W3C

DPVCG Meeting Call

20 FEB 2025

Attendees

Present
beatrizEsteves, georgKrog, harshPandit, iainHenderson, julianFlake, julioHernandez, markLizar, paulRyan
Regrets
delaramGolpayegani
Chair
beatrizEsteves
Scribe
harsh, harshPandit

Meeting minutes

Repository: w3c/dpv

Meeting minutes: https://w3id.org/dpv/meetings

purl for this meeting: https://w3id.org/dpv/meetings/meeting-2025-02-20

v2.1 release

<ghurlbot> Issue 235 DPV v2.1-RC hotfixes and feedback (by coolharsh55)

harsh: we had put up the v2.1 release candidate with open review until FEB-16; see https://lists.w3.org/Archives/Public/public-dpvcg/2025Feb/0002.html and w3c/dpv#235 for hotfixes. Are we ready to publish this or do we need more time to review?

iainHenderson: +2 weeks

julioHernandez: +1 week

beatrizEsteves: +1 week

georgKrog: +2 weeks

group agreed to take 2 more weeks to review the release; next meeting we will identify if there are any major concerns, and then the week after that we will aim to finalise and publish

Guides

<ghurlbot> Issue 242 Provide Guides for Supporting Adoption & Use of DPV (by coolharsh55)

julianFlake: guides are needed to understand DPV and use it otherwise it is difficult to understand what to use where as there is a large amount of information and no guidance - we should prioritise having guides to help use DPV, but this is not a blocking issue for the v2.1 release (so for v2.2)

harsh: agree, we have various guides listed but they have not been completed and delivered

julianFlake: want to help, but not sure of time

harshPandit: will a structure, time help e.g. to do short tasks?

julianFlake: would prefer to discuss rather than directly write something if possible, but otherwise okay to help with a paragraph

georgKrog: guides should be easy to write (in my head) but we need to think about content

harshPandit: we have papers for several topics which we can use to put something in the document as a draft - ROPA, DPIA, Data Breach, Rights; will use this to populate the documents and then we can discuss with this as a starting point next week with the aim to v2.2 being supported with guides

paulRyan: what would be present in these guides?

harsh: see for example the consent guide https://w3id.org/dpv/guides/consent-27560 which states how to represent information for consent records using DPV and how to use it to do specific tasks

group agreed to make this a priority for v2.2 release

ACTION: establish working plan for implementing guides for v2.2

v2.2 roadmap

see https://github.com/w3c/dpv/milestone/7

latest state of consent

<ghurlbot> Issue 114 In 27560-records, how to identify the latest consent state? (by coolharsh55)

beatrizEsteves: latest state of consent, Georg mentioned he has a implementation that is different from DCAT

georgKrog: no issue with DCAT, I meant we are not doing things with DCAT

harsh: DCAT v3, pointer to latest state = keep records separately, pointer to immutable consent = record changes separately - we discuss and show how these are implemented

georgKrog: need for historical status e.g. if an org sends a newsletter based on consent, and then you withdraw the consent, and then later reconsent again

ACTION: Add note to 27560 guide for above example in intro section

v2.2 planning

georgKrog: commonality or priority in v2.2 tasks?

beatrizEsteves: focus for next months is EHDS

harshPandit: (on behalf of Delaram) AI Act and risks/impacts associated with AI

georgKrog: AI Act, Rights from DGA and Data Act, to map all entities in new regulations - we have for DGA, but we don't have for Data Act, DSA, DMA;

harshPandit: clarify, priority as DSA and DMA are specific and if we have limited bandwidth what do we focus on

georgKrog: at least the entities and roles as these are useful in lots of use-cases

julianFlake: preference for privacy and data protection aspects, and how these are covered or affected by additional laws - we can discuss; but not particularly interested in covering new topics

julioHernandez: extensions, concepts, how to get these to work?

harsh: guides, purpose of guides …. also tutorials – we also had the idea to do a workshop on how to build things with DPV

beatriz: agree, would be nice to have it, for the next version we should aim to have a tutorial

iainHenderson: P7012 work - we should have an update soon, and extended approach to data types and purposes

harshPandit: last week we had a small chat on Google and IAB data taxonomies and concerns around simply adopting them as is due to their misuse or not being aligned with legal implications

georgKrog: sectorial things for HR and Marketing

harshPandit: HR in DPV, marketing in sector - lets take this up when we have concrete ideas

julioHernandez: would like to see more guidance - the primer is clear, but need more help with how to use classes and properties

harshPandit: OWL, not interested in maintaining complexity, can do RDFS+SKOS examples as we go along

julioHernandez: when reading the Primer, it is not clear what can be done or not with expressiveness

harshPandit: the guide on RDFS/SKOS is supposed to help with this but as we discussed earlier it isn't available - so if we complete that it should help

AI Training

<ghurlbot> Issue 82 Provide vocabulary to specify purposes and permissions related to AI training (by scottkellum)

harsh: there was a question raised in the last meeting as to the source of concepts - I used ISO 22989 which has concepts related to training. That standard is currently being revised. There are also other standards which build on top of this for specific aspects, but haven't used them here yet. There are some new standards coming later this year for privacy in/of AI systems which should be of interest to this group.

discussed implication of concepts - what is the focus?

julianFlake: the focus of this group is on privacy / data protection - so we should be careful about adding things simply because they are about AI

harsh: agree - can rely on you to be the voice of caution here. We want to explore this concepts to indicate things related to privacy / data protection such as what data is being used, where does training occur, and so on.

harshsr: the questions raised at the moment are about our concepts - do these new ai + privacy concepts go to DPV or AI extension? Should training be a Process or Processing? How to note where it occurs? etc.

group discussed the need for use-cases to discuss this work further, harsh will circulate these based on work done so far

ACTION: harsh to share AI training use-cases on mailing list

Subjective Locations

<ghurlbot> Issue 209 [Concept]: `AtX` subjective Location concepts (by coolharsh55)

harsh: similar to AI training, explored concepts (see issue) with three use-cases: home, shop/mall CCTV, and app/device - it seems to work.

group discussed wanting to see use-cases and examples to discuss this work further, harsh will circulate these based on work done so far

ACTION: harsh to share subjective locations examples on mailing list

Inverted Locations

<ghurlbot> Issue 208 [Concept]: Add Non-X (X = specific location) to represent locations that are not X (by coolharsh55)

harsh: identified rationale for why these are needed, most of the time they won't be useful or they can be replace by programmatically checking e.g. location not in EU, but at other times directly specifying the non-EU concept is useful

georgKrog: this is an important aspect as there are legal procedures which consider such distinctions; so saying this applies to a jurisdiction or things outside the jurisdiction helps (i.e. for this, and for not this but other things)

group discussed this, and agreed to continue the discussion with further use-cases and examples

ACTION: harsh to share rationale and examples for non-EU concept to mailing list

Next Meeting

The next meeting will be on FEB-27 Thursday 13:30WET/14:30CET

Agenda will be reviewing and finalising release of v2.1, and continuing discussion on topics started under v2.2

Summary of action items

  1. establish working plan for implementing guides for v2.2
  2. Add note to 27560 guide for above example in intro section
  3. harsh to share AI training use-cases on mailing list
  4. harsh to share subjective locations examples on mailing list
  5. harsh to share rationale and examples for non-EU concept to mailing list
Minutes manually created (not a transcript), formatted by scribe.perl version 217 (Fri Apr 7 17:23:01 2023 UTC).