W3C

DPVCG Meeting Call

11 MAY 2023

Attendees

Present
beatriz, delaram, georg, harsh, julian, markLizar, paul
Regrets
-
Chair
harsh
Scribe
harsh

Meeting minutes

Repository: w3c/dpv

ghurlbot, harsh is coolharsh55

<ghurlbot> harsh, I already had that GitHub account for harsh

Data Breach

Continuing from the previous discussion on data breach notifications and records.

Based on the analysis of DPC data breach reporting form, this is the data model.

1) Likelihood of Risk to Fundamental Rights - if present, then the breach has to be reported. If not, then the breach does not have to be reported.

2) Scales that determine DPA. This includes Data Subjects and whether there are multiple member states involved. If there are multiple member states, then the DPC form asks about impacts.

Same for organisation activities - whether there are multiple member states involved. Also if the organisation is based in EU or has a Representative.

Further questions about the main establishment of the organisation and a justification for why this is the case.

The DPC form also asks if the breach has been notified to other DPAs, and if there is a case id.

3) Organisation details - name, address, EU/EEA establishments, sector (public, private, voluntary, charity), sub-sector (NACE taxonomy), internal ID for breach

4) Processor details if applicable

5) Details of who is reporting the breach - DPO (requires details), Natual Person (requires functional role in connection with breach), Processor (on behalf of Controller).

6) Data Breach - source and cause, impacts - severity of risk to fundamental rights, when it occured (duration), how they became aware of it (data subject, third party, processor, audit, testing, employee).

Justification is delay more than 72 hours, type (confidentiality, integrity, availability), data affected and whether it is special category and number of records, data subject scale and if they are vulnerable.

technical and organisational measures before breach and after the breach to prevent it further, deficiencies identified, TOMs in response to breach, whether secured, retrieved, restored breached data

7) Communications to the data subject - medium, info about the breach, advice, direct communication or public announcement, justification for no individual communication (if not direct to individual)

8) Previous breach report - date, DPC id, more info (text)

Concepts we can model - DataBreach, BreachDetection, BreachDetectionRecord, dpv:hasDataSource as DataSubject ThirdParty DataProcessor, ThreatActor - cause of breach (actor), PreliminaryInvestigationRecord and ConclidingInvestigationRecord, BreachNotificationRecord.

To represent the communication, we can use https://schema.org/Message

schema.org about for referring to data breach

use dpv:hasJusticiation JustificationForDelayedBreachNotification, dpv:hasImpactAssessment to refer to DataBreachImpactAssesment, risk:ImpactOnFundamentalRights as a type of Impact

BreachMitigationMeasure, TerminatingBreach, BreachRecovery, BreachResilience, BreachTermination

use dpv:hasRecord to refer to data breach records

How to represent case identifier, e.g. provided by DPA for data breach - DataBreachIdentifier with dpv:hasIdentifier

BreachNotice with dpv:hasNotice for notices

ActivityStatus to indicate status of investigations

We use the existing risk concepts, i.e. risk, risk mitigation measure, risk source etc. to describe the data breach

delaram: we need to confirm the interpretation and definition of RiskSource as it does not seem consistent

Next meeting

harsh: The next meeting will take place on 18 May at 14:00 WEST / 15:00 CEST

Minutes manually created (not a transcript), formatted by scribe.perl version 217 (Fri Apr 7 17:23:01 2023 UTC).