w3c / dpv

Data Privacy Vocabularies and Controls CG (DPVCG)

Home Page:https://w3id.org/dpv

Geek Repo:Geek Repo

Github PK Tool:Github PK Tool

DPV v1.0 release candiate - feedback, discussions, and actions

coolharsh55 opened this issue · comments

This issue is a placeholder, and collective single representation of the feedback, discussions, and actions related to DPV v0.8.1 and its role as a release candidate for DPV 1.0.

(pinned edit) As per the last meeting on 19 OCT, the release date is set to (approx.) 15 NOV. The below are the list of tasks/issues to be addressed by then:

  • DPV-Legal - remove duplicate concepts, move to EU vocabs, add pending concepts ;
    • #61 - not fixed in v1
    • #48 - not fixed in v1
    • #46 - note added to this effect
  • OWL - correctness of syntax ;
  • Concepts
    • Technical Measures #23
    • Purpose #22
    • Consent #21
    • Rules #18
    • Data Collection Method #16
    • Personal Data and PII #14
    • Sensitivity of Data #11 - not fixed in v1
    • Data Subject category #5
  • Minor fixes
  • Release prep/docs
    • #40
    • #39
    • #38
    • #24 - not completed in v1
    • #12
    • #65
    • #66 - can be done after v1 publication
    • #67 - can be done after v1 publication
    • #68 - can be done after v1 publication
    • #71 - to detect errors in concepts
  • Notes on Future Work
    • #4 Rights Exercise - will be integrated in v1
    • #64 Data Breach - not fixed in v1

Figure 25 (https://w3c.github.io/dpv/primer/), EncryptionInRest and EncryptionInTransfer is confusing. What does EncryptionInRest represent? Is it TLS level encryption? I believe by EncryptionInTransfer, you mean the data encryption before transfer or?

"At Rest" refers to data being encrypted where it 'stays' or is stored. The other one, "In Transit", relates to encrypting when data 'moves' or is transferred. I don't remember how we ended up with the form "in rest/transfer", but I do remember selecting 'Transfer' instead of 'Transit' as it aligns better with transfer as the processing verb instead of transit which is not present in DPV. The term definitions in the spec do clarfify this, e.g. https://w3id.org/dpv#EncryptionInRest.