EU Data Governance Act (DGA)

version 2.2

Final Community Group Report

This version:
https://www.w3.org/community/reports/dpvcg/CG-FINAL-eu-dga-20250801/
Latest published version:
https://w3id.org/dpv/legal/eu/dga
Latest editor's draft:
https://dev.dpvcg.org//legal/eu/dga
Editors:
Harshvardhan J. Pandit (AI Accountability Lab (AIAL), Trinity College Dublin)
Beatriz Esteves (IDLab, IMEC, Ghent University)
Authors:
Beatriz Esteves (IDLab, IMEC, Ghent University)
Georg P. Krog (Signatu AS)
Harshvardhan J. Pandit (AI Accountability Lab (AIAL), Trinity College Dublin)
Feedback:
GitHub w3c/dpv (pull requests, new issue, open issues)
This Release
https://w3id.org/dpv/2.2/legal/eu/dga
Previous Release
https://w3id.org/dpv/2.1/legal/eu/dga
Changelog
Changelog for v2.2
Key Publications
Data Privacy Vocabulary (DPV) -- Version 2.0 (2024)

Contributors: (ordered alphabetically) Beatriz Esteves (IDLab, IMEC, Ghent University), Georg P. Krog (Signatu AS), Harshvardhan J. Pandit (AI Accountability Lab (AIAL), Trinity College Dublin). NOTE: The affiliations are informative, do not represent formal endorsements, and may be outdated as this list is generated automatically from existing data.

Abstract

The EU-DGA extension extends the Data Privacy Vocabulary (DPV) Specification to provide concepts such as entities, rights, and other relevant concepts based on the Data Governance Act (DGA). The canonical URL for the EU-DGA extension is https://w3id.org/dpv/legal/eu/dga, the namespace for EU-DGA terms is https://w3id.org/dpv/legal/eu/dga#, the suggested prefix is eu-dga, and this document along with source and releases are available at https://github.com/w3c/dpv.

This work was first presented in the article "Semantics for Implementing Data Reuse and Altruism under EU's Data Governance Act" by Beatriz Esteves, Victor Rodriguez Doncel, Harshvardhan J. Pandit, and Dave Lewis.

DPV Specifications: The [DPV] is the core specification within the DPV family, with the following extensions: Personal Data [PD], Locations [LOC], Risk Management [RISK], Technology [TECH] and [AI], [JUSTIFICATIONS], [SECTOR] specific extensions, and [LEGAL] extensions modelling specific jurisdictions and regulations. A [PRIMER] introduces the concepts and modelling of DPV specifications, and [GUIDES] describe application of DPV for specific applications and use-cases. The Search Index page provides a searchable hierarchy of all concepts. The Data Privacy Vocabularies and Controls Community Group (DPVCG) develops and manages these specifications through GitHub. For meetings, see the DPVCG calendar.

To cite and understand the structure of DPV, the article "Data Privacy Vocabulary (DPV) - Version 2.0" (2024) describes the current state of DPV and extensions from version 2.0 onwards (open access version here). The earlier article "Creating A Vocabulary for Data Privacy" (2019) describes how the DPV was developed (open access versions here, here, and here).

Contributing: The DPVCG welcomes participation to improve the DPV and associated resources, including expansion or refinement of concepts, requesting information and applications, and addressing open issues. See contributing guide for further information.

Status of This Document

This specification was published by the Data Privacy Vocabularies and Controls Community Group. It is not a W3C Standard nor is it on the W3C Standards Track. Please note that under the W3C Community Final Specification Agreement (FSA) other conditions apply. Learn more about W3C Community and Business Groups.

GitHub Issues are preferred for discussion of this specification.

1. Introduction

This extension provides concepts relevant for the implementation of EU's Data Governance Act (DGA). The DGA promotes availability of data and encourages its sharing and reuse through novel mechanisms such as 'data intermediaries' and 'data altruism'. It also provides specific rights, and requires implementation details such as specific technical measures in order to ensure such sharing and altruistic (re-)uses of data are compliant with existing regulations, such as [GDPR], and respect rights and freedoms.

Note: Extending the DGA vocabulary

This extension provides the following concepts defined or required by the DGA:

2. Entities

Entities in the [DGA] are defined by extending the dpv:LegalEntity concept, and are associated with using the relation dpv:hasEntity. DGA's entities are different from 'legal roles' in GDPR's use of 'controllers' and 'processors' as the DGA entities are established with a specific role and purpose. For example, a 'Data Co-operative' is a legal entity which is established to provide the data co-operative services - namely for intermediation and exercise of rights.

Note: Associating entities in context

5. Services

The [DGA] defines and regulates several 'services', such as those for data intermediation and altruism. To represent these, the concept dpv:Service is extended. Services can be associated using the relation dpv:hasService.

6. Registers

The [DGA] requires the creation and maintenance of specific registers or registries, such as those for data altruistic organisations. These are represented by extending the concept dpv:PublicRegisterOfEntities. Membership of the registry can be expressed using the concept dpv:hasEntity, or even through use of [SKOS] collections.

7. Tech/Org Measures

The specific technical and organisational measures defined or implied in the [DGA] are defined by extending the dpv:TechnicalOrganisationalMeasure concepts. These can be associated by using the relations dpv:hasTechnicalMeasure and dpv:hasOrganisationalMeasure. In addition to these, if a measure has legal enforcement, then the concept dpv:LegalMeasure and relation dpv:hasLegalMeasure can be used.

8. Compliance

The concepts in this section reflect the status of processing operations being in compliance with DGA, by extending the ComplianceStatus from DPV for DGA. It does not define the requirements for compliance itself. To indicate these, the relation dpv:hasLawfulness can be used.

9. Vocabulary Index

9.1 Classes

9.1.1 Art 12(e) Data Exchange Approval

Term A12-e-Exchange-Approval Prefix eu-dga
Label Art 12(e) Data Exchange Approval
IRI https://w3id.org/dpv/legal/eu/dga#A12-e-Exchange-Approval
Type rdfs:Class, skos:Concept, dpv:LegalBasis
Broader/Parent types dpv:LegalBasis
Object of relation dpv:hasLegalBasis
Definition Explicit request or approval of the data subject or data holder to utilise additional specific tools for the purposes of facilitating exchange of data
Source DGA 12.e
Date Created 2024-02-14
Contributors Beatriz Esteves
See More: section LEGAL-BASIS in EU-DGA

9.1.2 Art 2(6) Permission

Term A2-6-Permission Prefix eu-dga
Label Art 2(6) Permission
IRI https://w3id.org/dpv/legal/eu/dga#A2-6-Permission
Type rdfs:Class, skos:Concept, dpv:LegalBasis
Broader/Parent types dpv:LegalBasis
Object of relation dpv:hasLegalBasis
Definition The legal basis justifying processing of non-personal data based on the permission of an entity
Source DGA 2.6
Date Created 2024-02-14
Contributors Beatriz Esteves
See More: section LEGAL-BASIS in EU-DGA

9.1.3 A27 Right to Lodge Complaint

Term A27 Prefix eu-dga
Label A27 Right to Lodge Complaint
IRI https://w3id.org/dpv/legal/eu/dga#A27
Type rdfs:Class, skos:Concept, dpv:Right
Broader/Parent types dpv:Right
Object of relation dpv:hasRight
Definition Right of natural and legal persons to lodge a complaint
Source DGA 27
Date Created 2024-02-14
Date Modified 2024-12-17
Contributors Beatriz Esteves, Harshvardhan J. Pandit
See More: section LEGAL-RIGHTS in EU-DGA

9.1.4 Impact on A27 Right to Lodge Complaint

Term A27-Impact Prefix eu-dga
Label Impact on A27 Right to Lodge Complaint
IRI https://w3id.org/dpv/legal/eu/dga#A27-Impact
Type rdfs:Class, skos:Concept, dpv:RiskConcept, risk:PotentialConsequence, risk:PotentialImpact, risk:PotentialRisk
Broader/Parent types eu-dga:DGARightsImpactrisk:RightsImpactrisk:SocietalRiskConceptdpv:RiskConcept
Object of relation risk:avoids, risk:contains, risk:controls, risk:detects, risk:eliminates, risk:identifies, risk:interrupts, risk:intervenes, risk:investigates, risk:logs, risk:mitigates, risk:modifies, risk:monitors, risk:overrides, risk:recovers, risk:reduces, risk:remedies, risk:resolves, risk:reverses, risk:shares, risk:substitutes, risk:transfers
Definition Something that acts as or is considered as an impact on Right of natural and legal persons to lodge a complaint
Source DGA 27
Date Created 2024-12-17
Contributors Harshvardhan J. Pandit
See More: section RIGHTS-IMPACTS in EU-DGA

9.1.5 A28 Right to an effective judicial remedy

Term A28 Prefix eu-dga
Label A28 Right to an effective judicial remedy
IRI https://w3id.org/dpv/legal/eu/dga#A28
Type rdfs:Class, skos:Concept, dpv:Right
Broader/Parent types dpv:Right
Object of relation dpv:hasRight
Definition Right of affected natural and legal persons to an effective judicial remedy
Usage Note The right is scoped to legally binding decisions referred to in Article 14 taken by the competent authorities for data intermediation services in the management, control and enforcement of the notification regime for data intermediation services providers and legally binding decisions referred to in Articles 19 and 24 taken by the competent authorities for the registration of data altruism organisations in the monitoring of recognised data altruism organisations
Source DGA 28
Date Created 2024-12-17
Contributors Harshvardhan J. Pandit
See More: section LEGAL-RIGHTS in EU-DGA

9.1.6 A28-3 Right to Impartial Review

Term A28-3 Prefix eu-dga
Label A28-3 Right to Impartial Review
IRI https://w3id.org/dpv/legal/eu/dga#A28-3
Type rdfs:Class, skos:Concept, dpv:Right
Broader/Parent types eu-dga:A28dpv:Right
Object of relation dpv:hasRight
Definition Right of natural and legal persons to get a review by an impartial body with the appropriate expertise
Source DGA 28.3
Date Created 2024-02-14
Date Modified 2024-12-17
Contributors Beatriz Esteves, Harshvardhan J. Pandit
See More: section LEGAL-RIGHTS in EU-DGA

9.1.7 Impact on A28-3 Right to Impartial Review

Term A28-3-Impact Prefix eu-dga
Label Impact on A28-3 Right to Impartial Review
IRI https://w3id.org/dpv/legal/eu/dga#A28-3-Impact
Type rdfs:Class, skos:Concept, dpv:RiskConcept, risk:PotentialConsequence, risk:PotentialImpact, risk:PotentialRisk
Broader/Parent types eu-dga:A28-Impacteu-dga:DGARightsImpactrisk:RightsImpactrisk:SocietalRiskConceptdpv:RiskConcept
Object of relation risk:avoids, risk:contains, risk:controls, risk:detects, risk:eliminates, risk:identifies, risk:interrupts, risk:intervenes, risk:investigates, risk:logs, risk:mitigates, risk:modifies, risk:monitors, risk:overrides, risk:recovers, risk:reduces, risk:remedies, risk:resolves, risk:reverses, risk:shares, risk:substitutes, risk:transfers
Definition Something that acts as or is considered as an impact on Right of natural and legal persons to get a review by an impartial body with the appropriate expertise
Source DGA 28.3
Date Created 2024-02-14
Contributors Harshvardhan J. Pandit
See More: section RIGHTS-IMPACTS in EU-DGA

9.1.8 Impact on A28 Right to an effective judicial remedy

Term A28-Impact Prefix eu-dga
Label Impact on A28 Right to an effective judicial remedy
IRI https://w3id.org/dpv/legal/eu/dga#A28-Impact
Type rdfs:Class, skos:Concept, dpv:RiskConcept, risk:PotentialConsequence, risk:PotentialImpact, risk:PotentialRisk
Broader/Parent types eu-dga:DGARightsImpactrisk:RightsImpactrisk:SocietalRiskConceptdpv:RiskConcept
Object of relation risk:avoids, risk:contains, risk:controls, risk:detects, risk:eliminates, risk:identifies, risk:interrupts, risk:intervenes, risk:investigates, risk:logs, risk:mitigates, risk:modifies, risk:monitors, risk:overrides, risk:recovers, risk:reduces, risk:remedies, risk:resolves, risk:reverses, risk:shares, risk:substitutes, risk:transfers
Definition Something that acts as or is considered as an impact on Right of affected natural and legal persons to an effective judicial remedy
Source DGA 28
Date Created 2024-12-17
Contributors Harshvardhan J. Pandit
See More: section RIGHTS-IMPACTS in EU-DGA

9.1.9 Art 31(2) Data Transfer International Agreement

Term A31-2-Transfer-Agreement Prefix eu-dga
Label Art 31(2) Data Transfer International Agreement
IRI https://w3id.org/dpv/legal/eu/dga#A31-2-Transfer-Agreement
Type rdfs:Class, skos:Concept, dpv:LegalBasis
Broader/Parent types dpv:DataTransferLegalBasisdpv:LegalBasis
Object of relation dpv:hasLegalBasis
Definition Data Transfer International Agreement
Source DGA 31.2
Date Created 2024-02-14
Contributors Beatriz Esteves
See More: section LEGAL-BASIS in EU-DGA

9.1.10 Art 31(3) Data Transfer Third Country Judgement

Term A31-3-Third-Country-Judgement Prefix eu-dga
Label Art 31(3) Data Transfer Third Country Judgement
IRI https://w3id.org/dpv/legal/eu/dga#A31-3-Third-Country-Judgement
Type rdfs:Class, skos:Concept, dpv:LegalBasis
Broader/Parent types dpv:DataTransferLegalBasisdpv:LegalBasis
Object of relation dpv:hasLegalBasis
Definition Data Transfer Third Country Judgement
Source DGA 31.3
Date Created 2024-02-14
Contributors Beatriz Esteves
See More: section LEGAL-BASIS in EU-DGA

9.1.11 Art 5(11) Model Contractual Clauses

Term A5-11-MCC Prefix eu-dga
Label Art 5(11) Model Contractual Clauses
IRI https://w3id.org/dpv/legal/eu/dga#A5-11-MCC
Type rdfs:Class, skos:Concept, dpv:LegalBasis
Broader/Parent types dpv:DataTransferLegalBasisdpv:LegalBasis
Object of relation dpv:hasLegalBasis
Definition Model Contractual Clauses
Source DGA 5.11
Date Created 2024-02-14
Contributors Beatriz Esteves
See More: section LEGAL-BASIS in EU-DGA

9.1.12 Art 5(12) Adequacy Decision

Term A5-12-Adequacy-Decision Prefix eu-dga
Label Art 5(12) Adequacy Decision
IRI https://w3id.org/dpv/legal/eu/dga#A5-12-Adequacy-Decision
Type rdfs:Class, skos:Concept, dpv:LegalBasis
Broader/Parent types dpv:DataTransferLegalBasisdpv:LegalBasis
Object of relation dpv:hasLegalBasis
Definition Adequacy Decision permitting the transfer of data
Source DGA 5.12
Date Created 2024-02-14
Contributors Beatriz Esteves
See More: section LEGAL-BASIS in EU-DGA

9.1.13 Art 5(9) Permission for Transfer

Term A5-9-Transfer-Permission Prefix eu-dga
Label Art 5(9) Permission for Transfer
IRI https://w3id.org/dpv/legal/eu/dga#A5-9-Transfer-Permission
Type rdfs:Class, skos:Concept, dpv:LegalBasis
Broader/Parent types dpv:DataTransferLegalBasisdpv:LegalBasis
Object of relation dpv:hasLegalBasis
Definition The legal basis justifying processing of non-personal data based on the permission of an entity to transfer data
Source DGA 5.9
Date Created 2024-02-14
Contributors Beatriz Esteves
See More: section LEGAL-BASIS in EU-DGA

9.1.14 A9-2 Right to Redress

Term A9-2 Prefix eu-dga
Label A9-2 Right to Redress
IRI https://w3id.org/dpv/legal/eu/dga#A9-2
Type rdfs:Class, skos:Concept, dpv:Right
Broader/Parent types dpv:Right
Object of relation dpv:hasRight
Definition Right of redress for a natural or legal person directly affected by a decision regarding reuse (A9-1), in the Member State where the relevant body is located
Source DGA 9-3
Date Created 2024-12-17
Contributors Harshvardhan J. Pandit
See More: section LEGAL-RIGHTS in EU-DGA

9.1.15 Impact on A9-2 Right to Redress

Term A9-2-Impact Prefix eu-dga
Label Impact on A9-2 Right to Redress
IRI https://w3id.org/dpv/legal/eu/dga#A9-2-Impact
Type rdfs:Class, skos:Concept, dpv:RiskConcept, risk:PotentialConsequence, risk:PotentialImpact, risk:PotentialRisk
Broader/Parent types eu-dga:DGARightsImpactrisk:RightsImpactrisk:SocietalRiskConceptdpv:RiskConcept
Object of relation risk:avoids, risk:contains, risk:controls, risk:detects, risk:eliminates, risk:identifies, risk:interrupts, risk:intervenes, risk:investigates, risk:logs, risk:mitigates, risk:modifies, risk:monitors, risk:overrides, risk:recovers, risk:reduces, risk:remedies, risk:resolves, risk:reverses, risk:shares, risk:substitutes, risk:transfers
Definition Something that acts as or is considered as an impact on Right of redress for a natural or legal person directly affected by a decision regarding reuse (A9-1), in the Member State where the relevant body is located
Source DGA 9-3
Date Created 2024-12-17
Contributors Harshvardhan J. Pandit
See More: section RIGHTS-IMPACTS in EU-DGA

9.1.16 Public Register of Data Altruism Organisations

Term DAORegister Prefix eu-dga
Label Public Register of Data Altruism Organisations
IRI https://w3id.org/dpv/legal/eu/dga#DAORegister
Type rdfs:Class, skos:Concept, dpv:PublicRegisterOfEntities
Broader/Parent types dpv:PublicRegisterOfEntities
Definition Registry containing list of recognised data altruism organisations
Source DGA 19.5
Date Created 2024-02-14
Contributors Beatriz Esteves
See More: section REGISTERS in EU-DGA

9.1.17 EU's Public Register of Data Altruism Organisations

Term DAORegisterEU Prefix eu-dga
Label EU's Public Register of Data Altruism Organisations
IRI https://w3id.org/dpv/legal/eu/dga#DAORegisterEU
Type rdfs:Class, skos:Concept, dpv:PublicRegisterOfEntities
Broader/Parent types dpv:PublicRegisterOfEntities
Definition Registry maintained by EU containing list of recognised data altruism organisations
Source DGA 19.5
Date Created 2024-02-14
Contributors Beatriz Esteves
See More: section REGISTERS in EU-DGA

9.1.18 National Public Register of Data Altruism Organisations

Term DAORegisterNational Prefix eu-dga
Label National Public Register of Data Altruism Organisations
IRI https://w3id.org/dpv/legal/eu/dga#DAORegisterNational
Type rdfs:Class, skos:Concept, dpv:PublicRegisterOfEntities
Broader/Parent types dpv:PublicRegisterOfEntities
Definition Registry maintained at National level containing list of recognised data altruism organisations
Source DGA 19.6
Date Created 2024-02-14
Contributors Beatriz Esteves
See More: section REGISTERS in EU-DGA

9.1.19 Data Altruism Annual Activity Report

Term DataAltruismAnnualReport Prefix eu-dga
Label Data Altruism Annual Activity Report
IRI https://w3id.org/dpv/legal/eu/dga#DataAltruismAnnualReport
Type rdfs:Class, skos:Concept, dpv:OrganisationalMeasure
Broader/Parent types dpv:RecordsOfActivitiesdpv:OrganisationalMeasuredpv:TechnicalOrganisationalMeasure
Object of relation dpv:hasOrganisationalMeasure, dpv:hasRecordOfActivity, dpv:hasTechnicalOrganisationalMeasure
Definition Document containing the annual activities reported by a Data Altruism organisation
Source DGA 20.2
Date Created 2024-02-14
Contributors Beatriz Esteves
See More: section TOMS in EU-DGA

9.1.20 Data Altruism Authority

Term DataAltruismAuthority Prefix eu-dga
Label Data Altruism Authority
IRI https://w3id.org/dpv/legal/eu/dga#DataAltruismAuthority
Type rdfs:Class, skos:Concept
Broader/Parent types dpv:Authoritydpv:GovernmentalOrganisationdpv:Organisationdpv:LegalEntitydpv:Entity
Object of relation dpv:hasActiveEntity, dpv:hasAuthority, dpv:hasEntity, dpv:hasNonInvolvedEntity, dpv:hasParty, dpv:hasPassiveEntity, dpv:hasResponsibleEntity, dpv:hasSubsidiary, dpv:isDeterminedByEntity, dpv:isImplementedByEntity, dpv:isIndicatedBy, dpv:isOrganisationalUnitOf, dpv:isRepresentativeFor, dpv:isSubsidiaryOf, eu-gdpr:hasEstablishment, eu-gdpr:hasMainEstablishment, eu-gdpr:isMainEstablishmentFor
Definition An authority tasked with overseeing the activity of data altruism organisations and maintaining a public register of said entities
Source DGA 23
Date Created 2024-02-14
Contributors Beatriz Esteves
See More: section ENTITIES in EU-DGA

9.1.21 Data Altruism Notice

Term DataAltruismNotice Prefix eu-dga
Label Data Altruism Notice
IRI https://w3id.org/dpv/legal/eu/dga#DataAltruismNotice
Type rdfs:Class, skos:Concept, dpv:OrganisationalMeasure
Broader/Parent types dpv:Noticedpv:OrganisationalMeasuredpv:TechnicalOrganisationalMeasure
Object of relation dpv:hasNotice, dpv:hasOrganisationalMeasure, dpv:hasTechnicalOrganisationalMeasure
Definition Notice providing information regarding the processing of data for data altruistic purposes
Source DGA 21.1
Date Created 2024-02-14
Contributors Beatriz Esteves
See More: section TOMS in EU-DGA

9.1.22 Data Altruism Organisation

Term DataAltruismOrganisation Prefix eu-dga
Label Data Altruism Organisation
IRI https://w3id.org/dpv/legal/eu/dga#DataAltruismOrganisation
Type rdfs:Class, skos:Concept
Broader/Parent types dpv:NonProfitOrganisationdpv:Organisationdpv:LegalEntitydpv:Entity
Object of relation dpv:hasActiveEntity, dpv:hasEntity, dpv:hasNonInvolvedEntity, dpv:hasParty, dpv:hasPassiveEntity, dpv:hasResponsibleEntity, dpv:hasSubsidiary, dpv:isDeterminedByEntity, dpv:isImplementedByEntity, dpv:isIndicatedBy, dpv:isOrganisationalUnitOf, dpv:isRepresentativeFor, dpv:isSubsidiaryOf, eu-dga:hasDAO, eu-gdpr:hasEstablishment, eu-gdpr:hasMainEstablishment, eu-gdpr:isMainEstablishmentFor
Definition An non-profit organisation who collects and shares data for altruistic purposes
Source 18, DGA 2.16
Date Created 2024-02-14
Contributors Beatriz Esteves
See More: section ENTITIES in EU-DGA

9.1.23 Record of Data Altruism Activity

Term DataAltruismRecord Prefix eu-dga
Label Record of Data Altruism Activity
IRI https://w3id.org/dpv/legal/eu/dga#DataAltruismRecord
Type rdfs:Class, skos:Concept, dpv:OrganisationalMeasure
Broader/Parent types dpv:RecordsOfActivitiesdpv:OrganisationalMeasuredpv:TechnicalOrganisationalMeasure
Object of relation dpv:hasOrganisationalMeasure, dpv:hasRecordOfActivity, dpv:hasTechnicalOrganisationalMeasure
Definition Document that logs the activity of the data altruism organisation
Source DGA 20
Date Created 2024-02-14
Contributors Beatriz Esteves
See More: section TOMS in EU-DGA

9.1.24 Data Asset List

Term DataAssetList Prefix eu-dga
Label Data Asset List
IRI https://w3id.org/dpv/legal/eu/dga#DataAssetList
Type rdfs:Class, skos:Concept, dpv:OrganisationalMeasure
Broader/Parent types dpv:OrganisationalMeasuredpv:TechnicalOrganisationalMeasure
Object of relation dpv:hasOrganisationalMeasure, dpv:hasTechnicalOrganisationalMeasure
Definition Searchable asset list which contains available data resources including their data format and size and the conditions for their re-use
Source DGA 8.2
Date Created 2024-02-14
Contributors Beatriz Esteves
See More: section TOMS in EU-DGA

9.1.25 Data Cooperative

Term DataCooperative Prefix eu-dga
Label Data Cooperative
IRI https://w3id.org/dpv/legal/eu/dga#DataCooperative
Type rdfs:Class, skos:Concept
Broader/Parent types eu-dga:DISPdpv:LegalEntitydpv:Entity
Object of relation dpv:hasActiveEntity, dpv:hasEntity, dpv:hasNonInvolvedEntity, dpv:hasParty, dpv:hasPassiveEntity, dpv:hasResponsibleEntity, dpv:isDeterminedByEntity, dpv:isImplementedByEntity, dpv:isIndicatedBy, dpv:isOrganisationalUnitOf, dpv:isRepresentativeFor, eu-dga:hasDISP, eu-gdpr:hasEstablishment, eu-gdpr:hasMainEstablishment, eu-gdpr:isMainEstablishmentFor
Definition An entity constituted by data subjects, one-person undertakings or SMEs who provides data intermediation services and supports its members in the exercise of their data-related rights
Source 10.c, DGA 2.15
Date Created 2024-02-14
Contributors Beatriz Esteves
See More: section ENTITIES in EU-DGA

9.1.26 Data Cooperative Service

Term DataCooperativeService Prefix eu-dga
Label Data Cooperative Service
IRI https://w3id.org/dpv/legal/eu/dga#DataCooperativeService
Type rdfs:Class, skos:Concept
Broader/Parent types eu-dga:DataIntermediationServicedpv:Servicedpv:Process
Object of relation dpv:hasProcess, dpv:hasService
Definition Service provided by a data cooperative
Date Created 2024-02-14
Contributors Beatriz Esteves
See More: section SERVICES in EU-DGA

9.1.27 Data Holder

Term DataHolder Prefix eu-dga
Label Data Holder
IRI https://w3id.org/dpv/legal/eu/dga#DataHolder
Type rdfs:Class, skos:Concept
Broader/Parent types dpv:LegalEntitydpv:Entity
Object of relation dpv:hasActiveEntity, dpv:hasEntity, dpv:hasNonInvolvedEntity, dpv:hasParty, dpv:hasPassiveEntity, dpv:hasResponsibleEntity, dpv:isDeterminedByEntity, dpv:isImplementedByEntity, dpv:isIndicatedBy, dpv:isOrganisationalUnitOf, dpv:isRepresentativeFor, eu-dga:hasDataHolder, eu-gdpr:hasEstablishment, eu-gdpr:hasMainEstablishment, eu-gdpr:isMainEstablishmentFor
Definition An entity who has the right to grant access to or to share certain personal data or non-personal data
Source DGA 2.8
Date Created 2024-02-14
Contributors Beatriz Esteves
See More: section ENTITIES in EU-DGA

9.1.28 Data Intermediation Authority

Term DataIntermediationAuthority Prefix eu-dga
Label Data Intermediation Authority
IRI https://w3id.org/dpv/legal/eu/dga#DataIntermediationAuthority
Type rdfs:Class, skos:Concept
Broader/Parent types dpv:Authoritydpv:GovernmentalOrganisationdpv:Organisationdpv:LegalEntitydpv:Entity
Object of relation dpv:hasActiveEntity, dpv:hasAuthority, dpv:hasEntity, dpv:hasNonInvolvedEntity, dpv:hasParty, dpv:hasPassiveEntity, dpv:hasResponsibleEntity, dpv:hasSubsidiary, dpv:isDeterminedByEntity, dpv:isImplementedByEntity, dpv:isIndicatedBy, dpv:isOrganisationalUnitOf, dpv:isRepresentativeFor, dpv:isSubsidiaryOf, eu-gdpr:hasEstablishment, eu-gdpr:hasMainEstablishment, eu-gdpr:isMainEstablishmentFor
Definition An authority tasked with overseeing the activity of data intermediation service providers and maintaining a public register of said entities
Source DGA 13
Date Created 2024-02-14
Contributors Beatriz Esteves
See More: section ENTITIES in EU-DGA

9.1.29 Record of Data Intermediation Activity

Term DataIntermediationRecord Prefix eu-dga
Label Record of Data Intermediation Activity
IRI https://w3id.org/dpv/legal/eu/dga#DataIntermediationRecord
Type rdfs:Class, skos:Concept, dpv:OrganisationalMeasure
Broader/Parent types dpv:RecordsOfActivitiesdpv:OrganisationalMeasuredpv:TechnicalOrganisationalMeasure
Object of relation dpv:hasOrganisationalMeasure, dpv:hasRecordOfActivity, dpv:hasTechnicalOrganisationalMeasure
Definition Document that logs the activity of the data intermediation service provider
Source DGA 12.o
Date Created 2024-02-14
Contributors Beatriz Esteves
See More: section TOMS in EU-DGA

9.1.30 Data Intermediation Service

Term DataIntermediationService Prefix eu-dga
Label Data Intermediation Service
IRI https://w3id.org/dpv/legal/eu/dga#DataIntermediationService
Type rdfs:Class, skos:Concept
Broader/Parent types dpv:Servicedpv:Process
Object of relation dpv:hasProcess, dpv:hasService
Definition Service of data intermediation which aims to facilitate the sharing of data between Data Subjects, Data Holders and Data Users
Source DGA 2.11
Date Created 2024-02-14
Contributors Beatriz Esteves
See More: section SERVICES in EU-DGA

9.1.31 Data Intermediation Service between Data Holders and Data Users

Term DataIntermediationServiceBetweenHoldersUsers Prefix eu-dga
Label Data Intermediation Service between Data Holders and Data Users
IRI https://w3id.org/dpv/legal/eu/dga#DataIntermediationServiceBetweenHoldersUsers
Type rdfs:Class, skos:Concept
Broader/Parent types eu-dga:DataIntermediationServicedpv:Servicedpv:Process
Object of relation dpv:hasProcess, dpv:hasService
Definition Data intermediation service for data shared between Data Holders and Data Users
Source DGA 10.a
Date Created 2024-02-14
Contributors Beatriz Esteves
See More: section SERVICES in EU-DGA

9.1.32 Data Intermediation Service between Data Subjects and Data Users

Term DataIntermediationServiceBetweenSubjectsUsers Prefix eu-dga
Label Data Intermediation Service between Data Subjects and Data Users
IRI https://w3id.org/dpv/legal/eu/dga#DataIntermediationServiceBetweenSubjectsUsers
Type rdfs:Class, skos:Concept
Broader/Parent types eu-dga:DataIntermediationServicedpv:Servicedpv:Process
Object of relation dpv:hasProcess, dpv:hasService
Definition Data intermediation service for data shared between Data Subjects, Natural Persons who are Data Holders and Data Users
Source DGA 10.b
Date Created 2024-02-14
Contributors Beatriz Esteves
See More: section SERVICES in EU-DGA

9.1.33 Data Reuse Assistant

Term DataReuseAssistant Prefix eu-dga
Label Data Reuse Assistant
IRI https://w3id.org/dpv/legal/eu/dga#DataReuseAssistant
Type rdfs:Class, skos:Concept
Broader/Parent types dpv:Entity
Object of relation dpv:hasActiveEntity, dpv:hasEntity, dpv:hasNonInvolvedEntity, dpv:hasPassiveEntity, dpv:hasResponsibleEntity, dpv:isDeterminedByEntity, dpv:isImplementedByEntity, dpv:isIndicatedBy, dpv:isOrganisationalUnitOf, dpv:isRepresentativeFor, eu-dga:hasDataReuseAssistant
Definition An entity designated by the Member State to provide technical support and guidance to public sector bodies regarding access and reuse of data and for requesting consent and permissions
Source DGA 7
Date Created 2024-02-14
Contributors Beatriz Esteves
See More: section ENTITIES in EU-DGA

9.1.34 Data Reuse Request

Term DataReuseRequest Prefix eu-dga
Label Data Reuse Request
IRI https://w3id.org/dpv/legal/eu/dga#DataReuseRequest
Type rdfs:Class, skos:Concept, dpv:OrganisationalMeasure
Broader/Parent types dpv:OrganisationalMeasuredpv:TechnicalOrganisationalMeasure
Object of relation dpv:hasOrganisationalMeasure, dpv:hasTechnicalOrganisationalMeasure
Definition Procedure to handle requests and provide data for reuse via single information point
Source DGA 5.1
Date Created 2024-02-14
Contributors Beatriz Esteves
See More: section TOMS in EU-DGA

9.1.35 Data User

Term DataUser Prefix eu-dga
Label Data User
IRI https://w3id.org/dpv/legal/eu/dga#DataUser
Type rdfs:Class, skos:Concept
Broader/Parent types dpv:LegalEntitydpv:Entity
Object of relation dpv:hasActiveEntity, dpv:hasEntity, dpv:hasNonInvolvedEntity, dpv:hasParty, dpv:hasPassiveEntity, dpv:hasResponsibleEntity, dpv:isDeterminedByEntity, dpv:isImplementedByEntity, dpv:isIndicatedBy, dpv:isOrganisationalUnitOf, dpv:isRepresentativeFor, eu-dga:hasDataUser, eu-gdpr:hasEstablishment, eu-gdpr:hasMainEstablishment, eu-gdpr:isMainEstablishmentFor
Definition An entity who has access and the right to use personal or non-personal data for commercial or non-commercial purposes
Source DGA 2.9
Date Created 2024-02-14
Contributors Beatriz Esteves
See More: section ENTITIES in EU-DGA

9.1.36 DGA Compliance Unknown

Term DGAComplianceUnknown Prefix eu-dga
Label DGA Compliance Unknown
IRI https://w3id.org/dpv/legal/eu/dga#DGAComplianceUnknown
Type rdfs:Class, skos:Concept, dpv:Lawfulness
Broader/Parent types eu-dga:DGALawfulnessdpv:Lawfulnessdpv:ComplianceStatusdpv:Statusdpv:Context
Object of relation dpv:hasComplianceStatus, dpv:hasContext, dpv:hasLawfulness, dpv:hasStatus
Definition State where lawfulness or compliance with DGA is unknown
Date Created 2024-07-21
Contributors Beatriz Esteves, Harshvardhan J. Pandit
See More: section COMPLIANCE in EU-DGA

9.1.37 DGA Compliant

Term DGACompliant Prefix eu-dga
Label DGA Compliant
IRI https://w3id.org/dpv/legal/eu/dga#DGACompliant
Type rdfs:Class, skos:Concept, dpv:Lawfulness
Broader/Parent types eu-dga:DGALawfulnessdpv:Lawfulnessdpv:ComplianceStatusdpv:Statusdpv:Context
Object of relation dpv:hasComplianceStatus, dpv:hasContext, dpv:hasLawfulness, dpv:hasStatus
Definition State of being lawful or legally compliant for DGA
Date Created 2024-07-21
Contributors Beatriz Esteves, Harshvardhan J. Pandit
See More: section COMPLIANCE in EU-DGA

9.1.38 DGA Lawfulness

Term DGALawfulness Prefix eu-dga
Label DGA Lawfulness
IRI https://w3id.org/dpv/legal/eu/dga#DGALawfulness
Type rdfs:Class, skos:Concept, dpv:Lawfulness
Broader/Parent types dpv:Lawfulnessdpv:ComplianceStatusdpv:Statusdpv:Context
Object of relation dpv:hasComplianceStatus, dpv:hasContext, dpv:hasLawfulness, dpv:hasStatus
Definition Status or state associated with being lawful or legally compliant regarding DGA
Date Created 2024-07-21
Contributors Beatriz Esteves, Harshvardhan J. Pandit
See More: section COMPLIANCE in EU-DGA

9.1.39 DGA Non-compliant

Term DGANonCompliant Prefix eu-dga
Label DGA Non-compliant
IRI https://w3id.org/dpv/legal/eu/dga#DGANonCompliant
Type rdfs:Class, skos:Concept, dpv:Lawfulness
Broader/Parent types eu-dga:DGALawfulnessdpv:Lawfulnessdpv:ComplianceStatusdpv:Statusdpv:Context
Object of relation dpv:hasComplianceStatus, dpv:hasContext, dpv:hasLawfulness, dpv:hasStatus
Definition State of being unlawful or legally non-compliant for DGA
Date Created 2024-07-21
Contributors Beatriz Esteves, Harshvardhan J. Pandit
See More: section COMPLIANCE in EU-DGA

9.1.40 DGA Rights Impact

Term DGARightsImpact Prefix eu-dga
Label DGA Rights Impact
IRI https://w3id.org/dpv/legal/eu/dga#DGARightsImpact
Type rdfs:Class, skos:Concept, dpv:RiskConcept, risk:PotentialConsequence, risk:PotentialImpact, risk:PotentialRisk
Broader/Parent types risk:RightsImpactrisk:SocietalRiskConceptdpv:RiskConcept
Object of relation risk:avoids, risk:contains, risk:controls, risk:detects, risk:eliminates, risk:identifies, risk:interrupts, risk:intervenes, risk:investigates, risk:logs, risk:mitigates, risk:modifies, risk:monitors, risk:overrides, risk:recovers, risk:reduces, risk:remedies, risk:resolves, risk:reverses, risk:shares, risk:substitutes, risk:transfers
Definition Something that acts as or is considered as an impact on one or more rights defined by DGA
Date Created 2024-12-01
See More: section RIGHTS-IMPACTS in EU-DGA

9.1.41 Data Intermediation Service Provider

Term DISP Prefix eu-dga
Label Data Intermediation Service Provider
IRI https://w3id.org/dpv/legal/eu/dga#DISP
Type rdfs:Class, skos:Concept
Broader/Parent types dpv:LegalEntitydpv:Entity
Object of relation dpv:hasActiveEntity, dpv:hasEntity, dpv:hasNonInvolvedEntity, dpv:hasParty, dpv:hasPassiveEntity, dpv:hasResponsibleEntity, dpv:isDeterminedByEntity, dpv:isImplementedByEntity, dpv:isIndicatedBy, dpv:isOrganisationalUnitOf, dpv:isRepresentativeFor, eu-dga:hasDISP, eu-gdpr:hasEstablishment, eu-gdpr:hasMainEstablishment, eu-gdpr:isMainEstablishmentFor
Definition An entity who establishes commercial relationships for the data sharing between data subjects and data holders on the one hand and data users on the other
Source DGA 2.11
Date Created 2024-02-14
Contributors Beatriz Esteves
See More: section ENTITIES in EU-DGA

9.1.42 EU Approval for Data Intermediation Service Provider

Term DISPEUApproval Prefix eu-dga
Label EU Approval for Data Intermediation Service Provider
IRI https://w3id.org/dpv/legal/eu/dga#DISPEUApproval
Type rdfs:Class, skos:Concept, dpv:OrganisationalMeasure
Broader/Parent types dpv:CertificationSealdpv:OrganisationalMeasuredpv:TechnicalOrganisationalMeasure
Object of relation dpv:hasOrganisationalMeasure, dpv:hasTechnicalOrganisationalMeasure
Definition Confirmation and approval by a competent authority for the Data Intermediation Service Provider's compliance with Article 11 and Article 12 of the DGA
Source DGA 11.9
Date Created 2024-02-14
Contributors Beatriz Esteves
See More: section TOMS in EU-DGA

9.1.43 Data Intermediation Service Provider for Data Holder

Term DISPForDataHolder Prefix eu-dga
Label Data Intermediation Service Provider for Data Holder
IRI https://w3id.org/dpv/legal/eu/dga#DISPForDataHolder
Type rdfs:Class, skos:Concept
Broader/Parent types eu-dga:DISPdpv:LegalEntitydpv:Entity
Object of relation dpv:hasActiveEntity, dpv:hasEntity, dpv:hasNonInvolvedEntity, dpv:hasParty, dpv:hasPassiveEntity, dpv:hasResponsibleEntity, dpv:isDeterminedByEntity, dpv:isImplementedByEntity, dpv:isIndicatedBy, dpv:isOrganisationalUnitOf, dpv:isRepresentativeFor, eu-dga:hasDISP, eu-gdpr:hasEstablishment, eu-gdpr:hasMainEstablishment, eu-gdpr:isMainEstablishmentFor
Definition An entity who makes data holders' data available for potential data users, including bilateral or multilateral exchanges of data and platforms and databases for the joint exploitation of data
Source DGA 10.a
Date Created 2024-02-14
Contributors Beatriz Esteves
See More: section ENTITIES in EU-DGA

9.1.44 Data Intermediation Service Provider for Data Subject

Term DISPForDataSubject Prefix eu-dga
Label Data Intermediation Service Provider for Data Subject
IRI https://w3id.org/dpv/legal/eu/dga#DISPForDataSubject
Type rdfs:Class, skos:Concept
Broader/Parent types eu-dga:DISPdpv:LegalEntitydpv:Entity
Object of relation dpv:hasActiveEntity, dpv:hasEntity, dpv:hasNonInvolvedEntity, dpv:hasParty, dpv:hasPassiveEntity, dpv:hasResponsibleEntity, dpv:isDeterminedByEntity, dpv:isImplementedByEntity, dpv:isIndicatedBy, dpv:isOrganisationalUnitOf, dpv:isRepresentativeFor, eu-dga:hasDISP, eu-gdpr:hasEstablishment, eu-gdpr:hasMainEstablishment, eu-gdpr:isMainEstablishmentFor
Definition An entity who makes data subjects' personal data available for potential data users
Source DGA 10.b
Date Created 2024-02-14
Contributors Beatriz Esteves
See More: section ENTITIES in EU-DGA

9.1.45 Data Intermediation Service Notification

Term DISPNotice Prefix eu-dga
Label Data Intermediation Service Notification
IRI https://w3id.org/dpv/legal/eu/dga#DISPNotice
Type rdfs:Class, skos:Concept, dpv:OrganisationalMeasure
Broader/Parent types dpv:Noticedpv:OrganisationalMeasuredpv:TechnicalOrganisationalMeasure
Object of relation dpv:hasNotice, dpv:hasOrganisationalMeasure, dpv:hasTechnicalOrganisationalMeasure
Definition Notification by a Data Intermediation Service Provider to a competent authority concerning changes to details regarding its Data Intermediation Service
Source DGA 11.12, DGA 11.13, DGA 11.9, DGA 11.1
Date Created 2024-02-14
Contributors Beatriz Esteves
See More: section TOMS in EU-DGA

9.1.46 Public Register of Data Intermediation Service Providers

Term DISPRegister Prefix eu-dga
Label Public Register of Data Intermediation Service Providers
IRI https://w3id.org/dpv/legal/eu/dga#DISPRegister
Type rdfs:Class, skos:Concept, dpv:PublicRegisterOfEntities
Broader/Parent types dpv:PublicRegisterOfEntities
Definition Document that contains a publicly available list of data intermediation service providers
Source DGA 11.10
Date Created 2024-02-14
Contributors Beatriz Esteves
See More: section REGISTERS in EU-DGA
Term EUDataAltruismConsentForm Prefix eu-dga
Label European Data Altruism Consent Form
IRI https://w3id.org/dpv/legal/eu/dga#EUDataAltruismConsentForm
Type rdfs:Class, skos:Concept, dpv:OrganisationalMeasure
Broader/Parent types dpv:ConsentManagementdpv:PermissionManagementdpv:RightsManagementdpv:OrganisationalMeasuredpv:TechnicalOrganisationalMeasure
Object of relation dpv:hasOrganisationalMeasure, dpv:hasTechnicalOrganisationalMeasure
Definition A form provided by the European Commission for collecting consent
Source DGA 25.1
Date Created 2024-02-14
Contributors Beatriz Esteves
See More: section TOMS in EU-DGA

9.1.48 European Data Innovation Board

Term EuropeanDataInnovationBoard Prefix eu-dga
Label European Data Innovation Board
IRI https://w3id.org/dpv/legal/eu/dga#EuropeanDataInnovationBoard
Type rdfs:Class, skos:Concept
Broader/Parent types dpv:SupraNationalAuthoritydpv:Authoritydpv:GovernmentalOrganisationdpv:Organisationdpv:LegalEntitydpv:Entity
Object of relation dpv:hasActiveEntity, dpv:hasAuthority, dpv:hasEntity, dpv:hasNonInvolvedEntity, dpv:hasParty, dpv:hasPassiveEntity, dpv:hasResponsibleEntity, dpv:hasSubsidiary, dpv:isDeterminedByEntity, dpv:isImplementedByEntity, dpv:isIndicatedBy, dpv:isOrganisationalUnitOf, dpv:isRepresentativeFor, dpv:isSubsidiaryOf, eu-gdpr:hasEstablishment, eu-gdpr:hasMainEstablishment, eu-gdpr:isMainEstablishmentFor
Definition An authority tasked with overseeing the activities of data intermediation service providers and data altruism organisations
Source DGA 29
Date Created 2024-02-14
Contributors Beatriz Esteves
See More: section ENTITIES in EU-DGA

9.1.49 EU Single Information Point Provider

Term EUSIPProvider Prefix eu-dga
Label EU Single Information Point Provider
IRI https://w3id.org/dpv/legal/eu/dga#EUSIPProvider
Type rdfs:Class, skos:Concept
Broader/Parent types eu-dga:SIPProviderdpv:LegalEntitydpv:Entity
Object of relation dpv:hasActiveEntity, dpv:hasEntity, dpv:hasNonInvolvedEntity, dpv:hasParty, dpv:hasPassiveEntity, dpv:hasResponsibleEntity, dpv:isDeterminedByEntity, dpv:isImplementedByEntity, dpv:isIndicatedBy, dpv:isOrganisationalUnitOf, dpv:isRepresentativeFor, eu-gdpr:hasEstablishment, eu-gdpr:hasMainEstablishment, eu-gdpr:isMainEstablishmentFor
Definition An entity who is responsible for receiving and transmitting requests for the reuse of public data in the EU
Source DGA 8.4
Date Created 2024-02-14
Contributors Beatriz Esteves
See More: section ENTITIES in EU-DGA
Term LegalRepresentative Prefix eu-dga
Label Legal Representative
IRI https://w3id.org/dpv/legal/eu/dga#LegalRepresentative
Type rdfs:Class, skos:Concept
Broader/Parent types dpv:Representativedpv:LegalEntitydpv:Entity
Object of relation dpv:hasActiveEntity, dpv:hasEntity, dpv:hasNonInvolvedEntity, dpv:hasParty, dpv:hasPassiveEntity, dpv:hasRepresentative, dpv:hasResponsibleEntity, dpv:isDeterminedByEntity, dpv:isImplementedByEntity, dpv:isIndicatedBy, dpv:isOrganisationalUnitOf, dpv:isRepresentativeFor, eu-gdpr:hasEstablishment, eu-gdpr:hasMainEstablishment, eu-gdpr:isMainEstablishmentFor
Definition Legal Representative' means a natural or legal person established in the Union explicitly designated to act on behalf of a data intermediation services provider or an entity that collects data for objectives of general interest made available by natural or legal persons on the basis of data altruism not established in the Union, which may be addressed by the competent authorities for data intermediation services and the competent authorities for the registration of data altruism organisations in addition to or instead of the data intermediation services provider or entity with regard to the obligations under this Regulation, including with regard to initiating enforcement proceedings against a non-compliant data intermediation services provider or entity not established in the Union
Source DGA 2.21
Date Created 2025-01-01
Contributors Georg P. Krog
See More: section ENTITIES in EU-DGA

9.1.51 Local Single Information Point Provider

Term LocalSIPProvider Prefix eu-dga
Label Local Single Information Point Provider
IRI https://w3id.org/dpv/legal/eu/dga#LocalSIPProvider
Type rdfs:Class, skos:Concept
Broader/Parent types eu-dga:SIPProviderdpv:LegalEntitydpv:Entity
Object of relation dpv:hasActiveEntity, dpv:hasEntity, dpv:hasNonInvolvedEntity, dpv:hasParty, dpv:hasPassiveEntity, dpv:hasResponsibleEntity, dpv:isDeterminedByEntity, dpv:isImplementedByEntity, dpv:isIndicatedBy, dpv:isOrganisationalUnitOf, dpv:isRepresentativeFor, eu-gdpr:hasEstablishment, eu-gdpr:hasMainEstablishment, eu-gdpr:isMainEstablishmentFor
Definition A local entity who is responsible for receiving and transmitting requests for the reuse of public data
Date Created 2024-02-14
Contributors Beatriz Esteves
See More: section ENTITIES in EU-DGA

9.1.52 National Data Altruism Policy

Term NationalDataAltruismPolicy Prefix eu-dga
Label National Data Altruism Policy
IRI https://w3id.org/dpv/legal/eu/dga#NationalDataAltruismPolicy
Type rdfs:Class, skos:Concept, dpv:OrganisationalMeasure
Broader/Parent types dpv:Policydpv:GovernanceProceduresdpv:OrganisationalMeasuredpv:TechnicalOrganisationalMeasure
Object of relation dpv:hasOrganisationalMeasure, dpv:hasPolicy, dpv:hasTechnicalOrganisationalMeasure
Definition A Policy established at National level regarding Data Altruism
Source DGA 16
Date Created 2024-02-14
Contributors Beatriz Esteves
See More: section TOMS in EU-DGA

9.1.53 National Single Information Point Provider

Term NationalSIPProvider Prefix eu-dga
Label National Single Information Point Provider
IRI https://w3id.org/dpv/legal/eu/dga#NationalSIPProvider
Type rdfs:Class, skos:Concept
Broader/Parent types eu-dga:SIPProviderdpv:LegalEntitydpv:Entity
Object of relation dpv:hasActiveEntity, dpv:hasEntity, dpv:hasNonInvolvedEntity, dpv:hasParty, dpv:hasPassiveEntity, dpv:hasResponsibleEntity, dpv:isDeterminedByEntity, dpv:isImplementedByEntity, dpv:isIndicatedBy, dpv:isOrganisationalUnitOf, dpv:isRepresentativeFor, eu-gdpr:hasEstablishment, eu-gdpr:hasMainEstablishment, eu-gdpr:isMainEstablishmentFor
Definition A national entity who is responsible for receiving and transmitting requests for the reuse of public data
Date Created 2024-02-14
Contributors Beatriz Esteves
See More: section ENTITIES in EU-DGA

9.1.54 Personal Data Reuse Notice

Term PersonalDataReuseNotice Prefix eu-dga
Label Personal Data Reuse Notice
IRI https://w3id.org/dpv/legal/eu/dga#PersonalDataReuseNotice
Type rdfs:Class, skos:Concept, dpv:OrganisationalMeasure
Broader/Parent types dpv:ConsentNoticedpv:PrivacyNoticedpv:Noticedpv:OrganisationalMeasuredpv:TechnicalOrganisationalMeasure
Object of relation dpv:hasNotice, dpv:hasOrganisationalMeasure, dpv:hasTechnicalOrganisationalMeasure
Definition Notice for data subjects to provide consent based on information and advise regarding intended use of data, exercise of rights, and applicable terms and conditions
Source DGA 12.m
Date Created 2024-02-14
Contributors Beatriz Esteves
See More: section TOMS in EU-DGA

9.1.55 Public Law Governed Body

Term PublicLawGovernedBody Prefix eu-dga
Label Public Law Governed Body
IRI https://w3id.org/dpv/legal/eu/dga#PublicLawGovernedBody
Type rdfs:Class, skos:Concept
Broader/Parent types dpv:LegalEntitydpv:Entity
Object of relation dpv:hasActiveEntity, dpv:hasEntity, dpv:hasNonInvolvedEntity, dpv:hasParty, dpv:hasPassiveEntity, dpv:hasResponsibleEntity, dpv:isDeterminedByEntity, dpv:isImplementedByEntity, dpv:isIndicatedBy, dpv:isOrganisationalUnitOf, dpv:isRepresentativeFor, eu-gdpr:hasEstablishment, eu-gdpr:hasMainEstablishment, eu-gdpr:isMainEstablishmentFor
Definition Public Law Governed Body' or 'Body Governed by Public Law' means bodies that have the following characteristics: (a) they are established for the specific purpose of meeting needs in the general interest, and do not have an industrial or commercial character; (b) they have legal personality; (c) they are financed, for the most part, by the State, regional or local authorities, or other bodies governed by public law, are subject to management supervision by those authorities or bodies, or have an administrative, managerial or supervisory board, more than half of whose members are appointed by the State, regional or local authorities, or by other bodies governed by public law;
Source DGA 2.18
Date Created 2025-01-01
Contributors Georg P. Krog
See More: section ENTITIES in EU-DGA

9.1.56 Public Sector Body

Term PublicSectorBody Prefix eu-dga
Label Public Sector Body
IRI https://w3id.org/dpv/legal/eu/dga#PublicSectorBody
Type rdfs:Class, skos:Concept
Broader/Parent types dpv:PublicSectorBodydpv:LegalEntitydpv:Entity
Object of relation dpv:hasActiveEntity, dpv:hasEntity, dpv:hasNonInvolvedEntity, dpv:hasParty, dpv:hasPassiveEntity, dpv:hasResponsibleEntity, dpv:isDeterminedByEntity, dpv:isImplementedByEntity, dpv:isIndicatedBy, dpv:isOrganisationalUnitOf, dpv:isRepresentativeFor, eu-gdpr:hasEstablishment, eu-gdpr:hasMainEstablishment, eu-gdpr:isMainEstablishmentFor
Definition ‘Public Sector Body’ means the State, regional or local authorities, bodies governed by public law or associations formed by one or more such authorities, or one or more such bodies governed by public law
Source DGA 2.17
Date Created 2025-01-01
Contributors Georg P. Krog
See More: section ENTITIES in EU-DGA

9.1.57 Regional Single Information Point Provider

Term RegionalSIPProvider Prefix eu-dga
Label Regional Single Information Point Provider
IRI https://w3id.org/dpv/legal/eu/dga#RegionalSIPProvider
Type rdfs:Class, skos:Concept
Broader/Parent types eu-dga:SIPProviderdpv:LegalEntitydpv:Entity
Object of relation dpv:hasActiveEntity, dpv:hasEntity, dpv:hasNonInvolvedEntity, dpv:hasParty, dpv:hasPassiveEntity, dpv:hasResponsibleEntity, dpv:isDeterminedByEntity, dpv:isImplementedByEntity, dpv:isIndicatedBy, dpv:isOrganisationalUnitOf, dpv:isRepresentativeFor, eu-gdpr:hasEstablishment, eu-gdpr:hasMainEstablishment, eu-gdpr:isMainEstablishmentFor
Definition A regional entity who is responsible for receiving and transmitting requests for the reuse of public data
Date Created 2024-02-14
Contributors Beatriz Esteves
See More: section ENTITIES in EU-DGA

9.1.58 Sectorial Single Information Point Provider

Term SectorialSIPProvider Prefix eu-dga
Label Sectorial Single Information Point Provider
IRI https://w3id.org/dpv/legal/eu/dga#SectorialSIPProvider
Type rdfs:Class, skos:Concept
Broader/Parent types eu-dga:SIPProviderdpv:LegalEntitydpv:Entity
Object of relation dpv:hasActiveEntity, dpv:hasEntity, dpv:hasNonInvolvedEntity, dpv:hasParty, dpv:hasPassiveEntity, dpv:hasResponsibleEntity, dpv:isDeterminedByEntity, dpv:isImplementedByEntity, dpv:isIndicatedBy, dpv:isOrganisationalUnitOf, dpv:isRepresentativeFor, eu-gdpr:hasEstablishment, eu-gdpr:hasMainEstablishment, eu-gdpr:isMainEstablishmentFor
Definition An entity who is responsible for receiving and transmitting requests for the reuse of public data for a particular sector
Date Created 2024-02-14
Contributors Beatriz Esteves
See More: section ENTITIES in EU-DGA

9.1.59 Secure Processing Environment

Term SecureProcessingEnvironment Prefix eu-dga
Label Secure Processing Environment
IRI https://w3id.org/dpv/legal/eu/dga#SecureProcessingEnvironment
Type rdfs:Class, skos:Concept, dpv:TechnicalMeasure
Broader/Parent types dpv:SecureProcessingEnvironmentdpv:SecurityProceduredpv:OrganisationalMeasuredpv:TechnicalOrganisationalMeasure
Object of relation dpv:hasOrganisationalMeasure, dpv:hasTechnicalOrganisationalMeasure
Definition Physical or virtual environment to ensure compliance with EU law and allow the entity providing the secure processing environment to determine and supervise all data processing actions
Source DGA 2.20
Date Created 2024-02-14
Contributors Beatriz Esteves
See More: section TOMS in EU-DGA

9.1.60 Single Information Point (SIP)

Term SingleInformationPoint Prefix eu-dga
Label Single Information Point (SIP)
IRI https://w3id.org/dpv/legal/eu/dga#SingleInformationPoint
Type rdfs:Class, skos:Concept
Broader/Parent types dpv:Servicedpv:Process
Object of relation dpv:hasProcess, dpv:hasService
Definition Service responsible for receiving and transmitting requests for the re-use of public data
Date Created 2024-02-14
Contributors Beatriz Esteves
See More: section SERVICES in EU-DGA

9.1.61 Single Information Point Provider

Term SIPProvider Prefix eu-dga
Label Single Information Point Provider
IRI https://w3id.org/dpv/legal/eu/dga#SIPProvider
Type rdfs:Class, skos:Concept
Broader/Parent types dpv:LegalEntitydpv:Entity
Object of relation dpv:hasActiveEntity, dpv:hasEntity, dpv:hasNonInvolvedEntity, dpv:hasParty, dpv:hasPassiveEntity, dpv:hasResponsibleEntity, dpv:isDeterminedByEntity, dpv:isImplementedByEntity, dpv:isIndicatedBy, dpv:isOrganisationalUnitOf, dpv:isRepresentativeFor, eu-gdpr:hasEstablishment, eu-gdpr:hasMainEstablishment, eu-gdpr:isMainEstablishmentFor
Definition An entity who is responsible for receiving and transmitting requests for the reuse of public data
Source DGA 8
Date Created 2024-02-14
Contributors Beatriz Esteves
See More: section ENTITIES in EU-DGA

9.1.62 Third Country Data Request Notice

Term ThirdCountryDataRequestNotice Prefix eu-dga
Label Third Country Data Request Notice
IRI https://w3id.org/dpv/legal/eu/dga#ThirdCountryDataRequestNotice
Type rdfs:Class, skos:Concept, dpv:OrganisationalMeasure
Broader/Parent types dpv:DataTransferNoticedpv:Noticedpv:OrganisationalMeasuredpv:TechnicalOrganisationalMeasure
Object of relation dpv:hasNotice, dpv:hasOrganisationalMeasure, dpv:hasTechnicalOrganisationalMeasure
Definition Notice regarding a request of a third-country administrative authority to access data
Source DGA 31.5
Date Created 2024-02-14
Contributors Beatriz Esteves
See More: section TOMS in EU-DGA

9.2 Properties

9.2.1 has data altruism organisation

Term hasDAO Prefix eu-dga
Label has data altruism organisation
IRI https://w3id.org/dpv/legal/eu/dga#hasDAO
Type rdf:Property, skos:Concept
Broader/Parent types dpv:hasEntity
Sub-property of dpv:hasEntity
Range includes eu-dga:DataAltruismOrganisation
Definition Indicates association with data altruism organisation
Date Created 2024-02-14
Contributors Beatriz Esteves, Harshvardhan J. Pandit
See More: section ENTITIES in EU-DGA

9.2.2 has data holder

Term hasDataHolder Prefix eu-dga
Label has data holder
IRI https://w3id.org/dpv/legal/eu/dga#hasDataHolder
Type rdf:Property, skos:Concept
Broader/Parent types dpv:hasEntity
Sub-property of dpv:hasEntity
Range includes eu-dga:DataHolder
Definition Indicates association with data holder
Date Created 2024-02-14
Contributors Beatriz Esteves, Harshvardhan J. Pandit
See More: section ENTITIES in EU-DGA

9.2.3 has data reuse assistant

Term hasDataReuseAssistant Prefix eu-dga
Label has data reuse assistant
IRI https://w3id.org/dpv/legal/eu/dga#hasDataReuseAssistant
Type rdf:Property, skos:Concept
Broader/Parent types dpv:hasEntity
Sub-property of dpv:hasEntity
Range includes eu-dga:DataReuseAssistant
Definition Indicates association with competent body designated by the Member State to assist Public Bodies in activities related to data reuse
Source DGA 7
Date Created 2024-02-14
Contributors Beatriz Esteves, Harshvardhan J. Pandit
See More: section ENTITIES in EU-DGA

9.2.4 has data user

Term hasDataUser Prefix eu-dga
Label has data user
IRI https://w3id.org/dpv/legal/eu/dga#hasDataUser
Type rdf:Property, skos:Concept
Broader/Parent types dpv:hasEntity
Sub-property of dpv:hasEntity
Range includes eu-dga:DataUser
Definition Indicates association with data user
Date Created 2024-02-14
Contributors Beatriz Esteves, Harshvardhan J. Pandit
See More: section ENTITIES in EU-DGA

9.2.5 has data intermediation service provider

Term hasDISP Prefix eu-dga
Label has data intermediation service provider
IRI https://w3id.org/dpv/legal/eu/dga#hasDISP
Type rdf:Property, skos:Concept
Broader/Parent types dpv:hasEntity
Sub-property of dpv:hasEntity
Range includes eu-dga:DISP
Definition Indicates association with data intermediation service provider
Date Created 2024-02-14
Contributors Beatriz Esteves, Harshvardhan J. Pandit
See More: section ENTITIES in EU-DGA

9.3 External

DPV uses the following terms from [RDF] and [RDFS] with their defined meanings:

The following external concepts are re-used within DPV:

Funding Acknowledgements

Funding Sponsors

The DPVCG was established as part of the SPECIAL H2020 Project, which received funding from the European Union’s Horizon 2020 research and innovation programme under grant agreement No. 731601 from 2017 to 2019. Continued developments have been funded under: RECITALS Project funded under the EU's Horizon program with grant agreement No. 101168490.

Harshvardhan J. Pandit was funded to work on DPV from 2020 to 2022 by the Irish Research Council's Government of Ireland Postdoctoral Fellowship Grant#GOIPD/2020/790.

The ADAPT SFI Centre for Digital Media Technology is funded by Science Foundation Ireland through the SFI Research Centres Programme and is co-funded under the European Regional Development Fund (ERDF) through Grant#13/RC/2106 (2018 to 2020) and Grant#13/RC/2106_P2 (2021 onwards).

Funding Acknowledgements for Contributors

The contributions of Beatriz Esteves have received funding through the PROTECT ITN Project from the European Union’s Horizon 2020 research and innovation programme under the Marie Skłodowska-Curie grant agreement No 813497. Beatriz Esteves is funded by SolidLab Vlaanderen (Flemish Government, EWI and RRF project VV023/10), and by the imec.icon project PACSOI (HBC.2023.0752) which was co-financed by imec and VLAIO.

The contributions of Harshvardhan J. Pandit and Dave Lewis have been made with the financial support of Science Foundation Ireland under Grant Agreement No. 13/RC/2106_P2 at the ADAPT SFI Research Centre. The contributions of Harshvardhan J. Pandit have been made with the AI Accountability Lab (AIAL) which is supported by grants from following groups: the AI Collaborative, an Initiative of the Omidyar Group; Luminate; the Bestseller Foundation; and the John D. and Catherine T. MacArthur Foundation.

A. Issue summary

B. Future Work

Issue 234: Update DGA extension with practical concepts todohelp-wantedeu-dga

As the DGA comes in to effect, there are several additional sources of information and guidance that should be incorporated into the DPV extension, including representing more of DGA itself.

Overview of incident notification for the General Data Protection Regulation (GDPR)

This complements the existing data privacy vocabulary by providing specific details about notification requirements under the GDPR.

1. FROM: Controller (defined in Article 4(7))

INCIDENT: Personal data breach (defined in Article 4(12))
NOTIFICATION TO: Supervisory authority (defined in Article 4(21)) (Article 33(1))
TIMELINE: Without undue delay, when feasible within 72 hours (Article 33(1))
TRIGGER: Upon becoming aware of the personal data breach, unless unlikely to result in a risk to individuals (Article 33(1))

2. FROM: Controller (defined in Article 4(7))

INCIDENT: Personal data breach (defined in Article 4(12))
NOTIFICATION TO: Data subject (defined in Article 4(1)) (Articles 34(1) and 34(4))
TIMELINE: Without undue delay (Article 34(1))
TRIGGER: If the personal data breach is likely to result in a high risk to individuals, with exceptions when:

3. FROM: Processor (defined in Article 4(8))

INCIDENT: Personal data breach (defined in Article 4(12))
NOTIFICATION TO: Controller (Article 33(2))
TIMELINE: Without undue delay (Article 33(2))
TRIGGER: Upon becoming aware of the personal data breach (Article 33(2))

Overview of incident notification for the Law Enforcement Directive (LED) – 2016/680

This complements the existing data privacy vocabulary by providing specific details about notification requirements under the Law Enforcement Directive.

1. FROM: Law enforcement agencies, referred to as "competent authorities," in their capacity as controllers (defined in Articles 3(7) and 3(8))

INCIDENT: Personal data breach (defined in Article 3(11))
NOTIFICATION TO: Supervisory authority (defined in Article 3(15)) (Article 30(1))
TIMELINE: Without undue delay, where feasible within 72 hours (Article 30(1))
TRIGGER: Upon becoming aware of the personal data breach, unless unlikely to result in a risk to individuals (Article 30(1))

2. FROM: Law enforcement agencies, referred to as "competent authorities," in their capacity as controllers (defined in Articles 3(7) and 3(8))

INCIDENT: Personal data breach (defined in Article 3(11))
NOTIFICATION TO: Data subject (defined in Article 3(1)) (Articles 31(1) and 31(4))
TIMELINE: Without undue delay (may be delayed, restricted or omitted in specific circumstances, per Article 31(5)) (Article 31(1))
TRIGGER: If the personal data breach is likely to result in a high risk to individuals, with exceptions when:

3. FROM: Law enforcement agencies, referred to as "competent authorities," in their capacity as controllers (defined in Articles 3(7) and 3(8))

INCIDENT: Personal data breach (defined in Article 3(11))
NOTIFICATION TO: Controller of another member state by or to whom the personal data breached has been transmitted (Article 30(6))
TIMELINE: Without undue delay (Article 30(6))
TRIGGER: If the personal data breach involves personal data that have been transmitted by or to the controller of another member state (Article 30(6))

4. FROM: Processor (defined in Article 3(9))

INCIDENT: Personal data breach (defined in Article 3(11))
NOTIFICATION TO: Controller (Article 30(2))
TIMELINE: Without undue delay (Article 30(2))
TRIGGER: Upon becoming aware of the personal data breach (Article 30(2))

Overview of incident notification for the E-Privacy Directive – 2002/58/EC

This complements the existing data privacy vocabulary by providing specific details about notification requirements under the E-Privacy Directive.

1. FROM: Provider of publicly available electronic communications services

INCIDENT: Personal data breach (defined in Article 2(i))
NOTIFICATION TO: Competent national authority (Article 4(3-5))
TIMELINE: Without undue delay (Article 4(3))
TRIGGER: A personal data breach (Article 4(3))

2. FROM: Provider of publicly available electronic communications services

INCIDENT: Personal data breach (defined in Article 2(i))
NOTIFICATION TO: Subscriber or individual (Article 4(3-5))
TIMELINE: Without undue delay (Article 4(3))
TRIGGER: If the personal data breach is likely to adversely affect the personal data or privacy of a subscriber or individual, with exception when:

3. FROM: Provider of publicly available electronic communications services

INCIDENT: Particular risk of a breach of the security of the network
NOTIFICATION TO: Subscribers (Article 4(2)(2))
TIMELINE: Not specified in the law
TRIGGER: A particular risk of a breach of the security of the network (Article 4(2)(2))

Overview of incident notification for the Data Governance Act – 2022/868

This complements the existing data privacy vocabulary by providing specific details about notification requirements under the Data Governance Act.

1. FROM: Recognized data altruism organization (defined in Article 2(16))

INCIDENT: Unauthorized transfer, access or use of shared nonpersonal data
NOTIFICATION TO: Data holders (defined in Article 2(8)) (Articles 12(k) and 21(5))
TIMELINE: Without delay (Articles 12(k) and 21(5))
TRIGGER: Unauthorized transfer, access or use of shared nonpersonal data (Articles 12(k) and 21(5))

2. FROM: Data intermediation services provider (defined in Article 2(11))

INCIDENT: Unauthorized transfer, access or use of shared nonpersonal data
NOTIFICATION TO: Data holders (defined in Article 2(8)) (Articles 12(k) and 21(5))
TIMELINE: Without delay (Articles 12(k) and 21(5))
TRIGGER: Unauthorized transfer, access or use of shared nonpersonal data (Articles 12(k) and 21(5))

3. FROM: Re-user of data obtained from a public sector body (defined in Article 2(17))

INCIDENT: Unauthorized re-use (defined in Article 2(2)) of nonpersonal data
NOTIFICATION TO: Legal persons whose rights and interests may be affected (Article 5(5))
TIMELINE: Without delay (Article 5(5))
TRIGGER: Unauthorized re-use of nonpersonal data (Article 5(5))

4. FROM: Re-user of data obtained from a public sector body (defined in Article 2(17))

INCIDENT: Data breach resulting in the re-identification of the data subject
NOTIFICATION TO: Public sector body (Article 5(5))
TIMELINE: Not specified in the law (Article 5(5))
TRIGGER: Data breach resulting in the re-identification of the data subject (Article 5(5))

Overview of incident notification for the Data Act – 2023/2854

This complements the existing data privacy vocabulary by providing specific details about notification requirements under the Data Act.

1. FROM: Third party or data recipient (defined in Article 2(14)) that obtained data generated by a connected product

INCIDENT: Unauthorized use or disclosure of data under circumstances defined in Article 11(3)
NOTIFICATION TO: User of a connected product (defined in Article 2(12)) (Article 11(2)(c))
TIMELINE: Without undue delay (Article 11(2))
TRIGGER: If requested by the data holder (defined in Article 2(13)) or the trade secret holder (defined in Article 2(19)) (Article 11(2))

Overview of incident notification for the Network and Information Security Directive 2 – 2022/2555

This complements the existing data privacy vocabulary by providing specific details about notification requirements under the NIS2 Directive.

1. FROM: Essential and important entities (defined in Article 3)

INCIDENT: Significant Incident (defined in Articles 6(6), 23(3) and 23(11))
NOTIFICATION TO: CSIRT (defined in Article 10) (Article 23(1))
*The majority of essential and important entities will have to notify the authority(ies) of the member state(s) where the incident occurred or where they provide their services, while the Digital Infrastructure entities will have to notify the authority of the member state where they have their main establishment, per Article 26
TIMELINE: Early warning without undue delay, within 24 hours (Article 23(4)(a)); Notification without undue delay, within 72 hours, or 24 hours for trusted service providers (Article 23(4)(b)); Intermediate report at request of CSIRT or competent authority (Article 23(4)(c)); Final report within one month after notification (Article 23(4)(d)); Final report within one month of incident handling (Article 23(4)(e)); Progress report within one month if incident ongoing (Article 23(4)(e))
TRIGGER: Upon becoming aware of the significant incident (Article 23(4))

2. FROM: Essential and important entities (defined in Article 3)

INCIDENT: Significant Incident (defined in Articles 6(6), 23(3) and 23(11))
NOTIFICATION TO: Recipients of their services (Article 23(1))
TIMELINE: Without undue delay (Article 23(1))
TRIGGER: When appropriate, if the provision of these services is likely to be adversely affected by the significant incident (Article 23(1))

3. FROM: Essential and important entities (defined in Article 3)

INCIDENT: Significant Incident (defined in Articles 6(6), 23(3) and 23(11))
NOTIFICATION TO: Law enforcement authorities (Article 23(5))
TIMELINE: Without undue delay (Article 23(2))
TRIGGER: If the significant incident is suspected to be of criminal nature (Article 23(5))

4. FROM: Essential and important entities (defined in Article 3)

INCIDENT: Significant Incident (defined in Articles 6(6), 23(3) and 23(11))
NOTIFICATION TO: The public (Article 23(7))
TIMELINE: According to the guidance from the CSIRT of the competent authority (Article 23(5))
TRIGGER: If required by CSIRT or competent authority (Article 23(7))

5.** FROM: Essential and important entities (defined in Article 3)

INCIDENT: Significant cyber threat (defined in Articles 6(10) and 6(11))
NOTIFICATION TO: Recipients of their services (Article 23(2))
TIMELINE: Without undue delay (Article 23(2))
TRIGGER: When appropriate, if these services are potentially affected by the significant cyber threat (Article 23(2))

6. FROM: Essential and important entities (defined in Article 3)

INCIDENT: Incidents, cyber threats and near misses (defined in Article 6(5))
NOTIFICATION TO: CSIRT (defined in Article 10) or competent authority (defined in Article 8) (Article 23(1))
TIMELINE: Not explicitly specified for in the law
TRIGGER: Not explicitly specified for in the law

7. FROM: Other entities, regardless of whether they fall within the scope of the NIS2 Directive

INCIDENT: Incidents, cyber threats and near misses (defined in Article 6(5))
NOTIFICATION TO: CSIRT or competent authority (Article 30(1))
TIMELINE: Not specified in the law
TRIGGER: Not specified in the law

Overview of further and related information sharing for the Network and Information Security Directive 2 – 2022/2555

This complements the existing data privacy vocabulary by providing specific details about information sharing requirements under the NIS2 Directive.

1. FROM: Entities that fall within the scope of the NIS2 Directive and other relevant entities

TO: Entities that fall within the scope of the NIS2 Directive and other relevant entities (Article 29(1))
WHAT INFORMATION: Relevant cybersecurity information, e.g. information relating to cyber threats, near misses, vulnerabilities, techniques and procedures, indicators of compromise and adversarial tactics (Article 29(1))
TIMELINE: Not specified in the law
TRIGGER: When such information sharing aims to prevent, detect, respond to or recover from incidents or to mitigate their impacts or enhances the level of cybersecurity (Article 29(1))

2. FROM: Notified competent authority

TO: CSIRT (Article 23(1))
WHAT INFORMATION: The notification of a significant incident received from an essential or important entity (Article 23(1))
TIMELINE: Upon receipt of the notification (Article 23(1))
TRIGGER: When an essential or important entity notifies the competent authority of a significant incident (Article 23(1))

3. FROM: Notified CSIRT or competent authority

TO: Competent authorities under the Critical Entities Resilience Directive (Article 23(10))
WHAT INFORMATION: Information about notified significant incidents, incidents, cyber threats and near misses (Article 23(10))
TIMELINE: Not specified in the law
TRIGGER: When significant incidents, incidents, cyber threats and near misses are notified by entities identified as critical entities under the Critical Entities Resilience Directive (Article 23(10))

3. FROM: Notified CSIRT or competent authority

TO: Single point of contact (defined in Article 8(3)) (Article 23(1))
WHAT INFORMATION: Relevant information notified by essential and important entities (Article 23(1))
TIMELINE: In due time (Article 23(1))
TRIGGER: In case of a cross-border or cross-sectoral significant incident (Article 23(1))

4. FROM: Notified CSIRT or competent authority

TO: Single point of contact (defined in Article 8(3)) (Article 30(2))
WHAT INFORMATION: Information about voluntary notifications of incidents, significant incidents, cyber threats and near misses (Article 30(2))
TIMELINE: Not specified in the law (Article 30(2))
TRIGGER: When necessary (Article 30(2))

5. FROM: Notified CSIRT or competent authority

TO: Other affected member states and ENISA (Article 23(6))
WHAT INFORMATION: Information about the notified significant incident (Article 23(6))
TIMELINE: Without undue delay (Article 23(6))
TRIGGER: When a significant incident concerns two or more member states and when otherwise appropriate (Article 23(6))

6. FROM: Notified CSIRT or competent authority

TO: The public (Article 23(7))
WHAT INFORMATION: About the significant incident (Article 23(7))
TIMELINE: After consulting the entity concerned (Article 23(7))
TRIGGER: When public awareness is necessary to prevent a significant incident or to deal with an ongoing significant incident, or when its disclosure is otherwise in the public interest (Article 23(7))

7. FROM: Single point of contact (defined in Article 8(3))

TO: Other affected member states and ENISA (Article 23(6))
WHAT INFORMATION: Information about the notified significant incident (Article 23(6))
TIMELINE: Without undue delay (Article 23(6))
TRIGGER: When a significant incident concerns two or more member states and when otherwise appropriate (Article 23(6))

8. FROM: Single point of contact (defined in Article 8(3))

TO: Single points of contact of other affected member states (Article 23(8))
WHAT INFORMATION: Notifications received (Article 23(8))
TIMELINE: Not specified in the law
TRIGGER: When it is requested by CSIRT or the competent authority (Article 23(8))

9. FROM: Single point of contact (defined in Article 8(3))

TO: ENISA (Article 23(9))
WHAT INFORMATION: A summary report, including anonymized and aggregated data on significant incidents, incidents, cyber threats and near misses notified, including voluntarily (Article 23(9))
TIMELINE: Every three months (Article 23(9))
TRIGGER: Not specified in the law

10. FROM: CSIRT and competent authorities of other member states concerned

TO: The public (Article 23(7))
WHAT INFORMATION: About the significant incident (Article 23(7))
TIMELINE: After consulting the entity concerned (Article 23(7))
TRIGGER: When public awareness is necessary to prevent a significant incident or to deal with an ongoing significant incident, or when its disclosure is otherwise in the public interest (Article 23(7))

11. FROM: Competent authority

TO: Data protection authority of own member state (Article 35(1))
WHAT INFORMATION: That an infringement by an essential or important entity of their obligations under the NIS2 Directive can entail a personal data breach as defined in the GDPR (Article 35(1))
TIMELINE: Without undue delay (Article 35(1))
TRIGGER: When an infringement by an essential or important entity of their obligations under the NIS2 Directive can entail a personal data breach as defined in the GDPR (Article 35(1))

12. FROM: European Union Agency for Cybersecurity

TO: CSIRTs network and the Cooperation Group (defined in Article 14) (Article 23(9))
WHAT INFORMATION: Its findings on notifications received (Article 23(9))
TIMELINE: Every six months (Article 23(9))
TRIGGER: Not specified in the law

Overview of incident notification for the Digital Operational Resilience Act – 2022/2554

This complements the existing data privacy vocabulary by providing specific details about notification requirements under DORA.

1. FROM: Financial entities (defined in Article 2)

INCIDENT: Major information communication technology-related incident (defined in Article 3(10))
NOTIFICATION TO: Relevant competent authority (defined in Article 46) (Article 19(1))
TIMELINE: Initial notification four hours from the moment of classification of the incident as major, but no later than 24 hours from becoming aware of the incident; Intermediate report within 72 hours from the submission of the initial notification; Updated notifications every time a relevant status update is available or upon a request from the competent authority; Final report when the root cause analysis is complete, or within one month from the submission of the latest updated intermediate report (per draft Regulatory Technical Standard, subject to change)
TRIGGER: Upon becoming aware of the incident (Article 19(3))

2. FROM: Financial entities (defined in Article 2)

INCIDENT: Major information communication technology-related incident (defined in Article 3(10))
NOTIFICATION TO: Competent authorities or CSIRTs under the NIS2 Directive, if required by a member state (Article 19(1))
TIMELINE: Initial notification four hours from the moment of classification of the incident as major, but no later than 24 hours from becoming aware of the incident; Intermediate report within 72 hours from the submission of the initial notification; Updated notifications every time a relevant status update is available or upon a request from the competent authority; Final report when the root cause analysis is complete, or within one month from the submission of the latest updated intermediate report (per draft Regulatory Technical Standard, subject to change)
TRIGGER: Not specified in the law

3. FROM: Financial entities (defined in Article 2)

INCIDENT: Major information communication technology-related incident (defined in Article 3(10))
NOTIFICATION TO: Clients (Article 19(3))
TIMELINE: Without undue delay upon becoming aware of the incident (Article 19(3))
TRIGGER: When the incident has an impact on the financial interests of clients (Article 19(3))

4. FROM: Financial entities (defined in Article 2)

INCIDENT: Significant cyber threat (defined in Article 3(13))
NOTIFICATION TO: Relevant competent authority (defined in Article 46) (Article 19(2))
TIMELINE: Not specified in the law
TRIGGER: If the financial entity deems the threat to be of relevance to the financial system, service users or clients (Article 19(2))

5. FROM: Financial entities (defined in Article 2)

INCIDENT: Significant cyber threat (defined in Article 3(13))
NOTIFICATION TO: CSIRTs under the NIS2 Directive, if permitted by a member state (Article 19(2))
TIMELINE: Not specified in the law
TRIGGER: If the financial entity deems the threat to be of relevance to the financial system, service users or clients (Article 19(2))

6. FROM: Financial entities (defined in Article 2)

INCIDENT: Significant cyber threat (defined in Article 3(13))
NOTIFICATION TO: Potentially affected clients (Article 19(3))
TIMELINE: Not specified in the law
TRIGGER: Where applicable (Article 19(3))

7. FROM: Relevant competent authority

INFORMATION TO: Other relevant authorities, based on their respective competences (Article 19(6))
INFORMATION SHARED: Details of the major ICT-related incident (Article 19(6))
TIMELINE: In a timely manner (Article 19(6))
TRIGGER: Upon receipt of the initial notification and of each report about the major ICT-related incident (Article 19(6))

8. FROM: Relevant competent authority

INFORMATION TO: Other relevant authorities, defined in Article 19(6) (Article 19(2))
INFORMATION SHARED: Information about significant cyber threats notified by financial entities (Article 19(2))
TIMELINE: Not specified in the law
TRIGGER: Not specified in the law (Article 19(2))

9. FROM: European Central Bank

INFORMATION TO: Members of the European System of Central Banks (Article 19(7))
INFORMATION SHARED: On issues relevant to the payment system, in connection to the major ICT-related incident (Article 19(7))
TIMELINE: Not specified in the law
TRIGGER: If there are issues relevant to the payment system in connection to the major ICT-related incident (Article 19(7))

10. FROM: European Banking Authority, European Securities and Markets Authority or European Insurance and Occupational Pensions Authority

INFORMATION TO: Relevant competent authorities in other member states (Article 19(7))
INFORMATION SHARED: Not specified in the law
TIMELINE: As soon as possible following the assessment that the major ICT-related incident is relevant for competent authorities in other member states (Article 19(7))
TRIGGER: Upon receipt of information in relation to the major ICT-related incident from the competent authority, if it is determined that the major ICT-related incident is relevant for competent authorities in other member states (Article 19(7))

Overview of incident notification for the Payment Services Directive 2 – 2015/2366

This complements the existing data privacy vocabulary by providing specific details about notification requirements under PSD2.

1. FROM: Payment service providers (defined in Article 4(11))

INCIDENT: Major operational or security incident
NOTIFICATION TO: Competent authority (defined in Article 100) in the home member state (defined in Article 4(1)) of the payment service provider (Article 96(1))
TIMELINE: Without undue delay (Article 96(1))
TRIGGER: Major operational or security incident (Article 96(1))

2. FROM: Payment service providers (defined in Article 4(11))

INCIDENT: Major operational or security incident
NOTIFICATION TO: Payment service users (defined in Article 4(10)) (Article 96(1))
TIMELINE: Without undue delay (Article 96(1))
TRIGGER: If the incident has or may have an impact on the financial interests of its payment service users (Article 96(1))

3. FROM: Notified competent authority in the home member state of the payment service provider

INFORMATION TO: Other relevant authorities in its member state (Article 96(2))
INFORMATION SHARED: Not specified in the law
TIMELINE: After assessing the relevance of the notified incident to other relevant authorities in its member state (Article 96(2))
TRIGGER: If notified incident is relevant to other relevant authorities in its member state (Article 96(2))

4. FROM: Notified competent authority in the home member state of the payment service provider

INFORMATION TO: European Banking Authority and European Central Bank (Article 96(2))
INFORMATION SHARED: Relevant details of the notified incident (Article 96(2))
TIMELINE: Without undue delay (Article 96(2))
TRIGGER: Receipt of the notification of the incident from the payment service provider (Article 96(2))

5. FROM: European Banking Authority and European Central Bank

INFORMATION TO: Other relevant EU and national authorities (Article 96(2))
INFORMATION SHARED: Not specified in the law (Article 96(2))
TIMELINE: Not specified in the law
TRIGGER: If notified incident is relevant to other relevant EU and national authorities (Article 96(2))

6. FROM: European Central Bank

INFORMATION TO: Members of the European System of Central Banks (Article 96(2))
INFORMATION SHARED: Issues relevant to the payment system (defined in Article 4(7)) in connection to the notified incident (Article 96(2))
TIMELINE: Not specified in the law
TRIGGER: If there are issues relevant to the payment system in connection to the notified incident (Article 96(2))

C. Changelog for v2.2

No changes

D. References

D.1 Informative references

[AI]
AI Technology concepts for DPV. URL: https://w3id.org/dpv/ai
[DGA]
Data Governance Act (DGA). URL: https://eur-lex.europa.eu/eli/reg/2022/868/oj
[DPV]
Data Privacy Vocabulary (DPV) Specification. URL: https://w3id.org/dpv
[EU-GDPR]
EU GDPR concepts for DPV. URL: https://w3id.org/dpv/legal/eu/gdpr
[EU-RIGHTS]
EU Fundamental Rights concepts for DPV. URL: https://w3id.org/dpv/legal/eu/rights
[GDPR]
General Data Protection Regulation (GDPR). URL: https://eur-lex.europa.eu/eli/reg/2016/679/oj
[GUIDES]
Guides for DPV. URL: https://w3id.org/dpv/guides
[JUSTIFICATIONS]
Concepts representing Justifications for DPV. URL: https://w3id.org/dpv/justifications
Legal Jurisdiction-relevant concepts for DPV. URL: https://w3id.org/dpv/legal
[LOC]
Location and Geo-Political Membership concepts for DPV. URL: https://w3id.org/dpv/loc
[PD]
Personal Data categories for DPV. URL: https://w3id.org/dpv/pd
[PRIMER]
Primer for Data Privacy Vocabulary. URL: https://w3id.org/dpv/primer
[RDF]
RDF 1.1 Concepts and Abstract Syntax. URL: https://www.w3.org/TR/rdf11-concepts/
[RDFS]
RDF Schema 1.1. URL: https://www.w3.org/TR/rdf-schema/
[RISK]
Risk Assessment and Management concepts for DPV. URL: https://w3id.org/dpv/risk
[SECTOR]
Sector-specific Extensions for DPV. URL: https://w3id.org/dpv/sector
[SKOS]
SKOS Simple Knowledge Organization System. URL: https://www.w3.org/TR/skos-reference/
[TECH]
Technology concepts for DPV. URL: https://w3id.org/dpv/tech