W3C

DPV Meeting 2023-03-30

30 MAR 2023

Attendees

Present
Delaram, georg, harsh, jan, paul
Regrets
-
Chair
-
Scribe
harsh

Meeting minutes

ISO 27560

The standard has progressed to the next stage. We will take up its implementation as soon as a document is circulated by the national standards bodies.

Data Breach as an extension of Security Incident

harsh: https://lists.w3.org/Archives/Public/public-dpvcg/2023Mar/0005.html

georg: In a Security notification you have to be able to say what kind of breach, technologies involved, and the supplier and users of technologies, and what kind of security the technology had. In NIS2, there is a requirement for a due diligence report on the supply chain for technologies, which must be maintained. This means information about technologies is front and centre.

paul: https://www.dataprotection.ie/en/organisations/know-your-obligations/data-security-guidance

harsh: In the context of DPV, this means we need to consider Technology as a central concept. Currently we have a focus on specifying TOMs as associated with processing.

harsh: Data Breach, Security Incident, Incident. And Communication separately that has metadata. And then when we communicate about data breach, it has the additional fields regarding personal data affected, scale of data subjects, etc.

paul: Is the term “Data Breach” only limited to personal data? - in our scope yes it is, though 'data' can be non-personal data too.
… We do agree (4 yes, 2 abstain) 1) Parent taxonomy for Data Breach as Security Incidents 2) In DPV-Tech, consider technology specific measures 3) In Data Breach, associate breaches with technologies as well as personal data processing

AOB

jan: Items added to agenda regarding requesting CEN to provide privacy guidelines for eIDAS

Minutes manually created (not a transcript), formatted by scribe.perl version 217 (Fri Apr 7 17:23:01 2023 UTC).