Legal Concepts

version 2.0

Final Community Group Report

This version:
https://www.w3.org/community/reports/dpvcg/CG-FINAL-legal-20240801/
Latest published version:
https://w3id.org/dpv/legal
Latest editor's draft:
https://dev.dpvcg.org/legal
Editor:
Harshvardhan J. Pandit (ADAPT Centre, Dublin City University)
Author:
Harshvardhan J. Pandit (ADAPT Centre, Dublin City University)
Feedback:
GitHub w3c/dpv (pull requests, new issue, open issues)
This Release
https://w3id.org/dpv/legal
Previous Release
https://w3id.org/dpv/1.0/dpv-legal
Key Publications
Data Privacy Vocabulary (DPV) -- Version 2 (2024)

Abstract

The LEGAL extension extends the Data Privacy Vocabulary (DPV) Specification to represent laws, authorities, and other legal concepts in various jurisdictions.

The canonical URL for LEGAL extension is https://w3id.org/dpv/legal, the namespace is https://w3id.org/dpv/legal#, the suggested prefix is legal, and this document along with source and releases are available at https://github.com/w3c/dpv.

Status of This Document

This specification was published by the Data Privacy Vocabularies and Controls Community Group. It is not a W3C Standard nor is it on the W3C Standards Track. Please note that under the W3C Community Final Specification Agreement (FSA) other conditions apply. Learn more about W3C Community and Business Groups.

Contributing: The DPVCG welcomes participation to improve the DPV and associated resources, including expansion or refinement of concepts, requesting information and applications, and addressing open issues. See contributing guide for further information.

GitHub Issues are preferred for discussion of this specification.

Data Privacy Vocabulary (DPV) Specification: is the base/core specification for the 'Data Privacy Vocabulary', which is extended for Personal Data [PD], Locations [LOC], Risk Management [RISK], Technology [TECH], and [AI]. Specific [LEGAL] extensions are also provided which model jurisdiction specific regulations and concepts . To support understanding and applications of [DPV], various guides and resources [GUIDES] are provided, including a [PRIMER]. A Search Index of all concepts from DPV and extensions is available.

[DPV] and related resources are published on GitHub. For a general overview of the Data Protection Vocabularies and Controls Community Group [DPVCG], its history, deliverables, and activities - refer to DPVCG Website. For meetings, see the DPVCG calendar.

The peer-reviewed article “Creating A Vocabulary for Data Privacy” presents a historical overview of the DPVCG, and describes the methodology and structure of the DPV along with describing its creation. An open-access version can be accessed here, here, and here. The article Data Privacy Vocabulary (DPV) - Version 2, accepted for presentation at the 23rd International Semantic Web Conference (ISWC 2024), describes the changes made in DPV v2.

3. DPV Extensions for Laws

The following extensions to the [DPV] exist for modelling concepts from laws and regulations:

4. Laws

Laws are represented as instances of dpv:Law, and are associated with their jurisdictions using the [LOC] taxonomy and dpv:hasJurisdiction relation. The webpage for the law, if available, is indicated using foaf:homepage, and the temporal start and end if available, is represented using dct:temporal relation with an instance of time:ProperInterval.

ID Name Jurisdictions Authorities Webpage Start/End
legal-de:law-BDSG Federal Data Protection Act (BDSG) Germany legal-de:DPA-DE, legal-de:DPA-DE-BB, legal-de:DPA-DE-BE, legal-de:DPA-DE-BY-non-public, legal-de:DPA-DE-BY-public, legal-de:DPA-DE-HB, legal-de:DPA-DE-HE, legal-de:DPA-DE-HH, legal-de:DPA-DE-MV, legal-de:DPA-DE-NI, legal-de:DPA-DE-NW, legal-de:DPA-DE-RP, legal-de:DPA-DE-SH, legal-de:DPA-DE-SL, legal-de:DPA-DE-SN, legal-de:DPA-DE-ST, legal-de:DPA-DE-TH link 2019-11-20/ongoing
legal-de:law-BE-BbgDSG Brandenburg Data Protection Act (BbgDSG) Brandenburg, Germany legal-de:DPA-DE-BB link
legal-de:law-BE-BlnDSG Berlin Data Protection Act (BlnDSG) Berlin, Germany legal-de:DPA-DE-BE link
legal-de:law-BW-LDSG State Data Protection Act (LDSG) (BW) Baden-Württemberg, Germany link
legal-de:law-BY-BayDSG Bavarian Data Protection Act (BayDSG) Bavaria, Germany legal-de:DPA-DE-BY-non-public, legal-de:DPA-DE-BY-public link
legal-de:law-HB-BremDSGVOAG Bremen Implementing Act for the EU General Data Protection Regulation (BremDSGVOAG) Bremen, Germany legal-de:DPA-DE-HB link
legal-de:law-HE-HDISG Hessian Data Protection and Freedom of Information Act (HDSIG) Hesse, Germany legal-de:DPA-DE-HE link
legal-de:law-HH-HmbDSG Hamburg Data Protection Act (HmbDSG) Hamburg, Germany legal-de:DPA-DE-HH link
legal-de:law-LSA-DSG Law on the protection of personal data of citizens (Saxony-Anhalt Data Protection Act - DSG LSA) Saxony-Anhalt, Germany legal-de:DPA-DE-ST link
legal-de:law-MV-DSG Act to adapt the State Data Protection Act and other data protection regulations in the area of ​​responsibility of the Ministry of the Interior and Europe Mecklenburg-West Pomerania to Regulation (EU) 2016/679 and to implement Directive (EU) 2016/680 Mecklenburg-Western-Pomerania, Germany legal-de:DPA-DE-MV link
legal-de:law-NI-NDSG Lower Saxony Data Protection Act (NDSG) Lower-Saxony, Germany legal-de:DPA-DE-NI link
legal-de:law-NW-DSG North Rhine-Westphalia Data Protection Act (DSG NRW) North-Rhine Westphalia, Germany legal-de:DPA-DE-NW link
legal-de:law-RP-LDSG State Data Protection Act (LDSG) Rhineland-Palatinate, Germany legal-de:DPA-DE-RP link
legal-de:law-SH-LDSG Schleswig-Holstein law for the protection of personal data (state data protection law - LDSG) Schleswig-Holstein, Germany legal-de:DPA-DE-SH link
legal-de:law-SL-SDSG Saarland Data Protection Act Saarland, Germany legal-de:DPA-DE-SL link
legal-de:law-SN-SächsDSG Law for the Protection of Informational Self-Determination in the Free State of Saxony (Saxon Data Protection Act - SächsDSG) Saxony, Germany legal-de:DPA-DE-SN link
legal-de:law-TH-ThürDSG Thuringian Data Protection Act (ThürDSG) Thuringia, Germany legal-de:DPA-DE-TH link
legal-eu:law-AIAct AI Act European Union (EU) link
legal-eu:law-DGA Data Governance Act (DGA) European Union (EU) link 2023-09-24/ongoing
legal-eu:law-DMA Digital Markets Act (DMA) European Union (EU) link 2022-11-01/ongoing
legal-eu:law-DSA Digital Services Act (DSA) European Union (EU) link 2022-11-16/ongoing
legal-eu:law-DataAct Data Act European Union (EU) link
legal-eu:law-GDPR General Data Protection Regulation (GDPR) European Union (EU) ; Iceland ; Liechtenstein ; Norway legal-de:DPA-DE, legal-de:DPA-DE-BB, legal-de:DPA-DE-BE, legal-de:DPA-DE-BY-non-public, legal-de:DPA-DE-BY-public, legal-de:DPA-DE-HB, legal-de:DPA-DE-HE, legal-de:DPA-DE-HH, legal-de:DPA-DE-MV, legal-de:DPA-DE-NI, legal-de:DPA-DE-NW, legal-de:DPA-DE-RP, legal-de:DPA-DE-SH, legal-de:DPA-DE-SL, legal-de:DPA-DE-SN, legal-de:DPA-DE-ST, legal-de:DPA-DE-TH, legal-eu:DPA-EDPB, legal-eu:DPA-EDPS, legal-ie:DPA-IE link 2018-05-25/ongoing
legal-gb:law-DPA Data Protection Act (DPA) United Kingdom of Great Britain and Northern Ireland legal-gb:DPA-GB link 2018-05-25/ongoing
legal-gb:law-GDPR General Data Protection Regulation (GDPR) United Kingdom of Great Britain and Northern Ireland legal-gb:DPA-GB link 2019-02-28/ongoing
legal-ie:law-DPA Data Protection Act 2018 (DPA) Ireland legal-ie:DPA-IE link 2018-05-24/ongoing
legal-in:law-DPDP Digital Personal Data Protection Act 2023 (DPDP) India legal-in:DPA-IN link 2023-08-11/ongoing
legal-us:law-CA-CCPA California Consumer Privacy Act (CCPA) California, United States of America legal-us:DPA-US-CA link 2020-01-01/ongoing
legal-us:law-CA-CPRA California Privacy Rights Act (CPRA) California, United States of America legal-us:DPA-US-CA link 2023-01-01/ongoing
legal-us:law-CO-CPA Colorado Privacy Act (CPA) Colorado, United States of America legal-us:DPA-US-CO link 2024-01-07/ongoing
legal-us:law-CT-CTPA Connecticut Data Privacy Act (CTPA) Connecticut, United States of America legal-us:DPA-US-CT link 2023-01-07/ongoing
legal-us:law-NV-NPICICA Nevada Privacy of Information Collected on the Internet from Consumers Act (NPICICA) Nevada, United States of America legal-us:DPA-US-NV link 2021-01-10/ongoing
legal-us:law-UT-UCPA Utah Consumer Privacy Act (UCPA) Utah, United States of America legal-us:DPA-US-UT link 2023-12-31/ongoing
legal-us:law-VA-VCDPA Virginia Consumer Data Protection Act (VCDPA) Virginia, United States of America legal-us:DPA-US-VA link 2023-01-01/ongoing

5. Authorities

Authorities are represented as instances of dpv:Authority, and are associated with specific jurisdictions using dpv:hasJurisdiction. The law which the authorities enforce is indicated by dpv:hasApplicableLaw. The webpage for the authority, if available, is indicated using foaf:homepage.

ID Name Jurisdictions Laws Webpage
legal-de:DPA-DE The Federal Commissioner for Data Protection and Freedom of Information Germany legal-de:law-BDSG
legal-eu:law-GDPR
link
legal-de:DPA-DE-BB The state representative for data protection and the right to inspect files in Brandenburg Brandenburg, Germany legal-de:law-BDSG
legal-de:law-BE-BbgDSG
legal-eu:law-GDPR
link
legal-de:DPA-DE-BE Berlin Commissioner for Data Protection and Freedom of Information Berlin, Germany legal-de:law-BDSG
legal-de:law-BE-BlnDSG
legal-eu:law-GDPR
link
legal-de:DPA-DE-BY-non-public Bavarian State Office for Data Protection Supervision Bavaria, Germany legal-de:law-BDSG
legal-de:law-BY-BayDSG
legal-eu:law-GDPR
link
legal-de:DPA-DE-BY-public The Bavarian State Commissioner for Data Protection Bavaria, Germany legal-de:law-BDSG
legal-de:law-BY-BayDSG
legal-eu:law-GDPR
link
legal-de:DPA-DE-HB The State Commissioner for Data Protection and Freedom of Information of the Free Hanseatic City of Bremen Bremen, Germany legal-de:law-BDSG
legal-de:law-HB-BremDSGVOAG
legal-eu:law-GDPR
link
legal-de:DPA-DE-HE The Hessian Commissioner for Data Protection and Freedom of Information Hesse, Germany legal-de:law-BDSG
legal-de:law-HE-HDISG
legal-eu:law-GDPR
link
legal-de:DPA-DE-HH The Hamburg Commissioner for Data Protection and Freedom of Information Hamburg, Germany legal-de:law-BDSG
legal-de:law-HH-HmbDSG
legal-eu:law-GDPR
link
legal-de:DPA-DE-MV The State Commissioner for Data Protection and Freedom of Information Mecklenburg-West Pomerania Mecklenburg-Western-Pomerania, Germany legal-de:law-BDSG
legal-de:law-MV-DSG
legal-eu:law-GDPR
link
legal-de:DPA-DE-NI The State Commissioner for Data Protection Lower Saxony Lower-Saxony, Germany legal-de:law-BDSG
legal-de:law-NI-NDSG
legal-eu:law-GDPR
link
legal-de:DPA-DE-NW State Commissioner for Data Protection and Freedom of Information North Rhine-Westphalia North-Rhine Westphalia, Germany legal-de:law-BDSG
legal-de:law-NW-DSG
legal-eu:law-GDPR
link
legal-de:DPA-DE-RP The state commissioner for data protection and freedom of information in Rhineland-Palatinate Rhineland-Palatinate, Germany legal-de:law-BDSG
legal-de:law-RP-LDSG
legal-eu:law-GDPR
link
legal-de:DPA-DE-SH Independent State Center for Data Protection Schleswig-Holstein Schleswig-Holstein, Germany legal-de:law-BDSG
legal-de:law-SH-LDSG
legal-eu:law-GDPR
link
legal-de:DPA-DE-SL Independent Data Protection Center Saarland - State Commissioner for Data Protection and Freedom of Information Saarland, Germany legal-de:law-BDSG
legal-de:law-SL-SDSG
legal-eu:law-GDPR
link
legal-de:DPA-DE-SN The Saxon data protection officer Saxony, Germany legal-de:law-BDSG
legal-de:law-SN-SächsDSG
legal-eu:law-GDPR
link
legal-de:DPA-DE-ST State representative for data protection in Saxony-Anhalt Saxony-Anhalt, Germany legal-de:law-BDSG
legal-de:law-LSA-DSG
legal-eu:law-GDPR
link
legal-de:DPA-DE-TH Thuringia state commissioner for data protection and freedom of information Thuringia, Germany legal-de:law-BDSG
legal-de:law-TH-ThürDSG
legal-eu:law-GDPR
link
legal-eu:DPA-EDPB European Data Protection Board European Union (EU) ; Iceland ; Liechtenstein ; Norway legal-eu:law-GDPR link
legal-eu:DPA-EDPS European Data Protection Supervisor European Union (EU) legal-eu:law-GDPR link
legal-gb:DPA-GB Information Commissioner's Office (ICO) United Kingdom of Great Britain and Northern Ireland legal-gb:law-DPA
legal-gb:law-GDPR
link
legal-ie:DPA-IE Data Protection Commission (DPC) Ireland legal-eu:law-GDPR
legal-ie:law-DPA
link
legal-in:DPA-IN Data Protection Board of India India legal-in:law-DPDP
legal-us:DPA-US-CA California Privacy Protection Agency (CPPA) California, United States of America legal-us:law-CA-CCPA
legal-us:law-CA-CPRA
link
legal-us:DPA-US-CO Colorado Attorney General Colorado, United States of America legal-us:law-CO-CPA link
legal-us:DPA-US-CT Connecticut Attorney General Connecticut, United States of America legal-us:law-CT-CTPA link
legal-us:DPA-US-NV Nevada Attorney General Nevada, United States of America legal-us:law-NV-NPICICA link
legal-us:DPA-US-UT Utah Attorney General Utah, United States of America legal-us:law-UT-UCPA link
legal-us:DPA-US-VA Virginia Attorney General Virginia, United States of America legal-us:law-VA-VCDPA link

6. Vocabulary Index

6.1 Classes

6.2 Properties

6.3 External

DPV uses the following terms from [RDF] and [RDFS] with their defined meanings:

The following external concepts are re-used within DPV:

7. Contributors

The following people have contributed to this vocabulary. The names are ordered alphabetically. The affiliations are informative do not represent formal endorsements. Affiliations may be outdated. The list is generated automatically from the contributors listed for defined concepts.

Funding Acknowledgements

Funding Sponsors

The DPVCG was established as part of the SPECIAL H2020 Project, which received funding from the European Union’s Horizon 2020 research and innovation programme under grant agreement No. 731601 from 2017 to 2019.

Harshvardhan J. Pandit was funded to work on DPV from 2020 to 2022 by the Irish Research Council's Government of Ireland Postdoctoral Fellowship Grant#GOIPD/2020/790.

The ADAPT SFI Centre for Digital Media Technology is funded by Science Foundation Ireland through the SFI Research Centres Programme and is co-funded under the European Regional Development Fund (ERDF) through Grant#13/RC/2106 (2018 to 2020) and Grant#13/RC/2106_P2 (2021 onwards).

Funding Acknowledgements for Contributors

The contributions of Harshvardhan J. Pandit have been made with the financial support of Science Foundation Ireland under Grant Agreement No. 13/RC/2106_P2 at the ADAPT SFI Research Centre.

A. References

A.1 Informative references

[AI]
AI Technology concepts for DPV. URL: https://w3id.org/dpv/ai
[DPV]
Data Privacy Vocabulary (DPV) Specification. URL: https://w3id.org/dpv
[DPVCG]
W3C Data Privacy Vocabularies and Controls Community Group (DPVCG). URL: https://www.w3.org/community/dpvcg/
[EU-AIAct]
EU AI Act concepts for DPV. URL: https://w3id.org/dpv/legal/eu/aiact
[EU-DGA]
EU DGA concepts for DPV. URL: https://w3id.org/dpv/legal/eu/dga
[EU-GDPR]
EU GDPR concepts for DPV. URL: https://w3id.org/dpv/legal/eu/gdpr
[EU-NIS2]
EU NIS2 concepts for DPV. URL: https://w3id.org/dpv/legal/eu/nis2
[GUIDES]
Guides for DPV. URL: https://w3id.org/dpv/guides
Legal Jurisdiction-relevant concepts for DPV. URL: https://w3id.org/dpv/legal
[LOC]
Location and Geo-Political Membership concepts for DPV. URL: https://w3id.org/dpv/loc
[PD]
Personal Data categories for DPV. URL: https://w3id.org/dpv/pd
[PRIMER]
Primer for Data Privacy Vocabulary. URL: https://w3id.org/dpv/primer
[RDF]
RDF 1.1 Concepts and Abstract Syntax. URL: https://www.w3.org/TR/rdf11-concepts/
[RDFS]
RDF Schema 1.1. URL: https://www.w3.org/TR/rdf-schema/
[RISK]
Risk Assessment and Management concepts for DPV. URL: https://w3id.org/dpv/risk
[TECH]
Technology concepts for DPV. URL: https://w3id.org/dpv/tech