Meeting minutes
Repository: w3c/dpv
ghurlbot, harsh is coolharsh55
<ghurlbot> harsh, I already had that GitHub account for harsh
Associating GDPR Rights with Legal Bases
Issue #49 lists legal bases and what rights are applicable for each based on guidance provided by DPAs (IE, UK) and EDPB
<ghurlbot> Issue 49 Provide association and applicability between GDPR legal bases and rights (coolharsh55) documentation, concepts, todo, help-wanted
To associate the legal basis and the right, the property dpv:hasRigh would be used
Discussion in the meeting for whether 1) this is useful to provide 2) is the information in line with DPVCG's objectives and scope 3) what form to provide it in i.e. should we use dpv:hasRight? 4) Do we also model the 'not applicable' relations?
<Github> w3c/
Participants agree that this is useful and should be provided using dpv:hasRight within DPV-GDPR.
julian: Why is Article 19 not mentioned in the list?
… Article 19 is regarding the communication or notification of A.16, A.17, A.18 by the controller to other recipients and the confirmation of recipient for which this has taken place upon request by the data subject.
… This has not been modelled because the appropriate relevant guidance for this could not be found in the cited sources.
… If DPVCG is modelling these, then A.19 would be modelled with a Y or applicable for all cases where all of A.16-A.18 are also applicable, and a N or not applicable for any case where A.16-A.18 is not applicable.
… The group agrees only to model the Y relations in DPV and to represent N relations through lack of facts or concept i.e. imply closed world interpretation.
… This is in line with how rights are associated only in cases where they are applicable, and where they are not - nothing is specified and there is no 'not applicable' relation.
paul: What is the title of A.19 in DPV? It should reference notification in the title.
ISSUE: Add 'Notification' to A.19 title in DPV-GDPR
<ghurlbot> Created issue #92 Add 'Notification' to A.19 title in DPV-GDPR
Modelling Data Governance Act
<Github> w3c/
beatriz: have added developed terms to #62 which include classes and properties based on DGA
<ghurlbot> Issue 62 Add DGA/eIDAas entities (besteves4) scope, concepts
<Github> w3c/
beatriz: There are about 80 concepts in the submitted analysis by beatriz
… harsh and georg will analyse these and add further concepts
… Collated work will then be considered for inclusion within the DPV similar to GDPR i.e. as DPV-DGA along with additional implementations and guidances as needed
Providing guidance for ISO 27560
harsh: I have analysed the current 27560 DTS draft. Conclusion is that all concepts are present in DPV, which is expected. Annex A contains an example using DPV, which can be found at coolharsh55/
<ghurlbot> Issue 90 Provide guidance for implementing ISO/IEC 27560 Consent Records using DPV (coolharsh55) documentation, use-case, application
harsh: Additionally, the companion standard for 29184 is also being investigated to create machine-readable notices, see #91
<ghurlbot> Issue 91 Provide guidance for implementing ISO/IEC 29184 Privacy Notice using DPV (coolharsh55)
harsh: There will be updates next week on this.
<Github> w3c/
<Github> w3c/
Multi-lingual translations for DPV
harsh: Tobias from TRAPEZE has provided translations using DeepL which need to be analysed manually to identify quality and need for corrections
… Julian has volunteered to lead the German translations and we need translators for Italian and French (or other languages) - caveat that they have knowledge of legal terminology i.e. GDPR in that specific language
julian: issues with character encodings within the German translations, e.g. umlauts
harsh: these may have arised as a result of converting the CSVs to XLSX when uploading to shared Google Drive, will investigate the source
… Using #89 to track this work
<ghurlbot> Issue 89 Multi-lingual labels and descriptions for concepts (coolharsh55) documentation, todo, help-wanted
<Github> w3c/
julian: In the German labels for Base vocab properties, the use of 'einen' is incorrect and should not be present
… Julian will add comments to the document with issues as found which will be shared with the mutlilingual task group and used to decide further actions
Data Breach concepts
harsh: Going through the Irish DPC's data breach reporting form, there are a lot of different identifiers that are required to be maintained and shared. E.g. DPC issues a case identifier or reference that must be included in further reporting. Data Subjects as well as Processors and Controllers can have identifiers from Controllers that they should include if available. How to model such identifiers with DPV?
paul: we have dpv:hasIdentifier to indicate an identifier in the legal sense. Additionally dct:identifier is also an option.
harsh: The issue is how to distinguish between identifiers. Specifying the provider's identifier (i.e. controller reporting a breach specifies their own identifier) can be done using these, but the question is how to provide an externally created identifier
… Such identifiers can also occur in other use-cases, such as complaints with DPAs or organisations may have a case reference associated with communications
… Discussion on identifiers without resolution or identification of a solution.
… This can be tracked in #64
<ghurlbot> Issue 64 Provide concepts for Data Breach (coolharsh55) concepts, todo, help-wanted
<Github> w3c/
Next Meeting
harsh: harsh is away next week, paul will chair the meeting
… we will meet as usual on Thursday 27th 14:00 WEST / 15:00 CEST
… ghurlbot, bye
… Github, bye