Meeting minutes
Repository: w3c/dpv
ghurlbot, harsh is coolharsh55
<ghurlbot> harsh, I already had that GitHub account for harsh
W3C TPAC
We have the opportunity to meet at TPAC and have a session. It is also possible to do another joint session, e.g. as last year with ODRL.
Deadline for this is 22 May - so let harsh know before that.
So far we have 3 participants - harsh, georg, beatriz. This is not enough for the session.
Data Breach
Continuing from the previous discussion on data breach notifications and records.
There are some open questions regarding information required for data breach.
1) Impact on fundamental rights is expressed as a likelihood, rather than mere existence or applicability. This is so that DPV's existing risk assessment framework can be used. Note that it does not include specifying likelihood as 0, just that it is unlikely.
2) Establishments are complicated to represent - no idea on how to do these.
3) Sector is represented as four groupings of public, private, charity, and voluntary. These would need to be described as types of organisations since the NACE taxonomy already models the sectors.
4) Question of how to represent data breach IDs - there can be multiple ones such as internal, each DPAs own identifier. To assist with this, we can have DataBreachIdentifier as the concept and then annotate it to indicate who provided or when.
5) The cause of the breach can be modelled as a Threat Actor - this is not a concept in the ISO risk taxonomy but is needed since data breach actions can be intentional or accidental activities by specific individuals
6) Awareness of data breach is a notification if communicated by someone else which allows recording its time and the entity that sent it
7) Risk Source is the event or condition that causes the risk, e.g. someone was not secured which allowed the threat actor to access the data. The risk source exists because of e.g. vulnerability of a system which is mitigated by a mitigation measure.
8) Specific measures taken in response to the breach would be BreachMitigationMeasure
29184 and 27560
Processing Condition and how to specify withdrawal method and how to provide information about the withdrawal method when it is not a right
How to keep rectified rights i.e. say rights to erasure are not applicable
How to express and record choice vs consent
Machine-readable notice but would it also specify components e.g. buttons and implications
Next meeting
harsh: The next meeting will take place on 25 May at 14:00 WEST / 15:00 CEST