W3C

DPVCG Meeting Call

13 APR 2023

Attendees

Present
beatriz, delaram, harsh, karenVasquez, paul
Regrets
georg
Chair
harsh
Scribe
harsh

Meeting minutes

Repository: w3c/dpv

ghurlbot, harsh is coolharsh55

ISO/IEC 27560 Consent Record

The ISO/IEC work on 27560 consent records has progressed in stage to final approval with another round of (minor editorial) comments.

One of the appendices has an example of the consent record that uses the DPV for concepts. This is a good news as it represents usefulness of DPV and the work conducted within DPVCG.

A minor change to be suggested for DPV is to change the reference for DPV which currently refers to the draft report, and instead to have it refer to the final published report.

Further work on this will include analysing the 27560 for ensuring all relevant concepts are presentin DPV, resolving any deficiencies found, and then producing a guidance document for implementing 27560 using DPV. More on this will be circulated by harsh in the coming weeks.

DPVCG Minutes

The previous minutes have been moved over to GitHub, with the index at new URL https://w3id.org/dpv/meetings which includes the minutes as well. This is to enable better searching and use of minutes, such as to find when a concept was last discussed, or identify resolutions or discussions of relevance.

Data Breach concepts

We continue the discussion on concepts regarding data breaches. The earlier email https://lists.w3.org/Archives/Public/public-dpvcg/2023Mar/0005.html by harsh provided the set of initial concepts, and another email by georg https://lists.w3.org/Archives/Public/public-dpvcg/2023Apr/0000.html shared analysis of concepts based on EDPB guidelines for data breaches.

(via shared screen) based on this harsh is proposing identifying the relevant concepts and relations to create a minimal vocabulary consisting of concepts DataBreach, DBIA (Data Breach Impact Assessment) - which includes an investigation of breach and effects; and DataBreachCommunication - which includes notifications.

Next steps include adding concepts from EDPB guidelines for Data Breach (analysis provided by Georg) and expanding the minimal vocabulary; then applying it to DPC's breach reporting form to identify missing bits; and refine and expand as needed. Examples and detailed notes may be shared via the mailing list.

Next Meeting

We will meet again in one week on 20th April THU at 14:00 WEST / 15:00 CEST at the usual time slot. Agenda items carried over include Data Breach concepts.

Further topics of interest from members based on their current work.

paul: working on privacy notices

beatriz: a vocabulary for DGA, submitted to CPDP but wasn't accepted.

harsh: please share the vocabulary this week preferably as we have started discussions on DGA and it will be of essence to the work planend for May

karen: wants to expand rights concepts related to ethical considerations and how to propose additional taxonomies for this to DPVCG

delaram: AI risks and impacts - how to connect them to DPV.

Minutes manually created (not a transcript), formatted by scribe.perl version 217 (Fri Apr 7 17:23:01 2023 UTC).