Pierre-Antoine Champin is an associate professor (MCF HDR) in computer science at the IUT of the Claude Bernard Lyon 1 University (France), affiliated with the LIRIS research center. He is currently seconded to Inria, in the Wimmics team (since September 2024) and a W3C fellow since February 2021 involved in the Technical Strategy team on the topic of data interoperability.
Rigo Wenning works with W3C since 1999 and co-organized and co-chaired the first Workshop on Digital Rights in 2001 together with Renato Iannella. In W3C he is working in the legal team and in the Technical Strategy team with a focus on data interoperability. Rigo is also Rechtsanwalt in Frankfurt am Main.
Introduction
ODRL was first presented at the first Workshop on Digital Rights Management(DRM) for the Web in January 2001. At the time, publishers explored Digital Rights Management. ODRL provided a very good basis to express the copyright following the INDECS model. But ODRL did not insist on using a specific enforcement, it wasn't DRM in a strict sense. While many enforcement oriented efforts vanished, ODRL persisted as a rights labelling framework. It adapted over time and the decades of development and practice made it stronger. This Workshop is in line with that development.
Grown beyond copyright
Initially, long time ago, ODRL was tight to copyright. It was inspired by the INDECS Model that created a copyright workflow of creation, use and re-use to create new derivative works. INDECS is long gone, but it was at the origin of the DOI system. The DOI system solved the issue created by the INDECS workflow, namely the identification of intellectual works over multiple copies and transformations. But also DOI changed into the ID reference system for academia.
There is a list of ODRL Profiles showing the usage of ODRL beyond copyright. One can find profiles for access control, regulatory compliance and even data sovereignty. ODRL has moved from an expression of copyright constraints to a general constraint and usage control system.
Today, ODRL is widely used or copied. With IDS Usage Control Policies, the International Data Space Association based their own language on ODRL, adapting it to the specific needs of data spaces and creating their own derivate. The banking industry uses ODRL to make the compulsory Know-Your-Customer efforts more interoperable. A good overview was given by the ODRL Community Group in their Landscape document. New is that the community around Solid and Linked Web Storage is now also looking into managing constraints using ODRL.
ODRL is a module
Already at the 2006 Workshop on Languages for Privacy Policy Negotiation and Semantics-Driven Enforcement, Renato Iannella made the remark that Linked data can be used as a general constraint management system for data governance. This has proven to be true (as demonstrated on the previous section). In data protection, the Data Protection Vocabulary (DPV) was a breakthrough and allowed to address the semantics needed for data protection oriented usage control. It becomes possible to address real world constraints beyond mere access control. An algorithm would then use the DPV to identify the data item or data category to be addressed and ODRL is then used to express the usage constraints that apply to that data protection category. This has wide implications for Linked data in general and ODRL in particular.
This means ODRL needs to be combinable. To be combinable it needs to integrate well into the Linked Data landscape. This was enabled by the transition from XML (for early versions of ODRL) to RDF, but more good practices need to be established to articulate ODRL with other Linked Data vocabularies. This is important for the definitons of objects the constraints apply to, but it is evenly important to allow for an easy translation of legal constraints into machine readable and actionable code. One could therefore imagine a legal library of reusable ODRL modules or templates, for sharing of legal knowledge that could be applied out-of-the-box to web applications and knowledge systems.
Legal meaning and ODRL
The opportunity of the Workshop is also taken to address the particular issue of the legal validity of policy constraints and their observation and enforcement within the legal system all those ODRL applications are operating in. To do that, two aspects are crucial:
- In order to have a meaningful legal content, an assertion in ODRL should achieve a full sentence, namely contain a subject, a predicate and an object. Funnily this corresponds also to RDF triples, but ODRL constructs can be more complex. One of the more challenging issues is the definition of the object whose use the constraints and obligations are about.
- ODRL needs to be able to create the evidence needed to prove assertions in litigation and within the court system. An agreement to a constraint is not really efficient, if the subject having agreed to it has an easy way of denial.
Full legal sentence
While the legal system can cope with a relative high degree of ambiguity, an automatic reasoner will easily fail on those. There are many court decisions to decide whether an object of a given contract is determined or can be determined. While applying ODRL to copyright, this is relatively easy. Copyright has a good definition of "work" that is then linked to an author and subject to exclusive rights. As soon as ODRL has quit that retricted and well understood field, the requirements for objects or subjects are not that simple anymore and require the identification of use cases. This is partly already reflected in ODRL profiles. ODRL is generic and flexible enough to work in a range of different use cases. But this also allows for incomplete policies that do not address all constraints required to achieve a legal meaning beyond just a certain behaviour of a given system. ODRL is there to function beyond the system configuration, it needs to take things like audit, evaluation and conclusions into account.
A particular challenge for the legal meaning of ODRL expressions is the definition of the object. This already existed for the copyright use case and was already raised in 2000 by the INDECS model. One of the responses was the creation of the DOI system. As ODRL, DOI has grown beyond this initial purpose. Does the Asset - definition in ODRL really what we expect from it? Is it usable in the context of the Web of Things, Smart cities or within the new challenges of WebMCP? How can we cluster or package several objects to have the constraints being about a ensemble of objects? How can we make sure that the constraints remain intact even if parts of the object are re-used or transformed? The Asset Administration Shell [PDF] (AAS) is used in data spaces to cluster objects and describe them, but it raises difficult challenges with respect to interoperability and combinability. Which in turn means that the challenge of identification and packaging for objects remains intact. Further work, like the one made for the regulatory profile of ODRL will be needed to explore object identification of unseen simplicity that can be addressed with meaningful legal sentences. Achieving simplicity is the challenge that will decide on the success of the further work ahead.
A potential pitfall in the discussion around the legal meaning of ODRL concerns the completeness of legal considerations. Every ODRL policy and every reaction to that policy is a legal interpretation of the situation at hand. And there can be more than one legal interpretation. This can lead to endless discussions and complications. The aim shouldn't be to try to fully reproduce the full wealth of possible legal interpretations of a given situation, law, workflow. Every ODRL expression will be one subjective interpretation and implementation of a given legal framework, hopefully one that finds positive scrutiny in court. Admitting this up front will allow for a much higher simplicity.
Creating evidence
ODRL is used to express constraints. A downstream user can not fully use the asset at hand. A real world challenge in this context is the question, whether the downstream user really agreed to the constraints, has understood them, accepted them. For the regulatory part, the challenge is to demonstrate that regulatory constraints were observed and followed. ODRL has the chance to help replace very expensive manual audits by highly automated systems that create legal evidence in a secured way.
To secure Linked data, one could use Verifiable Credentials. Compared to other scenarios, the ODRL world needs to create best practices on what to secure for which use case. It remains to be seen whether all of the requirements from those use cases with ODRL, like Know-Your-Customer, ESG, Circular economy considerations and others can be achieved with the current Verifiable Credentials data format and how that combines with ODRL. It is certainly one of the core challenges around creating evidence with ODRL.
Contact: Rigo Wenning & Pierre-Antoine Champin$Id: 14-ChampinWenning.html,v 1.1 2026/06/25 17:24:12 rigo Exp $