FAPI1: [ISO/IEC 25791-2 Review Comments] Add PII and definition to clause 4

Issue #803 resolved
Hodari McClain created an issue
  • Type: Editorial
  • Subclause(s): 5.2.2.1
  • Comments: The abbreviation “PII” seems to be first used here in this document “6. should not return sensitive PII in the ID Token in the authorization response, but if it needs to, then it should encrypt the ID Token”
  • Proposed Change: Either rephrase “PII” to “Personally Identifiable Information (PII)” or “Personally Identifiable Information”.
  • WG Accept / Reject: Partially accepted.  Add PII to clause 4.

Comments (4)

  1. Nat Sakimura

    It is already fixed errata 1 drafts by adding PII to the abbreviated terms. PII itself is defined in ISO/IEC 29100, which is included in clause 3 by reference.

  2. Log in to comment