W3C

DPVCG Meeting Call

18 MAY 2023

Attendees

Present
beatriz, delaram, georg, harsh, paul
Regrets
-
Chair
harsh
Scribe
harsh

Meeting minutes

Repository: w3c/dpv

ghurlbot, harsh is coolharsh55

<ghurlbot> harsh, I already had that GitHub account for harsh

W3C TPAC

We have the opportunity to meet at TPAC and have a session. It is also possible to do another joint session, e.g. as last year with ODRL.

Deadline for this is 22 May - so let harsh know before that.

So far we have 3 participants - harsh, georg, beatriz. This is not enough for the session.

Data Breach

Continuing from the previous discussion on data breach notifications and records.

There are some open questions regarding information required for data breach.

1) Impact on fundamental rights is expressed as a likelihood, rather than mere existence or applicability. This is so that DPV's existing risk assessment framework can be used. Note that it does not include specifying likelihood as 0, just that it is unlikely.

2) Establishments are complicated to represent - no idea on how to do these.

3) Sector is represented as four groupings of public, private, charity, and voluntary. These would need to be described as types of organisations since the NACE taxonomy already models the sectors.

4) Question of how to represent data breach IDs - there can be multiple ones such as internal, each DPAs own identifier. To assist with this, we can have DataBreachIdentifier as the concept and then annotate it to indicate who provided or when.

5) The cause of the breach can be modelled as a Threat Actor - this is not a concept in the ISO risk taxonomy but is needed since data breach actions can be intentional or accidental activities by specific individuals

6) Awareness of data breach is a notification if communicated by someone else which allows recording its time and the entity that sent it

7) Risk Source is the event or condition that causes the risk, e.g. someone was not secured which allowed the threat actor to access the data. The risk source exists because of e.g. vulnerability of a system which is mitigated by a mitigation measure.

8) Specific measures taken in response to the breach would be BreachMitigationMeasure

29184 and 27560

Processing Condition and how to specify withdrawal method and how to provide information about the withdrawal method when it is not a right

How to keep rectified rights i.e. say rights to erasure are not applicable

How to express and record choice vs consent

Machine-readable notice but would it also specify components e.g. buttons and implications

Next meeting

harsh: The next meeting will take place on 25 May at 14:00 WEST / 15:00 CEST

Minutes manually created (not a transcript), formatted by scribe.perl version 217 (Fri Apr 7 17:23:01 2023 UTC).