W3C

DPVCG Meeting Call

20 APR 2023

Attendees

Present
beatriz, georg, harsh, julian, MarkLizar, paul
Regrets
-
Chair
harsh
Scribe
harsh

Meeting minutes

Repository: w3c/dpv

ghurlbot, harsh is coolharsh55

<ghurlbot> harsh, I already had that GitHub account for harsh

Associating GDPR Rights with Legal Bases

Issue #49 lists legal bases and what rights are applicable for each based on guidance provided by DPAs (IE, UK) and EDPB

<ghurlbot> Issue 49 Provide association and applicability between GDPR legal bases and rights (coolharsh55) documentation, concepts, todo, help-wanted

To associate the legal basis and the right, the property dpv:hasRigh would be used

Discussion in the meeting for whether 1) this is useful to provide 2) is the information in line with DPVCG's objectives and scope 3) what form to provide it in i.e. should we use dpv:hasRight? 4) Do we also model the 'not applicable' relations?

<Github> w3c/dpv#49 : Provide association and applicability between GDPR legal bases and rights

Participants agree that this is useful and should be provided using dpv:hasRight within DPV-GDPR.

julian: Why is Article 19 not mentioned in the list?
… Article 19 is regarding the communication or notification of A.16, A.17, A.18 by the controller to other recipients and the confirmation of recipient for which this has taken place upon request by the data subject.
… This has not been modelled because the appropriate relevant guidance for this could not be found in the cited sources.
… If DPVCG is modelling these, then A.19 would be modelled with a Y or applicable for all cases where all of A.16-A.18 are also applicable, and a N or not applicable for any case where A.16-A.18 is not applicable.
… The group agrees only to model the Y relations in DPV and to represent N relations through lack of facts or concept i.e. imply closed world interpretation.
… This is in line with how rights are associated only in cases where they are applicable, and where they are not - nothing is specified and there is no 'not applicable' relation.

paul: What is the title of A.19 in DPV? It should reference notification in the title.

ISSUE: Add 'Notification' to A.19 title in DPV-GDPR

<ghurlbot> Created issue #92 Add 'Notification' to A.19 title in DPV-GDPR

Modelling Data Governance Act

<Github> w3c/dpv#92 : Add 'Notification' to A.19 title in DPV-GDPR

beatriz: have added developed terms to #62 which include classes and properties based on DGA

<ghurlbot> Issue 62 Add DGA/eIDAas entities (besteves4) scope, concepts

<Github> w3c/dpv#62 : Add DGA/eIDAas entities

beatriz: There are about 80 concepts in the submitted analysis by beatriz
… harsh and georg will analyse these and add further concepts
… Collated work will then be considered for inclusion within the DPV similar to GDPR i.e. as DPV-DGA along with additional implementations and guidances as needed

Providing guidance for ISO 27560

harsh: I have analysed the current 27560 DTS draft. Conclusion is that all concepts are present in DPV, which is expected. Annex A contains an example using DPV, which can be found at coolharsh55/dpv-consent-recordAs Additional work include writing an implementation guidance note as per #90

<ghurlbot> Issue 90 Provide guidance for implementing ISO/IEC 27560 Consent Records using DPV (coolharsh55) documentation, use-case, application

harsh: Additionally, the companion standard for 29184 is also being investigated to create machine-readable notices, see #91

<ghurlbot> Issue 91 Provide guidance for implementing ISO/IEC 29184 Privacy Notice using DPV (coolharsh55)

harsh: There will be updates next week on this.

<Github> w3c/dpv#91 : Provide guidance for implementing ISO/IEC 29184 Privacy Notice using DPV

<Github> w3c/dpv#90 : Provide guidance for implementing ISO/IEC 27560 Consent Records using DPV

Multi-lingual translations for DPV

harsh: Tobias from TRAPEZE has provided translations using DeepL which need to be analysed manually to identify quality and need for corrections
… Julian has volunteered to lead the German translations and we need translators for Italian and French (or other languages) - caveat that they have knowledge of legal terminology i.e. GDPR in that specific language

julian: issues with character encodings within the German translations, e.g. umlauts

harsh: these may have arised as a result of converting the CSVs to XLSX when uploading to shared Google Drive, will investigate the source
… Using #89 to track this work

<ghurlbot> Issue 89 Multi-lingual labels and descriptions for concepts (coolharsh55) documentation, todo, help-wanted

<Github> w3c/dpv#89 : Multi-lingual labels and descriptions for concepts

julian: In the German labels for Base vocab properties, the use of 'einen' is incorrect and should not be present
… Julian will add comments to the document with issues as found which will be shared with the mutlilingual task group and used to decide further actions

Data Breach concepts

harsh: Going through the Irish DPC's data breach reporting form, there are a lot of different identifiers that are required to be maintained and shared. E.g. DPC issues a case identifier or reference that must be included in further reporting. Data Subjects as well as Processors and Controllers can have identifiers from Controllers that they should include if available. How to model such identifiers with DPV?

paul: we have dpv:hasIdentifier to indicate an identifier in the legal sense. Additionally dct:identifier is also an option.

harsh: The issue is how to distinguish between identifiers. Specifying the provider's identifier (i.e. controller reporting a breach specifies their own identifier) can be done using these, but the question is how to provide an externally created identifier
… Such identifiers can also occur in other use-cases, such as complaints with DPAs or organisations may have a case reference associated with communications
… Discussion on identifiers without resolution or identification of a solution.
… This can be tracked in #64

<ghurlbot> Issue 64 Provide concepts for Data Breach (coolharsh55) concepts, todo, help-wanted

<Github> w3c/dpv#64 : Provide concepts for Data Breach

Next Meeting

harsh: harsh is away next week, paul will chair the meeting
… we will meet as usual on Thursday 27th 14:00 WEST / 15:00 CEST
… ghurlbot, bye
… Github, bye

Summary of issues

  1. Add 'Notification' to A.19 title in DPV-GDPR
Minutes manually created (not a transcript), formatted by scribe.perl version 217 (Fri Apr 7 17:23:01 2023 UTC).