فا
← BACK TO THE WIRE
N°0195ZK Tech2 MIN2 SOURCES

ISO’s First ZK Privacy Guidance Is a Blueprint, Not a Compliance Badge

ISO/IEC 27565:2026 makes privacy-preserving zero-knowledge proofs legible to organisations—but its value lies in disciplined design, not automatic compliance.

SHARE
ZK Tech
ISO’s First ZK Privacy Guidance Is a Blueprint, Not a Compliance Badge
IMAGE: AI-GENERATED

Zero-knowledge proofs are often introduced as a cryptographic superpower: prove a fact without exposing the underlying data. ISO/IEC 27565:2026 gives that idea a more operational framing. Published in February, the 37-page international standard provides guidance for using ZK proofs to reduce unnecessary disclosure of personal data between organisations and users.

That is a meaningful shift for ZK builders. The conversation no longer has to begin and end with which proving system is fastest. It can begin with a plainer product question: what is the minimum fact a relying party actually needs? A service verifying eligibility may need an age threshold, an employment attribute, or membership in a group—not a reusable copy of a full credential.

The standard’s stated scope is guidance on functional requirements and secure ways that ZK models can meet them. In practice, that gives teams a vocabulary for separating a claim from the raw data used to support it, then designing the proof, verification flow, retention policy, and failure handling around that smaller disclosure surface.

Research such as Microsoft’s May 2026 Vega paper shows why this framing matters. Vega targets statements about existing credentials without revealing other credential contents. Its authors report, for a 1,920-byte credential, 92 ms proving, 23 ms verification, a 108 kB proof, and a 464 kB proving key. The design uses lookup-centric arithmetization to extract relevant values rather than fully parse a credential inside the circuit.

The practical lesson is not that every identity product should adopt Vega, or that one benchmark settles an architecture choice. It is that privacy-preserving credential systems are increasingly being evaluated as systems engineering: which assertions are proved, where inputs live, who verifies, what metadata remains visible, and how the system behaves when a proof or issuer cannot be trusted.

There is an important limit to keep clear: ISO/IEC 27565:2026 is guidance, not a certification, protocol-interoperability standard, or a legal-compliance determination. Implementing it does not by itself make a product compliant with a privacy law, nor does it remove the need for threat modelling, cryptographic review, and jurisdiction-specific legal assessment.

A second limit applies to performance claims. Vega’s figures are research-reported results for particular credential sizes and conditions, not a guarantee for every identity deployment. Integration costs, credential formats, devices, revocation, issuer trust, and metadata leakage can materially change the outcome.

Still, the direction is clear. ZK adoption becomes more credible when teams treat selective disclosure as a product requirement with explicit boundaries—not as a cryptographic feature bolted on after collecting too much data.

TAGSZero-Knowledge ProofsPrivacyDigital IdentityISO StandardsVerifiable Credentials
Grounded sources2 REFS
  1. [01]ISO/IEC 27565:2026 — Guidelines on privacy preservation based on zero-knowledge proofsiso.org
  2. [02]Vega: Low-Latency Zero-Knowledge Proofs over Existing Credentialsmicrosoft.com
Read next

Get the wire in your inbox

Every new signal, straight from the generator. No noise, unsubscribe anytime.

RSS AVAILABLE · NO SPAM