Identification card systems - European Citizen Card - Part 4: Recommendations for European Citizen Card issuance, operation and use

CEN/TS 15480-4 recommends card issuance and operational procedures including citizens' registration.
CEN/TS 15480-4 gives recommendations with regard to the end-user e.g. with respect to privacy and accessibility aspects.
CEN/TS 15480-4 also identifies a set of standard ECC card profiles (e.g. National ID Card, Health Card, Card issued by a Municipality), that can be used as basis for the specification of new ECC projects.
For each profile, this Technical Specification uses a specified template which
-  selects a subset of technical requirements from CEN/TS 15480-1, FprCEN/TS 15480-2:2011 and CEN/TS 15480-3:2010.
-  considers the operation of the ECC in its particular environment.
The target audience of CEN/TS 15480-4 is the card issuer.

Identifikationskartensysteme - Europäische Bürgerkarte - Teil 4: Empfehlungen für Ausgabe, Arbeitsweise und Benutzung der Europäischen Bürgerkarte

Systèmes de cartes d’identification - Carte Européenne du Citoyen - Partie 4: Recommandations pour l’émission, l’exploitation et l’utilisation de la Carte Européenne du Citoyen

Sistemi z identifikacijskimi karticami - Kartica evropskih državljanov - 4. del: Priporočila za izdajanje, delovanje in uporabo kartic evropskih državljanov

CEN/TS 15480-4 priporoča postopke izdajanja in delovanja kartic, vključno z registracijo državljanov. CEN/TS 15480-4 vsebuje priporočila glede končnega uporabnika, npr. glede vidikov zasebnosti in dostopnosti. CEN/TS 15480-4 določa tudi niz profilov standardnih kartic evropskega državljana (ECC) (npr. nacionalni identifikacijski dokument, zdravstvena kartica, kartica, ki jo izda občina), ki se lahko uporabljajo kot podlaga za specifikacijo novih projektov kartice evropskega državljana. Za posamezni profil je v tehnični specifikaciji uporabljena določena predloga za izbiro podmnožice tehničnih zahtev iz CEN/TS 15480-1, CEN/TS 15480-2:2011 in CEN/TS 15480-3:2010, pri čemer se upošteva delovanje kartice evropskega državljana v specifičnem okolju. Ciljna publika CEN/TS 15480-4 so izdajatelji kartic.

General Information

Publication Date
Withdrawal Date
Current Stage
9060 - Closure of 2 Year Review Enquiry - Review Enquiry
Start Date
Completion Date

Identification card systems - European Citizen Card - Part 4: Recommendations for
European Citizen Card issuance, operation and use
Identifikationskartensysteme - Europäische Bürgerkarte - Teil 4: Empfehlungen für
Ausgabe, Arbeitsweise und Benutzung der Europäischen Bürgerkarte
Systèmes de cartes d’identification - Carte Européenne du Citoyen - Partie 4:
Recommandations pour l’émission, l’exploitation et l’utilisation de la Carte Européenne
du Citoyen
Ta slovenski standard je istoveten z: CEN/TS 15480-4:2012
35.240.15 Identifikacijske kartice in Identification cards and
sorodne naprave related devices
2003-01.Slovenski inštitut za standardizacijo. Razmnoževanje celote ali delov tega standarda ni dovoljeno.

CEN/TS 15480-4
March 2012
ICS 35.240.15
English Version
Identification card systems - European Citizen Card - Part 4:
Recommendations for European Citizen Card issuance,
operation and use
Systèmes de cartes d'identification - Carte Européenne du Identifikationskartensysteme - Europäische Bürgerkarte -
Citoyen - Partie 4: Recommandations pour l'émission, Teil 4: Empfehlungen für Ausgabe, Arbeitsweise und
l'exploitation et l'utilisation de la Carte Européenne du Benutzung der Europäischen Bürgerkarte
This Technical Specification (CEN/TS) was approved by CEN on 23 January 2012 for provisional application.

The period of validity of this CEN/TS is limited initially to three years. After two years the members of CEN will be requested to submit their
comments, particularly on the question whether the CEN/TS can be converted into a European Standard.

CEN members are required to announce the existence of this CEN/TS in the same way as for an EN and to make the CEN/TS available
promptly at national level in an appropriate form. It is permissible to keep conflicting national standards in force (in parallel to the CEN/TS)
until the final decision about the possible conversion of the CEN/TS into an EN is reached.

CEN members are the national standards bodies of Austria, Belgium, Bulgaria, Croatia, Cyprus, Czech Republic, Denmark, Estonia,
Finland, France, Germany, Greece, Hungary, Iceland, Ireland, Italy, Latvia, Lithuania, Luxembourg, Malta, Netherlands, Norway, Poland,
Portugal, Romania, Slovakia, Slovenia, Spain, Sweden, Switzerland, Turkey and United Kingdom.



Management Centre: Avenue Marnix 17, B-1000 Brussels
© 2012 CEN All rights of exploitation in any form and by any means reserved Ref. No. CEN/TS 15480-4:2012: E
worldwide for CEN national Members.

Contents Page
Foreword .5
1 Scope .6
2 Normative references .6
3 Abbreviations .6
4 General recommendations on card issuance and operational procedures .7
4.1 Initial considerations for an ECC project .7
4.2 ECC Management System and ECC lifecycle description .9
4.3 ECC Management System functional organization . 11
4.4 ECC Management System Architecture . 12
4.4.1 General principles. 12
4.4.2 ARIS: Application Registration and Issuance Subsystem . 13
4.4.3 IVAS: Identity Authentication and Verification Subsystem . 14
4.5 ECC Management System Security Policy . 14
4.5.1 Common principles . 14
4.5.2 Establishing Detailed Security Requirements for specific ECC profiles – Data Access . 15
4.5.3 Basic set of requirements for ECC Digital Signature. 16
5 Recommendations with regard to the end user . 17
5.1 Privacy principles for card issuance and operation . 17
5.1.1 General . 17
5.1.2 Protection of the data . 18
5.1.3 Transparency . 18
5.1.4 Consent in data collection . 18
5.1.5 Preference for opt-in . 18
5.1.6 Limitation of purpose . 18
5.1.7 Limitation of period of retention . 18
5.1.8 Adherence to performance criteria . 18
5.1.9 Access rights of the data subject . 18
5.1.10 Secure audit . 18
5.1.11 Data transfer between jurisdictions . 18
5.2 Accessibility . 19
5.3 Usability . 20
5.3.1 Introduction . 20
5.3.2 Usability and the physical environment . 20
5.3.3 Location . 20
5.3.4 Ease of use . 21
5.3.5 Help . 21
5.3.6 Further issues . 21
6 Privacy features of the ECC . 21
7 ECC security evaluation . 22
7.1 General . 22
7.2 Digital signature services . 22
7.3 Other services provided by an ECC. 23
7.3.1 General . 23
7.3.2 Security evaluation recommendations . 23
7.3.3 Security criteria for interoperability . 23
8 Card profiles for the ECC . 25
8.1 General . 25
8.2 User accessibility profile . 26
8.3 Card profile template . 26
8.3.1 General . 26
8.3.2 User accessibility profile . 26
8.3.3 Card durability requirements . 27
8.3.4 Card layout requirements . 27
8.3.5 Applications . 27
8.3.6 Selected card services . 27
8.3.7 Card Info . 27
8.3.8 Cross application services . 27
8.3.9 References . 28
8.4 Identification scheme for ECC profiles . 28
8.4.1 Card profile . 28
8.4.2 User accessibility profile . 28
Annex A (informative) Card profiles . 29
A.1 General . 29
A.2 Card Profile 1: eID Application with mandatory ICAO functionality and conditional digital
signature functionality . 29
A.2.1 OID . 29
A.2.2 General . 29
A.2.3 Applications . 29
A.2.4 Selected card services . 30
A.2.5 Card Info . 30
A.2.6 Cross application services . 31
A.2.7 References . 31
A.3 Card Profile 2: Dual-chip card with respective eID and ICAO Application . 32
A.3.1 OID . 32
A.3.2 General . 32
A.3.3 Applications . 32
A.3.4 Selected card services for ICAO application . 32
A.3.5 References .

