Meeting minutes
Repository: w3c/dpv
ghurlbot, harsh is coolharsh55
<ghurlbot> harsh, I already had that GitHub account for harsh
Data Breach
Continuing from the previous discussion on data breach notifications and records.
Based on the analysis of DPC data breach reporting form, this is the data model.
1) Likelihood of Risk to Fundamental Rights - if present, then the breach has to be reported. If not, then the breach does not have to be reported.
2) Scales that determine DPA. This includes Data Subjects and whether there are multiple member states involved. If there are multiple member states, then the DPC form asks about impacts.
Same for organisation activities - whether there are multiple member states involved. Also if the organisation is based in EU or has a Representative.
Further questions about the main establishment of the organisation and a justification for why this is the case.
The DPC form also asks if the breach has been notified to other DPAs, and if there is a case id.
3) Organisation details - name, address, EU/EEA establishments, sector (public, private, voluntary, charity), sub-sector (NACE taxonomy), internal ID for breach
4) Processor details if applicable
5) Details of who is reporting the breach - DPO (requires details), Natual Person (requires functional role in connection with breach), Processor (on behalf of Controller).
6) Data Breach - source and cause, impacts - severity of risk to fundamental rights, when it occured (duration), how they became aware of it (data subject, third party, processor, audit, testing, employee).
Justification is delay more than 72 hours, type (confidentiality, integrity, availability), data affected and whether it is special category and number of records, data subject scale and if they are vulnerable.
technical and organisational measures before breach and after the breach to prevent it further, deficiencies identified, TOMs in response to breach, whether secured, retrieved, restored breached data
7) Communications to the data subject - medium, info about the breach, advice, direct communication or public announcement, justification for no individual communication (if not direct to individual)
8) Previous breach report - date, DPC id, more info (text)
Concepts we can model - DataBreach, BreachDetection, BreachDetectionRecord, dpv:hasDataSource as DataSubject ThirdParty DataProcessor, ThreatActor - cause of breach (actor), PreliminaryInvestigationRecord and ConclidingInvestigationRecord, BreachNotificationRecord.
To represent the communication, we can use https://
schema.org about for referring to data breach
use dpv:hasJusticiation JustificationForDelayedBreachNotification, dpv:hasImpactAssessment to refer to DataBreachImpactAssesment, risk:ImpactOnFundamentalRights as a type of Impact
BreachMitigationMeasure, TerminatingBreach, BreachRecovery, BreachResilience, BreachTermination
use dpv:hasRecord to refer to data breach records
How to represent case identifier, e.g. provided by DPA for data breach - DataBreachIdentifier with dpv:hasIdentifier
BreachNotice with dpv:hasNotice for notices
ActivityStatus to indicate status of investigations
We use the existing risk concepts, i.e. risk, risk mitigation measure, risk source etc. to describe the data breach
delaram: we need to confirm the interpretation and definition of RiskSource as it does not seem consistent
Next meeting
harsh: The next meeting will take place on 18 May at 14:00 WEST / 15:00 CEST