W3C

DPVCG Meeting Call

20 MAR 2024

Attendees

Present
art, beatriz, delaram, georg, harsh, steve, ted, tytti
Regrets
-
Chair
harsh
Scribe
harsh

Meeting minutes

Meeting minutes: https://w3id.org/dpv/meetings

purl for this meeting: https://w3id.org/dpv/meetings/meeting-2024-03-20

Workshop at SEMANTiCS

link to CFP https://2024-eu.semantics.cc/page/cfp_ws deadline is MAR-22

beatriz: interested people please reach out to help organise/review/etc.

GDPR Rights Justifications

<ghurlbot> Issue 63 Add Right Non-fulfilment Justifications for GDPR’s rights (by besteves4)

beatriz: no updates, requires implementation and integration in to the DPV code/specs

georg: might have more suggestions based on tooling support being implemented in Signatu.

Modelling Complaints

georg: if a right exercise is requested, and not completed by a Controller, then the data subject complaints - These complaints should also be modelled e.g. right was not exercised

harsh: when should we go to regulators to show the work?

harsh: is this a list/vocabulary of complaint concepts e.g. right exercise not completed, consent not valid? or the information in the complaint?

georg: the first should be the priority

harsh: this is expanding the scope of the group - so we should discuss a) it is useful? b) how much should we think about / prioritise at the moment? c) who will be implementing/working on this?

georg: this will make the DPV useful but we don't need to prioritise

beatriz: we don't have the capacity to do this, but would be good to have funding - happy to support this

AI Incident Reporting

delaram: obligation to report risks to the Provider under the AI Act - will this be relevant to that? There is information exchange regarding risks and incidents, maybe some more stuff in the liability directive as well?

art: incident report in general?

harsh: complaint as a list of issues, CVE like system

No updates

delaram: no updates for AI Act

harsh: no updates for TOM proposals - still open for reviewing

harsh: no updates for DPV Resource paper

Website for DPV

harsh: has funding for the domain name

Delaram: who is going to create it and maintain it?

harsh: me (probably) - if so then I plan to keep it simple e.g. https://solidproject.org/ as the template for what info to provide

harsh: no objections, some positive responses - so lets discuss further when we have an example

Data Act

georg: Data Act defines new data sharing contracts between data holders and data users who may not be data subjects, and can be to third parties as recipients and for public bodies, and mentions data processing services which you can select/switch. There is mention of interoperability standards which can come from EU SDOs. Can we be such a SDO?

harsh: no, these are CEN/CENELEC, ETSI, etc. and national standards authorities. We'd have to go through formal processes at W3C, IEEE, etc. which is difficult if the work is not 'global' in scope/nature

beatriz: what about SEMIC?

harsh: Good idea from EU policy view, they are not a SDO, but we'd be making a conscious choice about the work focusing (only) on EU considerations

Data Breach Reporting

georg: EDPB collection of data breach reporting across DPAs https://www.edpb.europa.eu/notify-data-breach_en

Next Meeting

Next meeting will be in 1 week, on WED MAR-27 15:00 WET / 16:00 CET.

Topics for discussion are

1) Rights Justification - finalise output and produce documentation - beatriz, harsh

2) AI Act and Tech concepts by delaram - identify 'simple' subset of concepts to add, start work on AIRO and VAIR integrations

3) TOMs by harsh - to resolve the proposed concepts

4) w3id config update by harsh

5) github issues update by harsh

6) dpv marketing page by harsh

7) dpv resource paper

Minutes manually created (not a transcript), formatted by scribe.perl version 217 (Fri Apr 7 17:23:01 2023 UTC).