Submission request to W3C (W3C Team Comment)
We, the W3C member International Business Machines (IBM), Inc. hereby submit to the Consortium the following specification, comprising the following document attached hereto:
which collectively are referred to as "the submission". We request the submission be known as the EPAL submission.
This is the Enterprise Privacy Authorization Language (EPAL) technical specification. EPAL is a formal language for writing enterprise privacy policies to govern data handling practices in IT systems according to fine-grained positive and negative authorization rights. It concentrates on the core privacy authorization while abstracting data models and user-authentication from all deployment details such as data model or user-authentication.
An EPAL policy defines lists of hierarchies of data-categories, user-categories, and purposes, and sets of (privacy) actions, obligations, and conditions. user-categories are the entities (users/groups) that use collected data (e.g., travel expense department or tax auditor). Data-categories define different categories of collected data that are handled differently from a privacy perspective (e.g., medical-record vs. contact-data). Purposes model the intended service for which data is used (e.g., processing a travel expense reimbursement or auditing purposes).
Actions model how the data is used (e.g., disclose vs. read). Obligations define actions that must be taken by the environment of EPAL (e.g., delete after 30 days or get consent). Conditions are Boolean expressions that evaluate the context (e.g., "the user-category must be an adult" or "the user-category must be the primary care physician of the data-subject").
These elements are then used to formulate privacy authorization rules that allow or deny actions on data-categories by user-categories for certain purposes under certain conditions while mandating certain obligations. In order to allow for general rules and exceptions, EPAL rules are sorted by descending precedence. E.g., a rule about a particular employee can be inserted before the rule about the department in order to implement an exception.
We hereby grant to the W3C, a perpetual, nonexclusive, royalty-free, world-wide right and license under any of our copyrights in this contribution to copy, publish and distribute the contribution as defined by the W3C Document License (see http://www.w3.org/Consortium/Legal/2002/copyright-documents-20021231)
We suggest that the W3C Consortium publish this document as a note in order to educate the WWW community.
Inquiries from the public or press about this submission should be directed to Steven Adler <adler1 (at) us.ibm.com>
10 November 2003
Arnaud Le Hors, IBM, firstname.lastname@example.org