Eva: It would be good to inform the community about Rigo's email.

link to Rigo's email https://lists.w3.org/Archives/Public/public-dpvcg/2018Nov/0002.html

-> https://www.w3.org/mid/2273843.xauRQj15pD@hegel Rigo's mail on GDPR taxonomy

... rigo's image: https://lists.w3.org/Archives/Public/public-dpvcg/2018Nov/att-0002/GDPR-taxonomy.pdf

The meeting / discussion happened at the SPECIAL consortium meeting in London

Eva: The email (has an attachment). Axel, Rigo and I met last week, and we were discussing lawfulness of processing, and Rigo said we should try to convey what a lawyer would look at first when auditing the legality of processing. Perhaps we can display the steps of what the auditor would map/show (?). That was Rigo's first attempt, but I will probably do one as well.

Eva: To see which kind of elements a lawyer would look at in the context of the GDPR

clarification: The whole consortium were involved in the discussion not just Eva, Rigo and Axel

AxelPolleres: The discussion was around the second layer of the tree (see attachment in Rigo's email). On the other hand, there was discussion where several people have replied via email. Can Eva and Rigo summarise these discussions?

Eva: We can do that. However, I can get around to it only in the next week.

ACTION: Eva (and Rigo) to summarize the discussion for legitmation of data processing and come up with a first proposal of categories

AxelPolleres: Next on the agenda, consent and comptency consent

Elements of consent/competency questions for consent https://lists.w3.org/Archives/Public/public-dpvcg/2018Oct/0025.html , https://lists.w3.org/Archives/Public/public-dpvcg/2018Oct/0038.html -> I would like to task someone to summarize these and make a proposal to the group we can discuss, e.g. based on what in the minutes last time:

consent = agreement through an [affirmative action] at a specific [time] with a [data controller] to specific [processing] and [storage] of specific [data categories] for specific [purpose] and [duration]

which of these aspects are similarly relevant for other forms of legitmation than consent?

AxelPolleres: There was discussion on elements on consent, there were some mails. In our last call, we got some attributes for what consent, which is an affirmative action (...) from email. The things in the square attributes would be the attributes, are we missing some attributes? There was some discussion on the mailing list. Someone needs to summarise these to see if we need more refined definitions.

AxelPolleres: As someone said, storage is also a kind of processing, but has advantages in having a special status.

Javier: It is missing the Data Subject

Niklas: [data subject] is missing

AxelPolleres: This is related to the action to Eva and Rigo. These attributes would hold for other forms of legal basis / lawfulness?

Harsh: had a go on attributes relevant for attributes on other legitimation

MarkLizar: I've been working on parameters of consent, I can provide some input regarding that

AxelPolleres: Harsh and Mark, can you summarise this? To give us a summary of the discussion? To review these by the group. The current definition could be "agreement by .. a data subject".

Mark: can provide input on that.

consent = agreement by a [data subject[ through an [affirmative action] at a specific [time] with a [data controller] to specific [processing] and [storage] of specific [data categories] for specific [purpose] and [duration]

harsh: I can add these to the wiki

MarkLizar: We have just written the GDPR version and added the elements, what is not clear, is regarding delegation of consent, sub-processing, the scope of consent. These things are missing in the definitions.

ACTION: Harsh to summarize elements of consent from the mails and align with Mark Lizar on "concent receipt" definition (e.g. on delegation)

MarkLizar: In a consent transaction, there is someone acting on the behalf of the consent, controller, etc. which is a delegation which is important to catch.

AxelPolleres: For e.g. consent for minors

MarkLizar: yes, consent for minor. A processor acting on the behalf of the controllor, or a trust provider acting on behalf of the regulator.

MarkLizar: often third party involved, also on behalf of Data Controller.

Axel: Please keep the discussion in the mailing list

Axel: please keep the discussion on the mailinglist.

I support this request, these are very important aspects Mark raised

topic: Harsh's mail on collecting terms from vocabularies: https://lists.w3.org/Archives/Public/public-dpvcg/2018Oct/0041.html, https://www.w3.org/community/dpvcg/wiki/Taxonomy

AxelPolleres: How do we structure or order these (collected) categories?

Axel: just lables there so far, definitions would be useful, anyway a great start.

AxelPolleres: the terms listed in the taxonomy are structured along different dimensions (such as scientific data). So we should ask what are these categories (to identify)?

MarkLizar: It has been difficult to find a consistent taxonomy or structure for categorisation (based on experience)

ACTION: Niklas to start structuring categories of personal data and involved dimensions together with Elmar and Harsh, Mark

MarkLizar: I can share some previous attempts that did not work

MarkLizar: GDPR has categories of controller, which are referenced lightly. We called them GDPR purpose categories, but they are different lists.

AxelPolleres: We are interested in different taxonomies for categories of data, processing, data subjects, etc. We have a starting point already. We should try to structure there, but we don't have these for the use-cases.

AxelPolleres: We should go through the use-cases, and task the owners (of use-case) to enter the applicable taxonomies (from email) to the use-case page.

AxelPolleres: This will allow us to cover the use-cases and to see if we are missing something. (suggested approach to go forward).

https://www.w3.org/community/dpvcg/wiki/Taxonomy

AxelPolleres: For the approved categories, we should start focusing on these.

ACTION: Mark to add previous classifications to subpages of https://www.w3.org/community/dpvcg/wiki/Taxonomy

MarkLizar: I have a few reasons why these categories/lists don't work (to be adde to Taxnomy wiki)

AxelPolleres: Next on the agenda, use-cases. Do we have some use-case owner's on call.

https://lists.w3.org/Archives/Public/public-dpvcg/2018Nov/0000.html points 1.-6. in the email

Harald can try to do that proposed action on the public entities obligations use case he added to the wiki

current use cases:
https://www.w3.org/community/dpvcg/wiki/Use-Cases,_Requirements,_Vocabularies#Use-Cases

AxelPolleres: What we need (w.r.t use-cases) is more description based on the points in the email.

ACTION: Rudy to add points 1.-6. from https://lists.w3.org/Archives/Public/public-dpvcg/2018Nov/0000.html to https://www.w3.org/community/dpvcg/wiki/SPECIAL/Proximus_use_case

Apologies - I have to drop - as I am at a security conference in Brussels and have to participate.. - very nice pace Axel !!

ACTION: MArtin to add points 1.-6. from https://lists.w3.org/Archives/Public/public-dpvcg/2018Nov/0000.html to https://www.w3.org/community/dpvcg/wiki/SPECIAL/DT_use_case I'm here and will tak the actions

for some reasins audio did not work:(

sorry for spelling errors

Yes I have sometimes trouble with the audio as well

ACTION: Ben to add points 1.-6. from https://lists.w3.org/Archives/Public/public-dpvcg/2018Nov/0000.html to https://www.w3.org/community/dpvcg/wiki/SPECIAL/TR_use_case

Axel, I think you've skipped the public entities use case - this would be an action point for Harald

ACTION: Stefano to Add points 1.-6. from https://lists.w3.org/archives/public/public-dpvcg/2018nov/0000.html to https://www.w3.org/community/dpvcg/wiki/DECODE/DEC01_use_case - https://www.w3.org/community/dpvcg/wiki/DECODE/DEC03_use_case

ACTION: Elmar to add points 1.-6. from https://lists.w3.org/archives/public/public-dpvcg/2018nov/0000.html to https://www.w3.org/community/dpvcg/wiki/ownyourdata/data_donation

AxelPolleres: About F2F in December. 