312\" class=\"cta-section has-gradient-navy color-white\">\n\t\t\t<div class=\"bg\">\n\t\t\t\t<img decoding=\"async\" src=\"https:\/\/trustarc.com\/wp-content\/uploads\/2024\/02\/bg-cta-plus-full-blue.png\" class=\"attachment-full size-full\" alt=\"\" srcset=\"https:\/\/trustarc.com\/wp-content\/uploads\/2024\/02\/bg-cta-plus-full-blue.png 1440w, https:\/\/trustarc.com\/wp-content\/uploads\/2024\/02\/bg-cta-plus-full-blue-300x102.png 300w, https:\/\/trustarc.com\/wp-content\/uploads\/2024\/02\/bg-cta-plus-full-blue-1024x347.png 1024w, https:\/\/trustarc.com\/wp-content\/uploads\/2024\/02\/bg-cta-plus-full-blue-768x260.png 768w\" sizes=\"(max-width: 1440px) 100vw, 1440px\" \/>\t\t\t<\/div>\n\t\t\t<div class=\"container\">\n\t\t\t\t<div class=\"text-block\">\n\t\t\t\t\t\t\t\t\t\t\t<span class=\"block h6\">Whitepaper<\/span>\n\t\t\t\t\t\t\t\t\t\t\t\t<h2 class=\"h1\">Privacy and Data Security in Mergers &amp; Acquisitions<\/h2>\n\t\t\t\t\t\t<p>Data can be a valuable asset or an incredible liability to your business. Proactive data privacy practices are strategically critical in this data economy because of the extreme cost of mistakes today. <\/p>\n\t\t\t\t\t\t<ul class=\"btn-list\">\n\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t<li>\n\t\t\t\t\t\t\t\t\t<a href=\"\/resource\/privacy-and-data-security-in-mergers-acquisitions\/\" class=\"btn\"><span>Learn More<\/span><\/a>\t\t\t\t\t\t\t\t<\/li>\n\t\t\t\t\t\t\t\t\t\t\t\t\t\t<\/ul>\n\t\t\t\t\t\t\t\t\t<\/div>\n\t\t\t<\/div>\n\t\t<\/section>\n\t\t\n\n\t\t<section id=\"block_a6d9b70b81048eebf8811b7e232d4340\" class=\"columns-one text-center\" style=\"padding-bottom:0;overflow:hidden;\">\n\t\t\t<div class=\"container\">\n\t\t\t\t\t\t\t\t\t<div class=\"img-holder\">\n\t\t\t\t\t\t<img decoding=\"async\" src=\"https:\/\/trustarc.com\/wp-content\/uploads\/2024\/02\/icon_Update.svg\" class=\"attachment-full size-full\" alt=\"\" \/>\t\t\t\t\t<\/div>\n\t\t\t\t\t\t\t\t\t\t<div class=\"text-holder\">\n\t\t\t\t\t\t<h2 style=\"text-align: center\">Achieve compliance<\/h2>\n\t\t\t\t\t<\/div>\n\t\t\t\t\t\t\t<\/div>\n\t\t<\/section>\n\t\t\n\n\t\t<section id=\"block_18344856aa5124a3c55dba494521158e\" class=\"cards-block\">\n\t\t\t<div class=\"container\">\n\t\t\t\t<div class=\"cards-holder\">\n\t\t\t\t\t\t\t\t\t\t\t\t<a class=\"card-no-img\" href=\"\/products\/privacy-data-governance\/privacycentral\/\">\n\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t<h6>PrivacyCentral<\/h6>\n\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t<h4>Privacy program development and compliance management<\/h4>\n\t\t\t\t\t\t\t\t\t<p>Automatically identify gaps and track compliance with PrivacyCentral for PC DSS v4.0, SOC2, ISO (e.g. 27701, 31700-01, 27550, etc.), NIST, and other privacy and security standards.<\/p>\n\t\t\t\t\t\t\t\t<span class=\"arrow\">\n\t\t\t\t\t\t\t\t\t<img decoding=\"async\" src=\"https:\/\/trustarc.com\/wp-content\/themes\/trustarc\/assets\/dist\/images\/icon-long-arrow.svg\" alt=\"\" \/>\n\t\t\t\t\t\t\t\t<\/span>\n\t\t\t\t\t\t\t<\/a>\n\t\t\t\t\t\t\t\t\t\t\t\t\t\t<a class=\"card-no-img\" href=\"\/products\/privacy-data-governance\/nymity-research\/\">\n\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t<h6>Nymity Research<\/h6>\n\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t<h4>Guidance and operational templates<\/h4>\n\t\t\t\t\t\t\t\t\t<p>Access expert privacy guidance, compliance alerts, and operational templates to ensure you stay ahead of global privacy regulatory changes.<\/p>\n\t\t\t\t\t\t\t\t<span class=\"arrow\">\n\t\t\t\t\t\t\t\t\t<img decoding=\"async\" src=\"https:\/\/trustarc.com\/wp-content\/themes\/trustarc\/assets\/dist\/images\/icon-long-arrow.svg\" alt=\"\" \/>\n\t\t\t\t\t\t\t\t<\/span>\n\t\t\t\t\t\t\t<\/a>\n\t\t\t\t\t\t\t\t\t\t\t\t\t\t<a class=\"card-no-img\" href=\"\/products\/privacy-data-governance\/data-inventory-mapping\/\">\n\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t<h6>Data Inventory Hub &amp; Risk Profile<\/h6>\n\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t<h4>Complete risk management process<\/h4>\n\t\t\t\t\t\t\t\t\t<p>Save time, enhance data visibility, and mitigate risk through automated data flow mapping, risk analysis, and remediation, making compliance effortless.<\/p>\n\t\t\t\t\t\t\t\t<span class=\"arrow\">\n\t\t\t\t\t\t\t\t\t<img decoding=\"async\" src=\"https:\/\/trustarc.com\/wp-content\/themes\/trustarc\/assets\/dist\/images\/icon-long-arrow.svg\" alt=\"\" \/>\n\t\t\t\t\t\t\t\t<\/span>\n\t\t\t\t\t\t\t<\/a>\n\t\t\t\t\t\t\t\t\t\t\t\t\t\t<a class=\"card-no-img\" href=\"\/products\/privacy-data-governance\/assessment-manager\/\">\n\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t<h6>Assessment Manager<\/h6>\n\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t<h4>Mitigate risks<\/h4>\n\t\t\t\t\t\t\t\t\t<p>Automate risk assessments, streamline compliance scoring, and reduce data risks with pre-built templates and customizable workflows to save time efficiently.<\/p>\n\t\t\t\t\t\t\t\t<span class=\"arrow\">\n\t\t\t\t\t\t\t\t\t<img decoding=\"async\" src=\"https:\/\/trustarc.com\/wp-content\/themes\/trustarc\/assets\/dist\/images\/icon-long-arrow.svg\" alt=\"\" \/>\n\t\t\t\t\t\t\t\t<\/span>\n\t\t\t\t\t\t\t<\/a>\n\t\t\t\t\t\t\t\t\t\t\t<\/div>\n\t\t\t<\/div>\n\t\t<\/section>\n\t\t\n\n\t\t<section id=\"block_0b3bfbaf1a543107c10d5cd937414739\" class=\"accordions-section\" style=\"\">\n\t\t\t<div class=\"container\">\n\t\t\t\t<div class=\"max-width\">\n\t\t\t\t\t\t\t\t\t\t  <h2>FAQs<\/h2>\n\t\t\t\t\t\t\t\t\t\t\t<ul class=\"accordion\">\n\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t<li>\n\t\t\t\t\t\t\t\t\t<a href=\"#\" class=\"opener\">What are the data subject rights that I must comply with?<\/a>\n\t\t\t\t\t\t\t\t\t<div class=\"slide\">\n\t\t\t\t\t\t\t\t\t\t<div class=\"slide-wrap\">\n\t\t\t\t\t\t\t\t\t\t\t<p>ISO 27550 does not establish explicit requirements for entities to comply with data subject rights. However, entities are required to develop system functionalities that enable individuals to control their PII and privacy preferences, and intervene in all privacy related data processing activities (e.g. request for data erasure and withdraw consent to processing).<\/p>\n\t\t\t\t\t\t\t\t\t\t<\/div>\n\t\t\t\t\t\t\t\t\t<\/div>\n\t\t\t\t\t\t\t\t<\/li>\n\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t<li>\n\t\t\t\t\t\t\t\t\t<a href=\"#\" class=\"opener\">Is there an obligation to obtain consent from individuals prior to collecting their PII?<\/a>\n\t\t\t\t\t\t\t\t\t<div class=\"slide\">\n\t\t\t\t\t\t\t\t\t\t<div class=\"slide-wrap\">\n\t\t\t\t\t\t\t\t\t\t\t<p>No, ISO 27550 does not provide explicit obligations to seek consent prior to collecting and processing PII. However, as a best practice, entities should comply with relevant data protection and consent obligations in the jurisdiction where processing will take place.<\/p>\n\t\t\t\t\t\t\t\t\t\t<\/div>\n\t\t\t\t\t\t\t\t\t<\/div>\n\t\t\t\t\t\t\t\t<\/li>\n\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t<li>\n\t\t\t\t\t\t\t\t\t<a href=\"#\" class=\"opener\">Do I need to designate an internal data protection officer?<\/a>\n\t\t\t\t\t\t\t\t\t<div class=\"slide\">\n\t\t\t\t\t\t\t\t\t\t<div class=\"slide-wrap\">\n\t\t\t\t\t\t\t\t\t\t\t<p>ISO 27550 does not establish explicit requirements for entities to designate a data protection officer. However, entities are required to create a point of contact with supervisory authorities who can intervene in data processing activities by requesting or enforcing the blocking, erasure or destruction of data or even shutting off the system. <\/p>\n\t\t\t\t\t\t\t\t\t\t<\/div>\n\t\t\t\t\t\t\t\t\t<\/div>\n\t\t\t\t\t\t\t\t<\/li>\n\t\t\t\t\t\t\t\t\t\t\t\t\t<\/ul>\n\t\t\t\t\t\t\t\t\t<\/div>\n\t\t\t<\/div>\n\t\t<\/section>\n\t\t\n\n\t\t<section id=\"block_c298b18275caa6a73c304f3e7992a8f4\" class=\"resource-section bg-light-grey\">\n\t\t\t<div class=\"container\">\n\t\t\t<div class=\"resource-head\">\n\t\t\t\t\t\t\t<h2>Related Resources<\/h2>\n\t\t\t\t\t\t<\/div>\n\t\t\t\t\t\t<ul class=\"resource-lists \">\n\t\t\t\t\t\t\t<li>\n\t\t\t\t\t<a href=\"https:\/\/trustarc.com\/resource\/webinar-privacy-in-healthcare-ensuring-data-security\/\" class=\"resource-single has-icon Webinars\">\n\t\t\t\t\t\t\t\t\t\t\t\t\t<div class=\"img-holder\">\n\t\t\t\t\t\t\t\t<img loading=\"lazy\" decoding=\"async\" width=\"380\" height=\"120\" src=\"https:\/\/trustarc.com\/wp-content\/uploads\/2024\/02\/res-feat-city-pink-380x120.png\" class=\"attachment-380x120 size-380x120 wp-post-image\" alt=\"\" \/>\t\t\t\t\t\t\t<\/div>\n\t\t\t\t\t\t\t\t\t\t\t\t<div class=\"text-holder\">\n\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t<span class=\"resource-label uppercase\">Webinars and Videos<\/span>\n\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t<h4>Privacy in Healthcare: Ensuring Data Security<\/h4>\n\t\t\t\t\t\t<\/div>\n\t\t\t\t\t<\/a>\n\t\t\t\t<\/li>\n\t\t\t\t\t\t\t\t<li>\n\t\t\t\t\t<a href=\"https:\/\/trustarc.com\/resource\/webinar-privacy-security-it-the-venn-diagram-of-compliance\/\" class=\"resource-single has-icon Webinars\">\n\t\t\t\t\t\t\t\t\t\t\t\t\t<div class=\"img-holder\">\n\t\t\t\t\t\t\t\t<img loading=\"lazy\" decoding=\"async\" width=\"380\" height=\"120\" src=\"https:\/\/trustarc.com\/wp-content\/uploads\/2024\/01\/res-feat-city-gray-test-380x120.png\" class=\"attachment-380x120 size-380x120 wp-post-image\" alt=\"\" \/>\t\t\t\t\t\t\t<\/div>\n\t\t\t\t\t\t\t\t\t\t\t\t<div class=\"text-holder\">\n\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t<span class=\"resource-label uppercase\">Webinars and Videos<\/span>\n\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t<h4>Privacy, Security, &#038; IT: The Venn Diagram of Compliance<\/h4>\n\t\t\t\t\t\t<\/div>\n\t\t\t\t\t<\/a>\n\t\t\t\t<\/li>\n\t\t\t\t\t\t\t\t<li>\n\t\t\t\t\t<a href=\"https:\/\/trustarc.com\/resource\/what-gdpr-means-cybersecurity-strategy\/\" class=\"resource-single\">\n\t\t\t\t\t\t\t\t\t\t\t\t\t<div class=\"img-holder\">\n\t\t\t\t\t\t\t\t<img loading=\"lazy\" decoding=\"async\" width=\"380\" height=\"120\" src=\"https:\/\/trustarc.com\/wp-content\/uploads\/2024\/01\/res-feat-plus-blue-test-380x120.png\" class=\"attachment-380x120 size-380x120 wp-post-image\" alt=\"\" \/>\t\t\t\t\t\t\t<\/div>\n\t\t\t\t\t\t\t\t\t\t\t\t<div class=\"text-holder\">\n\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t<span class=\"resource-label uppercase\">Articles<\/span>\n\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t<h4>What the GDPR Means for your Cybersecurity Strategy<\/h4>\n\t\t\t\t\t\t<\/div>\n\t\t\t\t\t<\/a>\n\t\t\t\t<\/li>\n\t\t\t\t\t\t<\/ul>\n\t\t\t\t\t<\/div>\t\t<\/section>\n\t\t\n\n\t\t<section id=\"block_867ca1dc824b4d57430d9adcf931e8ce\" class=\"columns-one text-center bg-light-grey\" style=\"padding-top:0;padding-bottom:0;overflow:hidden;\">\n\t\t\t<div class=\"container\">\n\t\t\t\t\t\t\t\t\t<div class=\"text-holder\">\n\t\t\t\t\t\t<p style=\"font-size: 80%\"><strong>The information provided does not, and is not intended to, constitute legal advice.<\/strong> Instead, all information, content, and materials presented are for general informational purposes only.<\/p>\n\t\t\t\t\t<\/div>\n\t\t\t\t\t\t\t<\/div>\n\t\t<\/section>\n\t\t","protected":false},"excerpt":{"rendered":"<p>ISO standard focused on privacy engineering across system lifecycle processes<\/p>\n","protected":false},"template":"","regulation":[97],"topic-regulation":[84,87],"class_list":["post-4326","regulations","type-regulations","status-publish","hentry","regulation-international","topic-regulation-privacy","topic-regulation-standard"],"acf":[],"yoast_head":"<!-- This site is optimized with the Yoast SEO Premium plugin v27.4 (Yoast SEO v27.4) - https:\/\/yoast.com\/product\/yoast-seo-premium-wordpress\/ -->\n<title>ISO standard focused on privacy engineering | TrustArc<\/title>\n<meta name=\"description\" content=\"The ISO 27550 establishes engineering guidelines designed to help entities to incorporate privacy engineering elements into various system lifecycle processes.\" \/>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/trustarc.com\/regulations\/iso-27550\/\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\\\/\\\/schema.org\",\"@graph\":[{\"@type\":\"WebPage\",\"@id\":\"https:\\\/\\\/trustarc.com\\\/regulations\\\/iso-27550\\\/\",\"url\":\"https:\\\/\\\/trustarc.com\\\/regulations\\\/iso-27550\\\/\",\"name\":\"ISO standard focused on privacy engineering | TrustArc\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/trustarc.com\\\/#website\"},\"datePublished\":\"2024-04-27T12:20:29+00:00\",\"dateModified\":\"2025-03-05T16:59:33+00:00\",\"description\":\"The ISO 27550 establishes engineering guidelines designed to help entities to incorporate privacy engineering elements into various system lifecycle processes.\",\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"https:\\\/\\\/trustarc.com\\\/regulations\\\/iso-27550\\\/\"]}]},{\"@type\":\"WebSite\",\"@id\":\"https:\\\/\\\/trustarc.com\\\/#website\",\"url\":\"https:\\\/\\\/trustarc.com\\\/\",\"name\":\"TrustArc\",\"description\":\"\",\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":{\"@type\":\"EntryPoint\",\"urlTemplate\":\"https:\\\/\\\/trustarc.com\\\/?s={search_term_string}\"},\"query-input\":{\"@type\":\"PropertyValueSpecification\",\"valueRequired\":true,\"valueName\":\"search_term_string\"}}],\"inLanguage\":\"en-US\"}]}<\/script>\n<!-- \/ Yoast SEO Premium plugin. -->","yoast_head_json":{"title":"ISO standard focused on privacy engineering | TrustArc","description":"The ISO 27550 establishes engineering guidelines designed to help entities to incorporate privacy engineering elements into various system lifecycle processes.","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/trustarc.com\/regulations\/iso-27550\/","schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"WebPage","@id":"https:\/\/trustarc.com\/regulations\/iso-27550\/","url":"https:\/\/trustarc.com\/regulations\/iso-27550\/","name":"ISO standard focused on privacy engineering | TrustArc","isPartOf":{"@id":"https:\/\/trustarc.com\/#website"},"datePublished":"2024-04-27T12:20:29+00:00","dateModified":"2025-03-05T16:59:33+00:00","description":"The ISO 27550 establishes engineering guidelines designed to help entities to incorporate privacy engineering elements into various system lifecycle processes.","inLanguage":"en-US","potentialAction":[{"@type":"ReadAction","target":["https:\/\/trustarc.com\/regulations\/iso-27550\/"]}]},{"@type":"WebSite","@id":"https:\/\/trustarc.com\/#website","url":"https:\/\/trustarc.com\/","name":"TrustArc","description":"","potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/trustarc.com\/?s={search_term_string}"},"query-input":{"@type":"PropertyValueSpecification","valueRequired":true,"valueName":"search_term_string"}}],"inLanguage":"en-US"}]}},"_links":{"self":[{"href":"https:\/\/trustarc.com\/wp-json\/wp\/v2\/regulations\/4326","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/trustarc.com\/wp-json\/wp\/v2\/regulations"}],"about":[{"href":"https:\/\/trustarc.com\/wp-json\/wp\/v2\/types\/regulations"}],"wp:attachment":[{"href":"https:\/\/trustarc.com\/wp-json\/wp\/v2\/media?parent=4326"}],"wp:term":[{"taxonomy":"regulation","embeddable":true,"href":"https:\/\/trustarc.com\/wp-json\/wp\/v2\/regulation?post=4326"},{"taxonomy":"topic-regulation","embeddable":true,"href":"https:\/\/trustarc.com\/wp-json\/wp\/v2\/topic-regulation?post=4326"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}