W3C

DPVCG Meeting Call

24 SEP 2025

Attendees

Present
BeatrizEsteves, DelaramGolpayegani, HarshPandit, JulianFlake, JulioHernandez, MaryamMohammadi, PaulRyan, TyttiRintamaki
Regrets
GeorgKrog
Chair
HarshPandit
Scribe
HarshPandit

Meeting minutes

Repository: w3c/dpv

Agenda: https://www.w3.org/events/meetings/178d1c71-a92d-4da7-a196-6a89d0fe2277/20250924T133000/

Meeting minutes: https://w3id.org/dpv/meetings

Persistent ID for current minutes: https://w3id.org/dpv/meetings/meeting-2025-09-24

Previous minutes: https://w3id.org/dpv/meetings/meeting-2025-09-17

v2.2 published

v2.2 has been published! -- https://lists.w3.org/Archives/Public/public-dpvcg/2025Sep/0004.html (mandatory 🍕🍺 celebration)

Nominating Chair

<ghurlbot> Issue 389 DPVCG chair nomination (discussion) (by coolharsh55)

HarshPandit: Call for nominating DPVCG chair https://lists.w3.org/Archives/Public/public-dpvcg/2025Sep/0005.html (tracking issue https://github.com/w3c/dpv/issues/389)

BeatrizEsteves: I suggest this be similar to ODRL CG which has several co-chairs so that different expertises can be utilised

HarshPandit: yes that is possible - its option 3 in the email

HarshPandit: suggest discussions going on until OCT-31 and we take a decision in the next meeting

Generic Places

<ghurlbot> Issue 384 Modelling Generic Locations/Places (e.g. Airport, School) (by coolharsh55)

JulianFlake: Christian mentioned in the last meeting that there must be a vocabulary for such concepts; and then whether these are public/private

HarshPandit: There are existing vocabularies e.g. https://lov.linkeddata.es/dataset/lov/terms?q=airport

JulianFlake: Also where to draw the line the line in terms of granularity? E.g. different kinds of airports, underground stations and such

HarshPandit: propose to keep issue open to collect concepts from normative sources and also other vocabularies that exist; once we have sufficient concepts we can discuss further

HarshPandit: Do what we have is sufficient for AI Act high-risk and prohibited cases?

DelaramGolpayegani: We have workplace and public places so it depends on how detailed we want to be. Guidelines on Prohibited published by the Commision https://digital-strategy.ec.europa.eu/en/library/commission-publishes-guidelines-prohibited-artificial-intelligence-ai-practices-defined-ai-act (so this is normative)

HarshPandit: thanks, this is a good source to find place concepts

DelaramGolpayegani: Commission will be publishing further guidelines on AI Act in two parts https://www.mlex.com/mlex/articles/2391196/eu-commission-splits-ai-act-s-guidelines-on-high-risk-systems - with clarification obligations and risk management etc. Don't know what happens after this due to the Draghi report and stop the clock etc.

the issue will be kept open to collect concepts and use-cases - in particular from authoritative sources like the prohibited systems guideline for AI Act, at the same time we will identify whether there are other vocabularies such as those in LOV that can represented these concepts; if not - then the discussion will be whether to provide these via DPV

Service Maintainence

<ghurlbot> Issue 287 [NEW]: Add Maintenance as a `dpv:Purpose` (by besteves4)

BeatrizEsteves: this was a use-case related to AI Act / IoT data. We wanted to use policy with a purpose about maintaining services and products.

HarshPandit: ServiceManagement is proposed as the top concept similar to other Management concepts, and then within this we have ServiceMaintainence and ServiceProvision. What needs to be discussed is what should be the hierarchy as currently we have put all service related concepts under ServiceProvision. This was because at the time, we were thinking that what should be expected as part of service provision.

BeatrizEsteves: Do definitions exist for these new concepts?

HarshPandit: Yes (explanation of concepts)

BeatrizEsteves: This will be a breaking change (for parents changed), so better check with people e.g. Georg who implement this

PaulRyan: +1

HarshPandit: The reason for separation is the possibility that there are different legal bases e.g. ServiceProvision is as per the contract, however ServicePersonalisation can be based on legitimate interest or consent, and ServiceMonitoring can be part of a legal obligation. So if there is a hierarchy of purposes and it would be good to keep the purposes distinct to reflect and support such distinctions.

PaulRyan: Agree, this is how it works for cookies, so this is a valid point

we agree on ServiceManagement and ServiceMaintainence as concepts but need to confirm the hierarchy

Purpose Compatibility for GDPR

<ghurlbot> Issue 298 Model Purpose Compatibility statuses for GDPR (by coolharsh55)

BeatrizEsteves: so is the idea that we take two purposes and then state whether they are compatible? (yes) Do we have a use case for this?

HarshPandit: yes, for example if you have obtained consent for purpose A, and now you want to use that data for purpose B, then you must assess and ensure that A is compatible with B. If not, then you must either ask for consent again or look for a different legal basis. This assessment is what is represented in this concept, and the outcomes are the instances.

HarshPandit: for reference, ICO page on compatible and incompatible purposes https://ico.org.uk/for-organisations/uk-gdpr-guidance-and-resources/data-protection-principles/a-guide-to-the-data-protection-principles/purpose-limitation

BeatrizEsteves: agree this is necessary, but thinking of how to use this process

HarshPandit: Using ODRL, Policy A exists and you want to check if policy B should be accepted or not. For this, you check the purpose compatibility and then record that B was accepted because PurposeCompatible or rejected because PurposeIncompatible. When modelling purpose constraints, you want to assert that they must be compatible -- whereas in an assessment you are checking whether two purposes are compatible. So you can note that in a contraint that the purposes must satisfy and give PurposeCompatible as outcome.

BeatrizEsteves: Have to think about this

HarshPandit: (we are only declaring there is an assessment and there are two outcomes possible - compatible and incompatible)

to be continued next week

Proportionality for GDPR

<ghurlbot> Issue 386 Model Proportionality for GDPR (by coolharsh55)

to be continued next week

ACTION: Review GDPR Proportionality by Georg and Stratis

CRDM AI taxonomy

<ghurlbot> Issue 385 Align DPV with CRDM AI concepts (by coolharsh55)

mapping is available - see issue ; to be discussed next week

LEGAL DE-GDNG

<ghurlbot> Issue 387 Extension for the German GDNG (by chhdraeger)

JulianFlake: meeting scheduled for this/next week, so will report back

AOB

Submit v2.2 to LOV

<ghurlbot> Issue 353 v2.2 LOV submission (by coolharsh55)

BeatrizEsteves: Should we discuss how to submit to LOV? (yes)

ACTION: Beatriz and Harsh to work on submitting DPV v2.2 to LOV

Next Meeting

The next meeting will be on OCT-01 Thursday 13:30WEST/14:30CEST

Agenda will be continuation of today's discussion regarding service maintainence, purpose compatibility, and proportionality/necessity, DPV 2.2 submissions, and additional items from v2.3 milestone.

Summary of action items

  1. Review GDPR Proportionality by Georg and Stratis
  2. Beatriz and Harsh to work on submitting DPV v2.2 to LOV
Minutes manually created (not a transcript), formatted by scribe.perl version 217 (Fri Apr 7 17:23:01 2023 UTC).