IRC log of dpvcg on 2024-07-16

Timestamps are in UTC.

14:55:00 [harsh]
Scribe: harsh
repo: w3c/dpv
repo: w3c/dpv
gb, harsh is coolharsh55
harsh, I already had that GitHub account for harsh
14:55:13 [harsh]
Meeting: DPVCG Meeting Call
Date: 16 JUL 2024
Date: 16 JUL 2024
Meeting minutes:
purl for this meeting:
Topic: Interpretation of Process
\ See
\ See
14:56:20 [harsh]
julianFlake: it would be better to have a property to associate the concepts e.g. purpose, personal data and so on
have process X with nested process X1 for PurposeA and Data1, and X2 for PurposeB and Data1 and Data2.
harsh: we shouldn't have additional properties as we would have to create too many of them e.g. for legal basis and processing
harsh: suggestion is to use nested processes to create units who meaning is based on combination of concepts present in the process
julian: so we would have subprocesses where a process has another process within itself where the subprocesses are processes in their own context
julian: this was discussed earlier at some point as well?
julian: this was discussed earlier at some point as well?
\ discussed - agreed, and add note to the specification explaining this interpretation of processes
Topic: Planning next release
\ see for list of issues
\ see for list of issues
Subtopic: workflow management
Subtopic: workflow management
15:14:25 [gb] -> CLOSED Issue 148 switch to Gitflow workflow for repo management (by coolharsh55) [help-wanted] [code] [review]
harsh: the workflow going ahead will be based on gitflow where we have a main branch representing the stable work, a dev branch, and then feature branches
\ we agreed on this workflow, and closed the issue
Subtopic: archiving DPV
\ we agreed on this workflow, and closed the issue
Subtopic: archiving DPV
Subtopic: diagrams for v2
15:22:11 [harsh]
julian: no further updates - all diagrams are present, some minor diagrams being tested out but nothing pending for the specs
\ no venues identified, issue marked as completed
\ issue marked as completed
Subtopic: low priority
harsh: this was a suggestion from beatriz to provide all legal basis, rights, etc. from laws within a jurisdiction in one place - do we need this?
julian: what would this mean in terms of implementation? sounds confusing
\ issue marked as completed
Subtopic: low priority
\ marked as low priority
harsh: this was the issue about associating a policy or indicating a preferred one - recent discussion there about interpretation of policies to identify preference / outcome.
julian: what would this mean in terms of implementation? sounds confusing
Note #36 this is related to ongoing work in ODRL CG - therefore we will wait for that work and reuse / integrate it here
\ issue assigned to beatriz to follow up on
\ marked as low priority
15:27:57 [gb] -> Issue 36 Expressing preferred policies or templates (by csarven) [help-wanted] [question]
harsh: this was related to providing a way to indicate AI training should not happen on a website
beatriz: would be relevant for ODRL work
delaram: we had the AI ODRL profile that could be relevant here
\ issue assigned to beatriz to follow up on
julian: not trivial as diagrams need some control over what concepts are used to produce the diagrams
harsh: trivial and easy to do - will do it at some point when I'm bored and have a bit of time
15:32:52 [gb] -> Issue 147 Create extension EU NIS2 (by coolharsh55) [WIP] [help-wanted] [eu-nis2]
harsh: also involves creating a vocabulary to represent standards and linking them to DPV concepts e.g. 27560 is for consent records
harsh: would be also helpful to represent specific standards and then use these e.g. indicate which are harmonised standards in the eu extension
beatriz: there is a standard associated with IDSA architecture that is being made an ISO standard
julian: think that is based on an older DIN / German standard - interested in that
beatriz: would be relevant for ODRL work
harsh: easy to do - will be done over time by anyone
harsh: this had a bit of discussion but no conclusion - any solutions?
beatriz: this is relevant to work here in Gent, can have a student who will work on this. Also spoke with OSLO folks who have consent vocabulary
\ assigned to beatriz to follow up on
Subtopic: medium priority
harsh: this refers to adding more categories to PD - are there any in AI Act or in DPIA work?
delaram: AI Act mentions some biometrics but no specific list is given
tyttiRintamaki: nothing in DPIA analysis either
harsh: then we will keep this open to get the list of concepts and add them
harsh: would be also helpful to represent specific standards and then use these e.g. indicate which are harmonised standards in the eu extension
harsh: data breaches are also categorised along the same concepts - so the cause can be expressed as a lack of some specific category measure
\ accepted the work is relevant
Note #138 work has been accepted and will be started in next version
Note #135 identify what categories are present and add them to PD
Note #114 beatriz to follow up on this from local implementation
\ assigned to delaram
harsh: this is about taking datasheets and model cards and seeing how to represent them using DPV
delaramGolpayegani: what is the extent of this work? does it start from zero?
\ assigned to beatriz to follow up on
Subtopic: medium priority
\ no takers so far
harsh: for ODRL there is a separate issue, so for the other vocabularies what do we need to do?
beatriz: interested in PROV as that is relevant to work here
\ assigned to beatriz
julian: is gist actually used or useful as it is listed here?
beatriz: it provides more details about organisations that is not present in DPV
harsh: an adopter requested it, so we added it to the list
harsh: this is straightforward to do as it will require providing a link to the eurovoc concept
\ accepted the work is relevant
beatriz: this is of interest to ODRL CG as well, aim to get this done in the next release
Subtopic: High priority
Note #135 identify what categories are present and add them to PD
\ assigned to delaram
harsh: some ongoing work here
Added -> comment
15:43:35 [gb] -> Issue 94 Represent Datasheets and Model Cards with DPV (by coolharsh55) [todo] [help-wanted] [AI]
\ assigned to delaram
harsh: this is about taking datasheets and model cards and seeing how to represent them using DPV
delaramGolpayegani: what is the extent of this work? does it start from zero?
harsh: no, we had two EMILDAI students last year who did a mapping from GDPR to fields from these which can be used to which DPV concepts apply and which are needed. Then it will lead to a better version of datasheets and model cards.
15:48:13 [gb] -> Issue 43 Declaring additional axioms for DPV-OWL (by coolharsh55) [help-wanted] [owl]
harsh: would be good to have some assertions e.g. properties are functional or transitive, with more complex assertions stating combinations for subclasses
\ no takers so far
15:48:57 [gb] -> Issue 31 Mappings from DPV to other vocabularies (by coolharsh55) [todo] [help-wanted]
harsh: for ODRL there is a separate issue, so for the other vocabularies what do we need to do?
beatriz: interested in PROV as that is relevant to work here
\ assigned to beatriz
julian: is gist actually used or useful as it is listed here?
beatriz: it provides more details about organisations that is not present in DPV
harsh: an adopter requested it, so we added it to the list
15:50:23 [gb] -> Issue 75 Reuse/Refer to EUROVOC concepts for EU's fundamental rights (by coolharsh55) [rights] [WIP] [help-wanted] [eu-rights]
harsh: this is straightforward to do as it will require providing a link to the eurovoc concept
15:50:55 [gb] -> Issue 89 Multi-lingual labels and descriptions for concepts (by coolharsh55) [todo] [docs] [help-wanted] [code]
harsh: this requires a bit of work, already started on this for v2 but stopped as we didn't have enough manual reviews - will have this for 2.1
15:51:27 [gb] -> Issue 130 Alignment with ODRL (by besteves4) [scope] [WIP] [help-wanted]
beatriz: this is of interest to ODRL CG as well, aim to get this done in the next release
Subtopic: High priority
15:52:08 [gb] -> Issue 123 Add concepts from ENISA SotA Tech/Org Measures (by coolharsh55) [WIP] [help-wanted] [dpv] [eu-nis2] [good first issue]
harsh: this includes measures mentioned in ENISA documents as well as the NIS2 work suggested by Jenni
15:52:51 [gb] -> Issue 110 Add concepts from ISO 22989:2022 AI Terminology (by coolharsh55) [todo] [help-wanted] [AI] [good first issue]
\ assigned to delaram
15:53:28 [gb] -> Issue 111 Model information about legal bases (by coolharsh55) [todo] [help-wanted] [dpv]
harsh: some ongoing work here
15:53:47 [gb] -> Issue 12 Use-Cases and Examples showing how vocab can be used (by coolharsh55) [use-case] [example] [todo]
harsh: important that we have use-cases and examples as best practice ; we have some 70 examples at the moment but need a review to see whether any examples should be provided which aren't
harsh: use-cases are important to show how concepts are produced and where applications of DPV are envisioned ; see e.g.
15:55:01 [gb] -> Issue 48 Specify association between law, authority, and jurisdiction in documentation of respective concepts (by coolharsh55) [legal] [fix-this]
harsh: this is an issue where the relation between law, authority, and jurisdiction is not shown in the HTML e.g. see legal page where only laws are listed
harsh: better to fix this in this version itself
Note #48 fix this in time for 2.0 release
15:56:59 [gb] -> Issue 170 Add Lawfulness concept for each Law/Regulation (by coolharsh55) [todo] [eu-nis2] [eu-aiact] [eu-dga]
harsh: simple to do - add lawfulness and compliant concepts to each law defined
15:57:46 [gb] -> Issue 147 Create extension EU NIS2 (by coolharsh55) [WIP] [help-wanted] [eu-nis2]
harsh: pending work for NIS2 includes adding concepts e.g. authorities, list of critical sectors
15:58:08 [gb] -> Issue 143 Integrate AIRO/VAIR concepts for AI and AI Act vocabulary (by coolharsh55) [todo] [help-wanted] [AI] [eu-aiact]
julian: what is the difference between this and 110 ?
harsh: 110 is about AI extension in general, this is about AIRO/VAIR which are delaram's outputs and how to integrate them
\ assigned to delaram, planned to be completed by September
15:59:22 [gb] -> Issue 126 AI Extension to provide AI-specific concepts (by coolharsh55) [WIP] [help-wanted] [AI]
\ same as above - about AI extension in general, 110 is about ISO standard, 143 is about AIRO/VAIR, this is about the extension overall
15:59:48 [gb] -> Issue 103 Guide for Data Breach (by coolharsh55) [guide] [WIP] [eu-gdpr]
harsh: work in progress
15:59:55 [gb] -> Issue 91 Provide guidance for implementing ISO/IEC 29184 Privacy Notice using DPV (by coolharsh55) [guide] [WIP] [help-wanted]
harsh: working on this right now - hope to have a demo ready for next week about machine-readable notices
16:00:20 [gb] -> Issue 74 Add Risk Management concepts from ISO 31000 series (by coolharsh55) [WIP] [help-wanted] [risk]
harsh: there is some pending proposals about adding in risk management
16:00:38 [gb] -> Issue 66 Provide a Guide on use of DPV for DPIA (by coolharsh55) [WIP] [docs] [eu-gdpr]
harsh: work in progress
\ assigned to tytti
16:01:01 [gb] -> Issue 67 Provide for Guide using DPV for ROPA (by coolharsh55) [WIP] [docs] [eu-gdpr]
harsh: work in progress - based on Paul's PhD work
16:01:15 [gb] -> Issue 63 Add Right Non-fulfilment Justifications for GDPR’s rights (by besteves4) [todo] [eu-gdpr]
harsh: this is about linking non-fulfilment justifications to GDPR rights similar to how legal basis and rights are related
\ assigned to beatriz
16:01:52 [gb] -> Issue 4 Machine-readable requests to execute rights (by coolharsh55) [rights] [guide] [WIP]
harsh: this is about how to exercise a right, what data is needed, how to specify in response identity is needed
beatriz: have work on this
harsh: good paper for JURIX, the CFP is out with deadline SEP-06, conference is on DEC-11 in Brno, Czech
Topic: Next Meeting
\ next meeting will be in 1 week on TUESDAY at 13:30 WEST / 14:40 CEST. Agenda will be continuation of current discussion with any updates on github/mailing list and AOB.
rrsagent, publish minutes v2
