W3C

DPVCG Meeting Call

06 AUG 2025

Attendees

Present
ArthitSuriyawongkul, BeatrizEsteves, DelaramGolpayegani, HarshPandit, JulianFlake, JulioHernandez, PaulRyan, SokolAnna, StratisKoulierakis, TyttiRintamaki
Regrets
GeorgKrog
Chair
HarshPandit
Scribe
HarshPandit

Meeting minutes

Repository: w3c/dpv

Agenda: https://www.w3.org/events/meetings/178d1c71-a92d-4da7-a196-6a89d0fe2277/20250806T133000/

Meeting minutes: https://w3id.org/dpv/meetings

Persistent ID for current minutes: https://w3id.org/dpv/meetings/meeting-2025-08-06

Note change in meeting link

v2.2

<ghurlbot> Issue 301 dpv 2.2 draft review (by coolharsh55)

Beatriz's review

<ghurlbot> Issue 351 DPV Rule Fulfilment Status - naming and alignment with ODRL (by coolharsh55)

BeatrizEsteves: breaking changes regarding how to name the Rules terms, this is for consistency with ODRL CG work that is ongoing (re. RuleFulfilmentStatus) – these are probably new concepts so not a breaking change

discussion around the phrasing i.e. the terms using Fulfilment vs Performed. ODRL CG prefers using Performed. Legal terminology may prefer fulfilment

BeatrizEsteves: have kept fulfilment for existing concepts except prohibition which uses not performed

JulianFlake: "performed" is about whether an activity i.e. whether it is being performed (while being prohibited). Phrasing is confusing as I cannot perform a prohibition

BeatrizEsteves: we can have a note that these concepts may change to be aligned with ODRL CG

HarshPandit: we have two choices then 1) we keep existing terms with this note; or 2) we change the terms to ODRL CG ones with the note for future change

JulianFlake: agree on trying to align with ODRL work, if there is a way to combine these phrasing with "Activity" then it will be more clear

BeatrizEsteves: then we might as well use ODRL terms like "Action" to keep things aligned / consistent

ACTION: Check with Georg regarding legal implication of Rules terminology

updates post-meeting discussion GeorgKrog: performance and fulfilment/violation are distinct. Performance can happen in stages where the state is in between things e.g. if parts of an obligation or prohibition must be performed at different times then performance can happen with incomplete fulfilment (or violation). So "performed" is ambigious here.

updates post-meeting discussion HarshPandit: for DPV, we should focus on explicit clarity for legal interpretation. So we should not use performance for this reason, and for prohibition, we should stick with ProhibitionViolated and ProhibitionNotViolated.

Breaking changes in IRIs

<ghurlbot> Issue 331 v2.2 breaking changes (by coolharsh55)

HarshPandit: last time we discussed typos, but we also have EN-US and we use EN-GB; Art has been busy figuring out where all of these occur - see issue.

PaulRyan: important to have consistency - so make the breaking changes

BeatrizEsteves: agree, otherwise there will be more changes in the future

JulianFlake: agree

HarshPandit: then I propose to implement these fixes

HarshPandit: I also propose we flag this as a major change due to the amount of changes and the change being in some old concepts

BeatrizEsteves: links will change so yes major

PaulRyan: we should check with Georg on this as he is using it

HarshPandit: they use these as identifiers AFAIK, so we should give a heads-up maybe via a month period before we implement these changes

HarshPandit: then let's publish 2.2 as beta, put in master branch, but leave the LATEST_VERSION w3id iri to 2.1

BeatrizEsteves: agree

ArthitSuriyawongkul: agree

discussed above — agreed

Submission to LOV

<ghurlbot> Issue 353 v2.2 LOV submission (by coolharsh55)

will be done after final release in September

political statement in LOC

<ghurlbot> Issue 328 Add statement on political implications of LOC modelling (by coolharsh55)

no issues identified, agree to continue with this note

AOB

policy on adoption of external work

HarshPandit: If there is a specific work that is not a standard (e.g. we have adopted ISO 27560 and 3166) or a law (e.g. EU GDPR), then what is our policy on adopting it? This work could be by an individual/group, or it could be by a community.

HarshPandit: Considerations:
… 1) Is it open? (i.e. the work being submitted is not proprietary, copyrighted, as this falls afoul of the W3C policies on contributions)
… 2) Why is it being put here / proposed here? Why not elsewhere?
… 3) Does it fit the scope of the DPVCG?
… 4) How does it relate to existing DPVCG work? E.g. is it extending any of these, and thus merits from being part of the DPVCG?
… 5) What is the effort required to integrate it? Maintain it? Is this support reciprocally provided by the contributors? Are they members of the DPVCG?
… Examples based on past adoption of external work
… 1) GConsent for consent modelling in DPV
… 2) ISO 27560 draft work for consent modelling in DPV
… 3) DPCat for enhancing DPV, and considering developing a guide based on DPCat for ROPA
… 4) AI Cards proposed to be adopted in DPV (represented)
… 5) Model Cards and Data Sheets proposed to be adopted (represented)
… 6) IEEE P7012 as an extension to support its implementation

ArthitSuriyawongkul: Will we take it differently if the community group is working towards the standardisation of some of their work? For example, the SPDX community (under Linux Foundation) that I work with is not a standard body but their work are going towards ISO/IEC 5962 or CycloneDX (under OWASP) that works toward ECMA https://tc54.org/cyclonedx/ --- but for these communities, not all of their work are go to the formal standardisation process

HarshPandit: in this case they are a level below standards orgs, but they are widely accepted as best practices / commonly used so we treat them as such

StratisKoulierakis: they are not widely accepted as such in the legal frameworks, but they have a level of acceptability by the data protection authorities; For these and codes of conduct you also need to see who is abiding/adopting them. But I don't consider them as standards for the data protection (privacy?) vocabulary

SokolAnna: IBM Risk Atlas Nexus work which has been suggested to be submitted to DPV -- documentation for benchmark data https://ibm.github.io/risk-atlas-nexus/ontology/BenchmarkMetadataCard/ and https://arxiv.org/abs/2410.12974

ACTION: Add this to the wiki page for contributions

standards

StratisKoulierakis: will share standards that can offer subclasses or profiles for controllers for example (shared as: https://www.edpb.europa.eu/our-work-tools/accountability-tools/certification-mechanisms-seals-and-marks_en and https://www.edpb.europa.eu/our-work-tools/accountability-tools/register-codes-conduct-amendments-and-extensions-art-4011_en)

StratisKoulierakis: codes of conducts are legal measures; some of them are not in English; they are candidates for creating extensions/profiles; there are also certifications. These standards are "checklists" for someone to receive data protection certification for compliance with the law e.g. for TOMs. These may not be for specific sector (i.e. sector-agnostic), but they are important as they can give clarity/emphasis to the DPV's concepts/vocabulary

HarshPandit: So the approach to utilise here is 1) identify the vocabulary from these documents and whether we have those concepts in DPV; 2) express the standard/certification as a DPV extension or guide and way to check/document these

Meeting links

MS Teams is okay

JulianFlake: suggested BBB room hosted by Uni. Koblenz

ACTION: Harsh to follow up to check on use of BBB

Next Meeting

The next meeting will be on AUG-13 Thursday 13:30WEST/14:30CEST (new time slot)

Agenda will be finalising DPV v2.2 beta release, and starting work on v2.3 -- with a preference to identify topics for discussion where materials/arguments exist and so that we can revist what needs to be done for them.

Summary of action items

  1. Check with Georg regarding legal implication of Rules terminology
  2. Add this to the wiki page for contributions
  3. Harsh to follow up to check on use of BBB
Minutes manually created (not a transcript), formatted by scribe.perl version 217 (Fri Apr 7 17:23:01 2023 UTC).