Meeting minutes
Repository: w3c/dpv
Meeting minutes: https://
purl for this meeting: https://
Risk Assessment
See email by harsh regarding concepts - https://
We will be meeting with Rob and Julio later today to discuss the risk concepts in DPV based on their experience with the ARK project which also has a risk vocabulary, see https://
Conclusions from the discussion will be shared back here to the group for consensus
see #104
<ghurlbot> Issue 104 Re-evaluate Risk Assessment concepts (by coolharsh55) [concepts] [application] [help-wanted]
Data Breach / Incident
For the ongoing data breach and incident concepts, they have a dependency on risk assessment concepts. Therefore, their further progress and documentation is paused until the risk assessment concepts have been finalised.
see #64
<ghurlbot> Issue 64 Provide concepts for Data Breach (by coolharsh55) [todo] [application] [help-wanted]
see #100
<ghurlbot> Issue 100 Proposal to add (security) Incident Reporting concepts (by coolharsh55) [concepts] [application] [help-wanted]
Risk Management
Tangential to the Risk Assessment concepts are the Risk Management concepts, which refer to the organisational processes in place to manage risk. These will be incorporated into the Risk Assessment structure once finalised, and will be based on the ISO 31K series.
see #74
<ghurlbot> Issue 74 Add Risk Management concepts from ISO 31000 series (by coolharsh55) [concepts] [help-wanted]
DGA
beatriz: discussing with georg, there is a pending review of legal basis and register concepts
beatriz will share current list actions and concepts to be reviewed to the mailing list as she will be on vacation next week
harsh: For the documentation of concepts, we need the spreadsheet to be in the same format (i.e. columns and ordering) as the other DPV CSVs. Then I can add it to the documentation generator and the RDF and HTML should be automatically generated.
beatriz: will make the spreadsheet in the required format
see #105
<ghurlbot> Issue 105 Generate documentation for proposed DGA concepts (by coolharsh55) [documentation] [todo]
Expanding scope to Non-Personal Data
harsh: No new inputs to this topic. As scheduled, we will take a decision at the end of August based on provided inputs, with further time until September to address the decision made.
Proposed Concepts
Associate Legal Basis with Rights
harsh: Scheduled for inclusion in DPV v1.1
… see #49
<ghurlbot> Issue 49 Provide association and applicability between GDPR legal bases and rights (by coolharsh55) [documentation] [concepts] [todo] [help-wanted]
indicating PII
Scheduled for inclusion in DPV v1.1
harsh: Instead of PII, which is a ambigious term due to ISO redefining to be similar to personal data (as data about an identifiable person or to data that identifies a person), we are proposing IdentifiablePersonalData with further specific types representing Explicit i.e. data directly identifies the person, and Implicit i.e. data indirectly identifies the person such as through combination or because of its uniqueness.
see #14
<ghurlbot> Issue 14 Indicating PII i.e. Personally Identifiable data category or categories in combination (by coolharsh55) [concepts] [question] [help-wanted]
Location concepts
see #46
harsh: We need to resolve this topic and move on. Based on the progress (or lack of it) so far, it would be easier to keep the location concepts in DPV and use owl:sameAs or skos:exactMatch to link with other vocabularies, e.g. the EUVOC concepts which are not well documented for reuse, see https://
<ghurlbot> Issue 46 Use/Align with EU location vocabularies (by coolharsh55) [documentation] [scope] [concepts] [todo]
Main Establishments and Lead SA
see #93
harsh: Earlier, Establishment was proposed as a concept to be included in the main DPV. Upon further thoughts, it would be better to move it to DPV-GDPR as it is a EU-specific concept, and MainEstablishment is a GDPR-defined concept (or role).
harsh: Similarly, Lead Supervisory Authority and Concerned Supervisory Authority are also GDPR only roles. See the proposed concepts in the issue linked.
<ghurlbot> Issue 93 Representing Main Establishment and Lead SA as a concept (by coolharsh55) [concepts] [help-wanted]
AI Act
See #106
harsh: planning ahead, it would be better to start now for the concepts regarding AI Act so we can know what is compatible with DPV, which concepts should be in core and which in extension. Learning from modelling DGA, we know that there can be substantial changes.
delaram: is the AI Act within the scope of the group?
harsh: I think so, because AI definitely involves personal data in several cases, and also forms the basis of "automated decision making" which we already include in DPV. Also, its too relevant to leave out. Most of the concepts can fit in the DPV-TECH vocabulary, and the AI Act specific concepts such as the legal basis and the roles can be in the extension. We can use your PhD outputs and also the EMPOWER outputs to start this by mapping them to DPV.
delaram: Will check with Julio and Dave about reusing the outputs.
<ghurlbot> Issue 106 Propose concepts from the AI Act (by coolharsh55)
Upcoming Documents
Guide on Consent Records
See #68
<ghurlbot> Issue 68 Provide Guide for using DPV to create Consent Records (by coolharsh55) [documentation] [todo]
Guide for Data Breach
See #103
harsh: This was earlier the Data Breach extension, which after moving the breach concepts to RISK and GDPR extensions, is now a guidance document for using them. Currently put on pause pending the resolution of risk assessment concepts for the examples and descriptions.
<ghurlbot> Issue 103 Guide for Data Breach (by coolharsh55) [documentation] [concepts] [todo] [application]
Next Meeting
The next meeting will be in 1 week, on THU AUG-10 15:00 CEST.
Agenda will continue from current topics as well as updates to topics discussed today.