OASIS Privacy Management Reference Model (PMRM) TC

 View Only

Quick Start Guide version 1.1

  • 1.  Quick Start Guide version 1.1

    Posted 03-05-2026 11:52
      |   view attached

    All other edits (except for pending ones in the title page) have been made to this Quick Start Guide. The following are Jassim's constructive comments. Please share your thoughts or textual suggestions:

    Were we going to include a side-by-side comparison of PMRM and POMME with an equivalence table of terminology? The relationship between PMRM and POMME is left ambiguous. The two standards are introduced side by side, but the introduction never explains how they relate to each other in practice. If i were an outsider I might ask: Are they interchangeable alternatives? Complementary tools used together? Is one more appropriate for certain contexts than the other? Readers are likely to arrive with this question and leave without an answer.

    Target Audience? States "privacy engineers and relevant stakeholders" but we don't define who that includes? Perhaps expand this list?

    The scope and limitations of the Guide are not clear (to me at least). The introduction doesn't tell readers what the Guide does not cover, or what level of detail they should expect. Making clear that this is a starting point, not a substitute for the full PMRM or POMME documents, would manage expectations and preempt frustration. The NOTE table buried later in the document gestures at this, but I think this point should be explicitly made in the introduction.

    The regulatory context is vague. There are references to "regulatory mandates" and "legal jurisdictions" without any examples. Briefly naming a few of the key regulatory frameworks this approach supports (GDPR, CCPA, HIPAA, or similar) would ground the introduction in the real-world compliance landscape that most readers are navigating, and immediately signal relevance. This is somewhat of a pedantic point I realise, but I think it shows polish.

    The recommendations list, while useful(!), feels a bit stranded. The bulleted list of process recommendations at the end of the introduction reads more like guidance that belongs inside the step-by-step section. I suggest we either integrate these points into a narrative paragraph that closes the introduction, or move them to the beginning of Section 2 where they'd have more immediate practical context. My preference is the former.



    ------------------------------
    Michele Drgon
    DataProbity
    ------------------------------