W3C

DPVCG Meeting Call

10 JAN 2024

Attendees

Present
beatriz, delaram, georg, harsh, iain, paul, tytti
Regrets
-
Chair
harsh
Scribe
harsh

Meeting minutes

Meeting minutes: https://w3id.org/dpv/meetings

purl for this meeting: https://w3id.org/dpv/meetings/meeting-2024-01-10

Code for Documentation

See email sent by harsh to the mailing list https://lists.w3.org/Archives/Public/public-dpvcg/2024Jan/0000.html

this represents the changes to be made to DPV data and documentation - and the goal is to integrate/apply these to the W3C repo in the coming weeks. The outcome will be the next release of DPV.

Using DPV for supporting individuals

Iain is working with IEEE P7012 group on machine readable privacy terms https://sagroups.ieee.org/7012/.

The idea is to have something similar to Creative Commons, called Customer Commons, that builds tools on side of the customer, to have a contract that articulates the agreement from the side of the individual. Similar to how Creative Commons works for media.

It will provide different descriptions for the contract e.g. lawyer view, human view, machine-readable view. The P7012 draft standard should be completed by April/May.

links shared by Iain for more information: https://customercommons.org/solutions/tools/terms/p2b1/ and https://customercommons.org/solutions/tools/terms/p2b1/p2b1beta-human/ and https://customercommons.org/p2b1beta-legalese/

The relation to this group, the link to DPV, is based on concepts and descriptions from DPV being focused on the organisation or being written from the organisation's perspective. We need something that is helpful for individuals. For example. "Service Provision" and "Service Consumption" - so it can be the same concept with different labels or it can be a separate vocabularty that operates on the same basic concepts but for the individual or data subject.

Iain will report back after asking P7012 how DPV can help. Meanwhile this group can discuss how to implement this or how it aligns with existing scope e.g. consent records or privacy notices where the target audience can be individuals.

Presenting Consent to EU Commission

Georg shared that earlier with harsh there was a meeting with EU Commission presenting DPV for different competencies and regulations in relation to Consent. That discussion is ongoing, and the current topic is regarding paralells between GDPR consent, DGA consent, and ISO 27560 and ISO 29184.

Tech vocabulary

Georg has highlighted the challenge of consistency - should we reflect industry terms or have consistency with DPV terms.

Georg has suggested creating or supporting necessary operations such as for Data Processing Agreement, and to provide the taxonomy and tooling for managing information. Georg suggests these as good features to have but does not want to impose a priority on their uptake within the group.

For security (tech and risk) we should have involvement from security people e.g. ISO standards to ensure this is correct and consistent. We also should look at case law e.g. CJEU decision - Controller using Processor is responsible for ensuring adequate security is implemented by Processor https://curia.europa.eu/juris/document/document.jsf?text=&docid=280623&pageIndex=0&doclang=EN&mode=lst&dir=&occ=first&part=1&cid=1066847.

Georg shared that the Norwegian authority working on digitisation, context was Health regulation and need of semantics for describing licenses and consent.

AI vocabulary

Delaram has raised the question about how we should create/place this work within the DPVCG. The consensus is that "AI" vocabulary be an extension of the Tech vocabulary, and then there will be a separate extension of the AI Act that reuses these concepts, similar to how GDPR is an extension of the core DPV concepts.

Question on how to manage 'risks of AI' e.g. a separate extension for these? To be discussed based on necessity. In either case, we will need to refine and provide a general risk vocabulary.

Georg has asked how are different assessments going to be managed? E.g. DPIA, AI risk assessment, transfer impact assessment, Legitimate interest assessment. For this the group can think about using DPV to identify common concepts and provide a common framework/language that applies DPV for 'common/shared' assessments.

Updates and Interests

DPV and ODRL

Beatriz, who is involved in both groups, has informed that there is a priority in establishing a connection with ODRL, and that Renato (ODRL editor) is looking into DPV - so there might be use-cases and questions. Ruben (IMEC/Solid) is also looking into DPV in terms of Solid road map and Flanders use-case.

Beatriz has shared a paper on consent in Solid https://lists.w3.org/Archives/Public/public-dpvcg/2024Jan/0003.html

Beatriz has shared a CFP for Solid, which can include use of DPV there https://lists.w3.org/Archives/Public/public-dpvcg/2024Jan/0002.html

Beatriz will be helping out in management of DPV.

DPIA and AI

Tytti mentioned she is writing a paper for FAccT on DPIAs and how the guidelines are across different authorities and how it relates to high-risk AI systems

ROPA and Privacy Notice

Paul mentioned he is working on a processing specification for ROPA vs Privacy Notice - checking both are consistent, Data Processing Agreements. His research with DPOs shows that this is needed.

Guidance

Georg mentioned that we should set up for each regulation an index whether DPV will be supporting them, and whether there is scope for or whether we want to provide/use as use-cases that DPV will provide guidance for e.g. Controller-Controller, Controller-Processor.

Next Meeting

Next meeting will be in 1 week, on WED JAN-17 15:00 WET / 16:00 CET.

Minutes manually created (not a transcript), formatted by scribe.perl version 217 (Fri Apr 7 17:23:01 2023 UTC).