Standards & Compliance

Industry standards, data privacy regulations, and compliance frameworks.

Components

IATA Standards

Aviation industry standards:

  • NDC (New Distribution Capability)
  • ONE Order
  • SSIM (Standard Schedules)
  • BCBP (Bar Coded Boarding Pass)
  • BSP/ARC settlement
  • Baggage messaging

Data Privacy

Privacy regulations:

  • GDPR (EU)
  • CCPA (California)
  • PII handling
  • Data retention
  • Subject access requests

Compliance

Security and regulatory compliance:

  • PCI-DSS
  • SOC 2
  • Aviation security
  • Accessibility (ADA, WCAG)

Standards Overview

IATA Technical Standards

StandardPurposeVersion
NDCDistribution21.3
ONE OrderOrder managementResolution 797
SSIMSchedule exchangeChapter 7
BCBPBoarding passesResolution 792 v8
PADISReservation messagingEDIFACT
BagMessageBaggage trackingRP 1745

Regulatory Frameworks

RegulationJurisdictionFocus
GDPREUData privacy
CCPACaliforniaConsumer privacy
PCI-DSSGlobalPayment security
DOTUSConsumer protection
EU261EUPassenger rights
SOC 2GlobalSecurity controls

Compliance Matrix

┌────────────────────────────────────────────────────────┐
│                  Compliance Requirements               │
├────────────────┬─────────┬─────────┬─────────┬────────┤
│ System         │ PCI-DSS │  GDPR   │  SOC 2  │  DOT   │
├────────────────┼─────────┼─────────┼─────────┼────────┤
│ Booking Engine │    ●    │    ●    │    ●    │   ●    │
│ Payment System │    ●    │    ●    │    ●    │        │
│ Customer Data  │         │    ●    │    ●    │        │
│ Operations     │         │    ●    │    ●    │   ●    │
│ Analytics      │         │    ●    │    ●    │        │
└────────────────┴─────────┴─────────┴─────────┴────────┘
● = Applicable

Implementation Approach

  1. Identify: Map applicable standards per system
  2. Gap Analysis: Assess current state vs. requirements
  3. Remediate: Address gaps with technical controls
  4. Document: Maintain evidence and policies
  5. Audit: Regular assessment and certification
  6. Monitor: Continuous compliance monitoring