W3C

DPV Meeting 23 Feb

23 FEB 2023

Attendees

Present
delaram, harsh, julian, paul
Regrets
georg
Chair
-
Scribe
harsh

Meeting minutes

Data Breach

Sharing data breach analysis from Georg. There are two types of events that are required to provided in terms of information, these are Impacts i.e. the impact of the data breach, and Cause i.e. the cause of the data breach.

The issue is that some Causes are also Impacts i.e. an impact caused from somewhere else or from the breach itself also becomes the cause

Extension Event, and consolidate Consequences, Impacts, and Data Breach related Events into it

RiskSource subclass DataBreachSource

For alignment, we provide guidance document that shows how to use concepts and changes in terminology

DataBreachRecord concept - needed

DataBreachImpactAssessment (DBIA) - needed

3 events - Notification to SA, Controller breach awareness, Data Breach

Notification may have justification about delay in reporting

Notification ⟶ SA, Data Subject; Process→Controller, Controller→JointController, Controller→Processor, Controller → Third Party, Processor→Processor

Generic notification - sender and recipient

Scope of data breach - PersonalDataHandling or open ended? ⟶ should be open ended because information may be specific to something not PDH or information may not be available

Types of breaches - Confidentiality, Integrity, Availability

Do we provide them through DPV? ⟶ If it is commonly used everywhere then we provide them in DPV, otherwise not. Support from Paul and Delaram.

Separately, do we categorise our consequences with these labels ⟶ yes from Julian.

We try to see how other Data breach guidelines model consequences.

Personal data affected by this breach ⟶ this is about approximate number of personal data records affected by breach.

Similarly, approx. number of data subjects concerned by the data breach.

Can we reuse DataScale and DataSubjectScale? e.g. Scale with a number? ⟶ possible.

What are the likely impacts of data breach? ⟶ Does the use of "likely impacts" affect whether we can

We can reuse existing properties for impacts, data subjects, risk likelihood, etc.

<harsh> Next Meeting: 13:00 instead of 14:00 based on whether Georg is available or not.

Minutes manually created (not a transcript), formatted by scribe.perl version 217 (Fri Apr 7 17:23:01 2023 UTC).