Meeting minutes
Persistent ID for current minutes: https://
Meeting minutes: https://
Previous minutes: https://
Admin
managing examples (volunteers?)
Julian: examples can be in DE-GDNG, but there are no numbers for extensions; and SECTOR-HEALTH examples which can help with GDNG
managing requirements, use-cases (how to do this? volunteers?)
DPV 2.4
proposed work program
Julian: https://
extension for India's DPDP
Julian: w3c/
Harsh: proposed way to do legal extensions
Julian: We went article by article and captured concepts that we felt are central and relevant to the law, and then captured them in the table; and discussed hypothetical use-case as we don't have a real case that already shows what is compliance. It was subjective or opinionated decision on whether a concept is relevant or not. And there was also the issue of whether to include all aspects of the regulation or only some.
Julian: We did one interpretation, so this could be changed in the future based on what the government. Having a real use-case is very helpful.
Christian: In terms of use-case, GDNG is a bit more complicated as it defines obligations or agencies that the govt is still implementing or figuring it. So we have something like a partial usecase and we thought about the technical use-case but not beyond that.
Christian: To go article by article, the question was then which concepts go into the extension, e.g. Julian was the expert who knows DPV and therefore could advise.
Julian: What is the definition or criteria that decides whether a concept is in an extension or not. The criteria we used was based on a synthetic use-case or by asking experts like Christian and colleagues. The question is how do we decide on whether to include a concept or exclude a concept. Except maybe a use-case demands to have an use-case included.
Ajay: Makes sense to go article by article to identify and prioritise the concepts. The govt. of India has notified about a deadline for specific parts of the law to be implemented. So it also helps decide the priorities on the concepts.
Ajay: Not sure about whether all of the articles would be relevant from the DPV perspective.
Harsh: let;s keep a document noting these things and then we can use them as a discussion / self-reflection e.g.
Christian: we can do this for some examples, but not all the concepts.
work program for EHDS
Christian: w3c/
… no updates
update DE-GDNG
Christian: w3c/
Julian: we have goals (see issue) for the next release and discussed how to disseminate and how to validate the work/extension. We felt we should have some use-cases. There is a new public register for health data applications and 2 weeks ago the first application was published. No other relevant updates.
Harsh: That's a good idea, i think we should do this for all other projects/works.
working with/on HealthDCAT-AP
Harsh: w3c/
… no updates
AI model openness
Harsh: w3c/
… look at the issue, the proposal is clear and complete, seems useful for AI Act etc.
AI Documentation (e.g. Datasheets and Model Cards)
Harsh: w3c/
working with/on MLDCAT-AP
Harsh: w3c/
… Fabian and Harsh will have proposals about AI Act documentation regarding gaps (in Datasheet, Model Card, but also other semantic resources like MLDCAT-AP and DPV)
proposal on AI Act Art.50 transparency regarding generation vs use
Harsh: w3c/
Muhsin: We are looking for concepts and think these are missing from DPV. If some data is generated by AI, there is a label for that. But then how to express whether the person uses it fully (directly) or modifies it?
… 1) concept for AI generated content
… 2) concept for directly using AI generated content
… 3) modifying and then using content generated by AI
Harsh: what is meant by modified?
Muhsin: e.g. paragraph generated by AI is modified
Delaram: If you use GenAI to generate text, then the obligation is to mark it as AI generated in a way that it is clear. So if you wrote a paper using AI, do you disclose that?
Muhsin: Our project is on how to disclose this accurately.
Delaram:
… https://
Delaram: Also relevant are the concepts for Human Oversight concepts
Harsh: First we should consider if this is in scope
Delaram: This is certainly in scope for the AI Act, but this is also going beyond it as it relates to transparency and accountability of AI
Delaram: Also thinking about GenAI watermarking, don't know what technical measures there are to implement that. Would be interesting to note if these concepts would be relevant to provide these measures for compliance.
AOB
Harsh: 1) consent work Article 88b and how it relates to DPV 2) Incident notification under AI Act and using DPV's work on data breach (GDPR) and security incident notification (NIS2)
Updates
(not on agenda, discuss on Github/mailing list)
Issues with DPV:27560 re. identifiers and notices
Harsh: w3c/
Clarification on structure of receipts in 27560
Harsh: w3c/