15:02:24 RRSAgent has joined #dpvcg 15:02:28 logging to https://www.w3.org/2023/04/20-dpvcg-irc 15:02:30 Scribe: harsh 15:02:56 repo: w3c/dpv 15:02:56 OK. 15:03:00 ghurlbot, harsh is coolharsh55 15:03:00 harsh, I already had that GitHub account for harsh 15:03:07 Meeting: DPVCG Meeting Call 15:03:08 Chair: harsh 15:04:51 Present: harsh, paul, julian, beatriz, georg, MarkLizar 15:04:51 Date: 20 APR 2023 15:04:51 Agenda: https://www.w3.org/events/meetings/6eddc640-8149-4ce3-9156-6bdec466b1ba 15:05:03 Topic: Associating GDPR Rights with Legal Bases 15:06:17 Issue #49 lists legal bases and what rights are applicable for each based on guidance provided by DPAs (IE, UK) and EDPB 15:06:18 https://github.com/w3c/dpv/issues/49 -> Issue 49 Provide association and applicability between GDPR legal bases and rights (coolharsh55) documentation, concepts, todo, help-wanted 15:06:44 To associate the legal basis and the right, the property `dpv:hasRigh` would be used 15:07:35 Discussion in the meeting for whether 1) this is useful to provide 2) is the information in line with DPVCG's objectives and scope 3) what form to provide it in i.e. should we use `dpv:hasRight`? 4) Do we also model the 'not applicable' relations? 15:07:36 https://github.com/w3c/dpv/issues/49 : Provide association and applicability between GDPR legal bases and rights 15:08:19 Participants agree that this is useful and should be provided using `dpv:hasRight` within DPV-GDPR. 15:08:30 julian: Why is Article 19 not mentioned in the list? 15:09:27 Article 19 is regarding the communication or notification of A.16, A.17, A.18 by the controller to other recipients and the confirmation of recipient for which this has taken place upon request by the data subject. 15:09:49 This has not been modelled because the appropriate relevant guidance for this could not be found in the cited sources. 15:10:33 If DPVCG is modelling these, then A.19 would be modelled with a Y or applicable for all cases where all of A.16-A.18 are also applicable, and a N or not applicable for any case where A.16-A.18 is not applicable. 15:11:06 The group agrees only to model the Y relations in DPV and to represent N relations through lack of facts or concept i.e. imply closed world interpretation. 15:11:48 This is in line with how rights are associated only in cases where they are applicable, and where they are not - nothing is specified and there is no 'not applicable' relation. 15:12:08 paul: What is the title of A.19 in DPV? It should reference notification in the title. 15:12:45 Issue: Add 'Notification' to A.19 title in DPV-GDPR 15:12:46 Created -> issue #92 https://github.com/w3c/dpv/issues/92 Add 'Notification' to A.19 title in DPV-GDPR 15:13:18 Topic: Modelling Data Governance Act 15:13:27 https://github.com/w3c/dpv/issues/92 : Add 'Notification' to A.19 title in DPV-GDPR 15:14:02 beatriz: have added developed terms to #62 which include classes and properties based on DGA 15:14:02 https://github.com/w3c/dpv/issues/62 -> Issue 62 Add DGA/eIDAas entities (besteves4) scope, concepts 15:14:15 https://github.com/w3c/dpv/issues/62 : Add DGA/eIDAas entities 15:26:26 There are about 80 concepts in the submitted analysis by beatriz 15:26:40 harsh and georg will analyse these and add further concepts 15:27:10 Collated work will then be considered for inclusion within the DPV similar to GDPR i.e. as DPV-DGA along with additional implementations and guidances as needed 15:27:26 Topic: Providing guidance for ISO 27560 15:28:38 harsh: I have analysed the current 27560 DTS draft. Conclusion is that all concepts are present in DPV, which is expected. Annex A contains an example using DPV, which can be found at https://github.com/coolharsh55/dpv-consent-recordAs Additional work include writing an implementation guidance note as per #90 15:28:39 https://github.com/w3c/dpv/issues/90 -> Issue 90 Provide guidance for implementing ISO/IEC 27560 Consent Records using DPV (coolharsh55) documentation, use-case, application 15:29:05 Additionally, the companion standard for 29184 is also being investigated to create machine-readable notices, see #91 15:29:06 https://github.com/w3c/dpv/issues/91 -> Issue 91 Provide guidance for implementing ISO/IEC 29184 Privacy Notice using DPV (coolharsh55) 15:29:18 There will be updates next week on this. 15:29:37 https://github.com/w3c/dpv/issues/91 : Provide guidance for implementing ISO/IEC 29184 Privacy Notice using DPV 15:29:39 https://github.com/w3c/dpv/issues/90 : Provide guidance for implementing ISO/IEC 27560 Consent Records using DPV 15:29:43 Topic: Multi-lingual translations for DPV 15:34:15 Tobias from TRAPEZE has provided translations using DeepL which need to be analysed manually to identify quality and need for corrections 15:34:58 Julian has volunteered to lead the German translations and we need translators for Italian and French (or other languages) - caveat that they have knowledge of legal terminology i.e. GDPR in that specific language 15:35:21 julian: issues with character encodings within the German translations, e.g. umlauts 15:35:43 harsh: these may have arised as a result of converting the CSVs to XLSX when uploading to shared Google Drive, will investigate the source 15:36:25 Using #89 to track this work 15:36:25 https://github.com/w3c/dpv/issues/89 -> Issue 89 Multi-lingual labels and descriptions for concepts (coolharsh55) documentation, todo, help-wanted 15:36:37 https://github.com/w3c/dpv/issues/89 : Multi-lingual labels and descriptions for concepts 15:41:36 julian: In the German labels for Base vocab properties, the use of 'einen' is incorrect and should not be present 15:42:15 Julian will add comments to the document with issues as found which will be shared with the mutlilingual task group and used to decide further actions 15:42:27 Topic: Data Breach concepts 15:43:34 harsh: Going through the Irish DPC's data breach reporting form, there are a lot of different identifiers that are required to be maintained and shared. E.g. DPC issues a case identifier or reference that must be included in further reporting. Data Subjects as well as Processors and Controllers can have identifiers from Controllers that they should include if available. How to model such identifiers with DPV? 15:44:02 paul: we have `dpv:hasIdentifier` to indicate an identifier in the legal sense. Additionally `dct:identifier` is also an option. 15:44:42 harsh: The issue is how to distinguish between identifiers. Specifying the provider's identifier (i.e. controller reporting a breach specifies their own identifier) can be done using these, but the question is how to provide an externally created identifier 15:45:06 Such identifiers can also occur in other use-cases, such as complaints with DPAs or organisations may have a case reference associated with communications 15:45:33 Discussion on identifiers without resolution or identification of a solution. 15:45:52 This can be tracked in #64 15:45:52 https://github.com/w3c/dpv/issues/64 -> Issue 64 Provide concepts for Data Breach (coolharsh55) concepts, todo, help-wanted 15:45:55 https://github.com/w3c/dpv/issues/64 : Provide concepts for Data Breach 15:45:56 Topic: Next Meeting 15:46:08 harsh is away next week, paul will chair the meeting 15:46:28 we will meet as usual on Thursday 27th 14:00 WEST / 15:00 CEST 15:46:40 rrsagent, please draft minutes v2 15:46:41 I have made the request to generate https://www.w3.org/2023/04/20-dpvcg-minutes.html harsh 15:46:52 rrsagent, set logs world-visible 15:47:54 ghurlbot, bye 15:47:55 ghurlbot has left #dpvcg 15:48:01 Github, bye 15:48:05 rrsagent, bye 15:48:05 I see no action items