Meeting minutes
Repository: w3c/dpv
Agenda: https://
Meeting minutes: https://
Persistent ID for current minutes: https://
Previous minutes: https://
DPVCG Charter
<ghurlbot> Issue 399 Establish DPVCG Charter (by coolharsh55)
HarshPandit: Working document: https://
HarshPandit: Thanks to comments from Julian and Beatriz.
BeatrizEsteves: For the scope, we have stated only privacy and data protection. So wondering if we should rephrase this to include our work on AI Act. Sentence added by Harsh for this is okay.
BeatrizEsteves: Lots of acronyms like ODRL, RDF, etc. Not sure everyone knows what this means.
BeatrizEsteves: (not much of relevance for CG charter) since this charter will also be going for the WG charter, so what should be the most important thing that goes to WG should be clear
HarshPandit: W3C CG council will help on this to put together a charter for the WG from the CG charter
BeatrizEsteves: ODRL CG is also working on converting the spec to a WG charter/work. Expected to happen in March.
JulianFlake: maybe list of liaisions and dependencies should be left our of the charter since they would imply constant updating. Liason is okay, but dependencies implies a strong requirement. List of liasons also implies a need to update the charter everytime we add/remove a liason, and also could be an issue for a group not listed here as to why we aren't we liasing with them.
HarshPandit: Proposed clarification and that we will update the list next time.
HarshPandit: Next step is to share this with the group on mailing list with a link to the document on our website - main repo. We have 20-30 days to comment and then we decide in these meetings through consensus.
agreed
Signals/GDPR Art.88b
<ghurlbot> Issue 410 Represent Privacy Signals like GPC, ADPC, and others (by coolharsh55)
HarshPandit: The proposed GDPR amendments under Omnibus have a good measure in Article 88b on signals for consent. The article states that the Commission will have to develop a harmonised standard to implement a setting for devices and browsers to implement a management interface to both give and refuse/withdraw consent. Obviously, this will take time as the law and the standard are both processes that take years. In the meantime, what should we do?
HarshPandit: The Commission may be interested to know more about DPV and how it works with MyTerms/IEEE 7012 where our extension provide privacy terms. Similarly, consenter.eu has proposed using ADPC with DPV to communicate what the consent is about.
HarshPandit: Should this be something that the DPVCG should work on more to support the measures? If so, how?
GeorgKrog: Also relevant here that Signatu implements DPV for consent management
HarshPandit: Indeed, but its important here to show that the specifics of Article 88b are being implemented (using DPV), so Signatu will need a new implementation that shows a new implementation for the management features. Could be based on MyTerms or ADPC and using DPV.
BeatrizEsteves: This is also relevant for Solid and the work in Flanders/Belgium. But the consent management only provides information, there is no enforcement. There should be enforcement / usage control.
HarshPandit: This is the current state of the proposals and law, where we must first work hard to even convince that signals/DPV/etc. are feasible and should be mandated to be used. Otherwise we have adverserial lobbying that says this is too expensive to implement or is technically not feasible. So our task here would be to show that this is feasible, we've done it, and that we also have real implementations like in Signatu and Solid/Flanders that shows this is needed and operationally feasible.
HarshPandit: For enforcement, we need support from environments like devices and browsers, which is very hard. We can do things after the initial steps are firmly in place, like if consent has been refused for a purpose, don't release the location information via the API. Someone will need to show how this needs to be done step by step. I'm planning to write something on this over the holiday break. Will share when done.
HarshPandit: Had written this previously about implementation, but didn't work on it further: "Proposals for Resolving Consenting Issues with Signals and User-side Dialogues" https://
HarshPandit: Of relevance, our recent paper "Can the GPC standard eliminate consent banners in the EU?" https://
Updates
ISO taxonomy
<ghurlbot> Issue 26 DPV-ISO providing concepts from ISO terminology and standards (by coolharsh55)
ACTION: Harsh to organise meeting with Stratis, then loop in others to create a proposed solution for ISO taxonomy
EHDS
<ghurlbot> Issue 238 Update EHDS extension with practical concepts (by coolharsh55)
ACTION: Beatriz, Georg, Harsh to discuss EHDS on DEC-17 16:00+2 CET
AI Act
<ghurlbot> Issue 229 Update EU-AIAct extension with practical concepts (by coolharsh55)
ACTION: Delaram, Georg, Harsh to discuss AI Act on DEC-19 14:00+2 CET
NIS2
<ghurlbot> Issue 222 Update NIS2 extension with practical concepts (by coolharsh55)
ACTION: Georg, Harsh to discuss NIS2 on incident notifications and assessments asnyc
DE-GDNG
<ghurlbot> Issue 387 Extension for the German GDNG (by chhdraeger)
JulianFlake: Had two meetings with Christian and colleagues to discuss use-cases and how DPV and ODRL fits. Work is progressing.
CRDM/EIT AI Concepts
<ghurlbot> Issue 385 Align DPV with CRDM AI concepts (by coolharsh55)
<ghurlbot> Issue 390 Adding the taxonomy of AI capablities from EIT report (by DelaramGlp)
HarshPandit: Suggest we resolve this async on github issues as we have identified the concepts and they are additions to the AI taxonomy. We can use the meetings only to reach conclusions while discussions happen on github.
AOB
HarshPandit: Came across this paper in 2024 on an ontology called "OntoPriv" https://
Next Meeting
The next meeting will be on DEC-17 Wednesday 13:30WET/14:30CET
timeline for last meeting wed before Christmas DEC-17, restart first Wed new year JAN-07 -- works for everyone