11:59:23 RRSAgent has joined #dpvcg 11:59:23 logging to https://www.w3.org/2021/10/06-dpvcg-irc 11:59:27 ScribeNick: harsh 12:00:17 Meeting: DPVCG Meeting Call 12:00:21 Chair: harsh 12:01:30 Date: 06 OCT 2021 12:01:43 Agenda: https://lists.w3.org/Archives/Public/public-dpvcg/2021Oct/0001.html 12:03:51 Present: paulR, julianF, harsh, markL 12:04:58 Topic: DPV & DPV-GDPR v0.3 12:05:06 present+: beatrizE 12:07:30 see https://lists.w3.org/Archives/Public/public-dpvcg/2021Oct/0000.html 12:08:32 Topic: Deciding next steps 12:09:15 paulR: tech & org measures are 'weak' compared to other vocabs, if there are aligned vocabularies to use/utilise 12:09:57 present+: georgK 12:10:28 paulR: these are essential to do in terms of practical use/application and do risk assessments 12:10:55 markL: notice & consent, relation to measures for security and safeguards. Relation from PIPEDA to GDPR regarding consent requirements. 12:11:16 markL: code of practice or code of conduct for consent 12:11:56 markL: work done in NGI TRUST PAECG project https://privacy-as-expected.org/ 12:12:47 georgK: ~13 different applications, and how DPV is used or mapped or usable there 12:13:11 georgK: DPV to express privacy policy (i.e. textual policies on websites) 12:13:37 georgK: e.g. related to GDPR A.13/A.14 12:15:09 markL: layered policies, signals, consent policies and descriptions 12:16:19 beatrizE: use-cases of DPV - code examples such as privacy policies, consent 12:17:20 julianF: privacy policies - natural language with standardised vocabularies - which are then transformed into enforceable policies 12:21:41 julianF: serialisations formats (mentioned, but not prioritised) 12:22:51 georgK: involved in health data group, which has considered DPV, and uses permissions and prohibitions, similar to DUO, which are granular and can be introduced and connected to other concepts 12:23:55 georgK: DPV is by design open/free to use, and not restricted, which has pros and cons, e.g. usable across jurisdictions 12:24:49 markL: specifying privacy rights in terms of technical details for what they mean 12:25:17 markL: purpose specification, privacy rights related to concepts 12:25:53 georgK: following from paulR, there is a need to measure data security measures 12:27:54 georgK: 'context' of where DPV is used in, e.g. privacy policy for employees, apps, services, policies 12:30:34 markL: permission vs purposes model, identity management technology, in terms of purposes having permissions; DPV should express scope of purpose e.g. 1 time use, limitations to use 12:36:52 harsh: purpose decomposition into 'validity' is mostly dependant on jurisdictional requirements which are tied closely to legal basis e.g. legitimate interest of a purpose 12:37:28 harsh: for DPV to consider this in scope, it should be usable in a general sense; for jurisdictional concepts, welcome concrete propositions, examples, and demonstrations 12:47:18 harsh: we start with top-2 ideas and choose according 12:47:38 harsh: for me, its consent attributes/requirements and real-world info such as security measures, but also standards, jurisdictions 12:48:43 markL: consent and rights 12:49:30 paulR: privacy notices/policies, and tech/org measures 12:50:05 beatrizE: privacy policies 12:51:54 georg: privacy policies, and user-centric consent management 12:52:38 s/georg/georgK 12:55:06 julianF: consent (legal basis as in GDPR), and privacy policies 13:09:23 consolidation and consensus - privacy policies, consent attributes, and real-world technical measures 13:09:34 Topic: Next Meeting 13:09:59 We will be meeting again next week, WED OCT-13 13:00 WEST / 14:00 CEST 13:10:14 Agenda will be about starting work on agreed topics in today's meetings 13:11:01 Following DPVCG's call, WU and NOYB are presenting their work in the RESPECTeD project about ADPC - an user-side consenting protocol https://www.sustainablecomputing.eu/event/advanced-data-protection-control-adpc-an-interdisciplinary-introduction/ 13:11:06 zakim, bye 13:11:06 leaving. As of this point the attendees have been paulR, julianF, harsh, markL, :, beatrizE, georgK 13:11:06 Zakim has left #dpvcg 13:11:14 rrsagent, publish minutes v2 13:11:14 I have made the request to generate https://www.w3.org/2021/10/06-dpvcg-minutes.html harsh 13:11:22 rrsagent, set logs world-visible 13:11:34 rrsagent, bye 13:11:34 I see no action items