Information compliance is the discipline of making sure that the way an organisation creates, keeps, shares and disposes of information satisfies the laws, regulations, contracts and professional standards that apply to it. For archives, libraries, museums and DAM services the landscape is unusually crowded: privacy law sits alongside freedom-of-information duties, copyright, cultural-heritage protection and sector recordkeeping standards, and they frequently pull in opposite directions.

Rather than memorising individual statutes, a practitioner needs a mental map of the families of obligation and how they interact, because the same record can be governed by several at once.

The main families of obligation

  • Data protection & privacy - the EU GDPR is the de facto international reference point, echoed by the UK GDPR, Brazil's LGPD, California's CCPA/CPRA and many others built on the same principles.
  • Access to information - freedom-of-information and open-data regimes that create a right to see records, in tension with privacy.
  • Recordkeeping standards - ISO 15489 (records management), ISO 16175 (digital records), and the OAIS reference model (ISO 14721) for long-term preservation.
  • Security & governance - ISO/IEC 27001 for information security, which shares the Annex SL high-level structure with other management-system standards so they can be integrated.

Why standards and law reinforce each other

Law tends to state what must be achieved; standards describe how. A retention schedule built on ISO 15489, preserved through an OAIS-conformant repository and secured under ISO 27001, is strong evidence that statutory duties are being met. Certification is never a legal defence in itself, but demonstrable conformance underpins the accountability principle that modern privacy law demands.

In practice. Build one register that maps each information asset to every regime touching it - privacy, access, copyright, recordkeeping - rather than running siloed compliance projects. When a subject-access request and an FOI request hit the same file, you will already know which rules win.

Key takeaways

  • Compliance spans several overlapping families - privacy, access, recordkeeping and security - that must be managed together.
  • Law sets the outcome; ISO 15489, 16175, 14721 (OAIS) and 27001 give you the method to prove it.
  • GDPR is the international benchmark most other privacy laws mirror, so principles travel well across markets.

Check your understanding

Last modified: Saturday, 1 August 2026, 10:37 AM