W3C

DPVCG Meeting Call

30 JAN 2025

Attendees

Present
beatrizEsteves, delaramGolpayegani, georgKrog, harshPandit, julianFlake, julioHernandez, markLizar, paulRyan
Regrets
tyttiRintamaki
Chair
harsh
Scribe
harsh, harshPandit

Meeting minutes

Repository: w3c/dpv

Meeting minutes: https://w3id.org/dpv/meetings

purl for this meeting: https://w3id.org/dpv/meetings/meeting-2025-01-30

v2.1 release

<ghurlbot> Issue 198 DPV v2.1 release management (by ghurlbot)

harsh: I/we are behind schedule on the release. So expecting tasks to be completed, have set the date for documents to FEB-01, and then the feedback period to +2 weeks ending on FEB-16.

harsh: Added a notice to HTML pages and to the README stating the release is open for feedback.

Authors/Contributors

harsh: A question was brought up by Delaram regarding how we decide on authors as people are listed as contributors and also as authors. My answer, which was implied so far in the drafting of documents but which should be discussed now, is that authors have a greater role in designing and shaping the document/resource. If someone has provided some concepts and that is the extent of their contribution, then they are listed as a contributor. For people who take a more active role in the work, especially in engagements which happen regularly or over time, we list them as authors.

harsh: This is a rather arbitrary criteria, but helps motivate and indicate who has been involved in 'decision making' for the document/work in question. Editors are then people who draft the document (only) and control its communication. This follows the W3C style of listing roles, but they do not have such a detailed interpretation and leave it to CGs to manage the roles.

group is okay with this criteria

delaramGolpayegani: Currently the contributors are listed at the bottom which is difficult to see and not in the same visible area as the authors. So it would be better for motivation and exposure to have them up in the document near the authors. WIDOCO output shows something similar in the document.

julianFlake: Agree that having contributors at the bottom is difficult to find and discouraging. So this change would be a good step. For amount of space this might take at the top, we can reduce this space e.g. between lists or in a 2-columns layout.

beatrizEsteves: Also agree, having contributors listed more visibly would be nice.

group agreed this would be a good change that would encourage contribution and better acknowledge it in documents

ACTION: Move contributors section in HTML up near the metadata section

w3id config

<ghurlbot> Issue 178 Add w3id config for `2.1-dev` (by besteves4)

<ghurlbot> Issue 200 [FIX]: Examples in the specification results in a HTTP 404 (by phochste)

harsh: We have resolved all of our open issues and tasks for v2.1, and only the release tasks remain which we expect to complete. We need to change the w3id config for v2.1, and also fix the issue with examples not resolving. Beatriz, would be good to have your help here.

beatrizEsteves: will do, let's talk on Friday

v2.2 work start

harsh: Any particular items we should discuss for this version?

beatrizEsteves: We have the PACSOI project starting now where one of the use-cases is sharing data with the doctor. So this will involve working on DPV purposes for healthcare which are currently absent - will share more as it develops.

harsh: We have the SECTOR-HEALTH extension where this would fit nicely

georgKrog: The EHDS concepts in our extension are outdated as they are based on an older draft. Working on the latest draft - will share more next week.

georgKrog: Another use-case is where lots of metadata isused by different organisations. Would be good to have that in DPV. Harsh had previously mentioned that this would be in TECH extension. For example for a gaming company where they have metadata which they tag players with an use that for analysis and profiling.

harsh: Not sure what we are trying to model as a concept as this would be personal data so existing concepts/properties can model this. Let's describe it in writing offline and then we can discuss a concrete proposal here.

AI Training

<ghurlbot> Issue 82 Provide vocabulary to specify purposes and permissions related to AI training (by scottkellum)

harsh: For starting work on v2.2, this is a pending issue that we said we would discuss later. Now that we have the AI and AI Act extension, I think we should discuss whether we should consider this issue about expressing whether AI training is allowed or not. I think we should provide concepts like this as they relate to our Purposes taxonomy e.g. AI training can be specified in relation to service delivery (e.g. trained/refined on provided data) or for improvements to services (e.g. using data for improving models used to provide service). The expression of allowed/denied can be done with ODRL in contracts and such, but we should provide concepts and taxonomies.

julianFlake: Would the focus still be 'privacy'?

harsh: Not completely - we are talking about training by itself as a concept which we can then expand rather than only privacy-conscious training or something like that

delaramGolpayegani: What sources would we use for this? AI Act? ISO standards? What would be included?

harsh: Yes, all of those sources. The idea here is that we can express what data is included for training using our existing concept. Same for technical measures and risks. So what is missing is the concepts about training itself. This can be different types of training like locally, fine-tuning, training from scratch. So we would have some top-level concept with a taxonomy to state what exactly happens as people use "training" in many different ways as a generic concept.

paulRyan: AI and training is a very hot topic at the moment.

delaramGolpayegani: When is the expected released for this version?

harsh: The plan is for June or July later this year.

delaramGolpayegani: The AI Act will have more enforcement and the GenAI code of conduct would be completed by then so this can be aligned with that.

group didn't raise any concerns or objections to this topic

harsh: Beatriz, will the PACSOI project involve any AI training aspects e.g. people want to enable use of their data in Solid Pods for training AI for healthcare services?

beatrizEsteves: yes, will need concepts to express that

harsh: Is there any AI training mentioned in the EHDS?

georgKrog: yes, there is a mention of algorithms in Art.53-e

julianFlake: The AI Act is also mentioned in Art.1

group will discuss this later based on more concrete concepts and a proposal for how this should be integrated in DPV specs

Biometric Data

<ghurlbot> Issue 135 Add biometric categories to Personal Data extension (by coolharsh55)

harsh: This was a proposal by Georg to add more specific biometric categories such as iris pattern and eye colour to the existing concepts in PD extension

georgKrog: Need to have a more detailed look at this to make sure that we have a good collection of concepts for the taxonomy

harsh: The issue lists some sources such as the ISO standard and concepts shared by you, but yes, let's find some good sources for adding these concepts

Subjective Locations

<ghurlbot> Issue 209 [Concept]: `AtX` subjective Location concepts (by coolharsh55)

harsh: The proposal here is to add subjective location concepts i.e. location that isn't rooted in a specific physical location but instead is used as a subjective label. For example, home or work. We add a prefix to clearly indicate that this is a location e.g. AtHome and AtWork. This is useful for cases where such locations are used and also where regulations refer to them. E.g. in DPIA requirements one of the conditions is public parks or public spaces. So we can add those through these.

paulRyan: Google Maps shows these for home and work, so there are use-cases that would need these

georgKrog: It would be useful but what would be the scope.

markLizar: This is relevant to 'scope disclosure' regarding the data and location which then requires a notice if data is crossing jurisdictions.

georgKrog: How to use these for saying I don't want location tracking? E.g. IP is used to decide location.

harsh: We should distinguish between the permission/prohibition here, and the data (IP that infers location). The inferred location might refer to physical concepts e.g. Dublin or Ireland - which we have in LOC extension. Or it would also be used to infer subjective locations e.g. based on IP or WiFi or GPS location tracking the system checks whether you are at work. So we need the concept to represent this subjective location as AtWork.

georgKrog: There could also be concepts such as tracking location inside a mall - so that would be an use-case for this.

markLizar: We should also think about modelling concepts as Privacy, Semi-Private, and Public. Or as Personal, Private, and Public. Maybe these would help indicate how these are used for the person's privacy contexts. These also affect what rights and expectations the person would have.

group will discuss these next week with a list of proposed concepts

Inverted Locations

<ghurlbot> Issue 208 [Concept]: Add Non-X (X = specific location) to represent locations that are not X (by coolharsh55)

harsh: I am using "inverted" for a lack of better phrasing for such concepts. The idea is that we have concepts such as EU and requirements such as data being in Non-EU locations. Programmatically we can represent this by checking whether a given location is included in EU - which our LOC extension helps with as we model countries in EU. However, to directly express Non-EU as a concept is not possible nor present anywhere else. So that's the proposal - that for each country we create a Non-X concept to help uses like this which are explicit and don't require programmatic techniques to identify what we mean. Also, we can model which countries are considered Non-EU for example which will help use-cases do things explicitly and faster.

group will discuss this next week

Next Meeting

The next meeting will be on FEB-06 Thursday 13:30WET/14:30CET

Agenda will be continuing discussion on topics started under v2.2

Summary of action items

  1. Move contributors section in HTML up near the metadata section
Minutes manually created (not a transcript), formatted by scribe.perl version 217 (Fri Apr 7 17:23:01 2023 UTC).