W3C

DPVCG Meeting Call

08 JUN 2023

Attendees

Present
beatriz, delaram, georg, markLizar, paul
Regrets
-
Chair
harsh
Scribe
harsh

Meeting minutes

Repository: w3c/dpv

General Discussions

Adoption of DPV

harsh: The Jamaican Data Protection regulation recently went into effect and some of its implementation is being handled by a company called Design Privacy https://designprivacy.io/

harsh: The law requires submitting ROPA-like information to the commissioner - for which design privacy has developed a platform to fill information. The fields are based on DPV and use the vocabulary to populate items as well provide assistance with common use-cases. I met with them recently where they presented their work. It went beyond what we have in DPV in terms of also providing support e.g. selecting a specific department shows associated purposes to reduce choice fatigue and guide in selecting concepts. It would be interesting to know more about this and see it in action. Will try to arrange a presentation. One of the things we can adopt into DPV from this experience is the 'support' aspect of providing pre-configured lists or patterns for implementation based on common use-cases.
… In terms of specifics, the base concept in their implementation is (prudently) called a Process instead of PersonalDataHandling which allows it be associated with common organisational terminology. We can think about adopting this as well.

georg: Presenting this to the EU DPAs would be a good way to demonstrate the value of using DPV and tech/tools for assisting with the compliance processes. The EDPB chair has commented on the need to reduce human effort in complaint procedures - this is something the group can help with.

Future Work

harsh: We can provide a taxonomy of issues and vulnerabilities to help with managing complaints and also to associate compliance with the concepts in DPV. It could be something like the CVE system for common security vulnerabilities. It would enable DPAs to offer guidance, track use-cases and annotate information using it.

harsh: I have been thinking about this for a while, and perhaps along with the general guidance for using DPV, we can also look into providing such a list as part of the vocabulary. It would enable a nice set of regulatory compliance tools.

DPV v2

harsh: For extending DPV to additional cases not forseen before, we need to start thinking about what DPV v2 should look like so we can plan ahead.
… Example - all of our concepts are regarding personal data, so personal data handling cannot be used where there is no personal data.

Data Breach

harsh: Continued discussion on data breach records. See issue w3c/dpv#64 for summary and discussion.
… Proposal shared on mailing list - https://lists.w3.org/Archives/Public/public-dpvcg/2023May/0007.html
… Discussion on hasAssessment as a relation to associate assessments. Currently we do not have such a relation, and use hasOrganisationalMeasure. It may be desirable to add this, as well as also add other types of assessment relations to quickly associate them in contexts. For example, hasImpactAssessment and hasRiskAssessment.
… The hasAssessment relation has been accepted, and the others remain as proposed and will be taken up later in discussions.

markLizar: For the Data Breach notifications, these should be categorised as dynamic and automated.

harsh: We would need definitions for these as well as their relevance and interpretation under some legal framework. Otherwise the onus would be on us to define and interpret this - which is a high and difficult bar we try to avoid. Proposals with the text can be sent to the mailing list.

Discussion on data breach have yielded no issues or objections. So we continue to the next step which is to write the data breach specification with guidance on how to use it.

Consent Records

harsh: We have already discussed the adoption of ISO/IEC 27560 within DPV. While we do that, the next goal of the ISO WG is to draft a general personal data processing record which covers other legal bases as well.
… In DPV, we should also look at other legal basis e.g. contract and legal obligations. For this, we can look at the smashHit project https://smashhit.eu/

harsh: I have emailed them, and got a reply circulating it to a wider group, but no reply or engagement so far. So we may have to take the concepts and map them ourselves.

harsh: On a relevant note, there is a recent paper on a vocabulary for cookies that may be on interest - https://www.semantic-web-journal.net/content/what-your-cookie-box-explaining-ingredients-web-cookies-knowledge-graphs-0

Next meeting

harsh: The next meeting will take place on 15 June at 14:00 WEST / 15:00 CEST

harsh: I will be away at the FAcct conference in Chicago - so if there are not enough people to attend, we will meet on 22 June. Otherwise I will have the meeting at the usual day/time.

Minutes manually created (not a transcript), formatted by scribe.perl version 217 (Fri Apr 7 17:23:01 2023 UTC).