The compliance landscape
- View
Information compliance is the discipline of making sure that the way an organisation creates, keeps, shares and disposes of information satisfies the laws, regulations, contracts and professional standards that apply to it. For archives, libraries, museums and DAM services the landscape is unusually crowded: privacy law sits alongside freedom-of-information duties, copyright, cultural-heritage protection and sector recordkeeping standards, and they frequently pull in opposite directions.
Rather than memorising individual statutes, a practitioner needs a mental map of the families of obligation and how they interact, because the same record can be governed by several at once.
The main families of obligation
- Data protection & privacy - the EU GDPR is the de facto international reference point, echoed by the UK GDPR, Brazil's LGPD, California's CCPA/CPRA and many others built on the same principles.
- Access to information - freedom-of-information and open-data regimes that create a right to see records, in tension with privacy.
- Recordkeeping standards - ISO 15489 (records management), ISO 16175 (digital records), and the OAIS reference model (ISO 14721) for long-term preservation.
- Security & governance - ISO/IEC 27001 for information security, which shares the Annex SL high-level structure with other management-system standards so they can be integrated.
Why standards and law reinforce each other
Law tends to state what must be achieved; standards describe how. A retention schedule built on ISO 15489, preserved through an OAIS-conformant repository and secured under ISO 27001, is strong evidence that statutory duties are being met. Certification is never a legal defence in itself, but demonstrable conformance underpins the accountability principle that modern privacy law demands.
Key takeaways
- Compliance spans several overlapping families - privacy, access, recordkeeping and security - that must be managed together.
- Law sets the outcome; ISO 15489, 16175, 14721 (OAIS) and 27001 give you the method to prove it.
- GDPR is the international benchmark most other privacy laws mirror, so principles travel well across markets.