Legal Basis

concepts in Data Privacy Vocabulary (DPV)

Final Community Group Report

This version:
https://www.w3.org/community/reports/dpvcg/CG-FINAL-dpv-20240128/
Latest published version:
https://w3id.org/dpv/dpv/modules/legal_basis
Latest editor's draft:
https://dev.dpvcg.org/dpv/modules/legal_basis
Editor:
Harshvardhan J. Pandit (ADAPT Centre, Dublin City University)
Feedback:
GitHub w3c/dpv (pull requests, new issue, open issues)
This Release
https://w3id.org/dpv/2.0
Previous Release
https://w3id.org/dpv/1.0
Key Publications
Data Privacy Vocabulary (DPV) -- Version 2 (2024)

Abstract

This document provides additional details and examples for legal bases used in the Data Privacy Vocabulary [DPV], and is a companion to the [DPV] specification.

Status of This Document

This specification was published by the Data Privacy Vocabularies and Controls Community Group. It is not a W3C Standard nor is it on the W3C Standards Track. Please note that under the W3C Community Final Specification Agreement (FSA) other conditions apply. Learn more about W3C Community and Business Groups.

Contributing: The DPVCG welcomes participation to improve the DPV and associated resources, including expansion or refinement of concepts, requesting information and applications, and addressing open issues. See contributing guide for further information.

GitHub Issues are preferred for discussion of this specification.

Data Privacy Vocabulary (DPV) Specification: is the base/core specification for the 'Data Privacy Vocabulary', which is extended for Personal Data [PD], Locations [LOC], Risk Management [RISK], Technology [TECH], and [AI]. Specific [LEGAL] extensions are also provided which model jurisdiction specific regulations and concepts - see the complete list of extensions. To support understanding and applications of [DPV], various guides and resources [GUIDES] are provided, including a [PRIMER]. A Search Index of all concepts from DPV and extensions is available.

[DPV] and related resources are published on GitHub. For a general overview of the Data Protection Vocabularies and Controls Community Group [DPVCG], its history, deliverables, and activities - refer to DPVCG Website. For meetings, see the DPVCG calendar.

The peer-reviewed article “Creating A Vocabulary for Data Privacy” presents a historical overview of the DPVCG, and describes the methodology and structure of the DPV along with describing its creation. An open-access version can be accessed here, here, and here. The article Data Privacy Vocabulary (DPV) - Version 2, accepted for presentation at the 23rd International Semantic Web Conference (ISWC 2024), describes the changes made in DPV v2.

3. Contract

Contract as a legal basis covers activities associated with creation of the contract (EnterIntoContract) and the performance of the contract ContractPerformance. Metadata associated with the contract such as date, time, subject, etc. can be represented using DCMI Metadata Terms (DCT).

Contracts are also a dpv:LegalMeasure that can be used by organisations to enforce obligations e.g. by a controller on a processor. Similarly, contracts can also be 'agreements' e.g. between a controller and a processor, where the processor uses this agreement as a legal basis to process personal data.

Note: Extending the contract concepts in DPV

6. Legitimate Interest

LegitimateInterest represents a 'legitimate' reason for the entity to carry out an activity. This reason can be about benefits to the entity, or risks/harms to another entity. Where such benefits or risks/harms can be considered to be of 'vital interest', the legal basis VitalInterest should be used. Where this benefit or risks/harms pertains to the wider society or general public, the legal basis PublicInterest should be used. Legitimate interests can be associated with the controller, or data subject, or third party, or other entities. As good practice (and for their legality), the relevant entity must always be specified. We recommend using a relevant property such as dpv:hasDataController for data controller's legitimate interest to specify this. If a relevant property is not present in DPV, dpv:hasEntity can be used.

LegitimateInterestOfController represents a legitimate interest of the controller - such as carrying out dpv:FraudPreventionDetection. LegitimateInterestOfDataSubject represents a legitimate interest of the data subject - such as having a copy of the transaction (data or agreement) that it is providing or keeping their own records. LegitimateInterestOfThirdParty represents a legitimate interest of a third party - for example to investigate dpv:CounterTerrorism activities.

7. Official Authority of Controller

OfficialAuthorityOfController represents the legal basis where the official authority vested in the controller (by law) is used as the justification for carrying out activities. Such official authority is provided to specific departments to enable them to carry out their duties - such as maintainence of tax records, or provision of postal serviecs. The relevant law should be indicated as part of the legal basis if needed by using dpv:hasApplicableLaw.

8. Public Interest

PublicInterest represents activities carried out because they are 'in the interest of the general public' or are necessary to 'provide benefit to the public', where such benefit might be actual benefits (e.g. archiving data of cultural importance) or prevention of harms (e.g. identify relevant medical conditions quickly to prevent an outbreak). We strongly recommend providing a description of the relevant 'benefits' when using this legal basis e.g. by using dpv:hasJustification for contextual justifications associated with the benefit.

9. Protecting Vital Interests

VitalInterest represents activities that are necessary or required to protect vital interests of a data subject or other natural person. For more specific indication, VitalInterestOfNaturalPerson refers to vital interests of (any or a specific) natural person, and VitalInterestOfDataSubject represents vital interests of (any or a specific) data subject. As with PublicInterest and LegitimateInterest, we strongly recommend specifying relevant information - the vital interest in this case - by using dpv:hasJustification.

10. Vocabulary Index

10.1 Classes

Term ConsentControl Prefix dpv
Label Consent Control
IRI https://w3id.org/dpv#ConsentControl
Type rdfs:Class, skos:Concept
Broader/Parent types dpv:EntityInvolvementdpv:ProcessingContextdpv:Context
Object of relation dpv:hasConsentControl, dpv:hasContext, dpv:hasEntityInvolvement
Definition The control or activity associated with obtaining, providing, withdrawing, or reaffirming consent
Date Created 2024-05-11
See More: section LEGAL-BASIS-CONSENT-CONTROLS in DPV
Term ConsentExpired Prefix dpv
Label Consent Expired
IRI https://w3id.org/dpv#ConsentExpired
Type rdfs:Class, skos:Concept, dpv:ConsentStatus
Broader/Parent types dpv:ConsentStatusInvalidForProcessingdpv:ConsentStatusdpv:Statusdpv:Context
Object of relation dpv:hasConsentStatus, dpv:hasContext, dpv:hasStatus
Definition The state where the temporal or contextual validity of consent has 'expired'
Usage Note An example of this state is when the obtained consent has been assigned a duration - which has lapsed or 'expired', making it invalid to be used further for processing data
Source GConsent
Date Created 2022-06-22
Contributors Georg P. Krog, Harshvardhan J. Pandit, Paul Ryan, Julian Flake
See More: section LEGAL-BASIS-CONSENT-STATUS in DPV
Term ConsentGiven Prefix dpv
Label Consent Given
IRI https://w3id.org/dpv#ConsentGiven
Type rdfs:Class, skos:Concept, dpv:ConsentStatus
Broader/Parent types dpv:ConsentStatusValidForProcessingdpv:ConsentStatusdpv:Statusdpv:Context
Object of relation dpv:hasConsentStatus, dpv:hasContext, dpv:hasStatus
Definition The state where consent has been given
Usage Note An example of this state is when the individual clicks on a button, ticks a checkbox, verbally agrees - or any other form that communicates their decision agreeing to the processing of data
Source GConsent
Date Created 2022-06-22
Contributors Georg P. Krog, Harshvardhan J. Pandit, Paul Ryan, Julian Flake
See More: section LEGAL-BASIS-CONSENT-STATUS in DPV
Term ConsentInvalidated Prefix dpv
Label Consent Invalidated
IRI https://w3id.org/dpv#ConsentInvalidated
Type rdfs:Class, skos:Concept, dpv:ConsentStatus
Broader/Parent types dpv:ConsentStatusInvalidForProcessingdpv:ConsentStatusdpv:Statusdpv:Context
Object of relation dpv:hasConsentStatus, dpv:hasContext, dpv:hasStatus
Definition The state where consent has been deemed to be invalid
Usage Note An example of this state is where an investigating authority or a court finds the collected consent did not meet requirements, and 'invalidates' both prior and future uses of it to carry out processing
Source GConsent
Date Created 2022-06-22
Contributors Georg P. Krog, Harshvardhan J. Pandit, Paul Ryan, Julian Flake
See More: section LEGAL-BASIS-CONSENT-STATUS in DPV
Term ConsentRefused Prefix dpv
Label Consent Refused
IRI https://w3id.org/dpv#ConsentRefused
Type rdfs:Class, skos:Concept, dpv:ConsentStatus
Broader/Parent types dpv:ConsentStatusInvalidForProcessingdpv:ConsentStatusdpv:Statusdpv:Context
Object of relation dpv:hasConsentStatus, dpv:hasContext, dpv:hasStatus
Definition The state where consent has been refused
Usage Note An example of this state is when the individual clicks on a 'disagree' or 'reject' or 'refuse' button, or leaves a checkbox unticked
Source GConsent
Date Created 2022-06-22
Contributors Georg P. Krog, Harshvardhan J. Pandit, Paul Ryan, Julian Flake
See More: section LEGAL-BASIS-CONSENT-STATUS in DPV
Term ConsentRequestDeferred Prefix dpv
Label Consent Request Deferred
IRI https://w3id.org/dpv#ConsentRequestDeferred
Type rdfs:Class, skos:Concept, dpv:ConsentStatus
Broader/Parent types dpv:ConsentStatusInvalidForProcessingdpv:ConsentStatusdpv:Statusdpv:Context
Object of relation dpv:hasConsentStatus, dpv:hasContext, dpv:hasStatus
Definition State where a request for consent has been deferred without a decision
Usage Note An example of this state is when the individual closes or dismisses a notice without making a decision. This state is intended for making the distinction between a notice being provided (as a consent request) and the individual interacting with the notice without making a decision - where the 'ignoring of a notice' is taken as consent being neither given nor refused
Source GConsent
Date Created 2022-06-22
Contributors Georg P. Krog, Harshvardhan J. Pandit, Paul Ryan, Julian Flake
See More: section LEGAL-BASIS-CONSENT-STATUS in DPV
Term ConsentRequested Prefix dpv
Label Consent Requested
IRI https://w3id.org/dpv#ConsentRequested
Type rdfs:Class, skos:Concept, dpv:ConsentStatus
Broader/Parent types dpv:ConsentStatusInvalidForProcessingdpv:ConsentStatusdpv:Statusdpv:Context
Object of relation dpv:hasConsentStatus, dpv:hasContext, dpv:hasStatus
Definition State where a request for consent has been made and is awaiting a decision
Usage Note An example of this state is when a notice has been presented to the individual but they have not made a decision
Source GConsent
Date Created 2022-06-22
Contributors Georg P. Krog, Harshvardhan J. Pandit, Paul Ryan, Julian Flake
See More: section LEGAL-BASIS-CONSENT-STATUS in DPV
Term ConsentRevoked Prefix dpv
Label Consent Revoked
IRI https://w3id.org/dpv#ConsentRevoked
Type rdfs:Class, skos:Concept, dpv:ConsentStatus
Broader/Parent types dpv:ConsentStatusInvalidForProcessingdpv:ConsentStatusdpv:Statusdpv:Context
Object of relation dpv:hasConsentStatus, dpv:hasContext, dpv:hasStatus
Definition The state where the consent is revoked by an entity other than the data subject and which prevents it from being further used as a valid state
Usage Note An example of this state is when a Data Controller stops utilising previously obtaining consent, such as when that service no longer exists
Source GConsent
Date Created 2022-06-22
Contributors Georg P. Krog, Harshvardhan J. Pandit, Paul Ryan, Julian Flake
See More: section LEGAL-BASIS-CONSENT-STATUS in DPV
Term ConsentStatus Prefix dpv
Label Consent Status
IRI https://w3id.org/dpv#ConsentStatus
Type rdfs:Class, skos:Concept
Broader/Parent types dpv:Statusdpv:Context
Object of relation dpv:hasConsentStatus, dpv:hasContext, dpv:hasStatus
Definition The state or status of 'consent' that provides information reflecting its operational status and validity for processing data
Usage Note States are useful as information artefacts to implement them in controlling processing, and to reflect the process and flow of obtaining and maintaining consent. For example, a database table that stores consent states for specific processing and can be queried to obtain them in an efficient manner. States are also useful in investigations to determine the use and validity of consenting practices
Source GConsent
Date Created 2022-06-22
Contributors Georg P. Krog, Harshvardhan J. Pandit, Paul Ryan, Julian Flake
See More: section LEGAL-BASIS-CONSENT-STATUS in DPV
Term ConsentStatusInvalidForProcessing Prefix dpv
Label Consent Status Invalid for Processing
IRI https://w3id.org/dpv#ConsentStatusInvalidForProcessing
Type rdfs:Class, skos:Concept, dpv:ConsentStatus
Broader/Parent types dpv:ConsentStatusdpv:Statusdpv:Context
Object of relation dpv:hasConsentStatus, dpv:hasContext, dpv:hasStatus
Definition States of consent that cannot be used as valid justifications for processing data
Usage Note This identifies the stages associated with consent that should not be used to process data
Source GConsent
Date Created 2022-06-22
Contributors Georg P. Krog, Harshvardhan J. Pandit, Paul Ryan, Julian Flake
See More: section LEGAL-BASIS-CONSENT-STATUS in DPV
Term ConsentStatusValidForProcessing Prefix dpv
Label Consent Status Valid for Processing
IRI https://w3id.org/dpv#ConsentStatusValidForProcessing
Type rdfs:Class, skos:Concept, dpv:ConsentStatus
Broader/Parent types dpv:ConsentStatusdpv:Statusdpv:Context
Object of relation dpv:hasConsentStatus, dpv:hasContext, dpv:hasStatus
Definition States of consent that can be used as valid justifications for processing data
Usage Note Practically, given consent is the only valid state for processing
Source GConsent
Date Created 2022-06-22
Contributors Georg P. Krog, Harshvardhan J. Pandit, Paul Ryan, Julian Flake
See More: section LEGAL-BASIS-CONSENT-STATUS in DPV
Term ConsentUnknown Prefix dpv
Label Consent Unknown
IRI https://w3id.org/dpv#ConsentUnknown
Type rdfs:Class, skos:Concept, dpv:ConsentStatus
Broader/Parent types dpv:ConsentStatusInvalidForProcessingdpv:ConsentStatusdpv:Statusdpv:Context
Object of relation dpv:hasConsentStatus, dpv:hasContext, dpv:hasStatus
Definition State where information about consent is not available or is unknown
Usage Note Consent states can be unknown, for example, when information is not available, or cannot be trusted, or is known to be inaccurate
Source GConsent
Date Created 2022-06-22
Contributors Georg P. Krog, Harshvardhan J. Pandit, Paul Ryan, Julian Flake
See More: section LEGAL-BASIS-CONSENT-STATUS in DPV
Term ConsentWithdrawn Prefix dpv
Label Consent Withdrawn
IRI https://w3id.org/dpv#ConsentWithdrawn
Type rdfs:Class, skos:Concept, dpv:ConsentStatus
Broader/Parent types dpv:ConsentStatusInvalidForProcessingdpv:ConsentStatusdpv:Statusdpv:Context
Object of relation dpv:hasConsentStatus, dpv:hasContext, dpv:hasStatus
Definition The state where the consent is withdrawn or revoked specifically by the data subject and which prevents it from being further used as a valid state
Usage Note This state can be considered a form of 'revocation' of consent, where the revocation can only be performed by the data subject. Therefore we suggest using ConsentRevoked when it is a non-data-subject entity, and ConsentWithdrawn when it is the data subject
Source GConsent
Date Created 2022-06-22
Contributors Georg P. Krog, Harshvardhan J. Pandit, Paul Ryan, Julian Flake
See More: section LEGAL-BASIS-CONSENT-STATUS in DPV

10.1.15 Contract

Term Contract Prefix dpv
Label Contract
IRI https://w3id.org/dpv#Contract
Type rdfs:Class, skos:Concept, dpv:LegalBasis
Broader/Parent types dpv:LegalAgreementdpv:LegalMeasuredpv:TechnicalOrganisationalMeasure
Object of relation dpv:hasLegalMeasure, dpv:hasTechnicalOrganisationalMeasure
Definition Creation, completion, fulfilment, or performance of a contract involving specified processing of data or technologies
Date Created 2021-04-07
Contributors Harshvardhan J. Pandit
See More: section LEGAL-BASIS in DPV

10.1.16 Contract Performance

Term ContractPerformance Prefix dpv
Label Contract Performance
IRI https://w3id.org/dpv#ContractPerformance
Type rdfs:Class, skos:Concept, dpv:LegalBasis
Broader/Parent types dpv:Contractdpv:LegalAgreementdpv:LegalMeasuredpv:TechnicalOrganisationalMeasure
Object of relation dpv:hasLegalMeasure, dpv:hasTechnicalOrganisationalMeasure
Definition Fulfilment or performance of a contract involving specified processing of data or technologies
Date Created 2021-04-07
Contributors Georg P. Krog, Harshvardhan J. Pandit, Paul Ryan
See More: section LEGAL-BASIS in DPV

10.1.17 Data Controller Contract

Term DataControllerContract Prefix dpv
Label Data Controller Contract
IRI https://w3id.org/dpv#DataControllerContract
Type rdfs:Class, skos:Concept, dpv:LegalBasis
Broader/Parent types dpv:Contractdpv:LegalAgreementdpv:LegalMeasuredpv:TechnicalOrganisationalMeasure
Object of relation dpv:hasLegalMeasure, dpv:hasTechnicalOrganisationalMeasure
Definition Creation, completion, fulfilment, or performance of a contract, with Data Controllers as parties being Joint Data Controllers, and involving specified processing of data or technologies
Date Created 2023-12-10
See More: section LEGAL-BASIS in DPV

10.1.18 Data Processor Contract

Term DataProcessorContract Prefix dpv
Label Data Processor Contract
IRI https://w3id.org/dpv#DataProcessorContract
Type rdfs:Class, skos:Concept, dpv:LegalBasis
Broader/Parent types dpv:Contractdpv:LegalAgreementdpv:LegalMeasuredpv:TechnicalOrganisationalMeasure
Object of relation dpv:hasLegalMeasure, dpv:hasTechnicalOrganisationalMeasure
Definition Creation, completion, fulfilment, or performance of a contract, with the Data Controller and Data Processor as parties, and involving specified processing of data or technologies
Date Created 2023-12-10
See More: section LEGAL-BASIS in DPV

10.1.19 Data Subject Contract

Term DataSubjectContract Prefix dpv
Label Data Subject Contract
IRI https://w3id.org/dpv#DataSubjectContract
Type rdfs:Class, skos:Concept, dpv:LegalBasis
Broader/Parent types dpv:Contractdpv:LegalAgreementdpv:LegalMeasuredpv:TechnicalOrganisationalMeasure
Object of relation dpv:hasLegalMeasure, dpv:hasTechnicalOrganisationalMeasure
Definition Creation, completion, fulfilment, or performance of a contract, with the Data Controller and Data Subject as parties, and involving specified processing of data or technologies
Date Created 2023-12-10
See More: section LEGAL-BASIS in DPV
Term DataTransferLegalBasis Prefix dpv
Label Data Transfer Legal Basis
IRI https://w3id.org/dpv#DataTransferLegalBasis
Type rdfs:Class, skos:Concept, dpv:LegalBasis
Broader/Parent types dpv:LegalBasis
Object of relation dpv:hasLegalBasis
Definition Specific or special categories and instances of legal basis intended for justifying data transfers
Date Created 2021-09-08
Contributors David Hickey, Georg P. Krog
See More: section LEGAL-BASIS in DPV

10.1.21 Enter Into Contract

Term EnterIntoContract Prefix dpv
Label Enter Into Contract
IRI https://w3id.org/dpv#EnterIntoContract
Type rdfs:Class, skos:Concept, dpv:LegalBasis
Broader/Parent types dpv:Contractdpv:LegalAgreementdpv:LegalMeasuredpv:TechnicalOrganisationalMeasure
Object of relation dpv:hasLegalMeasure, dpv:hasTechnicalOrganisationalMeasure
Definition Processing necessary to enter into contract
Date Created 2021-04-07
Contributors Georg P. Krog, Harshvardhan J. Pandit, Paul Ryan
See More: section LEGAL-BASIS in DPV
Term ExplicitlyExpressedConsent Prefix dpv
Label Explicitly Expressed Consent
IRI https://w3id.org/dpv#ExplicitlyExpressedConsent
Type rdfs:Class, skos:Concept, dpv:LegalBasis
Broader/Parent types dpv:ExpressedConsentdpv:InformedConsentdpv:Consentdpv:LegalBasis
Object of relation dpv:hasLegalBasis
Definition Consent that is expressed through an explicit action solely conveying a consenting decision
Usage Note Explicitly expressed consent is a more specific form of Expressed consent where the action taken must 'explicitly' relate to only the consent decision. Expressed consent where the consenting is part of other matters therefore cannot satisfy the requirements of explicitly expressed consent. An example of explicit action expressing the consenting decision is a button on a web form where the form only relates to consent, or it is accompanied with suitable text that reiterates what the consenting decision is about
Examples dex:E0018 :: Using consent types
Date Created 2022-06-21
Contributors Georg P. Krog, Harshvardhan J. Pandit, Paul Ryan, Julian Flake
See More: section LEGAL-BASIS-CONSENT-TYPES in DEX
Term ExpressedConsent Prefix dpv
Label Expressed Consent
IRI https://w3id.org/dpv#ExpressedConsent
Type rdfs:Class, skos:Concept, dpv:LegalBasis
Broader/Parent types dpv:InformedConsentdpv:Consentdpv:LegalBasis
Object of relation dpv:hasLegalBasis
Definition Consent that is expressed through an action intended to convey a consenting decision
Usage Note Expressed consent requires the individual take a specific and unambiguous action that directly indicates their consent. This action may be a part of other processes such as setting preferences, or agreeing to a contract, or other matters not relating to consent. An example of expressed consent is interacting with a checkbox within a dashboard or clicking a button on a web form
Examples dex:E0018 :: Using consent types
Date Created 2022-06-21
Contributors Georg P. Krog, Harshvardhan J. Pandit, Paul Ryan, Julian Flake
See More: section LEGAL-BASIS-CONSENT-TYPES in DEX
Term ImpliedConsent Prefix dpv
Label Implied Consent
IRI https://w3id.org/dpv#ImpliedConsent
Type rdfs:Class, skos:Concept, dpv:LegalBasis
Broader/Parent types dpv:InformedConsentdpv:Consentdpv:LegalBasis
Object of relation dpv:hasLegalBasis
Definition Consent that is implied indirectly through an action not associated solely with conveying a consenting decision
Usage Note Implied consent is expected to also be Informed Consent. An example is a CCTV notice outside a monitored area that informs the individuals that by walking in they would be consenting to the use of camera for surveillance.
Date Created 2022-06-21
Contributors Georg P. Krog, Harshvardhan J. Pandit, Paul Ryan, Julian Flake
See More: section LEGAL-BASIS-CONSENT-TYPES in DPV
Term InformedConsent Prefix dpv
Label Informed Consent
IRI https://w3id.org/dpv#InformedConsent
Type rdfs:Class, skos:Concept, dpv:LegalBasis
Broader/Parent types dpv:Consentdpv:LegalBasis
Object of relation dpv:hasLegalBasis
Definition Consent that is informed i.e. with the requirement to provide sufficient information to make a consenting decision
Usage Note The specifics for what information should be provided or made available will depend on the context, use-case, or relevant legal requirements
Date Created 2022-06-21
Contributors Georg P. Krog, Harshvardhan J. Pandit, Paul Ryan, Julian Flake
See More: section LEGAL-BASIS-CONSENT-TYPES in DPV
Term LegalBasis Prefix dpv
Label Legal Basis
IRI https://w3id.org/dpv#LegalBasis
Type rdfs:Class, skos:Concept
Object of relation dpv:hasLegalBasis
Definition Legal basis used to justify processing of data or use of technology in accordance with a law
Usage Note Legal basis (plural: legal bases) are defined by legislations and regulations, whose applicability is usually restricted to specific jurisdictions which can be represented using dpv:hasJurisdiction or dpv:hasLaw. Legal basis can be used without such declarations, e.g. 'Consent', however their interpretation will require association with a law, e.g. 'EU GDPR'.
Examples dex:E0014 :: Denoting Legal Basis within a Process
Date Created 2019-04-05
Date Modified 2020-11-04
See More: section LEGAL-BASIS in DEX
Term LegalObligation Prefix dpv
Label Legal Obligation
IRI https://w3id.org/dpv#LegalObligation
Type rdfs:Class, skos:Concept, dpv:LegalBasis
Broader/Parent types dpv:LegalBasis
Object of relation dpv:hasLegalBasis
Definition Legal Obligation to conduct the specified activities
Examples dex:E0042 :: Indicating legal compliance as a purpose along with the relevant law
Date Created 2021-04-07
Contributors Harshvardhan J. Pandit
See More: section LEGAL-BASIS in DEX

10.1.28 Legitimate Interest

Term LegitimateInterest Prefix dpv
Label Legitimate Interest
IRI https://w3id.org/dpv#LegitimateInterest
Type rdfs:Class, skos:Concept, dpv:LegalBasis
Broader/Parent types dpv:LegalBasis
Object of relation dpv:hasLegalBasis
Definition Legitimate Interests of a Party as justification for specified activities
Examples dex:E0065 :: Specifying legitimate interest of a controller
Date Created 2021-05-19
Contributors Harshvardhan J. Pandit
See More: section LEGAL-BASIS in DEX

10.1.29 Legitimate Interest of Controller

Term LegitimateInterestOfController Prefix dpv
Label Legitimate Interest of Controller
IRI https://w3id.org/dpv#LegitimateInterestOfController
Type rdfs:Class, skos:Concept, dpv:LegalBasis
Broader/Parent types dpv:LegitimateInterestdpv:LegalBasis
Object of relation dpv:hasLegalBasis
Definition Legitimate Interests of a Data Controller in conducting specified activities
Examples dex:E0065 :: Specifying legitimate interest of a controller
Date Created 2021-05-19
Contributors Georg P. Krog, Harshvardhan J. Pandit, Paul Ryan
See More: section LEGAL-BASIS in DEX

10.1.30 Legitimate Interest of Data Subject

Term LegitimateInterestOfDataSubject Prefix dpv
Label Legitimate Interest of Data Subject
IRI https://w3id.org/dpv#LegitimateInterestOfDataSubject
Type rdfs:Class, skos:Concept, dpv:LegalBasis
Broader/Parent types dpv:LegitimateInterestdpv:LegalBasis
Object of relation dpv:hasLegalBasis
Definition Legitimate Interests of the Data Subject in conducting specified activities
Date Created 2022-10-22
Contributors Georg P. Krog
See More: section LEGAL-BASIS in DPV

10.1.31 Legitimate Interest of Third Party

Term LegitimateInterestOfThirdParty Prefix dpv
Label Legitimate Interest of Third Party
IRI https://w3id.org/dpv#LegitimateInterestOfThirdParty
Type rdfs:Class, skos:Concept, dpv:LegalBasis
Broader/Parent types dpv:LegitimateInterestdpv:LegalBasis
Object of relation dpv:hasLegalBasis
Definition Legitimate Interests of a Third Party in conducting specified activities
Date Created 2021-05-19
Contributors Georg P. Krog, Harshvardhan J. Pandit, Paul Ryan
See More: section LEGAL-BASIS in DPV
Term ObtainConsent Prefix dpv
Label Obtain Consent
IRI https://w3id.org/dpv#ObtainConsent
Type rdfs:Class, skos:Concept
Broader/Parent types dpv:ConsentControldpv:EntityInvolvementdpv:ProcessingContextdpv:Context
Object of relation dpv:hasConsentControl, dpv:hasContext, dpv:hasEntityInvolvement
Definition Control for obtaining consent
Usage Note Indicates how the controller or entity can obtain consent e.g. used with dpv:isExercisedAt
Date Created 2024-05-11
See More: section LEGAL-BASIS-CONSENT-CONTROLS in DPV

10.1.33 Official Authority of Controller

Term OfficialAuthorityOfController Prefix dpv
Label Official Authority of Controller
IRI https://w3id.org/dpv#OfficialAuthorityOfController
Type rdfs:Class, skos:Concept, dpv:LegalBasis
Broader/Parent types dpv:LegalBasis
Object of relation dpv:hasLegalBasis
Definition Activities are necessary or authorised through the official authority granted to or vested in the Data Controller
Date Created 2021-05-05
Contributors Georg P. Krog, Harshvardhan J. Pandit, Paul Ryan
See More: section LEGAL-BASIS in DPV
Term ProvideConsent Prefix dpv
Label Provide Consent
IRI https://w3id.org/dpv#ProvideConsent
Type rdfs:Class, skos:Concept
Broader/Parent types dpv:ConsentControldpv:EntityInvolvementdpv:ProcessingContextdpv:Context
Broader/Parent types dpv:OptingInToProcessdpv:EntityPermissiveInvolvementdpv:EntityInvolvementdpv:ProcessingContextdpv:Context
Object of relation dpv:hasConsentControl, dpv:hasContext, dpv:hasEntityInvolvement
Definition Control for providing consent
Usage Note Indicates how the data subject can provide consent e.g. used with dpv:isExercisedAt
Date Created 2024-05-11
See More: section LEGAL-BASIS-CONSENT-CONTROLS in DPV

10.1.35 Public Interest

Term PublicInterest Prefix dpv
Label Public Interest
IRI https://w3id.org/dpv#PublicInterest
Type rdfs:Class, skos:Concept, dpv:LegalBasis
Broader/Parent types dpv:LegalBasis
Object of relation dpv:hasLegalBasis
Definition Activities are necessary or beneficial for interest of the public or society at large
Date Created 2021-04-21
Contributors Harshvardhan J. Pandit
See More: section LEGAL-BASIS in DPV
Term ReaffirmConsent Prefix dpv
Label Reaffirm Consent
IRI https://w3id.org/dpv#ReaffirmConsent
Type rdfs:Class, skos:Concept
Broader/Parent types dpv:ConsentControldpv:EntityInvolvementdpv:ProcessingContextdpv:Context
Object of relation dpv:hasConsentControl, dpv:hasContext, dpv:hasEntityInvolvement
Definition Control for affirming consent
Usage Note Indicates how the controller (with dpv:ObtainConsent) or data subject (with dpv:ProvideConsent) can reaffirm consent e.g. used with dpv:isExercisedAt
Date Created 2024-05-11
See More: section LEGAL-BASIS-CONSENT-CONTROLS in DPV
Term RenewedConsentGiven Prefix dpv
Label Renewed Consent Given
IRI https://w3id.org/dpv#RenewedConsentGiven
Type rdfs:Class, skos:Concept, dpv:ConsentStatus
Broader/Parent types dpv:ConsentStatusValidForProcessingdpv:ConsentStatusdpv:Statusdpv:Context
Object of relation dpv:hasConsentStatus, dpv:hasContext, dpv:hasStatus
Definition The state where a previously given consent has been 'renewed' or 'refreshed' or 'reaffirmed' to form a new instance of given consent
Usage Note An example of this state is when a previously given consent has expired, and the individual is presented a notice regarding continuing associated processing operations - to which they agree. This state can be useful to keep track of 'reconfirmed' or 'refreshed' consent within consent records, assist notices and contextual agents to create better consenting dialogues, and assist with specific legal obligations related to subsequent consenting
Source GConsent
Date Created 2022-06-22
Contributors Georg P. Krog, Harshvardhan J. Pandit, Paul Ryan, Julian Flake
See More: section LEGAL-BASIS-CONSENT-STATUS in DPV

10.1.38 Third Party Contract

Term ThirdPartyContract Prefix dpv
Label Third Party Contract
IRI https://w3id.org/dpv#ThirdPartyContract
Type rdfs:Class, skos:Concept, dpv:LegalBasis
Broader/Parent types dpv:Contractdpv:LegalAgreementdpv:LegalMeasuredpv:TechnicalOrganisationalMeasure
Object of relation dpv:hasLegalMeasure, dpv:hasTechnicalOrganisationalMeasure
Definition Creation, completion, fulfilment, or performance of a contract, with the Data Controller and Third Party as parties, and involving specified processing of data or technologies
Date Created 2023-12-10
See More: section LEGAL-BASIS in DPV
Term UninformedConsent Prefix dpv
Label Uninformed Consent
IRI https://w3id.org/dpv#UninformedConsent
Type rdfs:Class, skos:Concept, dpv:LegalBasis
Broader/Parent types dpv:Consentdpv:LegalBasis
Object of relation dpv:hasLegalBasis
Definition Consent that is uninformed i.e. without requirement to provide sufficient information to make a consenting decision
Date Created 2022-06-21
Contributors Georg P. Krog, Harshvardhan J. Pandit, Paul Ryan, Julian Flake
See More: section LEGAL-BASIS-CONSENT-TYPES in DPV

10.1.40 Vital Interest

Term VitalInterest Prefix dpv
Label Vital Interest
IRI https://w3id.org/dpv#VitalInterest
Type rdfs:Class, skos:Concept, dpv:LegalBasis
Broader/Parent types dpv:LegalBasis
Object of relation dpv:hasLegalBasis
Definition Activities are necessary or required to protect vital interests of a data subject or other natural person
Date Created 2021-04-21
Contributors Harshvardhan J. Pandit
See More: section LEGAL-BASIS in DPV

10.1.41 Vital Interest of Data Subject

Term VitalInterestOfDataSubject Prefix dpv
Label Vital Interest of Data Subject
IRI https://w3id.org/dpv#VitalInterestOfDataSubject
Type rdfs:Class, skos:Concept, dpv:LegalBasis
Broader/Parent types dpv:VitalInterestOfNaturalPersondpv:VitalInterestdpv:LegalBasis
Object of relation dpv:hasLegalBasis
Definition Activities are necessary or required to protect vital interests of a data subject
Date Created 2021-04-21
Contributors Georg P. Krog, Harshvardhan J. Pandit, Paul Ryan
See More: section LEGAL-BASIS in DPV

10.1.42 Vital Interest of Natural Person

Term VitalInterestOfNaturalPerson Prefix dpv
Label Vital Interest of Natural Person
IRI https://w3id.org/dpv#VitalInterestOfNaturalPerson
Type rdfs:Class, skos:Concept, dpv:LegalBasis
Broader/Parent types dpv:VitalInterestdpv:LegalBasis
Object of relation dpv:hasLegalBasis
Definition Activities are necessary or required to protect vital interests of a natural person
Date Created 2021-04-21
Contributors Georg P. Krog, Harshvardhan J. Pandit, Paul Ryan
See More: section LEGAL-BASIS in DPV
Term WithdrawConsent Prefix dpv
Label Withdraw Consent
IRI https://w3id.org/dpv#WithdrawConsent
Type rdfs:Class, skos:Concept
Broader/Parent types dpv:ConsentControldpv:EntityInvolvementdpv:ProcessingContextdpv:Context
Broader/Parent types dpv:WithdrawingFromProcessdpv:EntityPermissiveInvolvementdpv:EntityInvolvementdpv:ProcessingContextdpv:Context
Object of relation dpv:hasConsentControl, dpv:hasContext, dpv:hasEntityInvolvement
Definition Control for withdrawing consent
Usage Note Indicates how the data subject can withdraw consent e.g. used with dpv:isExercisedAt
Date Created 2024-05-11
See More: section LEGAL-BASIS-CONSENT-CONTROLS in DPV

10.2 Properties

Term hasConsentControl Prefix dpv
Label has consent control
IRI https://w3id.org/dpv#hasConsentControl
Type rdf:Property, skos:Concept
Range includes dpv:ConsentControl
Definition Specific a control associated with consent
Date Created 2024-05-11
See More: section LEGAL-BASIS-CONSENT in DPV
Term hasConsentStatus Prefix dpv
Label has consent status
IRI https://w3id.org/dpv#hasConsentStatus
Type rdf:Property, skos:Concept
Range includes dpv:ConsentStatus
Definition Specifies the state or status of consent
Date Created 2022-06-21
Contributors Georg P. Krog, Harshvardhan J. Pandit, Paul Ryan, Julian Flake
See More: section LEGAL-BASIS-CONSENT in DPV

10.2.3 has indication method

Term hasIndicationMethod Prefix dpv
Label has indication method
IRI https://w3id.org/dpv#hasIndicationMethod
Type rdf:Property, skos:Concept
Definition Specifies the method by which an entity has indicated the specific context
Date Created 2022-06-21
Contributors Georg P. Krog, Harshvardhan J. Pandit, Paul Ryan, Julian Flake
See More: section LEGAL-BASIS in DPV
Term hasLegalBasis Prefix dpv
Label has legal basis
IRI https://w3id.org/dpv#hasLegalBasis
Type rdf:Property, skos:Concept
Range includes dpv:LegalBasis
Definition Indicates use or applicability of a Legal Basis
Date Created 2019-04-04
Date Modified 2020-11-04
Contributors Axel Polleres, Javier Fernández
See More: section LEGAL-BASIS in DPV

10.2.5 is indicated at time

Term isIndicatedAtTime Prefix dpv
Label is indicated at time
IRI https://w3id.org/dpv#isIndicatedAtTime
Type rdf:Property, skos:Concept
Definition Specifies the temporal information for when the entity has indicated the specific context
Date Created 2022-06-21
Contributors Georg P. Krog, Harshvardhan J. Pandit, Paul Ryan, Julian Flake
See More: section LEGAL-BASIS in DPV

10.2.6 is indicated by

Term isIndicatedBy Prefix dpv
Label is indicated by
IRI https://w3id.org/dpv#isIndicatedBy
Type rdf:Property, skos:Concept
Range includes dpv:Entity
Definition Specifies entity who indicates the specific context
Date Created 2022-06-21
Contributors Georg P. Krog, Harshvardhan J. Pandit, Paul Ryan, Julian Flake
See More: section LEGAL-BASIS in DPV

10.3 External

DPV uses the following terms from [RDF] and [RDFS] with their defined meanings:

The following external concepts are re-used within DPV:

11. Contributors

The following people have contributed to this vocabulary. The names are ordered alphabetically. The affiliations are informative do not represent formal endorsements. Affiliations may be outdated. The list is generated automatically from the contributors listed for defined concepts.

Funding Acknowledgements

Funding Sponsors

The DPVCG was established as part of the SPECIAL H2020 Project, which received funding from the European Union’s Horizon 2020 research and innovation programme under grant agreement No. 731601 from 2017 to 2019.

Harshvardhan J. Pandit was funded to work on DPV from 2020 to 2022 by the Irish Research Council's Government of Ireland Postdoctoral Fellowship Grant#GOIPD/2020/790.

The ADAPT SFI Centre for Digital Media Technology is funded by Science Foundation Ireland through the SFI Research Centres Programme and is co-funded under the European Regional Development Fund (ERDF) through Grant#13/RC/2106 (2018 to 2020) and Grant#13/RC/2106_P2 (2021 onwards).

Funding Acknowledgements for Contributors

The contributions of Harshvardhan J. Pandit have been made with the financial support of Science Foundation Ireland under Grant Agreement No. 13/RC/2106_P2 at the ADAPT SFI Research Centre.

A. References

A.1 Informative references

[AI]
AI Technology concepts for DPV. URL: https://w3id.org/dpv/ai
[DCT]
DCMI Metadata Terms (DCT). URL: https://www.dublincore.org/specifications/dublin-core/dcmi-terms/
[DPV]
Data Privacy Vocabulary (DPV) Specification. URL: https://w3id.org/dpv
[DPV-27560]
DPV Profile for implementing ISO/IEC TS 27560:2023 Consent Records and Receipts. URL: https://w3id.org/dpv/schema/dpv-27560
[DPVCG]
W3C Data Privacy Vocabularies and Controls Community Group (DPVCG). URL: https://www.w3.org/community/dpvcg/
[EU-GDPR]
EU GDPR concepts for DPV. URL: https://w3id.org/dpv/legal/eu/gdpr
[GDPR]
General Data Protection Regulation (GDPR). URL: https://eur-lex.europa.eu/eli/reg/2016/679/oj
[GUIDES]
Guides for DPV. URL: https://w3id.org/dpv/guides
[ISO-27560]
ISO/IEC TS 27560 Privacy technologies — Consent record information structure. URL: https://www.iso.org/standard/80392.html
Legal Jurisdiction-relevant concepts for DPV. URL: https://w3id.org/dpv/legal
[LOC]
Location and Geo-Political Membership concepts for DPV. URL: https://w3id.org/dpv/loc
[PD]
Personal Data categories for DPV. URL: https://w3id.org/dpv/pd
[PRIMER]
Primer for Data Privacy Vocabulary. URL: https://w3id.org/dpv/primer
[RDF]
RDF 1.1 Concepts and Abstract Syntax. URL: https://www.w3.org/TR/rdf11-concepts/
[RDFS]
RDF Schema 1.1. URL: https://www.w3.org/TR/rdf-schema/
[RISK]
Risk Assessment and Management concepts for DPV. URL: https://w3id.org/dpv/risk
[TECH]
Technology concepts for DPV. URL: https://w3id.org/dpv/tech