14:00:43 RRSAgent has joined #dpvcg 14:00:43 logging to https://www.w3.org/2018/10/16-dpvcg-irc 14:01:51 stefano has joined #dpvcg 14:02:18 present+ Rigo 14:02:31 trackbot, start meeting 14:02:34 agenda: https://lists.w3.org/Archives/Public/public-dpvcg/2018Oct/0015.html 14:02:34 RRSAgent, make logs public 14:02:34 Zakim has joined #dpvcg 14:02:35 Meeting: Data Privacy Vocabularies and Controls Community Group Teleconference 14:02:35 Date: 16 October 2018 14:02:50 scribe: rigo 14:03:08 scribe: harsh 14:03:17 chair: axel 14:03:42 Axel: Introduction, New members (Niklas). 14:04:10 Niklas: Masters student at WU working on Privacy. Helping with existing categorisation and taxonomies (Axel). 14:04:53 Axel: Everyone who is new should create a web page with some details of their profile on the wiki. 14:05:34 PROPOSED: approve last meeting minutes https://www.w3.org/2018/09/18-dpvcg-minutes 14:05:40 +1 14:05:46 Axel: discussing minutes from last meeting (the previous telecall was cancelled,) so the last meeting was 18 September. 14:06:01 Axel: Any objections, questions? 14:06:06 Eva: No objections 14:06:18 RESOLVED: approve last meeting minutes https://www.w3.org/2018/09/18-dpvcg-minutes 14:06:51 Axel: Going through the action items. Currently, many items open (most for myself and Bert) 14:06:53 topic: https://www.w3.org/community/dpvcg/track/actions/open 14:07:00 Sabrina has joined #dpvcg 14:07:09 present+ sabrina 14:07:15 ACTION-6 continued 14:07:17 Axel: For Opera use-case, do we have Michael here? 14:07:27 14:07:38 ACTION-7 continued 14:07:55 Axel: Bert for discussion on SPECIAL use-cases (Bert N/A today) 14:08:50 Axel: Editing Action 14 14:09:14 Javier has joined #dpvcg 14:09:33 Rigo: It's easier to use the bot to interact with the Actions 14:09:45 it 14:09:57 's easier to use the web to edit actions 14:10:13 Axel: Action 17 - propose to close this action 14:10:35 Eva: it would be useful to know whether the template for the use-cases would be useful, feedback on changes would be useful 14:10:44 Axel: We can put this on the agenda for the next meeting 14:11:14 Eva: If anyone notices anything odd/wrong or to improve the template, we should discuss this 14:11:39 Axel: We are looking for categories of data, processing, etc. This should be reflected in the use-case, which it currently is not. 14:12:11 https://www.w3.org/community/dpvcg/wiki/Use-Cases,_Requirements,_Vocabularies 14:12:20 ... discuss templates next time, my feeling is that the categories we discussed now are better reflected in the template. 14:12:34 Eva: Maybe we can add a new option for looking at the required terms/concepts in the templates 14:13:08 Rigo: I can help with the templates 14:13:11 ACTION: eva to look over the use cases template to reflect better what we agreed upon as requirements/priorities last time. 14:13:11 Created ACTION-26 - Look over the use cases template to reflect better what we agreed upon as requirements/priorities last time. [on Eva Schlehahn - due 2018-10-23]. 14:13:29 close ACTION-14 with reference to new action-26 14:13:40 close ACTION-14 14:13:40 Closed ACTION-14. 14:13:59 close ACTION-17 14:13:59 Closed ACTION-17. 14:14:17 Axel: Accidentally closed Action 14 instead of Action 17. Re-opening Action 14. 14:14:30 ACTION-14 reopened. 14:14:55 Axel: Action 18 for MyData use-cases 14:15:10 Stefano: I went through the high-level use-cases and added them to the use-cases list 14:15:13 2 use cases added from myData added 14:15:27 close ACTION-18 14:15:27 Closed ACTION-18. 14:15:51 Axel: Action 19 contact digi.me is continued 14:16:31 ACTION-20 and ACTION-21 have been closed by Eva... 14:16:32 Eva: Action 20 (added to wiki) and 21 (talk to Eva regarding BDVA) were closed before call. 14:17:12 https://www.w3.org/community/dpvcg/track/actions 14:17:30 ACTION: Axel to put discussion on new use cases on the agenda 14:17:30 Created ACTION-27 - Put discussion on new use cases on the agenda [on Axel Polleres - due 2018-10-23]. 14:18:00 The above link shows all actions of the group, regardless of being closed or open 14:18:50 Axel: Action 23 Talking with Bert about refining scope/schedule of group. Proposed to postpone until F2F meeting. 14:19:06 Rigo: Where will it be? I will be there. 14:19:17 Axel: Propose to keep the action open and talk about it at F2F in London 14:19:24 Axel: talk about a timeline and milestones in London. 14:20:30 Axel: Action 24 This is a mixture of the new action for Eva. This could be left open, to specify that all use-cases reflect the requirements, regarding concepts. 14:20:36 https://www.w3.org/community/dpvcg/wiki/Taxonomy 14:20:44 close ACTION-25 14:20:44 Closed ACTION-25. 14:21:31 Axel: Definitions from terms appear to have been instantiated 14:21:43 These are from the email (from Niklas) containing defintions from GDPR 14:22:01 topic: definitions 14:22:32 Axel: Question - how far these definitions are sufficient for us? Are the definitions from GDPR sufficient? There was some discussion on the definition of consent in the mails. 14:23:15 Eva: How close should stick to the GDPR definitions? We should be careful if we deviate from the GDPR too much. Terms such as from USA, that sound similar, have different scopes in terms of legal definitions. 14:23:26 consent = agreement with a [data controller] to specific [processing] of specific [data categories] for specific [purpose] 14:24:28 Rigo: We have to think this for the goal we want to achieve. It's of no use if we re-define a legal definition. The legal definitions are what the courts will use. Such as what informed consent means. And if our definition doesn't contain that, then we need to transform the court decision to re-use the term. The taxonomy itself should use the data-controller. 14:25:42 Rigo: For taxonomy, we have to term Data Controller, and then we can dissect or find out if the term is made out of several additional requirements. For me, it is a second step. Because then, in law, you can dive into infinite refining of definitions. If we try to drill down, we can do that endlessly, and we end up in loops. 14:25:55 Eva: I agree with Rigo, we need to be clear with what the taxonomy is supposed to do 14:26:21 Axel: My point is that, for e.g. consent needs refinement. The current definition is only a definition. 14:27:04 Rigo: If we want to make this useful, we need to make machine testable points. E.g. if we have consent, and it has click okay button. Legal definitions do not have machine interpretations. 14:27:38 Eva: Technology can help in this, but cannot help for cases such as user has not responded 14:28:02 consent = agreement through an [affirmative action] at a specific [time] with a [data controller] to specific [processing] and [storage] of specific [data categories] for specific [purpose] and [duration] 14:28:04 Rigo: It should help us for data handling and not in explaining what consent is. Taxonomy should reduce legal compexcity. 14:28:44 Eva: You could add a label for valid/invalid consent. IF someone gives consent, and later it is decided to be invalid by courts, technology can label it as such 14:29:16 +q 14:29:17 Niklas: The concept of validity and invalidity is already present in the definition 14:29:28 q+ 14:29:45 q+ 14:30:14 ack stefan 14:30:35 Stefano: If the discussion is on the definition of consent, or we are also discussing what should be in the consent. The components of consent would also be useful. 14:30:48 Stefano: If the consent does not have purpose etc. then it would not be very useful 14:30:56 q? 14:30:58 ack ri 14:31:37 rigo: if we fully define what consent is, we will hit the wall 14:31:43 Rigo: If we define what consent is, we will hit the wall at some point in time, because it will get very complex, and it does not serve the purpose of the algorithms that will use the taxonomy. 14:32:04 ... but we would need the components in a taxonomy 14:32:07 Rigo: I would like to see the related concepts/things about consent in the taxonomy 14:32:10 q+ 14:32:27 Rigo: In linked data, with the open world assumption, the NOT operator does not work very well. 14:32:51 Question to technicians: if something is close to the requirements, but does not trigger the consent (yes) variable, we can have the unset operator. 14:33:01 Maybe we need something like invalid consent and have statements on that. 14:33:39 Rigo: We shouldn't formulate things that should be in, related to, consent but have them in the taxonomy 14:33:47 q? 14:33:56 Rigo: For other approaches after/similar to GDPR, they can reuse this work 14:33:57 ack Axel 14:34:00 14:34:14 Rigo: because they consider it good enough 14:34:35 Axel: We have taxonomy as a container 14:34:50 Any freely given, specific, informed and unambiguous indication of the data subject’s wishes by which he or she, by a statement or by a clear affirmative action, signifies agreement to the processing of personal data relating to him or her. 14:35:01 consent = agreement through an [affirmative action] at a specific [time] with a [data controller] to specific [processing] and [storage] of specific [data categories] for specific [purpose] and [duration] 14:35:02 [4:28pm] 14:35:36 q+ 14:35:37 Axel: Consent is just an object which has the attributes (see text above) 14:36:07 Axel: We did not discuss which kind of actions are associated with consent, but we should include those. Such as clicking a button, for how consent is given. 14:36:14 Axel: We want to define taxonomies for this. 14:36:18 q+ 14:36:21 ack Eva 14:36:24 14:36:26 q- later 14:36:45 RRSAgent, please draft minutes 14:36:45 I have made the request to generate https://www.w3.org/2018/10/16-dpvcg-minutes.html rigo 14:36:47 Eva: We are thinking in the same direction. Stefano said he wants to see what things consent entails. Axel has mentioned elements of consent. 14:37:07 q+ niklas 14:37:08 Eva: We should also label statuses of consent - pending, given, denied 14:37:11 eva wants properties of consent 14:37:19 valid, invalid, given, pending 14:37:35 Eva: My slides at DPVCG workshop in Vienna had suggestions on this. This could be an action point for what are the elements for consent we need to define for the taxonomy. 14:37:50 Eva: We can learn from each other (different domains) to express this 14:38:03 Axel: Formulate this as an issue instead of an Action. (Rigo agrees) 14:38:17 ISSUE: What are the elements of consent? starting from "onsent = agreement through an [affirmative action] at a specific [time] with a [data controller] to specific [processing] and [storage] of specific [data categories] for specific [purpose] and [duration]" 14:38:17 Created ISSUE-4 - What are the elements of consent? starting from "onsent = agreement through an [affirmative action] at a specific [time] with a [data controller] to specific [processing] and [storage] of specific [data categories] for specific [purpose] and [duration]". Please complete additional details at . 14:38:35 q? 14:38:42 Niklas: The data structure should also be present in the general structure 14:38:54 Axel: Data subject, not data structure 14:38:55 s/structure/subject/ 14:39:13 ( Axel tries regex replace ) 14:39:53 q? 14:39:58 ack harsh 14:40:01 ack rigo 14:41:23 Proposal: have comptenency questions for properties/answer related to consent, and the answer would be what we would describe in taxonomy 14:41:25 ACTION: harsh to propose competence questions on what consent comprises 14:41:25 Created ACTION-28 - Propose competence questions on what consent comprises [on Harshvardhan Pandit - due 2018-10-23]. 14:41:50 q+ 14:41:53 Rigo: These can be formulated as points or questions, and we can transform them between each other using machines/automation 14:42:57 Rigo: This discussion exemplifies other things, we have conditions before 'A' is met, and the systematic of the GDPR says, we need a processor, and data subject, and we need the 'condition' that makes processing legal - which is what consent is under. 14:43:23 ACTION: axel to put review of issues list and starting time on the agenda template (note to self) 14:43:24 Created ACTION-29 - Put review of issues list and starting time on the agenda template (note to self) [on Axel Polleres - due 2018-10-23]. 14:43:45 Rigo: We need an annotation - legal (question mark) for legal processing, and we can have legal reasons such as necessity, security, and we can import all public law, such as contract law, which goes under consent, There is legitimate interest. 14:43:59 Rigo: What we are doing now with consent, we have do with the others 14:44:22 Rigo: And the taxonomy will go down in to sub-terms. And these would things that constitute informed-ness in consent. 14:44:42 Rigo: What we can do here with consent would be a template for how we treat the other consents 14:45:06 Rigo: Data Controller, Data Subject, Legal Processing are the top terms. (Eva agrees) 14:45:10 Axel: What is Legal Processing 14:45:22 Rigo: It is the opposite of illegal processing 14:45:36 Axel: We need processing categories, and then we decide if there are consent based or not? 14:45:46 Rigo: No, there are more basis for legal processing 14:46:06 ... certain processing can be permitted or prohibited by definition. 14:46:23 So we need overall constraints. 14:46:33 Eva: This is why defining consent as a permission can be tricky. Because in GDPR there are more permissions than consent. 14:46:41 Eva: Consent is one of several permissions. 14:46:52 eva: Some entity may be permitted by law for certain processing. 14:46:54 q? 14:47:06 ack nikl 14:47:14 ack Eva 14:47:45 eva: lynx is also doing a taxonomy 14:47:56 Eva: LYNX has data controller as the accounting manager of the company. This does not meet the GDPR requirements. 14:48:09 ... their glossary seems to be not compliant with GDPR 14:48:10 Legal basis for processing mentioned in GDPR: Contract with Data Subject, Exempted by National Law, Employment Law, Given Consent, Historic, Statistical, or Scientific Purposes, Legal claims, Legal obligation, Legitimate Interest, Made public by Data Subject, Medical, Diagnostic, or Treatement, Not for Profit Org. Public Interest, Purpose of New Processing, Vital Interest 14:48:31 Rigo: (response to Eva) They mean the person who is responsible 14:48:40 Eva: It can be different based on organisation 14:48:52 Rigo: A Data Controller is a natural/legal person 14:49:29 +q 14:50:12 Axel: We should try to do this in a sparse manner. Niklas' article to analyse terms and conditions shows that they are not understandable. Not sure whether we need to cover those. 14:50:20 Rigo: Don't do this. They are hard. 14:51:08 Axel: They have very complicated, nested expressions ranging from very broad to very specific. Not sure whether we want to cover such T&C. 14:51:30 Rigo: It is very very difficult to design a tree from the branches. It's much easier to design from the roots. (Axel agrees) 14:52:23 Rigo: Imagine this like a mindmap, where the relation is clear to a human but not to a machine. The challenge to technicians is to know what are the things that trigger whether a processing is permitted. This is a modelling challenge 14:52:51 "rigo: where can we use conditions, where permissions, where obligations?" sounds to me like mapping to ODRL 14:52:52 Rigo: What are the points that combined define consent as a legal basis? What do we have as permissions / logic operators ? 14:53:35 Eva: Ideas about labelling things beyond permissions 14:53:54 "The challenge to technicians is to know what are the things that trigger whether a processing is permitted" ... reminds me of Business process modelling 14:54:01 Rigo: We can label it as ODRL, as in GDPR we have the paradigm where everything is prohibited until we have a permission 14:54:15 Axel: Due to time, postpone the discussion to mailing list / next meeting 14:54:15 continue Definitions discusion on the mailinglist. 14:54:21 then everything turns into a permission, which may be difficult for the machines 14:55:05 topic: 5) Plan next meeting(s) and revisit timeline, particularly: F2F in Nov or Dec (around EBDVF or ICT18, both in Vienna) 14:55:13 Axel: F2F in Vienna. Option 1: Meet around or during EDF (European Data Value Forum) in November or ICT in December. 14:55:18 eva: will be at both 14:55:20 Eva: I will be at both 14:55:34 I will not very likely 14:56:01 Axel: Let us have a Vote. 14:56:07 Option A: 12-14 Nov 14:56:45 Where is ICT 2018? 14:56:49 Option B: 15 November 14:56:50 Vienna 14:56:56 Option C: 5 December 14:57:02 15 Nov does not suit due to lectures 14:57:08 Option D: 3 December 14:57:10 Axel is lecturing also 14:57:48 +1 Option C & Option D 14:58:03 D,C 14:58:31 I favor options A, C or D 14:58:36 We should also formally ask for preferences over the mailing list 14:59:00 Niklas: A,B,C,D 14:59:02 +1 Option C 14:59:06 I cannot make it 14:59:15 B, C, D 14:59:43 NIklas has joined #dpvcg 14:59:54 Option C and Option D has most votes (6 votes) 15:00:20 We aready have an agenda 15:00:25 it depends on that 15:00:26 present+ Sabrina 15:01:02 Next call on 6th November in Three weeks 15:01:07 ACTION: Axel to send a doodle poll over the list for F2F 15:01:08 Created ACTION-30 - Send a doodle poll over the list for f2f [on Axel Polleres - due 2018-10-23]. 15:01:13 (query by Axel) 15:01:17 no objections 15:02:27 q? 15:02:33 ack harsh 15:03:05 Axel: Proposal - slot in SPECIAL meeting for update to the group, otherwise the regular call will be on 6th November. 15:03:34 ( end of meeting ) 15:03:39 next regular DPVCG call 6 Nov, maybe an extra short call on 30October, but not yet confirmed. 15:03:49 rrsagent, please draft minutes 15:03:49 I have made the request to generate https://www.w3.org/2018/10/16-dpvcg-minutes.html rigo 15:05:41 @rigo, will you prepare the final minutes please? I need to run, would appreciate! 15:22:12 AxelPollleres has joined #dpvcg 15:40:18 AxelPollleres has joined #dpvcg 17:53:17 Zakim has left #dpvcg