12:54:15 RRSAgent has joined #dpvcg 12:54:15 logging to https://www.w3.org/2019/02/12-dpvcg-irc 12:54:17 RRSAgent, make logs public 12:54:20 Meeting: Data Privacy Vocabularies and Controls Community Group Teleconference 12:54:20 Date: 12 February 2019 12:54:24 Eva_Bud has joined #dpvcg 12:54:36 harsh has joined #dpvcg 12:54:44 regrets+ Martin 12:54:50 chair: Axel 12:55:27 agendabot has joined #dpvcg 12:55:31 agenda: https://www.w3.org/mid/EC031F3B-800F-40DF-9C37-D6B5041C8FCF@wu.ac.at 12:55:33 clear agenda 12:55:33 agenda+ Roll call, select scribe, agenda 12:55:33 agenda+ Approval of last telcon's minutes: 12:55:33 agenda+ Action items 12:55:35 agenda+ Issues 12:55:38 agenda+ Status of vocabularies/taxonomies 12:55:40 agenda+ AOB 12:56:10 present+ Bert, Eva, Bud 12:56:19 RRSAgent, make minutes v2 12:56:19 I have made the request to generate https://www.w3.org/2019/02/12-dpvcg-minutes.html Bert 12:56:57 agenda? 12:57:22 present+ 13:00:22 AxelPollleres has joined #dpvcg 13:00:30 gimme a second, dialing. 13:00:39 stefano has joined #dpvcg 13:01:41 Ramisa has joined #dpvcg 13:01:49 Fajar has joined #dpvcg 13:01:59 present+ Javier, Ramisa, Stefano 13:03:40 present+ Axel 13:03:51 scribe vounteers? 13:03:56 Javier has joined #dpvcg 13:04:07 scribe: javier 13:04:10 I need to leave in ~35 min 13:04:44 present+ Fajar 13:05:23 PROPOSED: approve minutes from last call https://www.w3.org/2019/01/22-dpvcg-minutes 13:05:28 +1 13:05:32 +1 13:05:40 +1 13:05:41 +1 13:05:46 RESOLVED: approve minutes from last call https://www.w3.org/2019/01/22-dpvcg-minutes 13:05:55 +1 13:06:14 topic: action items 13:07:17 ACTION: write an email to Michael Markevich on ACTION-6 and whether he still plans to join. 13:07:17 Error finding 'write'. You can review and register nicknames at . 13:07:35 ACTION: Axel to write an email to Michael Markevich on ACTION-6 and whether he still plans to join 13:07:36 Created ACTION-62 - Write an email to michael markevich on action-6 and whether he still plans to join [on Axel Polleres - due 2019-02-19]. 13:08:47 ACTION-11, ACTION-19 saved for later, when we have a first stable version. 13:09:06 close ACTION-29 13:09:08 Closed ACTION-29. 13:09:22 actions? 13:09:35 ACTION-33 still continued 13:10:39 Harsh and Fajar are taking over ACTION-34 13:11:32 Mark just joined 13:11:53 Mark: looked at categories for purposes and description definition, looking at the scope 13:11:58 present+ Mark 13:12:11 ... e.g. data types are definitively in scope 13:12:53 ... sector categories as well, UK define the core business purpose as a key activity 13:13:14 ... good item to define what's expected from a company 13:13:42 i.e., the core sector + purpose + core business purpose could be a good indicator of the purpose 13:14:04 ... This could be a good discussion point for the WG 13:14:05 Mark, ACTION-33: definition of about core business (purpose) plus processing give a description of what purpose is. 13:15:32 present+ Simon 13:15:38 close ACTION-37 (Axel finished it) 13:15:46 close ACTION-37 13:15:47 Closed ACTION-37. 13:16:30 Harsh created a github repository, he can transfer the ownership to the WG: https://github.com/dpvcg 13:16:45 ACTION-52: we can just use harsh's repo https://github.com/dpvcg 13:16:45 Notes added to ACTION-52 Ask bert about w3c github repository action from august and create a github under w3c for dpvcg. 13:16:56 close ACTION-52 13:16:56 Closed ACTION-52. 13:17:12 Every let harsh know their github username. 13:17:12 ... Harsh can add people to the repository, he just needs the github username 13:17:51 close ACTION-56 13:17:51 Closed ACTION-56. 13:18:25 close ACTION-57 13:18:25 Closed ACTION-57. 13:19:16 ACTION-59 ... mail https://lists.w3.org/Archives/Public/public-dpvcg/2019Feb/0008.html 13:19:44 Eva doubts the criteria for data protection assessment from edpb can be used for the vocabularies 13:19:53 ... but she will send an email with the info 13:19:54 close ACTION-59 13:19:54 Closed ACTION-59. 13:19:58 https://lists.w3.org/Archives/Public/public-dpvcg/2019Feb/att-0008/2017-10-04_wp248_rev01_Guidelines_on_DPIA_updated.pdf 13:21:22 Axel: can we standardise the restrictions or measures of security ? 13:22:20 Mark:Low/high risks... Regulators say this cannot be standardise, but I think the criteria can be 13:22:25 Mark: we can't really standardise what is low or high risk 13:22:29 the only criterion useful for vocabulary from my point of view would be the data categories themselves, since they are key to detect whether sensitive information may be involved in the processing 13:22:55 e.g. in UK the number of employees impacts the high risks 13:23:44 also interesting (e.g. in Canada?) not only if it's risk, but what the risks are 13:23:52 Eva: It's always context dependent 13:24:08 ... depends of the process you have, which data, people involved.... 13:24:27 ... it's something that we also have partially in our vocabularies, e.g. with data categories 13:24:30 criteria can hardly be standardized, except maybe partially in the data categories 13:25:15 close ACTION-61 13:25:15 Closed ACTION-61. 13:25:22 ACTION-60 continued 13:26:03 topic: overview of our current status 13:27:12 MarL has joined #dpvcg 13:27:25 Axel presents a presentation summarising the status: see https://lists.w3.org/Archives/Public/public-dpvcg/2019Feb/0005.html 13:27:30 Hi.. 13:28:44 -> https://www.w3.org/community/dpvcg/wiki/images/f/f9/2019-02-12-DPVCG-status_update.pdf Axel's slides 13:29:42 Axel summarises the timeline and some numbers (#telcos, etc.) 13:29:56 ... Having a F2F on march or april might be good 13:30:18 ... We could maybe do it in Vienna again, or Dublin 13:30:36 +1 to a ftf, no pref for location 13:31:12 +1 to f2f, but depends on time/date, no pref on location 13:31:22 Fajar: I cannot do it in these months 13:31:36 ACTION: Bert to set up doodle preferrred dates for F2F in second half of MArch or first half of April 13:31:36 'Bert' is an ambiguous username. Please try a different identifier, such as family name or username (e.g., bbos, bertv). 13:32:02 ACTION: bbos to set up doodle preferred dates for F2F in second half of MArch or first half of April 13:32:03 Created ACTION-63 - Set up doodle preferred dates for f2f in second half of march or first half of april [on Bert Bos - due 2019-02-19]. 13:32:12 having trouble with sound and connection again, sorry 13:32:19 :( 13:33:12 Axel continues the presentation of the slides with the status of the DPVCG vocabularies, in particular personal data categories, purposes and processing, as they were discussed actively 13:33:36 ... we need how to connect the dots 13:33:55 ... "A personal Data Category is undergoing specified processing by a specific data controller and/or ? for a particular purpose, based on a specific legal ground, with (optionally?) transferred to some recipient specified security measures and restrictions (e.g. storage locations and storage durations)." 13:34:57 ... all "boxes" are already in some vocabularies e.g. SPECIAL, while others such as legal grounds or security measures are rather new 13:35:49 ... we also discussed (Axel, Harsh, Fajar, Javier) that maybe we need to restrict the purpose to certain business activity/sector 13:36:07 ... also Personal data Categories may be subdivided into sensitive data categories 13:37:03 ... As for the Personal Data categories, there is a proposal by Harsh and Fajar to start with the initial proposal by the Enterprise Consulting group 13:37:54 ... In addition we have more categories for the uses cases, the SPECIAL categories and more from the special categories, GDPR article 9 and 4 13:38:25 ... The proposal is to use the Enterprise Consulting group as the anchor, and map the other onto it 13:38:53 connection gone Nirwana again, sigh 13:38:57 Mark: I talked to them, we iterated on this (e.g. on inference data), I think it's CC 13:39:04 ... I can invite them to the WG 13:39:19 ACTION: Mark to reach out to enterprivacy.com on whether we can use their categories as a starting point, check License, and invite them to our working group. 13:39:20 Created ACTION-64 - Reach out to enterprivacy.com on whether we can use their categories as a starting point, check license, and invite them to our working group. [on Mark Lizar - due 2019-02-19]. 13:39:29 Paper for the personal data categories - D. J. Solove, ‘A Taxonomy of Privacy’, Social Science Research Network, Rochester, NY, SSRN Scholarly Paper ID 667622, Feb. 2005. und 13:40:00 Axel: the plan is that Harsh and Fajar can work on this and come with a first version within a month 13:40:27 I am very sorry I need to leave, will try to catch up from minutes 13:40:35 ... As for purposes, we had initial categories of purposes during the last F2F 13:40:46 https://www.w3.org/community/dpvcg/wiki/Purposes_for_handling_Personal_Data 13:41:24 ... see bottom of the page 13:42:03 we don't hear anything, let us know when you have specific things for us please 13:42:44 ... The plan is to integrate the different approaches (Axel and Javier) 13:42:53 ... The question was if we need to include business sectors 13:43:26 Mark: Hyperledger (content on the blockchain)... they spend several months to look at country codes 13:43:54 Mark: Hyperledger work on consent on Blockchain, looking at business codes and suggest to use financial industry codes GICS would be appropriate. 13:44:06 ... It makes sense to use global industry and sector classification GICS, updated in 2017 13:44:13 ... I would recommend that 13:44:54 ... when a company registers, e.g. in UK, they are assigned one code 13:45:27 ... there are multiple versions, the global ID seems to be the best option 13:45:43 ... the most interoperable 13:46:02 Mark: GICS code is driven by financial services, global, would make sense as astarting point. 13:46:03 Axel: are there mapping from the other codes to GICS? 13:46:09 MArk: no that I know 13:46:17 Axel: this could be something to do 13:46:38 https://opencorporates.com/ 13:46:40 ISSUE: Are there mappings to GICS from other coding systems NAICS/NACE/ISIC ... 13:46:40 Created ISSUE-10 - Are there mappings to gics from other coding systems naics/nace/isic .... Please complete additional details at . 13:46:42 Mark: I would recommend to have a look also to opencorporate.com 13:46:53 ... it's not global, it's local + ? 13:47:47 Axel: The next discussion was about legal grounds, we agreed to keep it separated 13:48:06 we see the slides but we still dont hear anything :( Eva plans on continuing on this legal "taxonomy" though 13:48:10 ... we don't have a taxonomy but the picture from Eva 13:48:57 Axel, can you make an action for me to tend further to this? 13:49:19 Axel: As for processing, we have worked less, we have some starting points but we need more work 13:49:44 ACTION: Eva and Bud to further elaborate on legal grounds taxonomy 13:49:45 Created ACTION-65 - And bud to further elaborate on legal grounds taxonomy [on Eva Schlehahn - due 2019-02-19]. 13:50:01 Axel: someone volunteering for the processing category? 13:50:13 Harsh: I have added some terms from the GDPR 13:50:23 Axel: The main point is to structure it 13:50:44 Harsh: I can do, but I might need someone to review 13:51:29 Bud and I can review 13:51:35 Ramisa: I can help a bit 13:51:45 ACTION: Harsh to look into structuring Processing categories, Ramisa, Bud, Eva to help/review. 13:51:46 Created ACTION-66 - Look into structuring processing categories, ramisa, bud, eva to help/review. [on Harshvardhan Pandit - due 2019-02-19]. 13:51:49 just trying to reconnect to webex, no luck so far 13:51:52 ack EVa and Bud 13:52:03 :) 13:52:19 Axel: As for data controllers/recipients... 13:53:08 ... we have some ideas on the country of the recipients, some initial pointers from SPECIAL, and maybe the possibility to add a sticky policy 13:53:11 ACTION: Javier to look into Data controllers and recipients taxonomy with help of Piero, Axel 13:53:12 Created ACTION-67 - Look into data controllers and recipients taxonomy with help of piero, axel [on Javier D. Fernández - due 2019-02-19]. 13:53:17 ... Javier and I can continue on that 13:53:25 ... with the help of Piero 13:54:01 Axel: Last points are storage location/duration, security measures... 13:54:09 stefano has joined #dpvcg 13:54:16 ... but maybe we can leave them now and focus on the first issues 13:54:40 Harsh: Myself and Mark can look at the forms of consent 13:54:57 Mark: +1 13:55:02 ACTION: Harsh looking into Consent elements and types with help of Mark 13:55:03 Created ACTION-68 - Looking into consent elements and types with help of mark [on Harshvardhan Pandit - due 2019-02-19]. 13:55:40 Axel: Then maybe we can leave the storage and security opened as an issue 13:56:00 ISSUE: taxonomies on storrage locations and restrictions as well as security measues and restrictions still undefined. 13:56:01 Created ISSUE-11 - Taxonomies on storrage locations and restrictions as well as security measues and restrictions still undefined.. Please complete additional details at . 13:56:19 All actions of today ideally done in a month. 13:56:39 topic: set next telco 13:56:53 26th at 16:00? 13:57:20 26th would be fine 13:57:35 regrets form harsh, but Mark can report. 13:58:09 Goal: progress on actions from today and decidfe for antoher F2F date and location. 13:58:17 Axel: Harsh, let us know if F2F is OK in Dublin, or you can travel elsewhere 13:58:19 AOB? 13:58:49 Mark: Maybe a good place is a privacy conference in May, Germany 13:58:56 if you plan f2f, can you make a doodle? 13:58:57 ... I will provide more info 13:59:02 Merk: EIC (european identity conference) in May ... in Germany might be a good space for us to meet/be present. 13:59:15 @Eva I think Bert has an action to create a doodle? 13:59:21 ok 13:59:29 ACTION: Mark to report on EIC conference next time 13:59:30 ACTION-63 13:59:30 Created ACTION-69 - Report on eic conference next time [on Mark Lizar - due 2019-02-19]. 13:59:30 ACTION-63 -- Bert Bos to Set up doodle preferred dates for f2f in second half of march or first half of april -- due 2019-02-19 -- OPEN 13:59:30 https://www.w3.org/community/dpvcg/track/actions/63 13:59:44 bye! 13:59:45 adjourned 13:59:47 thanks, bye 14:00:03 rrsagent, make minutes public 14:00:03 I'm logging. I don't understand 'make minutes public', AxelPollleres. Try /msg RRSAgent help 14:00:15 rrsagent, make public minutes 14:00:15 I'm logging. I don't understand 'make public minutes', AxelPollleres. Try /msg RRSAgent help 14:00:19 rrsagent, please create minutes 14:00:19 I have made the request to generate https://www.w3.org/2019/02/12-dpvcg-minutes.html Javier 14:00:28 (I always forget the command :-))