ISO/IEC 24789-1:2012
What is ISO/IEC 24789 standard
ISO/IEC 24789-1:2011 comprises a methodology for determining application profiles, their requirements and corresponding examples. It contains no additional or changed requirements for the ID card properties defined in other applicable standards. It seeks to define the relative rigour of each application defined herein in terms of a set of simple but justifiable methods of evaluation.
The purpose of ISO/IEC 24789 is to provide guidance on methods and their use to simulate a card’s service life. In order to achieve this purpose, two parameters of card service life are defined: age and usage. This can be represented as a two‑dimensional matrix in which each age/usage combination corresponds to a card service life class. The two parts of ISO/IEC 24789 together describe the evaluation methods to be used and their criteria.
ISO/IEC 24789 was originally developed for ID-1 cards conforming to ISO/IEC 7810, but might be found useful in whole or in part for other types and form factors.
References are given to the corresponding methods of evaluation in ISO/IEC 24789-2 and elsewhere.
The purpose of ISO/IEC 24789 is to provide guidance on methods and their use to simulate a card’s service life. In order to achieve this purpose, two parameters of card service life are defined: age and usage. This can be represented as a two-dimensional matrix in which each age/usage combination corresponds to a card service life class. The two parts of ISO/IEC 24789 together describe the evaluation methods to be used and their criteria.
ISO/IEC 24789 was originally developed for ID-1 cards conforming to ISO/IEC 7810, but might be found useful in whole or in part for other types and form factors.
References are given to the corresponding methods of evaluation in ISO/IEC 24789-2 and elsewhere.

Principles of ISO/IEC 24789-1:2012
ISO/IEC 24789-1:2012 provides a framework for the retention and disposal of personally identifiable information (PII) in identity management systems. It is essential for maintaining data privacy, security, and compliance in electronic identity systems.
- Data Retention Control
Defines policies for how long identity-related data should be kept. - Secure Data Disposal
Ensures proper and safe deletion of personal data when no longer required

3. Privacy by Design
Supports privacy laws by minimizing data retention and reducing risk exposure.
4. Accountability and Transparency
Promotes clear responsibilities and documentation in managing identity data.
5. Data Security
Requires protection of PII during storage, retention, and disposal processes.

Benefits of ISO/IEC 24789-1:2012
- Improved Privacy Compliance
- Lower Risk of Data Breaches
- Cost Efficiency
- Increased Trust
- Supports Identity Lifecycle Management