Copyright © 2025 the Contributors to the EU General Data Protection Regulation (GDPR) Specification, published by the Data Privacy Vocabularies and Controls Community Group under the W3C Community Final Specification Agreement (FSA). A human-readable summary is available.
Contributors: (ordered alphabetically) Beatriz Esteves (IDLab, IMEC, Ghent University), Bud Bruegger (Unabhängige Landeszentrum für Datenschutz Schleswig-Holstein), David Hickey (Dublin City University), Eva Schlehahn (Unabhängige Landeszentrum für Datenschutz Schleswig-Holstein), Georg P. Krog (Signatu AS), Harshvardhan J. Pandit (AI Accountability Lab (AIAL), Trinity College Dublin), Paul Ryan (Uniphar PLC), Rigo Wenning (W3C/ERCIM). NOTE: The affiliations are informative, do not represent formal endorsements, and may be outdated as this list is generated automatically from existing data.
The EU-GDPR extension extends the Data Privacy Vocabulary (DPV) Specification to provide concepts such as legal bases, rights, and data transfer tools based on the General Data Protection Regulation (GDPR). The canonical URL for EU-GDPR extension is https://w3id.org/dpv/legal/eu/gdpr, the namespace for terms is https://w3id.org/dpv/legal/eu/gdpr#
, the suggested prefix is eu-gdpr
, and this document along with source and releases are available at https://github.com/w3c/dpv.
DPV Specifications: The [DPV] is the core specification within the DPV family, with the following extensions: Personal Data [PD], Locations [LOC], Risk Management [RISK], Technology [TECH] and [AI], [JUSTIFICATIONS], [SECTOR] specific extensions, and [LEGAL] extensions modelling specific jurisdictions and regulations. A [PRIMER] introduces the concepts and modelling of DPV specifications, and [GUIDES] describe application of DPV for specific applications and use-cases. The Search Index page provides a searchable hierarchy of all concepts. The Data Privacy Vocabularies and Controls Community Group (DPVCG) develops and manages these specifications through GitHub. For meetings, see the DPVCG calendar.
To cite and understand the structure of DPV, the article "Data Privacy Vocabulary (DPV) - Version 2.0" (2024) describes the current state of DPV and extensions from version 2.0 onwards (open access version here). The earlier article "Creating A Vocabulary for Data Privacy" (2019) describes how the DPV was developed (open access versions here, here, and here).
Contributing: The DPVCG welcomes participation to improve the DPV and associated resources, including expansion or refinement of concepts, requesting information and applications, and addressing open issues. See contributing guide for further information.
This specification was published by the Data Privacy Vocabularies and Controls Community Group. It is not a W3C Standard nor is it on the W3C Standards Track. Please note that under the W3C Community Final Specification Agreement (FSA) other conditions apply. Learn more about W3C Community and Business Groups.
GitHub Issues are preferred for discussion of this specification.
The [EU-GDPR] extension provides concepts extending the [DPV] to represent information requirements from the [GDPR]. It enables the use of DPV to represent use-cases that are regulated by the GDPR, such as using specific legal bases defined in the GDPR, or to represent the applicability of rights, or requirements for conducting data protection impact assessments. It also enables representing practicalities such as organisations and their 'establishments' in the EU, data breach reporting and impact assessments, and data transfer tools. In particular, the [EU-GDPR] extension provides the following:
Proposal from Prinon Das: Create a mapping between GDPR clauses and DPV concepts.
This draft mapping table shows how the DPV and EU-GDPR extension represents specific concepts within the GDPR.
GDPR Article 6 specifies that it is mandatory for every processing to have one (or more) legal basis that justifies its compliance. These are represented as Core Legal Basis concepts by extending relevant dpv:LegalBasis
concepts, such as for consent or contract. Similarly, Article 9 legal basis are represented as Special Category Legal Basis, and those from Articles 45, 46, and 49 are represented as instances of dpv:DataTransferLegalBasis
to create Data Transfer Legal Basis.
These concepts represent the Article 6-1 legal bases from GDPR. They are defined by extending dpv:LegalBasis
and can be indicated by using dpv:hasLegalBasis
.
These concepts represent the Article 9-2 legal bases from GDPR regarding processing of special category personal data as defined in Article 9-1. They are defined by extending dpv:LegalBasis
and can be indicated by using dpv:hasLegalBasis
. The Personal Data categories for DPV extension provides an indication of whether its concepts belong to the special categories as defined in GDPR, which may be of interest here.
These concepts represent the legal bases from GDPR Articles 45 (adequacy decisions), 46 (data transfer tools), and 49 (consent, contract, etc.). They are defined by extending dpv:DataTransferLegalBasis
and can be indicated by using dpv:hasLegalBasis
. The Article 45 adequacy decisions between EU and other jurisdictions are provided as concepts for use with DPV in Location and Geo-Political Membership concepts for DPV.
Principles, as defined in GDPR Article 5, are represented as concepts by extending the concept dpv:Principle
, which is a type of organisational measure in [DPV]. How these principles are used or applied or evaluated is not defined in this extension. These concepts can be used as part of compliance assessments, for example with dpv:ComplianceStatus
or dpv:Lawfulness
, to indicate whether the principle has been fulfilled or violated.
GDPR provides several rights to the data subject, whose applicability depends on the context and nature of processing taking place. DPV lists these rights at an abstract level as concepts along with their origin in specific clauses of the GDPR.
In addition to DPV's concepts regarding exercise of rights, EU-GDPR provides additional concepts specific to the implementation of its rights. For example, SARNotice refers to the information provided in fulfilment of A15 Right of Access, or using dcat:Resource to represent the dataset provided in fulfilment of A20 Right to Data Portability.
GDPRRightsImpact, a specialised form of risk:RightsImpact
, represents an impact on right(s) within the GDPR. Further concepts are defined by extending this for each right within the GDPR, such as A20-Impact for impacts on A20 Right to Data Portability. These concepts are provided to aid in risk and impact assessments, particularly those associated with impacts on rights, and are to be used along with the relevant concepts and properties from [DPV] and [RISK] vocabularies.
The scope of each rights impact concept is to represent the impact at a broad level without providing specifics on the nature or category of impact. For example, A13-Impact only represents an impact on A13 and doesn't state what the impact is or what it implies. While the [RISK] extension provides a taxonomy of consequences and impacts which could be used to represent the nature of the impact, the DPVCG is currently exploring whether more contextual and appropriate concepts can be represented for the specific impacts associated with a right. For this, the A13-Impact is experimentally extended to represent categories of impact, e.g. A13 incorrectly being considered as not being applicable as A13-Denied. This follows a similar exercise for modelling impacts on EU Fundamental Rights and Freedoms in the [EU-RIGHTS] extension.
RISK, EU-GDPR, EU-Rights
See #184-comment with concepts proposed for each impact on right to be expressed as granular concepts:
And in addition to these, to interpret the right as a series of requirements or actions and create impacts based on that e.g. something is not fulfilled or something occurs (that wasn't supposed to). These concepts are proposed for EU-GDPR and EU-Rights extensions - but also for any rights concepts in DPV that can be accompanied by Rights Impact concepts.
No response
To support the effective implementation of GDPR, the [EU-GDPR] extension provides a mapping between legal bases and data subject rights to indicate which right should be provided based on the selected legal basis. This information is represented in machine-readable form within the [EU-GDPR] extension by using the relation dpv:hasRight
between instances of GDPR legal basis and rights.
Legal Basis (rows), Right (columns) | A13 Right to be Informed | A14 Right to be Informed | A15 Right of Access | A16 Right to Rectification | A17 Right to Erasure | A18 Right to Restrict Processing | A19 Right to Rectification Notification | A20 Right to Data Portability | A21 Right to object | A22 Right to object to automated decision making | A22 Right to human intervention | A22 Right to express point of view | A22 Right to contest decision | A7-3 Right to Withdraw Consent | A77 Right to Complaint | A78 Right to an effective judicial remedy against a supervisory authority | A79 Right to an effective judicial remedy against a controller or processor |
---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
Art.6(1-a) consent | ☒ | ☒ | ☒ | ☒ | ☒ | ☒ | ☐ | ☒ | ☐ | ☒ | ☐ | ☐ | ☐ | ☒ | ☒ | ☐ | ☐ |
Art 6(1-a) explicit consent | ☒ | ☒ | ☒ | ☒ | ☒ | ☒ | ☐ | ☒ | ☐ | ☒ | ☐ | ☐ | ☐ | ☒ | ☒ | ☐ | ☐ |
Art.6(1-a) regular consent | ☒ | ☒ | ☒ | ☒ | ☒ | ☒ | ☐ | ☒ | ☐ | ☒ | ☐ | ☐ | ☐ | ☒ | ☒ | ☐ | ☐ |
Art 6(1-b) contract | ☒ | ☒ | ☒ | ☒ | ☒ | ☒ | ☐ | ☒ | ☐ | ☒ | ☐ | ☐ | ☐ | ☐ | ☒ | ☐ | ☐ |
Art 6(1-b) contract performance | ☒ | ☒ | ☒ | ☒ | ☒ | ☒ | ☐ | ☒ | ☐ | ☒ | ☐ | ☐ | ☐ | ☐ | ☒ | ☐ | ☐ |
Art 6(1-b) enter into contract | ☒ | ☒ | ☒ | ☒ | ☒ | ☒ | ☐ | ☒ | ☐ | ☒ | ☐ | ☐ | ☐ | ☐ | ☒ | ☐ | ☐ |
Art 6(1-c) legal obligation | ☒ | ☐ | ☒ | ☒ | ☐ | ☒ | ☐ | ☐ | ☐ | ☐ | ☐ | ☐ | ☐ | ☐ | ☒ | ☐ | ☐ |
Art 6(1-d) protect vital interests | ☒ | ☒ | ☒ | ☒ | ☒ | ☒ | ☐ | ☐ | ☐ | ☒ | ☐ | ☐ | ☐ | ☐ | ☒ | ☐ | ☐ |
Art 6(1-d) protect vital interests of data subject | ☒ | ☒ | ☒ | ☒ | ☒ | ☒ | ☐ | ☐ | ☐ | ☒ | ☐ | ☐ | ☐ | ☐ | ☒ | ☐ | ☐ |
Art 6(1-d) protect vital interests of natural person | ☒ | ☒ | ☒ | ☒ | ☒ | ☒ | ☐ | ☐ | ☐ | ☒ | ☐ | ☐ | ☐ | ☐ | ☒ | ☐ | ☐ |
Art 6(1-e) public interest or official authority | ☒ | ☒ | ☒ | ☒ | ☐ | ☒ | ☐ | ☐ | ☒ | ☒ | ☐ | ☐ | ☐ | ☐ | ☒ | ☐ | ☐ |
Art 6(1-e) official authority | ☒ | ☒ | ☒ | ☒ | ☐ | ☒ | ☐ | ☐ | ☒ | ☒ | ☐ | ☐ | ☐ | ☐ | ☒ | ☐ | ☐ |
Art 6(1-e) public interest | ☒ | ☒ | ☒ | ☒ | ☐ | ☒ | ☐ | ☐ | ☒ | ☒ | ☐ | ☐ | ☐ | ☐ | ☒ | ☐ | ☐ |
Art 6(1-f) legitimate interest | ☒ | ☒ | ☒ | ☒ | ☒ | ☒ | ☐ | ☐ | ☒ | ☒ | ☐ | ☐ | ☐ | ☐ | ☒ | ☐ | ☐ |
Art 6(1-f) legitimate interest of controller | ☒ | ☒ | ☒ | ☒ | ☒ | ☒ | ☐ | ☐ | ☒ | ☒ | ☐ | ☐ | ☐ | ☐ | ☒ | ☐ | ☐ |
Art 6(1-f) legitimate interest of third party | ☒ | ☒ | ☒ | ☒ | ☒ | ☒ | ☐ | ☐ | ☒ | ☒ | ☐ | ☐ | ☐ | ☐ | ☒ | ☐ | ☐ |
GDPR defines instances for where right exercise can be denied, delayed, or be put on hold while more information or activities are required. For example, GDPR Art.12-3 states that fulfilling a rights exercise request may be delayed if it is sufficiently complex and/or there are a large number of requests to be handled at that time. These are modelled as JustificationA12Complexity and JustificationA12HighVolume respectively, which are instances of dpv:Justification
and can be associated using the relation dpv:hasJustification
. The justification concepts expand broader concepts in the [JUSTIFICATIONS] extension and are defined for interpretation in the context of specific rights. The below list provides a list of justifications derived from the GDPR for each specific right (click to expand).
GDPR regulates data transfers outside the EU/EEA based on jurisdictions the transfer is occurring within and the guarantees available regarding the protection of personal data and fundamental rights. To indicate the sufficiency of a data transfer being compatible and adherent to these requirements, the European Commission provides various 'data transfer tools' based on the legal bases provided within the GDPR. EU-GDPR models these as follows.
The EU-GDPR's concepts for transfer tools are currently symbolic, and do not provide a way to actually implement those tools. For example, to represent the information contained within a SCC or BCR. The DPVCG is interested in providing such implementations, and welcomes discussions and contributions for the same.
[GDPR] Article 35 specifies the conditions and requirements associated with Data Protection Impact Assessments. EU-GDPR expands on the DPIA
concept defined as an Organisational Measure within DPV by considering a DPIA as consisting of the following iterative process, and providing statuses for documenting their progression and outputs:
In addition to DPV's concepts for representing information about processing of personal data, EU-GDPR also recommends using DCMI Metadata Terms (DCT) concepts to represent relevant metadata, such as dates, identifiers, validity, etc.
The DPVCG is working on updating the Guide for GDPR DPIA's using DPV based on recent updates in DPV and EU-GDPR. In addition to these, we are also working on providing concepts for expressing impacts and risk management within Risk Assessment and Management concepts for DPV.
Specs
New Concept(s)
The EU-GDPR extension should provide information on which processing activities require a DPIA. This work will be led by @TyttiRintamaki and will be based on High-Risk Categorisations in GDPR vs AI Act: Overlaps and Implications
[GDPR] defines several obligations regarding the handling of data breach incidents, and authoritative guidance establishes the categories of data breach based on how it affects data. To support implementation of these, the [EU-GDPR] extension provides concepts that extend the [DPV] to define GDPR specific requirements.
DataBreach is a specific concept that reflects the GDPR's definition of data breaches, and is separate from a general data breach incident (such as that defined within the [RISK] extension) in terms of its involvement of personal data as well the use of GDPR 'processing' definition. Under GDPR, data breaches are categorised based on the CIA information security model as ConfidentialityBreach for disclosures e.g. accidentally sharing data, IntegrityBreach for alterations e.g. maliciously overwriting data, and AvailabilityBreach for loss or destruction e.g. erasing all data on disk. In addition to these, GDPR also requires awareness of when a breach affects multiple jurisdictions either due to involvement of data subjects from multiple EU countries or because the processing of personal data involves multiple locations spread across EU. Such breaches are categorised as CrossBorderDataBreach.
DataBreachNotice represents the communication of information regarding a data breach to another entity, such as reporting it to the authority or sending communications to data subjects. Specific notice concepts are defined to reflect the recipients, for example ControllerBreachNotice is a notice sent to the controller and DataSubjectBreachNotice is a notice sent to the data subject. For reporting data breaches to authorities, there are multiple types of notifications at various stages of investigations - these are represented by DPABreachNotice with additional concepts for initial notice sent within 72 hours, as well as 'phased' notices which are sent as information becomes available.
To represent status of GDPR obligations regarding data breach notifications, the concept DataBreachNoticeRequirement provides specific outcomes which can be documented. For example, BreachNotificationNotNeeded indicates that notifications are not needed, and DPABreachNotificationNeeded represents a notification to the authority is needed.
To support the documentation of data breaches, the concept DataBreachReport represents a report associated with the breach, which can contain information on how the breach was discovered, the duration and coverage of the breach, what measures were taken to handle it, and what notifications were sent as part of the data breach handling processes. Specific concepts are provided to represent different reports required for fulfilling GDPR requirements, for example DataBreachDetectionReport as a report regarding the detection of a data breach and DataBreachPreliminaryReport as a preliminary report (e.g. within 72 hours) when an investigation is underway.
DataBreachJustification represents a dpv:Justification
defined in the context of a data breach handling procedure, with specific concepts defined based on the provisions defined in the GDPR. For example, JustificationA33NotificationDelay represents the justification for why a data breach notification was delayed - which would require additional information for that particular instance, and JustificationA33RiskUnlikely represents the specific justification that a notification was deemed to not be necessary as the risk level was found to be low or unlikely (while this doesn't require more information to describe the justification, it is good practice to associate the risk/impact assessment with this for record keeping).
GDPR requires carrying out an impact assessment to determine the level of risk associated with the data breach, in particular on the processing of personal data and on the rights and freedoms of the data subjects. To represent this, the concept DBIARiskStatus is provided with specific outcomes. For example, DBIAIndicatesHighRisk indicates the data breach has a 'high-risk' status.
The concept 'establishment' is defined in the GDPR in Article 4-16 as 'main establishment' which is used to determine who will be the 'lead' supervisory authority responsible. An establishment in this context can be a subsidiary, a division or branch, or other forms of corporate structures through which multi-national corporations and organisations operate. To support representation of this, [EU-GDPR] defines the concept Establishment, and extends it as MainEstablishment to indicate which establishment is the 'main'. To indicate that there is only a single establishment and no other locations are involved, the concept SingleEstablishment is provided.
Establishments are indicated by using the relation hasEstablishment. Main establishment is associated by using the relation isMainEstablishmentFor, or the main establishment can be indicated using hasMainEstablishment. To represent organisation structures such as subsidiaries, the relation dpv:hasSubsidiary
and dpv:isSubsidiaryOf
can be reused.
The concepts in this section reflect the status of processing operations being in compliance with GDPR, by extending the ComplianceStatus
from DPV for GDPR. It does not define the requirements for compliance itself. To indicate these, the relation dpv:hasLawfulness
can be used.
These concepts are additionally defined in the EU-GDPR extension, but are not placed within the sections described earlier.
Term | A13 | Prefix | eu-gdpr |
---|---|---|---|
Label | A13 Right to be Informed | ||
IRI | https://w3id.org/dpv/legal/eu/gdpr#A13 | ||
Type | rdfs:Class, skos:Concept, dpv:Right | ||
Broader/Parent types | dpv:DataSubjectRight → dpv:Right | ||
Object of relation | dpv:hasRight | ||
Definition | information to be provided where personal data is directly collected from data subject | ||
Source | GDPR Art.13 | ||
Date Created | 2020-11-04 | ||
Contributors | Beatriz Esteves, Georg P. Krog, Harshvardhan J. Pandit | ||
has justification | Justification A12 - Lack Of Intent , Justification A12 - Malicious Intent , Justification A12 - Manifestly Excessive , Justification A12 - Manifestly Unfounded , Justification A13 - Entity Already Informed | ||
See More: | section RIGHTS in EU-GDPR , section RIGHTS-JUSTIFICATIONS in EU-GDPR |
Term | A13-Denied | Prefix | eu-gdpr |
---|---|---|---|
Label | A13 Denied | ||
IRI | https://w3id.org/dpv/legal/eu/gdpr#A13-Denied | ||
Type | rdfs:Class, skos:Concept, dpv:RiskConcept, risk:PotentialConsequence, risk:PotentialImpact, risk:PotentialRisk | ||
Broader/Parent types | eu-gdpr:A13-Impact → eu-gdpr:GDPRRightsImpact → risk:RightsImpact → risk:SocietalRiskConcept → dpv:RiskConcept | ||
Object of relation | risk:avoids, risk:contains, risk:controls, risk:detects, risk:eliminates, risk:identifies, risk:interrupts, risk:intervenes, risk:investigates, risk:logs, risk:mitigates, risk:modifies, risk:monitors, risk:overrides, risk:recovers, risk:reduces, risk:remedies, risk:resolves, risk:reverses, risk:shares, risk:substitutes, risk:transfers | ||
Definition | A denial that A13 applied to the situation | ||
Date Created | 2024-10-21 | ||
Date Modified | 2025-08-17 | ||
See More: | section RIGHTS-IMPACTS in EU-GDPR |
Term | A13-Eroded | Prefix | eu-gdpr |
---|---|---|---|
Label | A13 Eroded | ||
IRI | https://w3id.org/dpv/legal/eu/gdpr#A13-Eroded | ||
Type | rdfs:Class, skos:Concept, dpv:RiskConcept, risk:PotentialConsequence, risk:PotentialImpact, risk:PotentialRisk | ||
Broader/Parent types | eu-gdpr:A13-Impact → eu-gdpr:GDPRRightsImpact → risk:RightsImpact → risk:SocietalRiskConcept → dpv:RiskConcept | ||
Object of relation | risk:avoids, risk:contains, risk:controls, risk:detects, risk:eliminates, risk:identifies, risk:interrupts, risk:intervenes, risk:investigates, risk:logs, risk:mitigates, risk:modifies, risk:monitors, risk:overrides, risk:recovers, risk:reduces, risk:remedies, risk:resolves, risk:reverses, risk:shares, risk:substitutes, risk:transfers | ||
Definition | Erosion of A13 obligation to provide information e.g. by repeatedly and systematically limited or denying it | ||
Date Created | 2024-10-21 | ||
Date Modified | 2025-08-17 | ||
See More: | section RIGHTS-IMPACTS in EU-GDPR |
Term | A13-ExercisePrevented | Prefix | eu-gdpr |
---|---|---|---|
Label | A13 ExercisePrevented | ||
IRI | https://w3id.org/dpv/legal/eu/gdpr#A13-ExercisePrevented | ||
Type | rdfs:Class, skos:Concept, dpv:RiskConcept, risk:PotentialConsequence, risk:PotentialImpact, risk:PotentialRisk | ||
Broader/Parent types | eu-gdpr:A13-Impact → eu-gdpr:GDPRRightsImpact → risk:RightsImpact → risk:SocietalRiskConcept → dpv:RiskConcept | ||
Object of relation | risk:avoids, risk:contains, risk:controls, risk:detects, risk:eliminates, risk:identifies, risk:interrupts, risk:intervenes, risk:investigates, risk:logs, risk:mitigates, risk:modifies, risk:monitors, risk:overrides, risk:recovers, risk:reduces, risk:remedies, risk:resolves, risk:reverses, risk:shares, risk:substitutes, risk:transfers | ||
Definition | The prevention of A13 obligation to provide information e.g. by preventing the data subject from obtaining this information | ||
Date Created | 2024-10-21 | ||
Date Modified | 2025-08-17 | ||
See More: | section RIGHTS-IMPACTS in EU-GDPR |
Term | A13-Impact | Prefix | eu-gdpr |
---|---|---|---|
Label | Impact on A13 Right to be Informed | ||
IRI | https://w3id.org/dpv/legal/eu/gdpr#A13-Impact | ||
Type | rdfs:Class, skos:Concept, dpv:RiskConcept, risk:PotentialConsequence, risk:PotentialImpact, risk:PotentialRisk | ||
Broader/Parent types | eu-gdpr:GDPRRightsImpact → risk:RightsImpact → risk:SocietalRiskConcept → dpv:RiskConcept | ||
Object of relation | risk:avoids, risk:contains, risk:controls, risk:detects, risk:eliminates, risk:identifies, risk:interrupts, risk:intervenes, risk:investigates, risk:logs, risk:mitigates, risk:modifies, risk:monitors, risk:overrides, risk:recovers, risk:reduces, risk:remedies, risk:resolves, risk:reverses, risk:shares, risk:substitutes, risk:transfers | ||
Definition | Something that acts as or is considered as an impact on A13 Right to be Informed | ||
Source | GDPR Art.13 | ||
Date Created | 2024-10-21 | ||
Date Modified | 2025-08-17 | ||
See More: | section RIGHTS-IMPACTS in EU-GDPR |
Term | A13-Limited | Prefix | eu-gdpr |
---|---|---|---|
Label | A13 Limited | ||
IRI | https://w3id.org/dpv/legal/eu/gdpr#A13-Limited | ||
Type | rdfs:Class, skos:Concept, dpv:RiskConcept, risk:PotentialConsequence, risk:PotentialImpact, risk:PotentialRisk | ||
Broader/Parent types | eu-gdpr:A13-Impact → eu-gdpr:GDPRRightsImpact → risk:RightsImpact → risk:SocietalRiskConcept → dpv:RiskConcept | ||
Object of relation | risk:avoids, risk:contains, risk:controls, risk:detects, risk:eliminates, risk:identifies, risk:interrupts, risk:intervenes, risk:investigates, risk:logs, risk:mitigates, risk:modifies, risk:monitors, risk:overrides, risk:recovers, risk:reduces, risk:remedies, risk:resolves, risk:reverses, risk:shares, risk:substitutes, risk:transfers | ||
Definition | A limited fulfillment of A13 obligation to provide information e.g. not providing all required information | ||
Date Created | 2024-10-21 | ||
Date Modified | 2025-08-17 | ||
See More: | section RIGHTS-IMPACTS in EU-GDPR |
Term | A13-Obstructed | Prefix | eu-gdpr |
---|---|---|---|
Label | A13 Obstructed | ||
IRI | https://w3id.org/dpv/legal/eu/gdpr#A13-Obstructed | ||
Type | rdfs:Class, skos:Concept, dpv:RiskConcept, risk:PotentialConsequence, risk:PotentialImpact, risk:PotentialRisk | ||
Broader/Parent types | eu-gdpr:A13-Impact → eu-gdpr:GDPRRightsImpact → risk:RightsImpact → risk:SocietalRiskConcept → dpv:RiskConcept | ||
Object of relation | risk:avoids, risk:contains, risk:controls, risk:detects, risk:eliminates, risk:identifies, risk:interrupts, risk:intervenes, risk:investigates, risk:logs, risk:mitigates, risk:modifies, risk:monitors, risk:overrides, risk:recovers, risk:reduces, risk:remedies, risk:resolves, risk:reverses, risk:shares, risk:substitutes, risk:transfers | ||
Definition | Obstruction of A13 obligation to provide information e.g. asking for unnecessary identity verification and making it difficult to obtain information | ||
Date Created | 2024-10-21 | ||
Date Modified | 2025-08-17 | ||
See More: | section RIGHTS-IMPACTS in EU-GDPR |
Term | A13-Unfulfilled | Prefix | eu-gdpr |
---|---|---|---|
Label | A13 Unfulfilled | ||
IRI | https://w3id.org/dpv/legal/eu/gdpr#A13-Unfulfilled | ||
Type | rdfs:Class, skos:Concept, dpv:RiskConcept, risk:PotentialConsequence, risk:PotentialImpact, risk:PotentialRisk | ||
Broader/Parent types | eu-gdpr:A13-Impact → eu-gdpr:GDPRRightsImpact → risk:RightsImpact → risk:SocietalRiskConcept → dpv:RiskConcept | ||
Object of relation | risk:avoids, risk:contains, risk:controls, risk:detects, risk:eliminates, risk:identifies, risk:interrupts, risk:intervenes, risk:investigates, risk:logs, risk:mitigates, risk:modifies, risk:monitors, risk:overrides, risk:recovers, risk:reduces, risk:remedies, risk:resolves, risk:reverses, risk:shares, risk:substitutes, risk:transfers | ||
Definition | Non-fulfillment of A13 obligation to provide required information | ||
Date Created | 2024-10-21 | ||
Date Modified | 2025-08-17 | ||
See More: | section RIGHTS-IMPACTS in EU-GDPR |
Term | A13-Violated | Prefix | eu-gdpr |
---|---|---|---|
Label | A13 Violated | ||
IRI | https://w3id.org/dpv/legal/eu/gdpr#A13-Violated | ||
Type | rdfs:Class, skos:Concept, dpv:RiskConcept, risk:PotentialConsequence, risk:PotentialImpact, risk:PotentialRisk | ||
Broader/Parent types | eu-gdpr:A13-Impact → eu-gdpr:GDPRRightsImpact → risk:RightsImpact → risk:SocietalRiskConcept → dpv:RiskConcept | ||
Object of relation | risk:avoids, risk:contains, risk:controls, risk:detects, risk:eliminates, risk:identifies, risk:interrupts, risk:intervenes, risk:investigates, risk:logs, risk:mitigates, risk:modifies, risk:monitors, risk:overrides, risk:recovers, risk:reduces, risk:remedies, risk:resolves, risk:reverses, risk:shares, risk:substitutes, risk:transfers | ||
Definition | A violation of A13 obligation regarding providing information | ||
Usage Note | What constitutes as a violation of A13 depends on the particulars of the situation, therefore we suggest first representing the impact using the appropriate category of impact (e.g. denied, limited) and then assessing whether it constitutes as a violation | ||
Date Created | 2024-10-21 | ||
Date Modified | 2025-08-17 | ||
See More: | section RIGHTS-IMPACTS in EU-GDPR |
Term | A14-Impact | Prefix | eu-gdpr |
---|---|---|---|
Label | Impact on A14 Right to be Informed | ||
IRI | https://w3id.org/dpv/legal/eu/gdpr#A14-Impact | ||
Type | rdfs:Class, skos:Concept, dpv:RiskConcept, risk:PotentialConsequence, risk:PotentialImpact, risk:PotentialRisk | ||
Broader/Parent types | eu-gdpr:GDPRRightsImpact → risk:RightsImpact → risk:SocietalRiskConcept → dpv:RiskConcept | ||
Object of relation | risk:avoids, risk:contains, risk:controls, risk:detects, risk:eliminates, risk:identifies, risk:interrupts, risk:intervenes, risk:investigates, risk:logs, risk:mitigates, risk:modifies, risk:monitors, risk:overrides, risk:recovers, risk:reduces, risk:remedies, risk:resolves, risk:reverses, risk:shares, risk:substitutes, risk:transfers | ||
Definition | Something that acts as or is considered as an impact on A14 Right to be Informed | ||
Source | GDPR Art.14 | ||
Date Created | 2024-10-21 | ||
Date Modified | 2025-08-17 | ||
See More: | section RIGHTS-IMPACTS in EU-GDPR |
Term | A15 | Prefix | eu-gdpr |
---|---|---|---|
Label | A15 Right of Access | ||
IRI | https://w3id.org/dpv/legal/eu/gdpr#A15 | ||
Type | rdfs:Class, skos:Concept, dpv:Right | ||
Broader/Parent types | dpv:DataSubjectRight → dpv:Right | ||
Object of relation | dpv:hasRight | ||
Definition | Right of access | ||
Source | GDPR Art.15 | ||
Date Created | 2020-11-04 | ||
Contributors | Beatriz Esteves, Georg P. Krog, Harshvardhan J. Pandit | ||
has justification | Justification A12 - Complexity , Justification A12 - Delay , Justification A12 - High Volume , Justification A12 - Identity Failure , Justification A12 - Identity Required , Justification A12 - Information Required , Justification A12 - Lack Of Intent , Justification A12 - Malicious Intent , Justification A12 - Manifestly Excessive , Justification A12 - Manifestly Unfounded | ||
See More: | section RIGHTS in EU-GDPR , section RIGHTS-JUSTIFICATIONS in EU-GDPR |
Term | A15-Impact | Prefix | eu-gdpr |
---|---|---|---|
Label | Impact on A15 Right of Access | ||
IRI | https://w3id.org/dpv/legal/eu/gdpr#A15-Impact | ||
Type | rdfs:Class, skos:Concept, dpv:RiskConcept, risk:PotentialConsequence, risk:PotentialImpact, risk:PotentialRisk | ||
Broader/Parent types | eu-gdpr:GDPRRightsImpact → risk:RightsImpact → risk:SocietalRiskConcept → dpv:RiskConcept | ||
Object of relation | risk:avoids, risk:contains, risk:controls, risk:detects, risk:eliminates, risk:identifies, risk:interrupts, risk:intervenes, risk:investigates, risk:logs, risk:mitigates, risk:modifies, risk:monitors, risk:overrides, risk:recovers, risk:reduces, risk:remedies, risk:resolves, risk:reverses, risk:shares, risk:substitutes, risk:transfers | ||
Definition | Something that acts as or is considered as an impact on A15 Right of Access | ||
Source | GDPR Art.15 | ||
Date Created | 2024-10-21 | ||
Date Modified | 2025-08-17 | ||
See More: | section RIGHTS-IMPACTS in EU-GDPR |
Term | A16 | Prefix | eu-gdpr |
---|---|---|---|
Label | A16 Right to Rectification | ||
IRI | https://w3id.org/dpv/legal/eu/gdpr#A16 | ||
Type | rdfs:Class, skos:Concept, dpv:Right | ||
Broader/Parent types | dpv:DataSubjectRight → dpv:Right | ||
Object of relation | dpv:hasRight | ||
Definition | Right to rectification | ||
Source | GDPR Art.16 | ||
Date Created | 2020-11-04 | ||
Contributors | Beatriz Esteves, Georg P. Krog, Harshvardhan J. Pandit | ||
has justification | Justification A12 - Complexity , Justification A12 - Delay , Justification A12 - High Volume , Justification A12 - Identity Failure , Justification A12 - Identity Required , Justification A12 - Information Required , Justification A12 - Lack Of Intent , Justification A12 - Malicious Intent , Justification A12 - Manifestly Excessive , Justification A12 - Manifestly Unfounded | ||
See More: | section RIGHTS in EU-GDPR , section RIGHTS-JUSTIFICATIONS in EU-GDPR |
Term | A16-Impact | Prefix | eu-gdpr |
---|---|---|---|
Label | Impact on A16 Right to Rectification | ||
IRI | https://w3id.org/dpv/legal/eu/gdpr#A16-Impact | ||
Type | rdfs:Class, skos:Concept, dpv:RiskConcept, risk:PotentialConsequence, risk:PotentialImpact, risk:PotentialRisk | ||
Broader/Parent types | eu-gdpr:GDPRRightsImpact → risk:RightsImpact → risk:SocietalRiskConcept → dpv:RiskConcept | ||
Object of relation | risk:avoids, risk:contains, risk:controls, risk:detects, risk:eliminates, risk:identifies, risk:interrupts, risk:intervenes, risk:investigates, risk:logs, risk:mitigates, risk:modifies, risk:monitors, risk:overrides, risk:recovers, risk:reduces, risk:remedies, risk:resolves, risk:reverses, risk:shares, risk:substitutes, risk:transfers | ||
Definition | Something that acts as or is considered as an impact on A16 Right to Rectification | ||
Source | GDPR Art.16 | ||
Date Created | 2024-10-21 | ||
Date Modified | 2025-08-17 | ||
See More: | section RIGHTS-IMPACTS in EU-GDPR |
Term | A17-Impact | Prefix | eu-gdpr |
---|---|---|---|
Label | Impact on A17 Right to Erasure | ||
IRI | https://w3id.org/dpv/legal/eu/gdpr#A17-Impact | ||
Type | rdfs:Class, skos:Concept, dpv:RiskConcept, risk:PotentialConsequence, risk:PotentialImpact, risk:PotentialRisk | ||
Broader/Parent types | eu-gdpr:GDPRRightsImpact → risk:RightsImpact → risk:SocietalRiskConcept → dpv:RiskConcept | ||
Object of relation | risk:avoids, risk:contains, risk:controls, risk:detects, risk:eliminates, risk:identifies, risk:interrupts, risk:intervenes, risk:investigates, risk:logs, risk:mitigates, risk:modifies, risk:monitors, risk:overrides, risk:recovers, risk:reduces, risk:remedies, risk:resolves, risk:reverses, risk:shares, risk:substitutes, risk:transfers | ||
Definition | Something that acts as or is considered as an impact on A17 Right to Erasure | ||
Source | GDPR Art.17 | ||
Date Created | 2024-10-21 | ||
Date Modified | 2025-08-17 | ||
See More: | section RIGHTS-IMPACTS in EU-GDPR |
Term | A18 | Prefix | eu-gdpr |
---|---|---|---|
Label | A18 Right to Restrict Processing | ||
IRI | https://w3id.org/dpv/legal/eu/gdpr#A18 | ||
Type | rdfs:Class, skos:Concept, dpv:Right | ||
Broader/Parent types | dpv:DataSubjectRight → dpv:Right | ||
Object of relation | dpv:hasRight | ||
Definition | Right to restriction of processing | ||
Source | GDPR Art.18 | ||
Date Created | 2020-11-04 | ||
Contributors | Beatriz Esteves, Georg P. Krog, Harshvardhan J. Pandit | ||
has justification | Justification A12 - Complexity , Justification A12 - Delay , Justification A12 - High Volume , Justification A12 - Identity Failure , Justification A12 - Identity Required , Justification A12 - Information Required , Justification A12 - Lack Of Intent , Justification A12 - Malicious Intent , Justification A12 - Manifestly Excessive , Justification A12 - Manifestly Unfounded | ||
See More: | section RIGHTS in EU-GDPR , section RIGHTS-JUSTIFICATIONS in EU-GDPR |
Term | A18-Impact | Prefix | eu-gdpr |
---|---|---|---|
Label | Impact on A18 Right to Restrict Processing | ||
IRI | https://w3id.org/dpv/legal/eu/gdpr#A18-Impact | ||
Type | rdfs:Class, skos:Concept, dpv:RiskConcept, risk:PotentialConsequence, risk:PotentialImpact, risk:PotentialRisk | ||
Broader/Parent types | eu-gdpr:GDPRRightsImpact → risk:RightsImpact → risk:SocietalRiskConcept → dpv:RiskConcept | ||
Object of relation | risk:avoids, risk:contains, risk:controls, risk:detects, risk:eliminates, risk:identifies, risk:interrupts, risk:intervenes, risk:investigates, risk:logs, risk:mitigates, risk:modifies, risk:monitors, risk:overrides, risk:recovers, risk:reduces, risk:remedies, risk:resolves, risk:reverses, risk:shares, risk:substitutes, risk:transfers | ||
Definition | Something that acts as or is considered as an impact on A18 Right to Restrict Processing | ||
Source | GDPR Art.18 | ||
Date Created | 2024-10-21 | ||
Date Modified | 2025-08-17 | ||
See More: | section RIGHTS-IMPACTS in EU-GDPR |
Term | A19 | Prefix | eu-gdpr |
---|---|---|---|
Label | A19 Right to Rectification Notification | ||
IRI | https://w3id.org/dpv/legal/eu/gdpr#A19 | ||
Type | rdfs:Class, skos:Concept, dpv:Right | ||
Broader/Parent types | dpv:DataSubjectRight → dpv:Right | ||
Object of relation | dpv:hasRight | ||
Definition | Right to be notified in case of rectification or erasure of personal data or restriction of processing | ||
Source | GDPR Art.19 | ||
Date Created | 2020-11-04 | ||
Date Modified | 2024-04-14 | ||
Contributors | Beatriz Esteves, Georg P. Krog, Harshvardhan J. Pandit | ||
has justification | Justification A12 - Complexity , Justification A12 - Delay , Justification A12 - High Volume , Justification A12 - Identity Failure , Justification A12 - Identity Required , Justification A12 - Information Required , Justification A12 - Lack Of Intent , Justification A12 - Malicious Intent , Justification A12 - Manifestly Excessive , Justification A12 - Manifestly Unfounded | ||
See More: | section RIGHTS in EU-GDPR , section RIGHTS-JUSTIFICATIONS in EU-GDPR |
Term | A19-Impact | Prefix | eu-gdpr |
---|---|---|---|
Label | Impact on A19 Right to Rectification Notification | ||
IRI | https://w3id.org/dpv/legal/eu/gdpr#A19-Impact | ||
Type | rdfs:Class, skos:Concept, dpv:RiskConcept, risk:PotentialConsequence, risk:PotentialImpact, risk:PotentialRisk | ||
Broader/Parent types | eu-gdpr:GDPRRightsImpact → risk:RightsImpact → risk:SocietalRiskConcept → dpv:RiskConcept | ||
Object of relation | risk:avoids, risk:contains, risk:controls, risk:detects, risk:eliminates, risk:identifies, risk:interrupts, risk:intervenes, risk:investigates, risk:logs, risk:mitigates, risk:modifies, risk:monitors, risk:overrides, risk:recovers, risk:reduces, risk:remedies, risk:resolves, risk:reverses, risk:shares, risk:substitutes, risk:transfers | ||
Definition | Something that acts as or is considered as an impact on A19 Right to Rectification Notification | ||
Source | GDPR Art.19 | ||
Date Created | 2024-10-21 | ||
Date Modified | 2025-08-17 | ||
See More: | section RIGHTS-IMPACTS in EU-GDPR |
Term | A20 | Prefix | eu-gdpr |
---|---|---|---|
Label | A20 Right to Data Portability | ||
IRI | https://w3id.org/dpv/legal/eu/gdpr#A20 | ||
Type | rdfs:Class, skos:Concept, dpv:Right | ||
Broader/Parent types | dpv:DataSubjectRight → dpv:Right | ||
Object of relation | dpv:hasRight | ||
Definition | Right to data portability | ||
Source | GDPR Art.20 | ||
Date Created | 2020-11-04 | ||
Contributors | Beatriz Esteves, Georg P. Krog, Harshvardhan J. Pandit | ||
has justification | Justification A12 - Complexity , Justification A12 - Delay , Justification A12 - High Volume , Justification A12 - Identity Failure , Justification A12 - Identity Required , Justification A12 - Information Required , Justification A12 - Lack Of Intent , Justification A12 - Malicious Intent , Justification A12 - Manifestly Excessive , Justification A12 - Manifestly Unfounded | ||
See More: | section RIGHTS in EU-GDPR , section RIGHTS-JUSTIFICATIONS in EU-GDPR |
Term | A20-Impact | Prefix | eu-gdpr |
---|---|---|---|
Label | Impact on A20 Right to Data Portability | ||
IRI | https://w3id.org/dpv/legal/eu/gdpr#A20-Impact | ||
Type | rdfs:Class, skos:Concept, dpv:RiskConcept, risk:PotentialConsequence, risk:PotentialImpact, risk:PotentialRisk | ||
Broader/Parent types | eu-gdpr:GDPRRightsImpact → risk:RightsImpact → risk:SocietalRiskConcept → dpv:RiskConcept | ||
Object of relation | risk:avoids, risk:contains, risk:controls, risk:detects, risk:eliminates, risk:identifies, risk:interrupts, risk:intervenes, risk:investigates, risk:logs, risk:mitigates, risk:modifies, risk:monitors, risk:overrides, risk:recovers, risk:reduces, risk:remedies, risk:resolves, risk:reverses, risk:shares, risk:substitutes, risk:transfers | ||
Definition | Something that acts as or is considered as an impact on A20 Right to Data Portability | ||
Source | GDPR Art.20 | ||
Date Created | 2024-10-21 | ||
Date Modified | 2025-08-17 | ||
See More: | section RIGHTS-IMPACTS in EU-GDPR |
Term | A21 | Prefix | eu-gdpr |
---|---|---|---|
Label | A21 Right to object | ||
IRI | https://w3id.org/dpv/legal/eu/gdpr#A21 | ||
Type | rdfs:Class, skos:Concept, dpv:Right | ||
Broader/Parent types | dpv:DataSubjectRight → dpv:Right | ||
Object of relation | dpv:hasRight | ||
Definition | Right to object to processing of personal data | ||
Source | GDPR Art.21 | ||
Date Created | 2020-11-04 | ||
Contributors | Beatriz Esteves, Georg P. Krog, Harshvardhan J. Pandit | ||
has justification | Justification A12 - Complexity , Justification A12 - Delay , Justification A12 - High Volume , Justification A12 - Identity Failure , Justification A12 - Identity Required , Justification A12 - Information Required , Justification A12 - Lack Of Intent , Justification A12 - Malicious Intent , Justification A12 - Manifestly Excessive , Justification A12 - Manifestly Unfounded | ||
See More: | section RIGHTS in EU-GDPR , section RIGHTS-JUSTIFICATIONS in EU-GDPR |
Term | A21-Impact | Prefix | eu-gdpr |
---|---|---|---|
Label | Impact on A21 Right to object | ||
IRI | https://w3id.org/dpv/legal/eu/gdpr#A21-Impact | ||
Type | rdfs:Class, skos:Concept, dpv:RiskConcept, risk:PotentialConsequence, risk:PotentialImpact, risk:PotentialRisk | ||
Broader/Parent types | eu-gdpr:GDPRRightsImpact → risk:RightsImpact → risk:SocietalRiskConcept → dpv:RiskConcept | ||
Object of relation | risk:avoids, risk:contains, risk:controls, risk:detects, risk:eliminates, risk:identifies, risk:interrupts, risk:intervenes, risk:investigates, risk:logs, risk:mitigates, risk:modifies, risk:monitors, risk:overrides, risk:recovers, risk:reduces, risk:remedies, risk:resolves, risk:reverses, risk:shares, risk:substitutes, risk:transfers | ||
Definition | Something that acts as or is considered as an impact on A21 Right to object | ||
Source | GDPR Art.21 | ||
Date Created | 2024-10-21 | ||
Date Modified | 2025-08-17 | ||
See More: | section RIGHTS-IMPACTS in EU-GDPR |
Term | A22 | Prefix | eu-gdpr |
---|---|---|---|
Label | A22 Right to object to automated decision making | ||
IRI | https://w3id.org/dpv/legal/eu/gdpr#A22 | ||
Type | rdfs:Class, skos:Concept, dpv:Right | ||
Broader/Parent types | dpv:DataSubjectRight → dpv:Right | ||
Object of relation | dpv:hasRight | ||
Definition | Right not to be subject to a decision based solely on automated processing including profiling, and for the data subject to obtain human intervention on the part of the controller for the contested or objected activity, and for the data subject to express his or her point of view, and for the data subject to contest the decision | ||
Source | GDPR Art.22 | ||
Date Created | 2020-11-04 | ||
Date Modified | 2024-12-17 | ||
Contributors | Beatriz Esteves, Georg P. Krog, Harshvardhan J. Pandit | ||
has justification | Justification A12 - Complexity , Justification A12 - Delay , Justification A12 - High Volume , Justification A12 - Lack Of Intent , Justification A12 - Malicious Intent , Justification A12 - Manifestly Excessive , Justification A12 - Manifestly Unfounded | ||
See More: | section RIGHTS in EU-GDPR , section RIGHTS-JUSTIFICATIONS in EU-GDPR |
Term | A22-3-a | Prefix | eu-gdpr |
---|---|---|---|
Label | A22 Right to human intervention | ||
IRI | https://w3id.org/dpv/legal/eu/gdpr#A22-3-a | ||
Type | rdfs:Class, skos:Concept, dpv:Right | ||
Broader/Parent types | eu-gdpr:A22 → dpv:DataSubjectRight → dpv:Right | ||
Object of relation | dpv:hasRight | ||
Definition | Right of the data subject to obtain human intervention on the part of the controller for the contested or objected activity | ||
Source | GDPR Art.22 | ||
Date Created | 2020-11-04 | ||
Date Modified | 2024-12-17 | ||
Contributors | Beatriz Esteves, Georg P. Krog, Harshvardhan J. Pandit | ||
See More: | section RIGHTS in EU-GDPR |
Term | A22-3-b | Prefix | eu-gdpr |
---|---|---|---|
Label | A22 Right to express point of view | ||
IRI | https://w3id.org/dpv/legal/eu/gdpr#A22-3-b | ||
Type | rdfs:Class, skos:Concept, dpv:Right | ||
Broader/Parent types | eu-gdpr:A22 → dpv:DataSubjectRight → dpv:Right | ||
Object of relation | dpv:hasRight | ||
Definition | Right of the data subject to express his or her point of view | ||
Source | GDPR Art.22 | ||
Date Created | 2020-11-04 | ||
Date Modified | 2024-12-17 | ||
Contributors | Beatriz Esteves, Georg P. Krog, Harshvardhan J. Pandit | ||
See More: | section RIGHTS in EU-GDPR |
Term | A22-3-c | Prefix | eu-gdpr |
---|---|---|---|
Label | A22 Right to contest decision | ||
IRI | https://w3id.org/dpv/legal/eu/gdpr#A22-3-c | ||
Type | rdfs:Class, skos:Concept, dpv:Right | ||
Broader/Parent types | eu-gdpr:A22 → dpv:DataSubjectRight → dpv:Right | ||
Object of relation | dpv:hasRight | ||
Definition | Right of the data subject to contest the decision | ||
Source | GDPR Art.22 | ||
Date Created | 2020-11-04 | ||
Date Modified | 2024-12-17 | ||
Contributors | Beatriz Esteves, Georg P. Krog, Harshvardhan J. Pandit | ||
See More: | section RIGHTS in EU-GDPR |
Term | A22-Impact | Prefix | eu-gdpr |
---|---|---|---|
Label | Impact on A22 Right to object to automated decision making | ||
IRI | https://w3id.org/dpv/legal/eu/gdpr#A22-Impact | ||
Type | rdfs:Class, skos:Concept, dpv:RiskConcept, risk:PotentialConsequence, risk:PotentialImpact, risk:PotentialRisk | ||
Broader/Parent types | eu-gdpr:GDPRRightsImpact → risk:RightsImpact → risk:SocietalRiskConcept → dpv:RiskConcept | ||
Object of relation | risk:avoids, risk:contains, risk:controls, risk:detects, risk:eliminates, risk:identifies, risk:interrupts, risk:intervenes, risk:investigates, risk:logs, risk:mitigates, risk:modifies, risk:monitors, risk:overrides, risk:recovers, risk:reduces, risk:remedies, risk:resolves, risk:reverses, risk:shares, risk:substitutes, risk:transfers | ||
Definition | Something that acts as or is considered as an impact on A22 Right to object to automated decision making | ||
Source | GDPR Art.22 | ||
Date Created | 2024-10-21 | ||
Date Modified | 2025-08-17 | ||
See More: | section RIGHTS-IMPACTS in EU-GDPR |
Term | A45-3 | Prefix | eu-gdpr |
---|---|---|---|
Label | Art 45(3) adequacy decision | ||
IRI | https://w3id.org/dpv/legal/eu/gdpr#A45-3 | ||
Type | rdfs:Class, skos:Concept, dpv:LegalBasis | ||
Broader/Parent types | dpv:DataTransferLegalBasis → dpv:LegalBasis | ||
Object of relation | dpv:hasLegalBasis | ||
Definition | Personal data can flow freely from the EU to a third country with an Adequacy Decision without any further safeguard being necessary. | ||
Usage Note | Transfer from EU to a third country. Third country has Adequacy Decision. | ||
Source | GDPR Art.45-3 | ||
Date Created | 2020-11-04 | ||
Date Modified | 2021-09-08 | ||
Contributors | Georg P. Krog | ||
See More: | section LEGAL-BASIS-DATA-TRANSFER in EU-GDPR |
Term | A46-2-a | Prefix | eu-gdpr |
---|---|---|---|
Label | Art 46(2-a) legal instrument | ||
IRI | https://w3id.org/dpv/legal/eu/gdpr#A46-2-a | ||
Type | rdfs:Class, skos:Concept, dpv:LegalBasis | ||
Broader/Parent types | dpv:DataTransferLegalBasis → dpv:LegalBasis | ||
Object of relation | dpv:hasLegalBasis | ||
Definition | A legally binding and enforceable instrument between public authorities or bodies | ||
Usage Note | Transfer from EU to a third country. Third country has no Adequacy Decision. Third country has appropriate safeguards. Transfer does not require specific authorisation from a Supervisor Authority. | ||
Source | GDPR Art.46-2a | ||
Date Created | 2020-11-04 | ||
Date Modified | 2021-09-08 | ||
Contributors | Georg P. Krog | ||
See More: | section LEGAL-BASIS-DATA-TRANSFER in EU-GDPR |
Term | A46-2-b | Prefix | eu-gdpr |
---|---|---|---|
Label | Art 46(2-b) Binding Corporate Rules (BCR) | ||
IRI | https://w3id.org/dpv/legal/eu/gdpr#A46-2-b | ||
Type | rdfs:Class, skos:Concept, dpv:LegalBasis | ||
Broader/Parent types | eu-gdpr:BindingCorporateRules → eu-gdpr:DataTransferTool → dpv:OrganisationalMeasure → dpv:TechnicalOrganisationalMeasure | ||
Broader/Parent types | dpv:DataTransferLegalBasis → dpv:LegalBasis | ||
Object of relation | dpv:hasLegalBasis, dpv:hasOrganisationalMeasure, dpv:hasTechnicalOrganisationalMeasure | ||
Definition | ‘Binding Corporate Rules’ means personal data protection policies which are adhered to by a controller or processor established on the territory of a Member State for transfers or a set of transfers of personal data to a controller or processor in one or more third countries within a group of undertakings, or group of enterprises engaged in a joint economic activity | ||
Usage Note | Transfer from EU to a third country. Third country has no Adequacy Decision. Third country has appropriate safeguards. Transfer does not require specific authorisation from a Supervisor Authority. | ||
Source | GDPR Art.46-2b | ||
Date Created | 2020-11-04 | ||
Date Modified | 2021-09-08 | ||
Contributors | Georg P. Krog | ||
See More: | section LEGAL-BASIS-DATA-TRANSFER in EU-GDPR |
Term | A46-2-c | Prefix | eu-gdpr |
---|---|---|---|
Label | Art 46(2-c) Standard Contractual Clauses (SCC) by EC | ||
IRI | https://w3id.org/dpv/legal/eu/gdpr#A46-2-c | ||
Type | rdfs:Class, skos:Concept, dpv:LegalBasis | ||
Broader/Parent types | dpv:DataTransferLegalBasis → dpv:LegalBasis | ||
Broader/Parent types | eu-gdpr:SCCByCommission → eu-gdpr:DataTransferTool → dpv:OrganisationalMeasure → dpv:TechnicalOrganisationalMeasure | ||
Broader/Parent types | eu-gdpr:SCCByCommission → eu-gdpr:StandardContractualClauses → dpv:Contract → dpv:LegalBasis | ||
Broader/Parent types | eu-gdpr:SCCByCommission → eu-gdpr:StandardContractualClauses → eu-gdpr:DataTransferTool → dpv:OrganisationalMeasure → dpv:TechnicalOrganisationalMeasure | ||
Object of relation | dpv:hasLegalBasis, dpv:hasOrganisationalMeasure, dpv:hasTechnicalOrganisationalMeasure | ||
Definition | Standard data protection clauses adopted by the Commission | ||
Usage Note | Transfer from EU to a third country. Third country has no Adequacy Decision. Third country has appropriate safeguards. Transfer does not require specific authorisation from a Supervisor Authority. | ||
Source | GDPR Art.46-2c | ||
Date Created | 2020-11-04 | ||
Date Modified | 2021-09-08 | ||
Contributors | Georg P. Krog | ||
See More: | section LEGAL-BASIS-DATA-TRANSFER in EU-GDPR |
Term | A46-2-d | Prefix | eu-gdpr |
---|---|---|---|
Label | Art 46(2-d) Standard Contractual Clauses (SCC) by DPA | ||
IRI | https://w3id.org/dpv/legal/eu/gdpr#A46-2-d | ||
Type | rdfs:Class, skos:Concept, dpv:LegalBasis | ||
Broader/Parent types | dpv:DataTransferLegalBasis → dpv:LegalBasis | ||
Broader/Parent types | eu-gdpr:SCCBySupervisoryAuthority → eu-gdpr:DataTransferTool → dpv:OrganisationalMeasure → dpv:TechnicalOrganisationalMeasure | ||
Broader/Parent types | eu-gdpr:SCCBySupervisoryAuthority → eu-gdpr:StandardContractualClauses → dpv:Contract → dpv:LegalBasis | ||
Broader/Parent types | eu-gdpr:SCCBySupervisoryAuthority → eu-gdpr:StandardContractualClauses → eu-gdpr:DataTransferTool → dpv:OrganisationalMeasure → dpv:TechnicalOrganisationalMeasure | ||
Object of relation | dpv:hasLegalBasis, dpv:hasOrganisationalMeasure, dpv:hasTechnicalOrganisationalMeasure | ||
Definition | Standard data protection clauses adopted by a Supervisory Authority | ||
Usage Note | Transfer from EU to a third country. Third country has no Adequacy Decision. Third country has appropriate safeguards. Transfer does not require specific authorisation from a Supervisor Authority | ||
Source | GDPR Art.46-2d | ||
Date Created | 2020-11-04 | ||
Date Modified | 2021-09-08 | ||
Contributors | Georg P. Krog | ||
See More: | section LEGAL-BASIS-DATA-TRANSFER in EU-GDPR |
Term | A46-2-e | Prefix | eu-gdpr |
---|---|---|---|
Label | Art 46(2-e) code of conduct | ||
IRI | https://w3id.org/dpv/legal/eu/gdpr#A46-2-e | ||
Type | rdfs:Class, skos:Concept, dpv:LegalBasis | ||
Broader/Parent types | dpv:DataTransferLegalBasis → dpv:LegalBasis | ||
Object of relation | dpv:hasLegalBasis | ||
Definition | An approved code of conduct pursuant to GDPR Article 40 together with binding and enforceable commitments of the controller or processor in the third country to apply the appropriate safeguards, including as regards individuals´ rights | ||
Usage Note | Transfer from EU to a third country. Third country has no Adequacy Decision. Third country has appropriate safeguards. Transfer does not require specific authorisation from a Supervisor Authority. | ||
Source | GDPR Art.46-2e | ||
Date Created | 2020-11-04 | ||
Date Modified | 2021-09-08 | ||
Contributors | Georg P. Krog | ||
See More: | section LEGAL-BASIS-DATA-TRANSFER in EU-GDPR |
Term | A46-2-f | Prefix | eu-gdpr |
---|---|---|---|
Label | Art 46(2-f) certification | ||
IRI | https://w3id.org/dpv/legal/eu/gdpr#A46-2-f | ||
Type | rdfs:Class, skos:Concept, dpv:LegalBasis | ||
Broader/Parent types | dpv:DataTransferLegalBasis → dpv:LegalBasis | ||
Object of relation | dpv:hasLegalBasis | ||
Definition | An approved certification mechanism pursuant to GDPR Article 42 together with binding and enforceable commitments of the controller or processor in the third country to apply the appropriate safeguards, including as regards individuals` rights | ||
Usage Note | Transfer from EU to a third country. Third country has no Adequacy Decision. Third country has appropriate safeguards. Transfer does not require specific authorisation from a Supervisor Authority. | ||
Source | GDPR Art.46-2f | ||
Date Created | 2020-11-04 | ||
Date Modified | 2021-09-08 | ||
Contributors | Georg P. Krog | ||
See More: | section LEGAL-BASIS-DATA-TRANSFER in EU-GDPR |
Term | A46-3-a | Prefix | eu-gdpr |
---|---|---|---|
Label | Art 46(3-a) contractual clauses | ||
IRI | https://w3id.org/dpv/legal/eu/gdpr#A46-3-a | ||
Type | rdfs:Class, skos:Concept, dpv:LegalBasis | ||
Broader/Parent types | dpv:DataTransferLegalBasis → dpv:LegalBasis | ||
Object of relation | dpv:hasLegalBasis | ||
Definition | Contractual clauses with controller, processor or recipient of the personal data in the third country or the international organisation. | ||
Usage Note | Transfer from EU to a third country. Third country has no Adequacy Decision. Appropriate safeguards exist. Transfer does requires specific authorisation from a Supervisor Authority. | ||
Source | GDPR Art.46-3a | ||
Date Created | 2020-11-04 | ||
Date Modified | 2021-09-08 | ||
Contributors | Georg P. Krog | ||
See More: | section LEGAL-BASIS-DATA-TRANSFER in EU-GDPR |
Term | A46-3-b | Prefix | eu-gdpr |
---|---|---|---|
Label | Art 46(3-b) administrative arrangements | ||
IRI | https://w3id.org/dpv/legal/eu/gdpr#A46-3-b | ||
Type | rdfs:Class, skos:Concept, dpv:LegalBasis | ||
Broader/Parent types | dpv:DataTransferLegalBasis → dpv:LegalBasis | ||
Object of relation | dpv:hasLegalBasis | ||
Definition | Provisions to be inserted into administrative arrangements between public authorities or bodies which include enforceable and effective data subject rights | ||
Usage Note | Transfer from EU to a third country. Third country has no Adequacy Decision. Appropriate safeguards exist. Transfer does requires specific authorisation from a Supervisor Authority. | ||
Source | GDPR Art.46-3b | ||
Date Created | 2020-11-04 | ||
Date Modified | 2021-09-08 | ||
Contributors | Georg P. Krog | ||
See More: | section LEGAL-BASIS-DATA-TRANSFER in EU-GDPR |
Term | A49-1-a | Prefix | eu-gdpr |
---|---|---|---|
Label | Art 49(1-a) explicit consent | ||
IRI | https://w3id.org/dpv/legal/eu/gdpr#A49-1-a | ||
Type | rdfs:Class, skos:Concept, dpv:LegalBasis | ||
Broader/Parent types | eu-gdpr:Consent → dpv:Consent → dpv:LegalBasis | ||
Broader/Parent types | dpv:DataTransferLegalBasis → dpv:LegalBasis | ||
Broader/Parent types | dpv:ExplicitlyExpressedConsent → dpv:ExpressedConsent → dpv:InformedConsent → dpv:Consent → dpv:LegalBasis | ||
Object of relation | dpv:hasLegalBasis | ||
Definition | The data subject has explicitly consented to the proposed transfer, after having been informed of the possible risks of such transfers for the data subject due to the absence of an adequacy decision and appropriate safeguards. | ||
Usage Note | Transfer from EU to a third country. Third country has no Adequacy Decision. Appropriate safeguards do not exist. | ||
Source | GDPR Art.49-1a | ||
Date Created | 2020-11-04 | ||
Date Modified | 2024-12-17 | ||
Contributors | Georg P. Krog | ||
See More: | section LEGAL-BASIS-DATA-TRANSFER in EU-GDPR |
Term | A49-1-b | Prefix | eu-gdpr |
---|---|---|---|
Label | Art 49(1-b) performance of contract | ||
IRI | https://w3id.org/dpv/legal/eu/gdpr#A49-1-b | ||
Type | rdfs:Class, skos:Concept, dpv:LegalBasis | ||
Broader/Parent types | dpv:Contract → dpv:LegalBasis | ||
Broader/Parent types | dpv:DataTransferLegalBasis → dpv:LegalBasis | ||
Object of relation | dpv:hasLegalBasis | ||
Definition | The transfer is necessary for the performance of a contract between the data subject and controller or the implementation of pre-contractual measures taken at the data subject´s request. | ||
Usage Note | Transfer from EU to a third country. Third country has no Adequacy Decision. Appropriate safeguards do not exist. | ||
Source | GDPR Art.49-1b | ||
Date Created | 2020-11-04 | ||
Date Modified | 2021-09-08 | ||
Contributors | Georg P. Krog | ||
See More: | section LEGAL-BASIS-DATA-TRANSFER in EU-GDPR |
Term | A49-1-c | Prefix | eu-gdpr |
---|---|---|---|
Label | Art 49(1-c) conclusion of contract | ||
IRI | https://w3id.org/dpv/legal/eu/gdpr#A49-1-c | ||
Type | rdfs:Class, skos:Concept, dpv:LegalBasis | ||
Broader/Parent types | dpv:Contract → dpv:LegalBasis | ||
Broader/Parent types | dpv:DataTransferLegalBasis → dpv:LegalBasis | ||
Object of relation | dpv:hasLegalBasis | ||
Definition | The transfer is necessary for the conclusion or performance of a contract concluded in the interest of the data subject and controller and another natural or legal person. | ||
Usage Note | Transfer from EU to a third country. Third country has no Adequacy Decision. Appropriate safeguards do not exist. | ||
Source | GDPR Art.49-1c | ||
Date Created | 2020-11-04 | ||
Date Modified | 2021-09-08 | ||
Contributors | Georg P. Krog | ||
See More: | section LEGAL-BASIS-DATA-TRANSFER in EU-GDPR |
Term | A49-1-d | Prefix | eu-gdpr |
---|---|---|---|
Label | Art 49(1-d) public interest | ||
IRI | https://w3id.org/dpv/legal/eu/gdpr#A49-1-d | ||
Type | rdfs:Class, skos:Concept, dpv:LegalBasis | ||
Broader/Parent types | dpv:DataTransferLegalBasis → dpv:LegalBasis | ||
Broader/Parent types | dpv:PublicInterest → dpv:LegalBasis | ||
Object of relation | dpv:hasLegalBasis | ||
Definition | The transfer is necessary for important reasons of public interest. | ||
Usage Note | Transfer from EU to a third country. Third country has no Adequacy Decision. Appropriate safeguards do not exist. | ||
Source | GDPR Art.49-1d | ||
Date Created | 2020-11-04 | ||
Date Modified | 2021-09-08 | ||
Contributors | Georg P. Krog | ||
See More: | section LEGAL-BASIS-DATA-TRANSFER in EU-GDPR |
Term | A49-1-e | Prefix | eu-gdpr |
---|---|---|---|
Label | Art 49(1-e) legal claims | ||
IRI | https://w3id.org/dpv/legal/eu/gdpr#A49-1-e | ||
Type | rdfs:Class, skos:Concept, dpv:LegalBasis | ||
Broader/Parent types | dpv:DataTransferLegalBasis → dpv:LegalBasis | ||
Object of relation | dpv:hasLegalBasis | ||
Definition | The transfer is necessary for the establishment, exercise or defence of legal claims. | ||
Usage Note | Transfer from EU to a third country. Third country has no Adequacy Decision. Appropriate safeguards do not exist. | ||
Source | GDPR Art.49-1e | ||
Date Created | 2020-11-04 | ||
Date Modified | 2021-09-08 | ||
Contributors | Georg P. Krog | ||
See More: | section LEGAL-BASIS-DATA-TRANSFER in EU-GDPR |
Term | A49-1-f | Prefix | eu-gdpr |
---|---|---|---|
Label | Art 49(1-f) protect vital interests | ||
IRI | https://w3id.org/dpv/legal/eu/gdpr#A49-1-f | ||
Type | rdfs:Class, skos:Concept, dpv:LegalBasis | ||
Broader/Parent types | dpv:DataTransferLegalBasis → dpv:LegalBasis | ||
Broader/Parent types | dpv:VitalInterestOfNaturalPerson → dpv:VitalInterest → dpv:LegalBasis | ||
Object of relation | dpv:hasLegalBasis | ||
Definition | The transfer is necessary in order to protect the vital interests of the data subject or of other persons, where the person is physically or legally incapable of giving consent. | ||
Usage Note | Transfer from EU to a third country. Third country has no Adequacy Decision. Appropriate safeguards do not exist. | ||
Source | GDPR Art.49-1f | ||
Date Created | 2020-11-04 | ||
Date Modified | 2021-09-08 | ||
Contributors | Georg P. Krog | ||
See More: | section LEGAL-BASIS-DATA-TRANSFER in EU-GDPR |
Term | A49-1-g | Prefix | eu-gdpr |
---|---|---|---|
Label | Art 49(1-g) public register | ||
IRI | https://w3id.org/dpv/legal/eu/gdpr#A49-1-g | ||
Type | rdfs:Class, skos:Concept, dpv:LegalBasis | ||
Broader/Parent types | dpv:DataTransferLegalBasis → dpv:LegalBasis | ||
Object of relation | dpv:hasLegalBasis | ||
Definition | The transfer is made from a register which according to Union or Member State law is intended to provide information to the public in general or by any person who can demonstrate a legitimate interest, but only to the extent that the conditions laid down by Union or Member State law for consultation are fulfilled in the particular case. | ||
Usage Note | Transfer from EU to a third country. Third country has not Adequacy Decision. Appropriate safeguards do not exist. | ||
Source | GDPR Art.49-1g | ||
Date Created | 2020-11-04 | ||
Date Modified | 2021-09-08 | ||
Contributors | Georg P. Krog | ||
See More: | section LEGAL-BASIS-DATA-TRANSFER in EU-GDPR |
Term | A49-2 | Prefix | eu-gdpr |
---|---|---|---|
Label | Art 49(2) legitimate interests | ||
IRI | https://w3id.org/dpv/legal/eu/gdpr#A49-2 | ||
Type | rdfs:Class, skos:Concept, dpv:LegalBasis | ||
Broader/Parent types | dpv:DataTransferLegalBasis → dpv:LegalBasis | ||
Broader/Parent types | dpv:LegitimateInterest → dpv:LegalBasis | ||
Object of relation | dpv:hasLegalBasis | ||
Definition | The transfer is not repetitive, concerns only a limited number of data subjects, is necessary for the purposes of compelling legitimate interests pursued by controller which are not overridden by the interests or rights and freedoms of the data subject, and controller has assessed all the circumstances surrounding the data transfer and have on the basis of that assessment provided suitable safeguards with regard to the protection of personal data. | ||
Usage Note | Transfer from EU to a third country. Third country has no Adequacy Decision. Appropriate safeguards do not exist and no other options apply. | ||
Source | GDPR Art.49-2 | ||
Date Created | 2020-11-04 | ||
Date Modified | 2021-09-08 | ||
Contributors | Georg P. Krog | ||
See More: | section LEGAL-BASIS-DATA-TRANSFER in EU-GDPR |
Term | A6-1-a | Prefix | eu-gdpr |
---|---|---|---|
Label | Art.6(1-a) consent | ||
IRI | https://w3id.org/dpv/legal/eu/gdpr#A6-1-a | ||
Type | rdfs:Class, skos:Concept, dpv:LegalBasis | ||
Broader/Parent types | eu-gdpr:Consent → dpv:Consent → dpv:LegalBasis | ||
Broader/Parent types | dpv:ExpressedConsent → dpv:InformedConsent → dpv:Consent → dpv:LegalBasis | ||
Object of relation | dpv:hasLegalBasis | ||
Definition | Legal basis based on data subject's given consent to the processing of his or her personal data for one or more specific purposes | ||
Usage Note | Consent can be explicit or non-explicit. To express these specifically, see the explicit and non-explicit variations provided for Art.6-1a. | ||
Source | GDPR Art.6-1a | ||
Date Created | 2022-09-07 | ||
Date Modified | 2024-12-17 | ||
Contributors | Harshvardhan J. Pandit | ||
has right | A13 Right to be Informed , A14 Right to be Informed , A15 Right of Access , A16 Right to Rectification , A17 Right to Erasure , A18 Right to Restrict Processing , A20 Right to Data Portability , A22 Right to object to automated decision making , A7-3 Right to Withdraw Consent , A77 Right to Complaint | ||
See More: | section LEGAL-BASIS in EU-GDPR , section LEGAL-BASIS-RIGHTS-MAPPING in EU-GDPR |
Term | A6-1-a-explicit-consent | Prefix | eu-gdpr |
---|---|---|---|
Label | Art 6(1-a) explicit consent | ||
IRI | https://w3id.org/dpv/legal/eu/gdpr#A6-1-a-explicit-consent | ||
Type | rdfs:Class, skos:Concept, dpv:LegalBasis | ||
Broader/Parent types | eu-gdpr:A6-1-a → dpv:ExpressedConsent → dpv:InformedConsent → dpv:Consent → dpv:LegalBasis | ||
Broader/Parent types | eu-gdpr:A6-1-a → eu-gdpr:Consent → dpv:Consent → dpv:LegalBasis | ||
Broader/Parent types | dpv:ExplicitlyExpressedConsent → dpv:ExpressedConsent → dpv:InformedConsent → dpv:Consent → dpv:LegalBasis | ||
Object of relation | dpv:hasLegalBasis | ||
Definition | Legal basis based on data subject's given explicit consent to the processing of his or her personal data for one or more specific purposes | ||
Usage Note | Valid consent in this case would have requirements for being 'explicit' in addition to requirements defined by A4-11. This is also mentioned in the Article 29 Working Party document "Guidelines on Consent under Regulation 2016/679 (wp259rev.01)" | ||
Source | GDPR Art.6-1a | ||
Date Created | 2022-06-22 | ||
Date Modified | 2024-12-17 | ||
Contributors | Bud Bruegger, Eva Schlehahn, Harshvardhan J. Pandit, Rigo Wenning | ||
has right | A13 Right to be Informed , A14 Right to be Informed , A15 Right of Access , A16 Right to Rectification , A17 Right to Erasure , A18 Right to Restrict Processing , A20 Right to Data Portability , A22 Right to object to automated decision making , A7-3 Right to Withdraw Consent , A77 Right to Complaint | ||
See More: | section LEGAL-BASIS in EU-GDPR , section LEGAL-BASIS-RIGHTS-MAPPING in EU-GDPR |
Term | A6-1-a-non-explicit-consent | Prefix | eu-gdpr |
---|---|---|---|
Label | Art.6(1-a) regular consent | ||
IRI | https://w3id.org/dpv/legal/eu/gdpr#A6-1-a-non-explicit-consent | ||
Type | rdfs:Class, skos:Concept, dpv:LegalBasis | ||
Broader/Parent types | eu-gdpr:A6-1-a → dpv:ExpressedConsent → dpv:InformedConsent → dpv:Consent → dpv:LegalBasis | ||
Broader/Parent types | eu-gdpr:A6-1-a → eu-gdpr:Consent → dpv:Consent → dpv:LegalBasis | ||
Object of relation | dpv:hasLegalBasis | ||
Definition | Legal basis based on data subject's given non-explicit express consent to the processing of his or her personal data for one or more specific purposes | ||
Usage Note | Definition of consent: A data subject's unambiguous/clear affirmative action that signifies an agreement to process their personal data (Rigo Wenning) . What is referred to as 'non-explicit consent' here is also termed as 'regular' consent in the Article 29 Working Party document "Guidelines on Consent under Regulation 2016/679 (wp259rev.01)". This is the legal basis that requires consent but not at the level of being 'explicit'. | ||
Source | GDPR Art.6-1a | ||
Date Created | 2019-04-10 | ||
Date Modified | 2024-12-17 | ||
Contributors | Bud Bruegger, Eva Schlehahn, Harshvardhan J. Pandit, Rigo Wenning | ||
has right | A13 Right to be Informed , A14 Right to be Informed , A15 Right of Access , A16 Right to Rectification , A17 Right to Erasure , A18 Right to Restrict Processing , A20 Right to Data Portability , A22 Right to object to automated decision making , A7-3 Right to Withdraw Consent , A77 Right to Complaint | ||
See More: | section LEGAL-BASIS in EU-GDPR , section LEGAL-BASIS-RIGHTS-MAPPING in EU-GDPR |
Term | A6-1-b | Prefix | eu-gdpr |
---|---|---|---|
Label | Art 6(1-b) contract | ||
IRI | https://w3id.org/dpv/legal/eu/gdpr#A6-1-b | ||
Type | rdfs:Class, skos:Concept, dpv:LegalBasis | ||
Broader/Parent types | dpv:Contract → dpv:LegalBasis | ||
Object of relation | dpv:hasLegalBasis | ||
Definition | Legal basis based on performance of a contract to which the data subject is party or in order to take steps at the request of the data subject prior to entering into a contract | ||
Source | GDPR Art.6-1b | ||
Date Created | 2019-04-05 | ||
Date Modified | 2022-11-24 | ||
Contributors | Bud Bruegger, Eva Schlehahn, Harshvardhan J. Pandit | ||
has right | A13 Right to be Informed , A14 Right to be Informed , A15 Right of Access , A16 Right to Rectification , A17 Right to Erasure , A18 Right to Restrict Processing , A20 Right to Data Portability , A22 Right to object to automated decision making , A77 Right to Complaint | ||
See More: | section LEGAL-BASIS in EU-GDPR , section LEGAL-BASIS-RIGHTS-MAPPING in EU-GDPR |
Term | A6-1-b-contract-performance | Prefix | eu-gdpr |
---|---|---|---|
Label | Art 6(1-b) contract performance | ||
IRI | https://w3id.org/dpv/legal/eu/gdpr#A6-1-b-contract-performance | ||
Type | rdfs:Class, skos:Concept, dpv:LegalBasis | ||
Broader/Parent types | eu-gdpr:A6-1-b → dpv:Contract → dpv:LegalBasis | ||
Broader/Parent types | dpv:ContractPerformance → dpv:Contract → dpv:LegalBasis | ||
Object of relation | dpv:hasLegalBasis | ||
Definition | Legal basis based on performance of a contract to which the data subject is party | ||
Source | GDPR Art.6-1b | ||
Date Created | 2022-11-24 | ||
Date Modified | 2022-11-24 | ||
Contributors | Georg P. Krog | ||
has right | A13 Right to be Informed , A14 Right to be Informed , A15 Right of Access , A16 Right to Rectification , A17 Right to Erasure , A18 Right to Restrict Processing , A20 Right to Data Portability , A22 Right to object to automated decision making , A77 Right to Complaint | ||
See More: | section LEGAL-BASIS in EU-GDPR , section LEGAL-BASIS-RIGHTS-MAPPING in EU-GDPR |
Term | A6-1-b-enter-into-contract | Prefix | eu-gdpr |
---|---|---|---|
Label | Art 6(1-b) enter into contract | ||
IRI | https://w3id.org/dpv/legal/eu/gdpr#A6-1-b-enter-into-contract | ||
Type | rdfs:Class, skos:Concept, dpv:LegalBasis | ||
Broader/Parent types | eu-gdpr:A6-1-b → dpv:Contract → dpv:LegalBasis | ||
Broader/Parent types | dpv:EnterIntoContract → dpv:Contract → dpv:LegalBasis | ||
Object of relation | dpv:hasLegalBasis | ||
Definition | Legal basis based on taking steps at the request of the data subject prior to entering into a contract | ||
Source | GDPR Art.6-1b | ||
Date Created | 2022-11-24 | ||
Date Modified | 2022-11-24 | ||
Contributors | Georg P. Krog | ||
has right | A13 Right to be Informed , A14 Right to be Informed , A15 Right of Access , A16 Right to Rectification , A17 Right to Erasure , A18 Right to Restrict Processing , A20 Right to Data Portability , A22 Right to object to automated decision making , A77 Right to Complaint | ||
See More: | section LEGAL-BASIS in EU-GDPR , section LEGAL-BASIS-RIGHTS-MAPPING in EU-GDPR |
Term | A6-1-c | Prefix | eu-gdpr |
---|---|---|---|
Label | Art 6(1-c) legal obligation | ||
IRI | https://w3id.org/dpv/legal/eu/gdpr#A6-1-c | ||
Type | rdfs:Class, skos:Concept, dpv:LegalBasis | ||
Broader/Parent types | dpv:LegalObligation → dpv:LegalBasis | ||
Object of relation | dpv:hasLegalBasis | ||
Definition | Legal basis based on compliance with a legal obligation to which the controller is subject | ||
Source | GDPR Art.6-1c | ||
Date Created | 2019-04-05 | ||
Date Modified | 2022-11-24 | ||
Contributors | Bud Bruegger, Eva Schlehahn, Harshvardhan J. Pandit | ||
has right | A13 Right to be Informed , A15 Right of Access , A16 Right to Rectification , A18 Right to Restrict Processing , A77 Right to Complaint | ||
See More: | section LEGAL-BASIS in EU-GDPR , section LEGAL-BASIS-RIGHTS-MAPPING in EU-GDPR |
Term | A6-1-d | Prefix | eu-gdpr |
---|---|---|---|
Label | Art 6(1-d) protect vital interests | ||
IRI | https://w3id.org/dpv/legal/eu/gdpr#A6-1-d | ||
Type | rdfs:Class, skos:Concept, dpv:LegalBasis | ||
Broader/Parent types | dpv:VitalInterest → dpv:LegalBasis | ||
Object of relation | dpv:hasLegalBasis | ||
Definition | Legal basis based on protecting the vital interests of the data subject or of another natural person | ||
Source | GDPR Art.6-1d | ||
Date Created | 2019-04-05 | ||
Date Modified | 2022-11-24 | ||
Contributors | Bud Bruegger, Eva Schlehahn, Harshvardhan J. Pandit | ||
has right | A13 Right to be Informed , A14 Right to be Informed , A15 Right of Access , A16 Right to Rectification , A17 Right to Erasure , A18 Right to Restrict Processing , A22 Right to object to automated decision making , A77 Right to Complaint | ||
See More: | section LEGAL-BASIS in EU-GDPR , section LEGAL-BASIS-RIGHTS-MAPPING in EU-GDPR |
Term | A6-1-d-data-subject | Prefix | eu-gdpr |
---|---|---|---|
Label | Art 6(1-d) protect vital interests of data subject | ||
IRI | https://w3id.org/dpv/legal/eu/gdpr#A6-1-d-data-subject | ||
Type | rdfs:Class, skos:Concept, dpv:LegalBasis | ||
Broader/Parent types | eu-gdpr:A6-1-d → dpv:VitalInterest → dpv:LegalBasis | ||
Broader/Parent types | dpv:VitalInterestOfDataSubject → dpv:VitalInterestOfNaturalPerson → dpv:VitalInterest → dpv:LegalBasis | ||
Object of relation | dpv:hasLegalBasis | ||
Definition | Legal basis based on protecting the vital interests of the data subject | ||
Source | GDPR Art.6-1d | ||
Date Created | 2022-11-24 | ||
Date Modified | 2022-11-24 | ||
Contributors | Georg P. Krog | ||
has right | A13 Right to be Informed , A14 Right to be Informed , A15 Right of Access , A16 Right to Rectification , A17 Right to Erasure , A18 Right to Restrict Processing , A22 Right to object to automated decision making , A77 Right to Complaint | ||
See More: | section LEGAL-BASIS in EU-GDPR , section LEGAL-BASIS-RIGHTS-MAPPING in EU-GDPR |
Term | A6-1-d-natural-person | Prefix | eu-gdpr |
---|---|---|---|
Label | Art 6(1-d) protect vital interests of natural person | ||
IRI | https://w3id.org/dpv/legal/eu/gdpr#A6-1-d-natural-person | ||
Type | rdfs:Class, skos:Concept, dpv:LegalBasis | ||
Broader/Parent types | eu-gdpr:A6-1-d → dpv:VitalInterest → dpv:LegalBasis | ||
Broader/Parent types | dpv:VitalInterestOfNaturalPerson → dpv:VitalInterest → dpv:LegalBasis | ||
Object of relation | dpv:hasLegalBasis | ||
Definition | Legal basis based on protecting the vital interests of another natural person that is not the data subject | ||
Source | GDPR Art.6-1d | ||
Date Created | 2022-11-24 | ||
Date Modified | 2024-02-15 | ||
Contributors | Georg P. Krog | ||
has right | A13 Right to be Informed , A14 Right to be Informed , A15 Right of Access , A16 Right to Rectification , A17 Right to Erasure , A18 Right to Restrict Processing , A22 Right to object to automated decision making , A77 Right to Complaint | ||
See More: | section LEGAL-BASIS in EU-GDPR , section LEGAL-BASIS-RIGHTS-MAPPING in EU-GDPR |
Term | A6-1-e | Prefix | eu-gdpr |
---|---|---|---|
Label | Art 6(1-e) public interest or official authority | ||
IRI | https://w3id.org/dpv/legal/eu/gdpr#A6-1-e | ||
Type | rdfs:Class, skos:Concept, dpv:LegalBasis | ||
Broader/Parent types | dpv:OfficialAuthorityOfController → dpv:LegalBasis | ||
Broader/Parent types | dpv:PublicInterest → dpv:LegalBasis | ||
Object of relation | dpv:hasLegalBasis | ||
Definition | Legal basis based on performance of a task carried out in the public interest or in the exercise of official authority vested in the controller | ||
Source | GDPR Art.6-1e | ||
Date Created | 2019-04-05 | ||
Date Modified | 2022-11-24 | ||
Contributors | Bud Bruegger, Eva Schlehahn, Harshvardhan J. Pandit | ||
has right | A13 Right to be Informed , A14 Right to be Informed , A15 Right of Access , A16 Right to Rectification , A18 Right to Restrict Processing , A21 Right to object , A22 Right to object to automated decision making , A77 Right to Complaint | ||
See More: | section LEGAL-BASIS in EU-GDPR , section LEGAL-BASIS-RIGHTS-MAPPING in EU-GDPR |
Term | A6-1-e-official-authority | Prefix | eu-gdpr |
---|---|---|---|
Label | Art 6(1-e) official authority | ||
IRI | https://w3id.org/dpv/legal/eu/gdpr#A6-1-e-official-authority | ||
Type | rdfs:Class, skos:Concept, dpv:LegalBasis | ||
Broader/Parent types | eu-gdpr:A6-1-e → dpv:OfficialAuthorityOfController → dpv:LegalBasis | ||
Broader/Parent types | eu-gdpr:A6-1-e → dpv:PublicInterest → dpv:LegalBasis | ||
Object of relation | dpv:hasLegalBasis | ||
Definition | Legal basis based on the exercise of official authority vested in the controller | ||
Source | GDPR Art.6-1e | ||
Date Created | 2022-08-24 | ||
Date Modified | 2022-11-24 | ||
Contributors | Harshvardhan J. Pandit | ||
has right | A13 Right to be Informed , A14 Right to be Informed , A15 Right of Access , A16 Right to Rectification , A18 Right to Restrict Processing , A21 Right to object , A22 Right to object to automated decision making , A77 Right to Complaint | ||
See More: | section LEGAL-BASIS in EU-GDPR , section LEGAL-BASIS-RIGHTS-MAPPING in EU-GDPR |
Term | A6-1-e-public-interest | Prefix | eu-gdpr |
---|---|---|---|
Label | Art 6(1-e) public interest | ||
IRI | https://w3id.org/dpv/legal/eu/gdpr#A6-1-e-public-interest | ||
Type | rdfs:Class, skos:Concept, dpv:LegalBasis | ||
Broader/Parent types | eu-gdpr:A6-1-e → dpv:OfficialAuthorityOfController → dpv:LegalBasis | ||
Broader/Parent types | eu-gdpr:A6-1-e → dpv:PublicInterest → dpv:LegalBasis | ||
Object of relation | dpv:hasLegalBasis | ||
Definition | Legal basis based on performance of a task carried out in the public interest | ||
Source | GDPR Art.6-1e | ||
Date Created | 2022-08-24 | ||
Date Modified | 2022-11-24 | ||
Contributors | Harshvardhan J. Pandit | ||
has right | A13 Right to be Informed , A14 Right to be Informed , A15 Right of Access , A16 Right to Rectification , A18 Right to Restrict Processing , A21 Right to object , A22 Right to object to automated decision making , A77 Right to Complaint | ||
See More: | section LEGAL-BASIS in EU-GDPR , section LEGAL-BASIS-RIGHTS-MAPPING in EU-GDPR |
Term | A6-1-f | Prefix | eu-gdpr |
---|---|---|---|
Label | Art 6(1-f) legitimate interest | ||
IRI | https://w3id.org/dpv/legal/eu/gdpr#A6-1-f | ||
Type | rdfs:Class, skos:Concept, dpv:LegalBasis | ||
Broader/Parent types | dpv:LegitimateInterest → dpv:LegalBasis | ||
Object of relation | dpv:hasLegalBasis | ||
Definition | Legal basis based on the purposes of the legitimate interests pursued by the controller or by a third party, except where such interests are overridden by the interests or fundamental rights and freedoms of the data subject which require protection of personal data, in particular where the data subject is a child | ||
Source | GDPR Art.6-1f | ||
Date Created | 2019-04-05 | ||
Date Modified | 2022-11-24 | ||
Contributors | Bud Bruegger, Eva Schlehahn, Harshvardhan J. Pandit | ||
has right | A13 Right to be Informed , A14 Right to be Informed , A15 Right of Access , A16 Right to Rectification , A17 Right to Erasure , A18 Right to Restrict Processing , A21 Right to object , A22 Right to object to automated decision making , A77 Right to Complaint | ||
See More: | section LEGAL-BASIS in EU-GDPR , section LEGAL-BASIS-RIGHTS-MAPPING in EU-GDPR |
Term | A6-1-f-controller | Prefix | eu-gdpr |
---|---|---|---|
Label | Art 6(1-f) legitimate interest of controller | ||
IRI | https://w3id.org/dpv/legal/eu/gdpr#A6-1-f-controller | ||
Type | rdfs:Class, skos:Concept, dpv:LegalBasis | ||
Broader/Parent types | eu-gdpr:A6-1-f → dpv:LegitimateInterest → dpv:LegalBasis | ||
Broader/Parent types | dpv:LegitimateInterestOfController → dpv:LegitimateInterest → dpv:LegalBasis | ||
Object of relation | dpv:hasLegalBasis | ||
Definition | Legal basis based on the purposes of the legitimate interests pursued by the controller, except where such interests are overridden by the interests or fundamental rights and freedoms of the data subject which require protection of personal data, in particular where the data subject is a child | ||
Source | GDPR Art.6-1f | ||
Date Created | 2022-11-24 | ||
Date Modified | 2022-11-24 | ||
Contributors | Georg P. Krog | ||
has right | A13 Right to be Informed , A14 Right to be Informed , A15 Right of Access , A16 Right to Rectification , A17 Right to Erasure , A18 Right to Restrict Processing , A21 Right to object , A22 Right to object to automated decision making , A77 Right to Complaint | ||
See More: | section LEGAL-BASIS in EU-GDPR , section LEGAL-BASIS-RIGHTS-MAPPING in EU-GDPR |
Term | A6-1-f-third-party | Prefix | eu-gdpr |
---|---|---|---|
Label | Art 6(1-f) legitimate interest of third party | ||
IRI | https://w3id.org/dpv/legal/eu/gdpr#A6-1-f-third-party | ||
Type | rdfs:Class, skos:Concept, dpv:LegalBasis | ||
Broader/Parent types | eu-gdpr:A6-1-f → dpv:LegitimateInterest → dpv:LegalBasis | ||
Broader/Parent types | dpv:LegitimateInterestOfThirdParty → dpv:LegitimateInterest → dpv:LegalBasis | ||
Object of relation | dpv:hasLegalBasis | ||
Definition | Legal basis based on the purposes of the legitimate interests pursued by a third party, except where such interests are overridden by the interests or fundamental rights and freedoms of the data subject which require protection of personal data, in particular where the data subject is a child | ||
Source | GDPR Art.6-1f | ||
Date Created | 2022-11-24 | ||
Date Modified | 2022-11-24 | ||
Contributors | Georg P. Krog | ||
has right | A13 Right to be Informed , A14 Right to be Informed , A15 Right of Access , A16 Right to Rectification , A17 Right to Erasure , A18 Right to Restrict Processing , A21 Right to object , A22 Right to object to automated decision making , A77 Right to Complaint | ||
See More: | section LEGAL-BASIS in EU-GDPR , section LEGAL-BASIS-RIGHTS-MAPPING in EU-GDPR |
Term | A7-3 | Prefix | eu-gdpr |
---|---|---|---|
Label | A7-3 Right to Withdraw Consent | ||
IRI | https://w3id.org/dpv/legal/eu/gdpr#A7-3 | ||
Type | rdfs:Class, skos:Concept, dpv:Right | ||
Broader/Parent types | dpv:DataSubjectRight → dpv:Right | ||
Object of relation | dpv:hasRight | ||
Definition | Right to withdraw consent at any time | ||
Source | GDPR Art.7-3 | ||
Date Created | 2020-11-04 | ||
Contributors | Beatriz Esteves, Georg P. Krog, Harshvardhan J. Pandit | ||
See More: | section RIGHTS in EU-GDPR |
Term | A7-3-Impact | Prefix | eu-gdpr |
---|---|---|---|
Label | Impact on A7-3 Right to Withdraw Consent | ||
IRI | https://w3id.org/dpv/legal/eu/gdpr#A7-3-Impact | ||
Type | rdfs:Class, skos:Concept, dpv:RiskConcept, risk:PotentialConsequence, risk:PotentialImpact, risk:PotentialRisk | ||
Broader/Parent types | eu-gdpr:GDPRRightsImpact → risk:RightsImpact → risk:SocietalRiskConcept → dpv:RiskConcept | ||
Object of relation | risk:avoids, risk:contains, risk:controls, risk:detects, risk:eliminates, risk:identifies, risk:interrupts, risk:intervenes, risk:investigates, risk:logs, risk:mitigates, risk:modifies, risk:monitors, risk:overrides, risk:recovers, risk:reduces, risk:remedies, risk:resolves, risk:reverses, risk:shares, risk:substitutes, risk:transfers | ||
Definition | Something that acts as or is considered as an impact on A7-3 Right to Withdraw Consent | ||
Source | GDPR Art.7-3 | ||
Date Created | 2024-10-21 | ||
Date Modified | 2025-08-17 | ||
See More: | section RIGHTS-IMPACTS in EU-GDPR |
Term | A77 | Prefix | eu-gdpr |
---|---|---|---|
Label | A77 Right to Complaint | ||
IRI | https://w3id.org/dpv/legal/eu/gdpr#A77 | ||
Type | rdfs:Class, skos:Concept, dpv:Right | ||
Broader/Parent types | dpv:DataSubjectRight → dpv:Right | ||
Object of relation | dpv:hasRight | ||
Definition | Right to lodge a complaint with a supervisory authority | ||
Source | GDPR Art.77 | ||
Date Created | 2020-11-04 | ||
Contributors | Beatriz Esteves, Georg P. Krog, Harshvardhan J. Pandit | ||
See More: | section RIGHTS in EU-GDPR |
Term | A77-Impact | Prefix | eu-gdpr |
---|---|---|---|
Label | Impact on A77 Right to Complaint | ||
IRI | https://w3id.org/dpv/legal/eu/gdpr#A77-Impact | ||
Type | rdfs:Class, skos:Concept, dpv:RiskConcept, risk:PotentialConsequence, risk:PotentialImpact, risk:PotentialRisk | ||
Broader/Parent types | eu-gdpr:GDPRRightsImpact → risk:RightsImpact → risk:SocietalRiskConcept → dpv:RiskConcept | ||
Object of relation | risk:avoids, risk:contains, risk:controls, risk:detects, risk:eliminates, risk:identifies, risk:interrupts, risk:intervenes, risk:investigates, risk:logs, risk:mitigates, risk:modifies, risk:monitors, risk:overrides, risk:recovers, risk:reduces, risk:remedies, risk:resolves, risk:reverses, risk:shares, risk:substitutes, risk:transfers | ||
Definition | Something that acts as or is considered as an impact on A77 Right to Complaint | ||
Source | GDPR Art.77 | ||
Date Created | 2024-10-21 | ||
Date Modified | 2025-08-17 | ||
See More: | section RIGHTS-IMPACTS in EU-GDPR |
Term | A78 | Prefix | eu-gdpr |
---|---|---|---|
Label | A78 Right to an effective judicial remedy against a supervisory authority | ||
IRI | https://w3id.org/dpv/legal/eu/gdpr#A78 | ||
Type | rdfs:Class, skos:Concept, dpv:Right | ||
Broader/Parent types | dpv:Right | ||
Object of relation | dpv:hasRight | ||
Definition | Right to an effective judicial remedy against a legally binding decision of a supervisory authority concerning natural or legal person | ||
Source | GDPR Art.78 | ||
Date Created | 2024-12-17 | ||
Contributors | Beatriz Esteves, Georg P. Krog, Harshvardhan J. Pandit | ||
See More: | section RIGHTS in EU-GDPR |
Term | A79 | Prefix | eu-gdpr |
---|---|---|---|
Label | A79 Right to an effective judicial remedy against a controller or processor | ||
IRI | https://w3id.org/dpv/legal/eu/gdpr#A79 | ||
Type | rdfs:Class, skos:Concept, dpv:Right | ||
Broader/Parent types | dpv:DataSubjectRight → dpv:Right | ||
Object of relation | dpv:hasRight | ||
Definition | Right to an effective judicial remedy where the data subject considers that his or her rights have been infringed as a result of the processing of his or her personal data | ||
Source | GDPR Art.79 | ||
Date Created | 2024-12-17 | ||
Contributors | Beatriz Esteves, Georg P. Krog, Harshvardhan J. Pandit | ||
See More: | section RIGHTS in EU-GDPR |
Term | A9-2-a | Prefix | eu-gdpr |
---|---|---|---|
Label | Art 9(2-a) explicit consent | ||
IRI | https://w3id.org/dpv/legal/eu/gdpr#A9-2-a | ||
Type | rdfs:Class, skos:Concept, dpv:LegalBasis | ||
Broader/Parent types | eu-gdpr:Consent → dpv:Consent → dpv:LegalBasis | ||
Broader/Parent types | dpv:ExplicitlyExpressedConsent → dpv:ExpressedConsent → dpv:InformedConsent → dpv:Consent → dpv:LegalBasis | ||
Object of relation | dpv:hasLegalBasis | ||
Definition | explicit consent with special categories of data | ||
Source | GDPR Art.9-2a | ||
Date Created | 2019-04-05 | ||
Date Modified | 2024-12-17 | ||
Contributors | Bud Bruegger, Eva Schlehahn | ||
See More: | section LEGAL-BASIS-SPECIAL in EU-GDPR |
Term | A9-2-b | Prefix | eu-gdpr |
---|---|---|---|
Label | Art 9(2-b) employment, social security, social protection law | ||
IRI | https://w3id.org/dpv/legal/eu/gdpr#A9-2-b | ||
Type | rdfs:Class, skos:Concept, dpv:LegalBasis | ||
Broader/Parent types | dpv:LegalBasis | ||
Object of relation | dpv:hasLegalBasis | ||
Definition | employment and social security and social protection law | ||
Source | GDPR Art.9-2b | ||
Date Created | 2019-04-05 | ||
Contributors | Bud Bruegger, Eva Schlehahn | ||
See More: | section LEGAL-BASIS-SPECIAL in EU-GDPR |
Term | A9-2-c | Prefix | eu-gdpr |
---|---|---|---|
Label | Art 9(2-c) protect vital interest | ||
IRI | https://w3id.org/dpv/legal/eu/gdpr#A9-2-c | ||
Type | rdfs:Class, skos:Concept, dpv:LegalBasis | ||
Broader/Parent types | dpv:VitalInterest → dpv:LegalBasis | ||
Object of relation | dpv:hasLegalBasis | ||
Definition | protection of the vital interests | ||
Source | GDPR Art.9-2c | ||
Date Created | 2019-04-05 | ||
Date Modified | 2021-09-08 | ||
Contributors | Bud Bruegger, Eva Schlehahn | ||
See More: | section LEGAL-BASIS-SPECIAL in EU-GDPR |
Term | A9-2-d | Prefix | eu-gdpr |
---|---|---|---|
Label | Art 9(2-d) legitimate activities | ||
IRI | https://w3id.org/dpv/legal/eu/gdpr#A9-2-d | ||
Type | rdfs:Class, skos:Concept, dpv:LegalBasis | ||
Broader/Parent types | dpv:LegitimateInterest → dpv:LegalBasis | ||
Object of relation | dpv:hasLegalBasis | ||
Definition | legitimate activities with appropriate safeguards by a foundation, association or any other not-for-profit body with a political, philosophical, religious or trade union aim and on condition that the processing relates solely to the members or to former members of the body or to persons who have regular contact with it in connection with its purposes and that the personal data are not disclosed outside that body without the consent of the data subjects; | ||
Source | GDPR Art.9-2d | ||
Date Created | 2019-04-05 | ||
Date Modified | 2021-09-08 | ||
Contributors | Bud Bruegger, Eva Schlehahn | ||
See More: | section LEGAL-BASIS-SPECIAL in EU-GDPR |
Term | A9-2-e | Prefix | eu-gdpr |
---|---|---|---|
Label | Art 9(2-e) data made public | ||
IRI | https://w3id.org/dpv/legal/eu/gdpr#A9-2-e | ||
Type | rdfs:Class, skos:Concept, dpv:LegalBasis | ||
Broader/Parent types | dpv:LegalBasis | ||
Object of relation | dpv:hasLegalBasis | ||
Definition | data manifestly made public by the data subject | ||
Source | GDPR Art.9-2e | ||
Date Created | 2019-04-05 | ||
Contributors | Bud Bruegger, Eva Schlehahn | ||
See More: | section LEGAL-BASIS-SPECIAL in EU-GDPR |
Term | A9-2-f | Prefix | eu-gdpr |
---|---|---|---|
Label | Art 9(2-f) judicial process | ||
IRI | https://w3id.org/dpv/legal/eu/gdpr#A9-2-f | ||
Type | rdfs:Class, skos:Concept, dpv:LegalBasis | ||
Broader/Parent types | dpv:LegalBasis | ||
Object of relation | dpv:hasLegalBasis | ||
Definition | establishment, exercise or defence of legal claims / courts acting in their judicial capacity | ||
Source | GDPR Art.9-2f | ||
Date Created | 2019-04-05 | ||
Contributors | Bud Bruegger, Eva Schlehahn | ||
See More: | section LEGAL-BASIS-SPECIAL in EU-GDPR |
Term | A9-2-g | Prefix | eu-gdpr |
---|---|---|---|
Label | Art 9(2-g) public interest | ||
IRI | https://w3id.org/dpv/legal/eu/gdpr#A9-2-g | ||
Type | rdfs:Class, skos:Concept, dpv:LegalBasis | ||
Broader/Parent types | dpv:PublicInterest → dpv:LegalBasis | ||
Object of relation | dpv:hasLegalBasis | ||
Definition | substantial public interest, on the basis of Union or Member State law | ||
Source | GDPR Art.9-2g | ||
Date Created | 2019-04-05 | ||
Date Modified | 2021-09-08 | ||
Contributors | Bud Bruegger, Eva Schlehahn | ||
See More: | section LEGAL-BASIS-SPECIAL in EU-GDPR |
Term | A9-2-h | Prefix | eu-gdpr |
---|---|---|---|
Label | Art 9(2-h) health & medicine | ||
IRI | https://w3id.org/dpv/legal/eu/gdpr#A9-2-h | ||
Type | rdfs:Class, skos:Concept, dpv:LegalBasis | ||
Broader/Parent types | dpv:LegalBasis | ||
Object of relation | dpv:hasLegalBasis | ||
Definition | preventive or occupational medicine, for the assessment of the working capacity of the employee, medical diagnosis, the provision of health or social care or treatment or the management of health or social care systems and services on the basis of Union or Member State law or pursuant to contract with a health professional and subject to the conditions and safeguards referred to in paragraph 3 | ||
Source | GDPR Art.9-2h | ||
Date Created | 2019-04-05 | ||
Contributors | Bud Bruegger, Eva Schlehahn | ||
See More: | section LEGAL-BASIS-SPECIAL in EU-GDPR |
Term | A9-2-i | Prefix | eu-gdpr |
---|---|---|---|
Label | Art 9(2-i) public interest in public health | ||
IRI | https://w3id.org/dpv/legal/eu/gdpr#A9-2-i | ||
Type | rdfs:Class, skos:Concept, dpv:LegalBasis | ||
Broader/Parent types | dpv:PublicInterest → dpv:LegalBasis | ||
Object of relation | dpv:hasLegalBasis | ||
Definition | public interest in public health | ||
Source | GDPR Art.9-2i | ||
Date Created | 2019-04-05 | ||
Date Modified | 2021-09-08 | ||
Contributors | Bud Bruegger, Eva Schlehahn | ||
See More: | section LEGAL-BASIS-SPECIAL in EU-GDPR |
Term | A9-2-j | Prefix | eu-gdpr |
---|---|---|---|
Label | Art 9(2-j) public interest, scientific research, statistical purpose | ||
IRI | https://w3id.org/dpv/legal/eu/gdpr#A9-2-j | ||
Type | rdfs:Class, skos:Concept, dpv:LegalBasis | ||
Broader/Parent types | dpv:PublicInterest → dpv:LegalBasis | ||
Object of relation | dpv:hasLegalBasis | ||
Definition | public interest, scientific or historical research purposes or statistical purposes based on Union or Member State law | ||
Source | GDPR Art.9-2j | ||
Date Created | 2019-04-05 | ||
Date Modified | 2021-09-08 | ||
Contributors | Bud Bruegger, Eva Schlehahn | ||
See More: | section LEGAL-BASIS-SPECIAL in EU-GDPR |
Term | AccountabilityPrinciple | Prefix | eu-gdpr |
---|---|---|---|
Label | Accountability Principle | ||
IRI | https://w3id.org/dpv/legal/eu/gdpr#AccountabilityPrinciple | ||
Type | rdfs:Class, skos:Concept, dpv:OrganisationalMeasure | ||
Broader/Parent types | dpv:Principle → dpv:GuidelinesPrinciple → dpv:OrganisationalMeasure → dpv:TechnicalOrganisationalMeasure | ||
Object of relation | dpv:hasOrganisationalMeasure, dpv:hasTechnicalOrganisationalMeasure | ||
Definition | Principle stating the controller shall be responsible for, and be able to demonstrate compliance with the other principles (from Art.5-1) | ||
Source | GDPR Art.5-2 | ||
Date Created | 2024-05-12 | ||
Contributors | Georg P. Krog | ||
See More: | section PRINCIPLES in EU-GDPR |
Term | AccuracyPrinciple | Prefix | eu-gdpr |
---|---|---|---|
Label | Accuracy Principle | ||
IRI | https://w3id.org/dpv/legal/eu/gdpr#AccuracyPrinciple | ||
Type | rdfs:Class, skos:Concept, dpv:OrganisationalMeasure | ||
Broader/Parent types | dpv:Principle → dpv:GuidelinesPrinciple → dpv:OrganisationalMeasure → dpv:TechnicalOrganisationalMeasure | ||
Object of relation | dpv:hasOrganisationalMeasure, dpv:hasTechnicalOrganisationalMeasure | ||
Definition | Principle stating personal data must be accurate and, where necessary, kept up to date; every reasonable step must be taken to ensure that personal data that are inaccurate, having regard to the purposes for which they are processed, are erased or rectified without delay used for | ||
Source | GDPR Art.5-1d | ||
Date Created | 2024-05-12 | ||
Contributors | Georg P. Krog | ||
See More: | section PRINCIPLES in EU-GDPR |
Term | AdequacyDecision | Prefix | eu-gdpr |
---|---|---|---|
Label | Adequacy Decision | ||
IRI | https://w3id.org/dpv/legal/eu/gdpr#AdequacyDecision | ||
Type | rdfs:Class, skos:Concept, dpv:LegalBasis | ||
Broader/Parent types | eu-gdpr:A45-3 → dpv:DataTransferLegalBasis → dpv:LegalBasis | ||
Object of relation | dpv:hasLegalBasis | ||
Definition | An adequacy decision as per GDPR Art.45(3) for the transfer of data to a third country or an international organisation | ||
Source | GDPR Art.45-3 | ||
Date Created | 2024-06-22 | ||
Contributors | Harshvardhan J. Pandit | ||
See More: | section LEGAL-BASIS-DATA-TRANSFER in LEGAL-EU |
Term | AdHocContractualClauses | Prefix | eu-gdpr |
---|---|---|---|
Label | AdHoc Contractual Clauses | ||
IRI | https://w3id.org/dpv/legal/eu/gdpr#AdHocContractualClauses | ||
Type | rdfs:Class, skos:Concept, dpv:OrganisationalMeasure | ||
Broader/Parent types | dpv:Contract → dpv:LegalBasis | ||
Broader/Parent types | eu-gdpr:DataTransferTool → dpv:OrganisationalMeasure → dpv:TechnicalOrganisationalMeasure | ||
Object of relation | dpv:hasLegalBasis, dpv:hasOrganisationalMeasure, dpv:hasTechnicalOrganisationalMeasure | ||
Definition | Contractual Clauses not drafted by the EU Commission, e.g. by the Controller | ||
Source | EDPB Recommendations 01/2020 on Supplementary Measures and Transfer Tools | ||
Date Created | 2021-09-22 | ||
Contributors | Harshvardhan J. Pandit | ||
See More: | section DATA-TRANSFERS in EU-GDPR |
Term | AvailabilityBreach | Prefix | eu-gdpr |
---|---|---|---|
Label | Availability Breach | ||
IRI | https://w3id.org/dpv/legal/eu/gdpr#AvailabilityBreach | ||
Type | rdfs:Class, skos:Concept | ||
Broader/Parent types | eu-gdpr:DataBreach → risk:Incident → dpv:RiskConcept | ||
Object of relation | risk:avoids, risk:contains, risk:controls, risk:detects, risk:eliminates, risk:hasIncident, risk:identifies, risk:interrupts, risk:intervenes, risk:investigates, risk:logs, risk:mitigates, risk:modifies, risk:monitors, risk:overrides, risk:recovers, risk:reduces, risk:remedies, risk:resolves, risk:reverses, risk:shares, risk:substitutes, risk:transfers | ||
Definition | A data breach where there is an accidental or unauthorised loss of access to or destruction of personal data | ||
Source | EDPB Guidelines 9/2022 on personal data breach notification under GDPR | ||
Date Created | 2024-05-19 | ||
See More: | section DATA-BREACH in EU-GDPR |
Term | BindingCorporateRules | Prefix | eu-gdpr |
---|---|---|---|
Label | Binding Corporate Rules (BCR) | ||
IRI | https://w3id.org/dpv/legal/eu/gdpr#BindingCorporateRules | ||
Type | rdfs:Class, skos:Concept, dpv:OrganisationalMeasure | ||
Broader/Parent types | eu-gdpr:DataTransferTool → dpv:OrganisationalMeasure → dpv:TechnicalOrganisationalMeasure | ||
Object of relation | dpv:hasOrganisationalMeasure, dpv:hasTechnicalOrganisationalMeasure | ||
Definition | ‘Binding Corporate Rules’ means personal data protection policies which are adhered to by a controller or processor established on the territory of a Member State for transfers or a set of transfers of personal data to a controller or processor in one or more third countries within a group of undertakings, or group of enterprises engaged in a joint economic activity | ||
Usage Note | Binding corporate rules (BCR) are data protection policies adhered to by companies established in the EU for transfers of personal data outside the EU within a group of undertakings or enterprises. | ||
Source | GDPR Art.4-20 | ||
Date Created | 2021-09-22 | ||
Contributors | David Hickey, Georg P. Krog, Harshvardhan J. Pandit, Paul Ryan | ||
See More: | section DATA-TRANSFERS in EU-GDPR |
Term | BiometricData | Prefix | eu-gdpr |
---|---|---|---|
Label | Biometric Data | ||
IRI | https://w3id.org/dpv/legal/eu/gdpr#BiometricData | ||
Type | rdfs:Class, skos:Concept, dpv:PersonalData | ||
Broader/Parent types | pd:Biometric → dpv:SpecialCategoryPersonalData → dpv:SensitivePersonalData → dpv:PersonalData → dpv:Data | ||
Broader/Parent types | pd:Biometric → dpv:SpecialCategoryPersonalData → dpv:SensitivePersonalData → dpv:SensitiveData → dpv:Data | ||
Broader/Parent types | pd:Biometric → pd:Identifying → pd:External → dpv:PersonalData → dpv:Data | ||
Object of relation | dpv:hasData, dpv:hasPersonalData | ||
Definition | ‘Biometric Data’ means personal data resulting from specific technical processing relating to the physical, physiological or behavioural characteristics of a natural person, which allow or confirm the unique identification of that natural person, such as facial images or dactyloscopic data | ||
Date Created | 2024-12-17 | ||
Date Modified | 2025-07-27 | ||
Contributors | Harshvardhan J. Pandit | ||
See More: | section MISC-CONCEPTS in EU-GDPR |
Term | BreachNotificationNotNeeded | Prefix | eu-gdpr |
---|---|---|---|
Label | Breach Notification Not Needed | ||
IRI | https://w3id.org/dpv/legal/eu/gdpr#BreachNotificationNotNeeded | ||
Type | rdfs:Class, skos:Concept, eu-gdpr:DataBreachNoticeRequirement | ||
Broader/Parent types | eu-gdpr:DataBreachNoticeRequirement → dpv:AuditStatus → dpv:Status → dpv:Context | ||
Object of relation | dpv:hasAuditStatus, dpv:hasContext, dpv:hasStatus | ||
Definition | Data Breach notifications to DPA or Data Subjects are not required | ||
Source | GDPR Article 33 | ||
Date Created | 2024-05-19 | ||
See More: | section DATA-BREACH in EU-GDPR |
Term | CertificationMechanismsForDataTransfers | Prefix | eu-gdpr |
---|---|---|---|
Label | Certification Mechanisms for Data Transfers | ||
IRI | https://w3id.org/dpv/legal/eu/gdpr#CertificationMechanismsForDataTransfers | ||
Type | rdfs:Class, skos:Concept, dpv:OrganisationalMeasure | ||
Broader/Parent types | eu-gdpr:DataTransferTool → dpv:OrganisationalMeasure → dpv:TechnicalOrganisationalMeasure | ||
Object of relation | dpv:hasOrganisationalMeasure, dpv:hasTechnicalOrganisationalMeasure | ||
Definition | Certification and its binding or specified mechanisms intended to provide sufficient safeguards for data transfers | ||
Source | EDPB Recommendations 01/2020 on Supplementary Measures and Transfer Tools | ||
Date Created | 2021-09-22 | ||
Contributors | Harshvardhan J. Pandit | ||
See More: | section DATA-TRANSFERS in EU-GDPR |
Term | CodesOfConductForDataTransfers | Prefix | eu-gdpr |
---|---|---|---|
Label | Codes of Conduct for Data Transfers | ||
IRI | https://w3id.org/dpv/legal/eu/gdpr#CodesOfConductForDataTransfers | ||
Type | rdfs:Class, skos:Concept, dpv:OrganisationalMeasure | ||
Broader/Parent types | eu-gdpr:DataTransferTool → dpv:OrganisationalMeasure → dpv:TechnicalOrganisationalMeasure | ||
Object of relation | dpv:hasOrganisationalMeasure, dpv:hasTechnicalOrganisationalMeasure | ||
Definition | Codes of Conduct that outline sufficient safeguards for carrying out data transfers | ||
Source | EDPB Recommendations 01/2020 on Supplementary Measures and Transfer Tools | ||
Date Created | 2021-09-22 | ||
Contributors | Harshvardhan J. Pandit | ||
See More: | section DATA-TRANSFERS in EU-GDPR |
Term | ConcernedSupervisoryAuthority | Prefix | eu-gdpr |
---|---|---|---|
Label | Concerned Supervisory Authority | ||
IRI | https://w3id.org/dpv/legal/eu/gdpr#ConcernedSupervisoryAuthority | ||
Type | rdfs:Class, skos:Concept | ||
Broader/Parent types | eu-gdpr:DataProtectionAuthority → dpv:DataProtectionAuthority → dpv:Authority → dpv:GovernmentalOrganisation → dpv:Organisation → dpv:LegalEntity → dpv:Entity | ||
Object of relation | dpv:hasActiveEntity, dpv:hasAuthority, dpv:hasEntity, dpv:hasNonInvolvedEntity, dpv:hasParty, dpv:hasPassiveEntity, dpv:hasResponsibleEntity, dpv:hasSubsidiary, dpv:isDeterminedByEntity, dpv:isImplementedByEntity, dpv:isIndicatedBy, dpv:isOrganisationalUnitOf, dpv:isRepresentativeFor, dpv:isSubsidiaryOf, eu-gdpr:hasConcernedSA, eu-gdpr:hasEstablishment, eu-gdpr:hasLeadSA, eu-gdpr:hasLocalSA, eu-gdpr:hasMainEstablishment, eu-gdpr:isMainEstablishmentFor | ||
Definition | Concerned Supervisory Authority' or 'supervisory authority concerned’ means a supervisory authority which is concerned by the processing of personal data because: (a) the controller or processor is established on the territory of the Member State of that supervisory authority; (b) data subjects residing in the Member State of that supervisory authority are substantially affected or likely to be substantially affected by the processing; or (c) a complaint has been lodged with that supervisory authority | ||
Source | Guidelines 3/2018 on the territorial scope of the GDPR (Article 3) Version 2.1, GDPR Art.56 | ||
Date Created | 2024-02-14 | ||
Contributors | Georg P. Krog, Harshvardhan J. Pandit | ||
See More: | section ENTITIES in EU-GDPR |
Term | ConfidentialityBreach | Prefix | eu-gdpr |
---|---|---|---|
Label | Confidentiality Breach | ||
IRI | https://w3id.org/dpv/legal/eu/gdpr#ConfidentialityBreach | ||
Type | rdfs:Class, skos:Concept | ||
Broader/Parent types | eu-gdpr:DataBreach → risk:Incident → dpv:RiskConcept | ||
Object of relation | risk:avoids, risk:contains, risk:controls, risk:detects, risk:eliminates, risk:hasIncident, risk:identifies, risk:interrupts, risk:intervenes, risk:investigates, risk:logs, risk:mitigates, risk:modifies, risk:monitors, risk:overrides, risk:recovers, risk:reduces, risk:remedies, risk:resolves, risk:reverses, risk:shares, risk:substitutes, risk:transfers | ||
Definition | A data breach where there is an unauthorised or accidental disclosure of or access to personal data | ||
Source | EDPB Guidelines 9/2022 on personal data breach notification under GDPR | ||
Date Created | 2024-05-19 | ||
See More: | section DATA-BREACH in EU-GDPR |
Term | Consent | Prefix | eu-gdpr |
---|---|---|---|
Label | Consent | ||
IRI | https://w3id.org/dpv/legal/eu/gdpr#Consent | ||
Type | rdfs:Class, skos:Concept, dpv:LegalBasis | ||
Broader/Parent types | dpv:Consent → dpv:LegalBasis | ||
Object of relation | dpv:hasLegalBasis | ||
Definition | Consent’ of the data subject means any freely given, specific, informed and unambiguous indication of the data subject’s wishes by which he or she, by a statement or by a clear affirmative action, signifies agreement to the processing of personal data relating to him or her | ||
Source | GDPR Art.4-11 | ||
Date Created | 2024-12-17 | ||
Contributors | Harshvardhan J. Pandit | ||
See More: | section LEGAL-BASIS in EU-GDPR |
Term | Controller | Prefix | eu-gdpr |
---|---|---|---|
Label | Controller | ||
IRI | https://w3id.org/dpv/legal/eu/gdpr#Controller | ||
Type | rdfs:Class, skos:Concept | ||
Broader/Parent types | dpv:DataController → dpv:LegalEntity → dpv:Entity | ||
Object of relation | dpv:hasActiveEntity, dpv:hasDataController, dpv:hasEntity, dpv:hasNonInvolvedEntity, dpv:hasParty, dpv:hasPassiveEntity, dpv:hasRecipientDataController, dpv:hasResponsibleEntity, dpv:isDeterminedByEntity, dpv:isImplementedByEntity, dpv:isIndicatedBy, dpv:isOrganisationalUnitOf, dpv:isRepresentativeFor, eu-gdpr:hasEstablishment, eu-gdpr:hasMainEstablishment, eu-gdpr:isMainEstablishmentFor | ||
Definition | ‘Controller’ means the natural or legal person, public authority, agency or other body which, alone or jointly with others, determines the purposes and means of the processing of personal data; where the purposes and means of such processing are determined by Union or Member State law, the controller or the specific criteria for its nomination may be provided for by Union or Member State law | ||
Source | GDPR Art.4-7 | ||
Date Created | 2024-12-17 | ||
Contributors | Harshvardhan J. Pandit | ||
See More: | section ENTITIES in EU-GDPR |
Term | ControllerBreachNotice | Prefix | eu-gdpr |
---|---|---|---|
Label | Controller Breach Notice | ||
IRI | https://w3id.org/dpv/legal/eu/gdpr#ControllerBreachNotice | ||
Type | rdfs:Class, skos:Concept, eu-gdpr:DataBreachNotice | ||
Broader/Parent types | eu-gdpr:DataBreachNotice → dpv:DataBreachNotice → dpv:SecurityIncidentNotice → dpv:Notice → dpv:OrganisationalMeasure → dpv:TechnicalOrganisationalMeasure | ||
Object of relation | dpv:hasNotice, dpv:hasOrganisationalMeasure, dpv:hasTechnicalOrganisationalMeasure | ||
Definition | Notice regarding a data breach to the Controller | ||
Source | GDPR Article 33 | ||
Date Created | 2024-05-19 | ||
See More: | section DATA-BREACH in EU-GDPR |
Term | ControllerBreachNotificationNeeded | Prefix | eu-gdpr |
---|---|---|---|
Label | Controller Breach Notification Needed | ||
IRI | https://w3id.org/dpv/legal/eu/gdpr#ControllerBreachNotificationNeeded | ||
Type | rdfs:Class, skos:Concept, eu-gdpr:DataBreachNoticeRequirement | ||
Broader/Parent types | eu-gdpr:DataBreachNoticeRequirement → dpv:AuditStatus → dpv:Status → dpv:Context | ||
Object of relation | dpv:hasAuditStatus, dpv:hasContext, dpv:hasStatus | ||
Definition | Data Breach notification to the Controller is required | ||
Source | GDPR Article 33 | ||
Date Created | 2024-05-19 | ||
See More: | section DATA-BREACH in EU-GDPR |
Term | CrossBorderDataBreach | Prefix | eu-gdpr |
---|---|---|---|
Label | Cross-Border Data Breach | ||
IRI | https://w3id.org/dpv/legal/eu/gdpr#CrossBorderDataBreach | ||
Type | rdfs:Class, skos:Concept | ||
Broader/Parent types | eu-gdpr:DataBreach → risk:Incident → dpv:RiskConcept | ||
Object of relation | risk:avoids, risk:contains, risk:controls, risk:detects, risk:eliminates, risk:hasIncident, risk:identifies, risk:interrupts, risk:intervenes, risk:investigates, risk:logs, risk:mitigates, risk:modifies, risk:monitors, risk:overrides, risk:recovers, risk:reduces, risk:remedies, risk:resolves, risk:reverses, risk:shares, risk:substitutes, risk:transfers | ||
Definition | A data breach involving cross-border data subjects or processing operations | ||
Source | EDPB Guidelines 9/2022 on personal data breach notification under GDPR | ||
Date Created | 2024-05-19 | ||
See More: | section DATA-BREACH in EU-GDPR |
Term | CrossBorderProcessing | Prefix | eu-gdpr |
---|---|---|---|
Label | Cross Border Processing | ||
IRI | https://w3id.org/dpv/legal/eu/gdpr#CrossBorderProcessing | ||
Type | rdfs:Class, skos:Concept | ||
Broader/Parent types | dpv:Processing | ||
Object of relation | dpv:hasProcessing | ||
Definition | ‘Cross-Border Processing’ means either: (a) processing of personal data which takes place in the context of the activities of establishments in more than one Member State of a controller or processor in the Union where the controller or processor is established in more than one Member State; or (b) processing of personal data which takes place in the context of the activities of a single establishment of a controller or processor in the Union but which substantially affects or is likely to substantially affect data subjects in more than one Member State | ||
Date Created | 2024-12-17 | ||
Date Modified | 2025-07-29 | ||
Contributors | Harshvardhan J. Pandit | ||
See More: | section MISC-CONCEPTS in EU-GDPR |
Term | DataBreach | Prefix | eu-gdpr |
---|---|---|---|
Label | Data Breach | ||
IRI | https://w3id.org/dpv/legal/eu/gdpr#DataBreach | ||
Type | rdfs:Class, skos:Concept | ||
Broader/Parent types | risk:Incident → dpv:RiskConcept | ||
Object of relation | risk:avoids, risk:contains, risk:controls, risk:detects, risk:eliminates, risk:hasIncident, risk:identifies, risk:interrupts, risk:intervenes, risk:investigates, risk:logs, risk:mitigates, risk:modifies, risk:monitors, risk:overrides, risk:recovers, risk:reduces, risk:remedies, risk:resolves, risk:reverses, risk:shares, risk:substitutes, risk:transfers | ||
Definition | Data Breach' or ‘Personal Data Breach’ means a breach of security leading to the accidental or unlawful destruction, loss, alteration, unauthorised disclosure of, or access to, personal data transmitted, stored or otherwise processed | ||
Usage Note | GDPR's notion of data breach includes any incident that affects the confidentiality, integrity, and availability of personal data and its processing without distinguishing between internal or external actors involved in the incident | ||
Source | GDPR Article 4(12) | ||
Date Created | 2024-05-19 | ||
See More: | section DATA-BREACH in EU-GDPR |
Term | DataBreachConcludingReport | Prefix | eu-gdpr |
---|---|---|---|
Label | Data Breach Concluding Report | ||
IRI | https://w3id.org/dpv/legal/eu/gdpr#DataBreachConcludingReport | ||
Type | rdfs:Class, skos:Concept | ||
Broader/Parent types | eu-gdpr:DataBreachReport → risk:IncidentReport → dpv:RecordsOfActivities → dpv:OrganisationalMeasure → dpv:TechnicalOrganisationalMeasure | ||
Broader/Parent types | risk:IncidentHandlingReport → risk:IncidentReport → dpv:RecordsOfActivities → dpv:OrganisationalMeasure → dpv:TechnicalOrganisationalMeasure | ||
Object of relation | dpv:hasOrganisationalMeasure, dpv:hasRecordOfActivity, dpv:hasTechnicalOrganisationalMeasure | ||
Definition | Documented information about a concluded data breach incident | ||
Source | GDPR Article 33 | ||
Date Created | 2024-05-19 | ||
See More: | section DATA-BREACH in EU-GDPR |
Term | DataBreachDetectionReport | Prefix | eu-gdpr |
---|---|---|---|
Label | Data Breach Detection Report | ||
IRI | https://w3id.org/dpv/legal/eu/gdpr#DataBreachDetectionReport | ||
Type | rdfs:Class, skos:Concept | ||
Broader/Parent types | eu-gdpr:DataBreachReport → risk:IncidentReport → dpv:RecordsOfActivities → dpv:OrganisationalMeasure → dpv:TechnicalOrganisationalMeasure | ||
Broader/Parent types | risk:IncidentDetectionReport → risk:IncidentReport → dpv:RecordsOfActivities → dpv:OrganisationalMeasure → dpv:TechnicalOrganisationalMeasure | ||
Object of relation | dpv:hasOrganisationalMeasure, dpv:hasRecordOfActivity, dpv:hasTechnicalOrganisationalMeasure | ||
Definition | Documented information about a data breach being detected | ||
Source | GDPR Article 33 | ||
Date Created | 2024-05-19 | ||
See More: | section DATA-BREACH in EU-GDPR |
Term | DataBreachJustification | Prefix | eu-gdpr |
---|---|---|---|
Label | Data Breach Justification | ||
IRI | https://w3id.org/dpv/legal/eu/gdpr#DataBreachJustification | ||
Type | rdfs:Class, skos:Concept, dpv:Justification | ||
Broader/Parent types | dpv:Justification → dpv:Context | ||
Object of relation | dpv:hasContext, dpv:hasJustification | ||
Definition | A Justification used in the context of data breach related processes and communications | ||
Date Created | 2024-12-17 | ||
Contributors | Beatriz Esteves, Georg P. Krog, Harshvardhan J. Pandit | ||
See More: | section DATA-BREACH in EU-GDPR |
Term | DataBreachNotice | Prefix | eu-gdpr |
---|---|---|---|
Label | Data Breach Notice | ||
IRI | https://w3id.org/dpv/legal/eu/gdpr#DataBreachNotice | ||
Type | rdfs:Class, skos:Concept | ||
Broader/Parent types | dpv:DataBreachNotice → dpv:SecurityIncidentNotice → dpv:Notice → dpv:OrganisationalMeasure → dpv:TechnicalOrganisationalMeasure | ||
Object of relation | dpv:hasNotice, dpv:hasOrganisationalMeasure, dpv:hasTechnicalOrganisationalMeasure | ||
Definition | Notice associated with data breach providing information in compliance with GDPR | ||
Source | GDPR Article 33 | ||
Date Created | 2024-05-19 | ||
See More: | section DATA-BREACH in EU-GDPR |
Term | DataBreachNoticeRequirement | Prefix | eu-gdpr |
---|---|---|---|
Label | Data Breach Notice Requirement | ||
IRI | https://w3id.org/dpv/legal/eu/gdpr#DataBreachNoticeRequirement | ||
Type | rdfs:Class, skos:Concept | ||
Broader/Parent types | dpv:AuditStatus → dpv:Status → dpv:Context | ||
Object of relation | dpv:hasAuditStatus, dpv:hasContext, dpv:hasStatus | ||
Definition | Whether a Data Breach notification is required | ||
Source | GDPR Article 33 | ||
Date Created | 2024-05-19 | ||
Contributors | Harshvardhan J. Pandit | ||
See More: | section DATA-BREACH in EU-GDPR |
Term | DataBreachOngoingReport | Prefix | eu-gdpr |
---|---|---|---|
Label | Data Breach Ongoing Report | ||
IRI | https://w3id.org/dpv/legal/eu/gdpr#DataBreachOngoingReport | ||
Type | rdfs:Class, skos:Concept | ||
Broader/Parent types | eu-gdpr:DataBreachReport → risk:IncidentReport → dpv:RecordsOfActivities → dpv:OrganisationalMeasure → dpv:TechnicalOrganisationalMeasure | ||
Broader/Parent types | risk:IncidentAssessmentReport → risk:IncidentReport → dpv:RecordsOfActivities → dpv:OrganisationalMeasure → dpv:TechnicalOrganisationalMeasure | ||
Object of relation | dpv:hasOrganisationalMeasure, dpv:hasRecordOfActivity, dpv:hasTechnicalOrganisationalMeasure | ||
Definition | Documented information about an ongoing data breach | ||
Source | GDPR Article 33 | ||
Date Created | 2024-05-19 | ||
See More: | section DATA-BREACH in EU-GDPR |
Term | DataBreachPreliminaryReport | Prefix | eu-gdpr |
---|---|---|---|
Label | Data Breach Preliminary Report | ||
IRI | https://w3id.org/dpv/legal/eu/gdpr#DataBreachPreliminaryReport | ||
Type | rdfs:Class, skos:Concept | ||
Broader/Parent types | eu-gdpr:DataBreachReport → risk:IncidentReport → dpv:RecordsOfActivities → dpv:OrganisationalMeasure → dpv:TechnicalOrganisationalMeasure | ||
Broader/Parent types | risk:IncidentAssessmentReport → risk:IncidentReport → dpv:RecordsOfActivities → dpv:OrganisationalMeasure → dpv:TechnicalOrganisationalMeasure | ||
Object of relation | dpv:hasOrganisationalMeasure, dpv:hasRecordOfActivity, dpv:hasTechnicalOrganisationalMeasure | ||
Definition | Documented information about preliminary assessment regarding a data breach | ||
Source | GDPR Article 33 | ||
Date Created | 2024-05-19 | ||
See More: | section DATA-BREACH in EU-GDPR |
Term | DataBreachRegister | Prefix | eu-gdpr |
---|---|---|---|
Label | Data Breach Register | ||
IRI | https://w3id.org/dpv/legal/eu/gdpr#DataBreachRegister | ||
Type | rdfs:Class, skos:Concept | ||
Broader/Parent types | dpv:RecordsOfActivities → dpv:OrganisationalMeasure → dpv:TechnicalOrganisationalMeasure | ||
Object of relation | dpv:hasOrganisationalMeasure, dpv:hasRecordOfActivity, dpv:hasTechnicalOrganisationalMeasure | ||
Definition | Register of data breaches containing facts relating to the personal data breach, its effects and the remedial action taken | ||
Source | GDPR Article 33(5) | ||
Date Created | 2024-05-19 | ||
See More: | section DATA-BREACH in EU-GDPR |
Term | DataBreachReport | Prefix | eu-gdpr |
---|---|---|---|
Label | Data Breach Report | ||
IRI | https://w3id.org/dpv/legal/eu/gdpr#DataBreachReport | ||
Type | rdfs:Class, skos:Concept | ||
Broader/Parent types | risk:IncidentReport → dpv:RecordsOfActivities → dpv:OrganisationalMeasure → dpv:TechnicalOrganisationalMeasure | ||
Object of relation | dpv:hasOrganisationalMeasure, dpv:hasRecordOfActivity, dpv:hasTechnicalOrganisationalMeasure | ||
Definition | Documented information about a data breach incident, its handling, assessments, and notifications | ||
Source | GDPR Article 33 | ||
Date Created | 2024-05-19 | ||
See More: | section DATA-BREACH in EU-GDPR |
Term | DataMinimisationPrinciple | Prefix | eu-gdpr |
---|---|---|---|
Label | Data Minimisation Principle | ||
IRI | https://w3id.org/dpv/legal/eu/gdpr#DataMinimisationPrinciple | ||
Type | rdfs:Class, skos:Concept, dpv:OrganisationalMeasure | ||
Broader/Parent types | dpv:Principle → dpv:GuidelinesPrinciple → dpv:OrganisationalMeasure → dpv:TechnicalOrganisationalMeasure | ||
Object of relation | dpv:hasOrganisationalMeasure, dpv:hasTechnicalOrganisationalMeasure | ||
Definition | Principle stating personal data must be processed adequate, relevant and limited to what is necessary in relation to the purposes for which they are processed | ||
Source | GDPR Art.5-1c | ||
Date Created | 2024-05-12 | ||
Contributors | Georg P. Krog | ||
See More: | section PRINCIPLES in EU-GDPR |
Term | DataSubject | Prefix | eu-gdpr |
---|---|---|---|
Label | Data Subject | ||
IRI | https://w3id.org/dpv/legal/eu/gdpr#DataSubject | ||
Type | rdfs:Class, skos:Concept | ||
Broader/Parent types | dpv:DataSubject → dpv:HumanSubject → dpv:LegalEntity → dpv:Entity | ||
Object of relation | dpv:hasActiveEntity, dpv:hasDataSubject, dpv:hasEntity, dpv:hasHumanSubject, dpv:hasNonInvolvedEntity, dpv:hasParty, dpv:hasPassiveEntity, dpv:hasResponsibleEntity, dpv:isDeterminedByEntity, dpv:isImplementedByEntity, dpv:isIndicatedBy, dpv:isOrganisationalUnitOf, dpv:isRepresentativeFor, eu-gdpr:hasEstablishment, eu-gdpr:hasMainEstablishment, eu-gdpr:isMainEstablishmentFor | ||
Definition | Data Subject' means a natural person who can be identified, directly or indirectly, in particular by reference to an identifier such as a name, an identification number, location data, an online identifier or to one or more factors specific to the physical, physiological, genetic, mental, economic, cultural or social identity of that natural person | ||
Source | GDPR Art.4-1 | ||
Date Created | 2024-12-17 | ||
Contributors | Harshvardhan J. Pandit | ||
See More: | section ENTITIES in EU-GDPR |
Term | DataSubjectBreachNotice | Prefix | eu-gdpr |
---|---|---|---|
Label | Data Subject Breach Notice | ||
IRI | https://w3id.org/dpv/legal/eu/gdpr#DataSubjectBreachNotice | ||
Type | rdfs:Class, skos:Concept, eu-gdpr:DataBreachNotice | ||
Broader/Parent types | eu-gdpr:DataBreachNotice → dpv:DataBreachNotice → dpv:SecurityIncidentNotice → dpv:Notice → dpv:OrganisationalMeasure → dpv:TechnicalOrganisationalMeasure | ||
Object of relation | dpv:hasNotice, dpv:hasOrganisationalMeasure, dpv:hasTechnicalOrganisationalMeasure | ||
Definition | Notice regarding a data breach to the Data Subject | ||
Source | GDPR Article 34 | ||
Date Created | 2024-05-19 | ||
See More: | section DATA-BREACH in EU-GDPR |
Term | DataSubjectBreachNotificationNeeded | Prefix | eu-gdpr |
---|---|---|---|
Label | Data Subject Breach Notification Needed | ||
IRI | https://w3id.org/dpv/legal/eu/gdpr#DataSubjectBreachNotificationNeeded | ||
Type | rdfs:Class, skos:Concept, eu-gdpr:DataBreachNoticeRequirement | ||
Broader/Parent types | eu-gdpr:DataBreachNoticeRequirement → dpv:AuditStatus → dpv:Status → dpv:Context | ||
Object of relation | dpv:hasAuditStatus, dpv:hasContext, dpv:hasStatus | ||
Definition | Data Breach notification to the Data Subject is required | ||
Source | GDPR Article 34 | ||
Date Created | 2024-05-19 | ||
See More: | section DATA-BREACH in EU-GDPR |
Term | DataTransferTool | Prefix | eu-gdpr |
---|---|---|---|
Label | Data Transfer Tool | ||
IRI | https://w3id.org/dpv/legal/eu/gdpr#DataTransferTool | ||
Type | rdfs:Class, skos:Concept, dpv:OrganisationalMeasure | ||
Broader/Parent types | dpv:OrganisationalMeasure → dpv:TechnicalOrganisationalMeasure | ||
Object of relation | dpv:hasOrganisationalMeasure, dpv:hasTechnicalOrganisationalMeasure | ||
Definition | A legal instrument or tool intended to assist or justify data transfers | ||
Source | GDPR Art.46 and EDPB Recommendations 01/2020 on Supplementary Measures and Transfer Tools | ||
Date Created | 2021-09-22 | ||
Date Modified | 2023-10-30 | ||
Contributors | David Hickey, Harshvardhan J. Pandit | ||
See More: | section DATA-TRANSFERS in EU-GDPR |
Term | DBIAIndicatesHighRisk | Prefix | eu-gdpr |
---|---|---|---|
Label | DBIA Indicates High Risk | ||
IRI | https://w3id.org/dpv/legal/eu/gdpr#DBIAIndicatesHighRisk | ||
Type | rdfs:Class, skos:Concept, eu-gdpr:DBIARiskStatus | ||
Broader/Parent types | eu-gdpr:DBIARiskStatus → dpv:AuditStatus → dpv:Status → dpv:Context | ||
Object of relation | dpv:hasAuditStatus, dpv:hasContext, dpv:hasStatus | ||
Definition | DBIA identifying high risk levels regarding rights and freedoms of natural persons | ||
Source | GDPR Article 33 | ||
Date Created | 2024-05-19 | ||
Contributors | Harshvardhan J. Pandit | ||
See More: | section DATA-BREACH in EU-GDPR |
Term | DBIAIndicatesLowRisk | Prefix | eu-gdpr |
---|---|---|---|
Label | DBIA Indicates Low Risk | ||
IRI | https://w3id.org/dpv/legal/eu/gdpr#DBIAIndicatesLowRisk | ||
Type | rdfs:Class, skos:Concept, eu-gdpr:DBIARiskStatus | ||
Broader/Parent types | eu-gdpr:DBIARiskStatus → dpv:AuditStatus → dpv:Status → dpv:Context | ||
Object of relation | dpv:hasAuditStatus, dpv:hasContext, dpv:hasStatus | ||
Definition | DBIA identifying low risk levels regarding rights and freedoms of natural persons | ||
Source | GDPR Article 33 | ||
Date Created | 2024-05-19 | ||
Contributors | Harshvardhan J. Pandit | ||
See More: | section DATA-BREACH in EU-GDPR |
Term | DBIAIndicatesNoRisk | Prefix | eu-gdpr |
---|---|---|---|
Label | DBIA Indicates No Risk | ||
IRI | https://w3id.org/dpv/legal/eu/gdpr#DBIAIndicatesNoRisk | ||
Type | rdfs:Class, skos:Concept, eu-gdpr:DBIARiskStatus | ||
Broader/Parent types | eu-gdpr:DBIARiskStatus → dpv:AuditStatus → dpv:Status → dpv:Context | ||
Object of relation | dpv:hasAuditStatus, dpv:hasContext, dpv:hasStatus | ||
Definition | DBIA identifying no risk is present regarding rights and freedoms of natural persons | ||
Source | GDPR Article 33 | ||
Date Created | 2024-05-19 | ||
Contributors | Harshvardhan J. Pandit | ||
See More: | section DATA-BREACH in EU-GDPR |
Term | DBIARiskStatus | Prefix | eu-gdpr |
---|---|---|---|
Label | DBIA Risk Status | ||
IRI | https://w3id.org/dpv/legal/eu/gdpr#DBIARiskStatus | ||
Type | rdfs:Class, skos:Concept | ||
Broader/Parent types | dpv:AuditStatus → dpv:Status → dpv:Context | ||
Object of relation | dpv:hasAuditStatus, dpv:hasContext, dpv:hasStatus | ||
Definition | Status reflecting the status of risk associated with a DBIA regarding rights and freedoms of natural persons | ||
Source | GDPR Article 33 | ||
Date Created | 2024-05-19 | ||
Contributors | Harshvardhan J. Pandit | ||
See More: | section DATA-BREACH in EU-GDPR |
Term | DirectDataCollectionNotice | Prefix | eu-gdpr |
---|---|---|---|
Label | Direct Data Collection Notice | ||
IRI | https://w3id.org/dpv/legal/eu/gdpr#DirectDataCollectionNotice | ||
Type | rdfs:Class, skos:Concept, dpv:OrganisationalMeasure | ||
Broader/Parent types | dpv:RightFulfilmentNotice → dpv:RightExerciseNotice → dpv:RightNotice → dpv:Notice → dpv:OrganisationalMeasure → dpv:TechnicalOrganisationalMeasure | ||
Object of relation | dpv:hasNotice, dpv:hasOrganisationalMeasure, dpv:hasTechnicalOrganisationalMeasure, dpv:isExercisedAt | ||
Definition | A Notice provided in fulfilment of GDPR's Art.13 regarding information to be provided where personal data are collected from the data subject | ||
Date Created | 2022-11-09 | ||
Contributors | Beatriz Esteves, Georg P. Krog, Harshvardhan J. Pandit | ||
See More: | section RIGHTS in EU-GDPR |
Term | DPABreachInitialNotice | Prefix | eu-gdpr |
---|---|---|---|
Label | DPA Breach Initial Notice | ||
IRI | https://w3id.org/dpv/legal/eu/gdpr#DPABreachInitialNotice | ||
Type | rdfs:Class, skos:Concept, eu-gdpr:DataBreachNotice | ||
Broader/Parent types | eu-gdpr:DPABreachNotice → eu-gdpr:DataBreachNotice → dpv:DataBreachNotice → dpv:SecurityIncidentNotice → dpv:Notice → dpv:OrganisationalMeasure → dpv:TechnicalOrganisationalMeasure | ||
Object of relation | dpv:hasNotice, dpv:hasOrganisationalMeasure, dpv:hasTechnicalOrganisationalMeasure | ||
Definition | Notice sent by a Controller within 72 hours of becoming aware of a personal data breach to the competent DPA, with justifications provided where the notice is made after 72 hours | ||
Source | GDPR Article 33 | ||
Date Created | 2024-05-19 | ||
See More: | section DATA-BREACH in EU-GDPR |
Term | DPABreachNotice | Prefix | eu-gdpr |
---|---|---|---|
Label | DPA Breach Notice | ||
IRI | https://w3id.org/dpv/legal/eu/gdpr#DPABreachNotice | ||
Type | rdfs:Class, skos:Concept, eu-gdpr:DataBreachNotice | ||
Broader/Parent types | eu-gdpr:DataBreachNotice → dpv:DataBreachNotice → dpv:SecurityIncidentNotice → dpv:Notice → dpv:OrganisationalMeasure → dpv:TechnicalOrganisationalMeasure | ||
Object of relation | dpv:hasNotice, dpv:hasOrganisationalMeasure, dpv:hasTechnicalOrganisationalMeasure | ||
Definition | Notice regarding a data breach to the DPA | ||
Source | GDPR Article 33 | ||
Date Created | 2024-05-19 | ||
See More: | section DATA-BREACH in EU-GDPR |
Term | DPABreachNotificationNeeded | Prefix | eu-gdpr |
---|---|---|---|
Label | DPA Breach Notification Needed | ||
IRI | https://w3id.org/dpv/legal/eu/gdpr#DPABreachNotificationNeeded | ||
Type | rdfs:Class, skos:Concept, eu-gdpr:DataBreachNoticeRequirement | ||
Broader/Parent types | eu-gdpr:DataBreachNoticeRequirement → dpv:AuditStatus → dpv:Status → dpv:Context | ||
Object of relation | dpv:hasAuditStatus, dpv:hasContext, dpv:hasStatus | ||
Definition | Data Breach notification to the DPA is required | ||
Source | GDPR Article 33 | ||
Date Created | 2024-05-19 | ||
Contributors | Harshvardhan J. Pandit | ||
See More: | section DATA-BREACH in EU-GDPR |
Term | DPABundledBreachNotice | Prefix | eu-gdpr |
---|---|---|---|
Label | DPA Bundled Breach Notice | ||
IRI | https://w3id.org/dpv/legal/eu/gdpr#DPABundledBreachNotice | ||
Type | rdfs:Class, skos:Concept, eu-gdpr:DataBreachNotice | ||
Broader/Parent types | eu-gdpr:DPABreachNotice → eu-gdpr:DataBreachNotice → dpv:DataBreachNotice → dpv:SecurityIncidentNotice → dpv:Notice → dpv:OrganisationalMeasure → dpv:TechnicalOrganisationalMeasure | ||
Object of relation | dpv:hasNotice, dpv:hasOrganisationalMeasure, dpv:hasTechnicalOrganisationalMeasure | ||
Definition | Notice sent by a Controller to the DPA regarding multiple data breaches concerning the same type of personal data | ||
Source | EDPB Guidelines 9/2022 on personal data breach notification under GDPR | ||
Date Created | 2024-05-19 | ||
See More: | section DATA-BREACH in EU-GDPR |
Term | DPAPhasedBreachNotice | Prefix | eu-gdpr |
---|---|---|---|
Label | DPA Phased Breach Notice | ||
IRI | https://w3id.org/dpv/legal/eu/gdpr#DPAPhasedBreachNotice | ||
Type | rdfs:Class, skos:Concept, eu-gdpr:DataBreachNotice | ||
Broader/Parent types | eu-gdpr:DPABreachNotice → eu-gdpr:DataBreachNotice → dpv:DataBreachNotice → dpv:SecurityIncidentNotice → dpv:Notice → dpv:OrganisationalMeasure → dpv:TechnicalOrganisationalMeasure | ||
Object of relation | dpv:hasNotice, dpv:hasOrganisationalMeasure, dpv:hasTechnicalOrganisationalMeasure | ||
Definition | Notice sent to a DPA in phases i.e. by providing incremental information as it becomes available or is requested following previously submitted notifications | ||
Source | EDPB Guidelines 9/2022 on personal data breach notification under GDPR | ||
Date Created | 2024-05-19 | ||
See More: | section DATA-BREACH in EU-GDPR |
Term | DPIAConformant | Prefix | eu-gdpr |
---|---|---|---|
Label | DPIA Conformant | ||
IRI | https://w3id.org/dpv/legal/eu/gdpr#DPIAConformant | ||
Type | rdfs:Class, skos:Concept, eu-gdpr:DPIAConformity | ||
Broader/Parent types | eu-gdpr:DPIAConformity → dpv:ConformanceStatus → dpv:Status → dpv:Context | ||
Object of relation | dpv:hasConformanceStatus, dpv:hasContext, dpv:hasStatus | ||
Definition | Expressing the specified process is conformant with a DPIA | ||
Date Created | 2022-10-22 | ||
Contributors | Georg P. Krog, Harshvardhan J. Pandit | ||
See More: | section DPIA in EU-GDPR |
Term | DPIAConformity | Prefix | eu-gdpr |
---|---|---|---|
Label | DPIA Conformity | ||
IRI | https://w3id.org/dpv/legal/eu/gdpr#DPIAConformity | ||
Type | rdfs:Class, skos:Concept | ||
Broader/Parent types | dpv:ConformanceStatus → dpv:Status → dpv:Context | ||
Object of relation | dpv:hasConformanceStatus, dpv:hasContext, dpv:hasStatus | ||
Definition | Conformity of a process with a DPIA | ||
Date Created | 2022-10-22 | ||
Contributors | Georg P. Krog, Harshvardhan J. Pandit | ||
See More: | section DPIA in EU-GDPR |
Term | DPIAIndicatesHighRisk | Prefix | eu-gdpr |
---|---|---|---|
Label | DPIA Indicates High Risk | ||
IRI | https://w3id.org/dpv/legal/eu/gdpr#DPIAIndicatesHighRisk | ||
Type | rdfs:Class, skos:Concept, eu-gdpr:DPIARiskStatus | ||
Broader/Parent types | eu-gdpr:DPIARiskStatus → dpv:AuditStatus → dpv:Status → dpv:Context | ||
Object of relation | dpv:hasAuditStatus, dpv:hasContext, dpv:hasStatus | ||
Definition | DPIA identifying high risk levels | ||
Date Created | 2022-06-22 | ||
Contributors | Harshvardhan J. Pandit | ||
See More: | section DPIA in EU-GDPR |
Term | DPIAIndicatesLowRisk | Prefix | eu-gdpr |
---|---|---|---|
Label | DPIA Indicates Low Risk | ||
IRI | https://w3id.org/dpv/legal/eu/gdpr#DPIAIndicatesLowRisk | ||
Type | rdfs:Class, skos:Concept, eu-gdpr:DPIARiskStatus | ||
Broader/Parent types | eu-gdpr:DPIARiskStatus → dpv:AuditStatus → dpv:Status → dpv:Context | ||
Object of relation | dpv:hasAuditStatus, dpv:hasContext, dpv:hasStatus | ||
Definition | DPIA identifying low risk levels | ||
Date Created | 2022-06-22 | ||
Contributors | Harshvardhan J. Pandit | ||
See More: | section DPIA in EU-GDPR |
Term | DPIAIndicatesNoRisk | Prefix | eu-gdpr |
---|---|---|---|
Label | DPIA Indicates No Risk | ||
IRI | https://w3id.org/dpv/legal/eu/gdpr#DPIAIndicatesNoRisk | ||
Type | rdfs:Class, skos:Concept, eu-gdpr:DPIARiskStatus | ||
Broader/Parent types | eu-gdpr:DPIARiskStatus → dpv:AuditStatus → dpv:Status → dpv:Context | ||
Object of relation | dpv:hasAuditStatus, dpv:hasContext, dpv:hasStatus | ||
Definition | DPIA identifying no risk is present | ||
Date Created | 2022-06-22 | ||
Contributors | Harshvardhan J. Pandit | ||
See More: | section DPIA in EU-GDPR |
Term | DPIANecessityAssessment | Prefix | eu-gdpr |
---|---|---|---|
Label | DPIA Necessity Assessment | ||
IRI | https://w3id.org/dpv/legal/eu/gdpr#DPIANecessityAssessment | ||
Type | rdfs:Class, skos:Concept, dpv:OrganisationalMeasure | ||
Broader/Parent types | dpv:DPIA → dpv:RightsImpactAssessment → dpv:ImpactAssessment → dpv:RiskAssessment → dpv:Assessment → dpv:OrganisationalMeasure → dpv:TechnicalOrganisationalMeasure | ||
Object of relation | dpv:hasAssessment, dpv:hasImpactAssessment, dpv:hasOrganisationalMeasure, dpv:hasRiskAssessment, dpv:hasTechnicalOrganisationalMeasure | ||
Definition | Process that determines whether a DPIA is necessary | ||
Date Created | 2022-06-22 | ||
Contributors | Harshvardhan J. Pandit | ||
See More: | section DPIA in EU-GDPR |
Term | DPIANecessityStatus | Prefix | eu-gdpr |
---|---|---|---|
Label | DPIA Necessity Status | ||
IRI | https://w3id.org/dpv/legal/eu/gdpr#DPIANecessityStatus | ||
Type | rdfs:Class, skos:Concept | ||
Broader/Parent types | dpv:AuditStatus → dpv:Status → dpv:Context | ||
Object of relation | dpv:hasAuditStatus, dpv:hasContext, dpv:hasStatus | ||
Definition | Status reflecting whether a DPIA is necessary | ||
Date Created | 2022-06-22 | ||
Contributors | Harshvardhan J. Pandit | ||
See More: | section DPIA in EU-GDPR |
Term | DPIANonConformant | Prefix | eu-gdpr |
---|---|---|---|
Label | DPIA Non-Conformant | ||
IRI | https://w3id.org/dpv/legal/eu/gdpr#DPIANonConformant | ||
Type | rdfs:Class, skos:Concept, eu-gdpr:DPIAConformity | ||
Broader/Parent types | eu-gdpr:DPIAConformity → dpv:ConformanceStatus → dpv:Status → dpv:Context | ||
Object of relation | dpv:hasConformanceStatus, dpv:hasContext, dpv:hasStatus | ||
Definition | Expressing the specified process is not conformant with a DPIA | ||
Date Created | 2022-10-22 | ||
Contributors | Georg P. Krog, Harshvardhan J. Pandit | ||
See More: | section DPIA in EU-GDPR |
Term | DPIANotRequired | Prefix | eu-gdpr |
---|---|---|---|
Label | DPIA Not Required | ||
IRI | https://w3id.org/dpv/legal/eu/gdpr#DPIANotRequired | ||
Type | rdfs:Class, skos:Concept, eu-gdpr:DPIANecessityStatus | ||
Broader/Parent types | eu-gdpr:DPIANecessityStatus → dpv:AuditStatus → dpv:Status → dpv:Context | ||
Object of relation | dpv:hasAuditStatus, dpv:hasContext, dpv:hasStatus | ||
Definition | Condition where a DPIA is not required | ||
Date Created | 2022-06-22 | ||
Contributors | Harshvardhan J. Pandit | ||
See More: | section DPIA in EU-GDPR |
Term | DPIAOutcome | Prefix | eu-gdpr |
---|---|---|---|
Label | DPIA Outcome | ||
IRI | https://w3id.org/dpv/legal/eu/gdpr#DPIAOutcome | ||
Type | rdfs:Class, skos:Concept, dpv:OrganisationalMeasure | ||
Broader/Parent types | dpv:DPIA → dpv:RightsImpactAssessment → dpv:ImpactAssessment → dpv:RiskAssessment → dpv:Assessment → dpv:OrganisationalMeasure → dpv:TechnicalOrganisationalMeasure | ||
Object of relation | dpv:hasAssessment, dpv:hasImpactAssessment, dpv:hasOrganisationalMeasure, dpv:hasRiskAssessment, dpv:hasTechnicalOrganisationalMeasure | ||
Definition | Process representing determining outcome of a DPIA | ||
Date Created | 2022-06-22 | ||
Contributors | Harshvardhan J. Pandit | ||
See More: | section DPIA in EU-GDPR |
Term | DPIAOutcomeDPAConsultation | Prefix | eu-gdpr |
---|---|---|---|
Label | DPIA Outcome DPA Consultation | ||
IRI | https://w3id.org/dpv/legal/eu/gdpr#DPIAOutcomeDPAConsultation | ||
Type | rdfs:Class, skos:Concept, eu-gdpr:DPIAOutcomeStatus | ||
Broader/Parent types | eu-gdpr:DPIAOutcomeStatus → dpv:AuditStatus → dpv:Status → dpv:Context | ||
Object of relation | dpv:hasAuditStatus, dpv:hasContext, dpv:hasStatus | ||
Definition | DPIA outcome status indicating a DPA consultation is required | ||
Date Created | 2022-06-22 | ||
Contributors | Harshvardhan J. Pandit | ||
See More: | section DPIA in EU-GDPR |
Term | DPIAOutcomeHighResidualRisk | Prefix | eu-gdpr |
---|---|---|---|
Label | DPIA Outcome High Residual Risk | ||
IRI | https://w3id.org/dpv/legal/eu/gdpr#DPIAOutcomeHighResidualRisk | ||
Type | rdfs:Class, skos:Concept, eu-gdpr:DPIAOutcomeStatus | ||
Broader/Parent types | eu-gdpr:DPIAOutcomeStatus → dpv:AuditStatus → dpv:Status → dpv:Context | ||
Object of relation | dpv:hasAuditStatus, dpv:hasContext, dpv:hasStatus | ||
Definition | DPIA outcome status indicating high residual risk which are not acceptable for continuation | ||
Date Created | 2022-06-22 | ||
Contributors | Harshvardhan J. Pandit | ||
See More: | section DPIA in EU-GDPR |
Term | DPIAOutcomeRisksAcceptable | Prefix | eu-gdpr |
---|---|---|---|
Label | DPIA Outcome Risks Acceptable | ||
IRI | https://w3id.org/dpv/legal/eu/gdpr#DPIAOutcomeRisksAcceptable | ||
Type | rdfs:Class, skos:Concept, eu-gdpr:DPIAOutcomeStatus | ||
Broader/Parent types | eu-gdpr:DPIAOutcomeStatus → dpv:AuditStatus → dpv:Status → dpv:Context | ||
Object of relation | dpv:hasAuditStatus, dpv:hasContext, dpv:hasStatus | ||
Definition | DPIA outcome status indicating residual risks remain and are acceptable for continuation | ||
Date Created | 2024-05-19 | ||
Contributors | Harshvardhan J. Pandit | ||
See More: | section DPIA in EU-GDPR |
Term | DPIAOutcomeRisksMitigated | Prefix | eu-gdpr |
---|---|---|---|
Label | DPIA Outcome Risks Mitigated | ||
IRI | https://w3id.org/dpv/legal/eu/gdpr#DPIAOutcomeRisksMitigated | ||
Type | rdfs:Class, skos:Concept, eu-gdpr:DPIAOutcomeStatus | ||
Broader/Parent types | eu-gdpr:DPIAOutcomeStatus → dpv:AuditStatus → dpv:Status → dpv:Context | ||
Object of relation | dpv:hasAuditStatus, dpv:hasContext, dpv:hasStatus | ||
Definition | DPIA outcome status indicating (all) risks have been mitigated | ||
Date Created | 2022-06-22 | ||
Contributors | Harshvardhan J. Pandit | ||
See More: | section DPIA in EU-GDPR |
Term | DPIAOutcomeStatus | Prefix | eu-gdpr |
---|---|---|---|
Label | DPIA Outcome Status | ||
IRI | https://w3id.org/dpv/legal/eu/gdpr#DPIAOutcomeStatus | ||
Type | rdfs:Class, skos:Concept | ||
Broader/Parent types | dpv:AuditStatus → dpv:Status → dpv:Context | ||
Object of relation | dpv:hasAuditStatus, dpv:hasContext, dpv:hasStatus | ||
Definition | Status reflecting the outcomes of a DPIA | ||
Date Created | 2022-06-22 | ||
Contributors | Harshvardhan J. Pandit | ||
See More: | section DPIA in EU-GDPR |
Term | DPIAProcedure | Prefix | eu-gdpr |
---|---|---|---|
Label | DPIA Procedure | ||
IRI | https://w3id.org/dpv/legal/eu/gdpr#DPIAProcedure | ||
Type | rdfs:Class, skos:Concept, dpv:OrganisationalMeasure | ||
Broader/Parent types | dpv:DPIA → dpv:RightsImpactAssessment → dpv:ImpactAssessment → dpv:RiskAssessment → dpv:Assessment → dpv:OrganisationalMeasure → dpv:TechnicalOrganisationalMeasure | ||
Object of relation | dpv:hasAssessment, dpv:hasImpactAssessment, dpv:hasOrganisationalMeasure, dpv:hasRiskAssessment, dpv:hasTechnicalOrganisationalMeasure | ||
Definition | Process representing carrying out a DPIA | ||
Date Created | 2022-06-22 | ||
Contributors | Harshvardhan J. Pandit | ||
See More: | section DPIA in EU-GDPR |
Term | DPIAProcessingRecommendation | Prefix | eu-gdpr |
---|---|---|---|
Label | DPIA Processing Recommendation | ||
IRI | https://w3id.org/dpv/legal/eu/gdpr#DPIAProcessingRecommendation | ||
Type | rdfs:Class, skos:Concept | ||
Broader/Parent types | dpv:AuditStatus → dpv:Status → dpv:Context | ||
Object of relation | dpv:hasAuditStatus, dpv:hasContext, dpv:hasStatus | ||
Definition | Recommendation from the DPIA regarding processing | ||
Date Created | 2022-10-22 | ||
Contributors | Georg P. Krog, Harshvardhan J. Pandit | ||
See More: | section DPIA in EU-GDPR |
Term | DPIARecommendsProcessingContinue | Prefix | eu-gdpr |
---|---|---|---|
Label | DPIA Recommends Processing Continue | ||
IRI | https://w3id.org/dpv/legal/eu/gdpr#DPIARecommendsProcessingContinue | ||
Type | rdfs:Class, skos:Concept, eu-gdpr:DPIAProcessingRecommendation | ||
Broader/Parent types | eu-gdpr:DPIAProcessingRecommendation → dpv:AuditStatus → dpv:Status → dpv:Context | ||
Object of relation | dpv:hasAuditStatus, dpv:hasContext, dpv:hasStatus | ||
Definition | Recommendation from a DPIA that the processing may continue | ||
Date Created | 2022-10-22 | ||
Contributors | Georg P. Krog, Harshvardhan J. Pandit | ||
See More: | section DPIA in EU-GDPR |
Term | DPIARecommendsProcessingNotContinue | Prefix | eu-gdpr |
---|---|---|---|
Label | DPIA Recommends Processing Not Continue | ||
IRI | https://w3id.org/dpv/legal/eu/gdpr#DPIARecommendsProcessingNotContinue | ||
Type | rdfs:Class, skos:Concept, eu-gdpr:DPIAProcessingRecommendation | ||
Broader/Parent types | eu-gdpr:DPIAProcessingRecommendation → dpv:AuditStatus → dpv:Status → dpv:Context | ||
Object of relation | dpv:hasAuditStatus, dpv:hasContext, dpv:hasStatus | ||
Definition | Recommendation from a DPIA that the processing should not continue | ||
Date Created | 2022-10-22 | ||
Contributors | Georg P. Krog, Harshvardhan J. Pandit | ||
See More: | section DPIA in EU-GDPR |
Term | DPIARequired | Prefix | eu-gdpr |
---|---|---|---|
Label | DPIA Required | ||
IRI | https://w3id.org/dpv/legal/eu/gdpr#DPIARequired | ||
Type | rdfs:Class, skos:Concept, eu-gdpr:DPIANecessityStatus | ||
Broader/Parent types | eu-gdpr:DPIANecessityStatus → dpv:AuditStatus → dpv:Status → dpv:Context | ||
Object of relation | dpv:hasAuditStatus, dpv:hasContext, dpv:hasStatus | ||
Definition | Condition where a DPIA is required | ||
Date Created | 2022-06-22 | ||
Contributors | Harshvardhan J. Pandit | ||
See More: | section DPIA in EU-GDPR |
Term | DPIARiskStatus | Prefix | eu-gdpr |
---|---|---|---|
Label | DPIA Risk Status | ||
IRI | https://w3id.org/dpv/legal/eu/gdpr#DPIARiskStatus | ||
Type | rdfs:Class, skos:Concept | ||
Broader/Parent types | dpv:AuditStatus → dpv:Status → dpv:Context | ||
Object of relation | dpv:hasAuditStatus, dpv:hasContext, dpv:hasStatus | ||
Definition | Status reflecting the status of risk associated with a DPIA | ||
Date Created | 2022-06-22 | ||
Contributors | Harshvardhan J. Pandit | ||
See More: | section DPIA in EU-GDPR |
Term | Establishment | Prefix | eu-gdpr |
---|---|---|---|
Label | Establishment | ||
IRI | https://w3id.org/dpv/legal/eu/gdpr#Establishment | ||
Type | rdfs:Class, skos:Concept | ||
Broader/Parent types | dpv:Organisation → dpv:LegalEntity → dpv:Entity | ||
Object of relation | dpv:hasActiveEntity, dpv:hasEntity, dpv:hasNonInvolvedEntity, dpv:hasParty, dpv:hasPassiveEntity, dpv:hasResponsibleEntity, dpv:hasSubsidiary, dpv:isDeterminedByEntity, dpv:isImplementedByEntity, dpv:isIndicatedBy, dpv:isOrganisationalUnitOf, dpv:isRepresentativeFor, dpv:isSubsidiaryOf, eu-gdpr:hasEstablishment, eu-gdpr:hasMainEstablishment, eu-gdpr:isMainEstablishmentFor | ||
Definition | Establishment is a Legal Entity which implies the effective and real exercise of activities through stable arrangements (with a presumed parent or primary establishment) | ||
Source | GDPR Art.56, Guidelines 3/2018 on the territorial scope of the GDPR (Article 3) Version 2.1, GDPR Recital 22 | ||
Date Created | 2024-02-14 | ||
Contributors | Georg P. Krog, Harshvardhan J. Pandit | ||
See More: | section ENTITIES in EU-GDPR |
Term | FairnessPrinciple | Prefix | eu-gdpr |
---|---|---|---|
Label | Fairness Principle | ||
IRI | https://w3id.org/dpv/legal/eu/gdpr#FairnessPrinciple | ||
Type | rdfs:Class, skos:Concept, dpv:OrganisationalMeasure | ||
Broader/Parent types | dpv:Principle → dpv:GuidelinesPrinciple → dpv:OrganisationalMeasure → dpv:TechnicalOrganisationalMeasure | ||
Object of relation | dpv:hasOrganisationalMeasure, dpv:hasTechnicalOrganisationalMeasure | ||
Definition | Principle stating personal data must be processed processed fairly in relation to the data subject | ||
Source | GDPR Art.5-1a | ||
Date Created | 2024-05-12 | ||
Contributors | Georg P. Krog | ||
See More: | section PRINCIPLES in EU-GDPR |
Term | GDPRComplianceUnknown | Prefix | eu-gdpr |
---|---|---|---|
Label | GDPR Compliance Unknown | ||
IRI | https://w3id.org/dpv/legal/eu/gdpr#GDPRComplianceUnknown | ||
Type | rdfs:Class, skos:Concept, dpv:Lawfulness | ||
Broader/Parent types | eu-gdpr:GDPRLawfulness → dpv:Lawfulness → dpv:ComplianceStatus → dpv:Status → dpv:Context | ||
Object of relation | dpv:hasComplianceStatus, dpv:hasContext, dpv:hasLawfulness, dpv:hasStatus | ||
Definition | State where lawfulness or compliance with GDPR is unknown | ||
Date Created | 2022-10-22 | ||
Contributors | Harshvardhan J. Pandit | ||
See More: | section COMPLIANCE in EU-GDPR |
Term | GDPRCompliant | Prefix | eu-gdpr |
---|---|---|---|
Label | GDPR Compliant | ||
IRI | https://w3id.org/dpv/legal/eu/gdpr#GDPRCompliant | ||
Type | rdfs:Class, skos:Concept, dpv:Lawfulness | ||
Broader/Parent types | eu-gdpr:GDPRLawfulness → dpv:Lawfulness → dpv:ComplianceStatus → dpv:Status → dpv:Context | ||
Object of relation | dpv:hasComplianceStatus, dpv:hasContext, dpv:hasLawfulness, dpv:hasStatus | ||
Definition | State of being lawful or legally compliant for GDPR | ||
Date Created | 2022-10-22 | ||
Contributors | Harshvardhan J. Pandit | ||
See More: | section COMPLIANCE in EU-GDPR |
Term | GDPRLawfulness | Prefix | eu-gdpr |
---|---|---|---|
Label | GDPR Lawfulness | ||
IRI | https://w3id.org/dpv/legal/eu/gdpr#GDPRLawfulness | ||
Type | rdfs:Class, skos:Concept, dpv:Lawfulness | ||
Broader/Parent types | dpv:Lawfulness → dpv:ComplianceStatus → dpv:Status → dpv:Context | ||
Object of relation | dpv:hasComplianceStatus, dpv:hasContext, dpv:hasLawfulness, dpv:hasStatus | ||
Definition | Status or state associated with being lawful or legally compliant regarding GDPR | ||
Examples | dex:E0055 :: Specifying compliance status and lawfulness |
||
Date Created | 2022-10-22 | ||
Contributors | Harshvardhan J. Pandit | ||
See More: | section COMPLIANCE in DEX |
Term | GDPRNonCompliant | Prefix | eu-gdpr |
---|---|---|---|
Label | GDPR Non-compliant | ||
IRI | https://w3id.org/dpv/legal/eu/gdpr#GDPRNonCompliant | ||
Type | rdfs:Class, skos:Concept, dpv:Lawfulness | ||
Broader/Parent types | eu-gdpr:GDPRLawfulness → dpv:Lawfulness → dpv:ComplianceStatus → dpv:Status → dpv:Context | ||
Object of relation | dpv:hasComplianceStatus, dpv:hasContext, dpv:hasLawfulness, dpv:hasStatus | ||
Definition | State of being unlawful or legally non-compliant for GDPR | ||
Date Created | 2022-10-22 | ||
Contributors | Harshvardhan J. Pandit | ||
See More: | section COMPLIANCE in EU-GDPR |
Term | GDPRRightsImpact | Prefix | eu-gdpr |
---|---|---|---|
Label | GDPR Rights Impact | ||
IRI | https://w3id.org/dpv/legal/eu/gdpr#GDPRRightsImpact | ||
Type | rdfs:Class, skos:Concept, dpv:RiskConcept, risk:PotentialConsequence, risk:PotentialImpact, risk:PotentialRisk | ||
Broader/Parent types | risk:RightsImpact → risk:SocietalRiskConcept → dpv:RiskConcept | ||
Object of relation | risk:avoids, risk:contains, risk:controls, risk:detects, risk:eliminates, risk:identifies, risk:interrupts, risk:intervenes, risk:investigates, risk:logs, risk:mitigates, risk:modifies, risk:monitors, risk:overrides, risk:recovers, risk:reduces, risk:remedies, risk:resolves, risk:reverses, risk:shares, risk:substitutes, risk:transfers | ||
Definition | Something that acts as or is considered as an impact on one or more rights defined by GDPR | ||
Date Created | 2024-12-01 | ||
Date Modified | 2025-08-17 | ||
See More: | section RIGHTS-IMPACTS in EU-GDPR |
Term | GeneticData | Prefix | eu-gdpr |
---|---|---|---|
Label | Genetic Data | ||
IRI | https://w3id.org/dpv/legal/eu/gdpr#GeneticData | ||
Type | rdfs:Class, skos:Concept, dpv:PersonalData | ||
Broader/Parent types | pd:Genetic → pd:Health → pd:MedicalHealth → dpv:SpecialCategoryPersonalData → dpv:SensitivePersonalData → dpv:PersonalData → dpv:Data | ||
Broader/Parent types | pd:Genetic → pd:Health → pd:MedicalHealth → dpv:SpecialCategoryPersonalData → dpv:SensitivePersonalData → dpv:SensitiveData → dpv:Data | ||
Broader/Parent types | pd:Genetic → pd:Health → pd:MedicalHealth → pd:External → dpv:PersonalData → dpv:Data | ||
Object of relation | dpv:hasData, dpv:hasPersonalData | ||
Definition | ‘Genetic Data’ means personal data relating to the inherited or acquired genetic characteristics of a natural person which give unique information about the physiology or the health of that natural person and which result, in particular, from an analysis of a biological sample from the natural person in question | ||
Date Created | 2024-12-17 | ||
Date Modified | 2025-07-26 | ||
Contributors | Harshvardhan J. Pandit | ||
See More: | section MISC-CONCEPTS in EU-GDPR |
Term | HealthData | Prefix | eu-gdpr |
---|---|---|---|
Label | Health Data | ||
IRI | https://w3id.org/dpv/legal/eu/gdpr#HealthData | ||
Type | rdfs:Class, skos:Concept, dpv:PersonalData | ||
Broader/Parent types | pd:MedicalHealth → dpv:SpecialCategoryPersonalData → dpv:SensitivePersonalData → dpv:PersonalData → dpv:Data | ||
Broader/Parent types | pd:MedicalHealth → dpv:SpecialCategoryPersonalData → dpv:SensitivePersonalData → dpv:SensitiveData → dpv:Data | ||
Broader/Parent types | pd:MedicalHealth → pd:External → dpv:PersonalData → dpv:Data | ||
Object of relation | dpv:hasData, dpv:hasPersonalData | ||
Definition | Health Data' or 'data concerning health’ means personal data related to the physical or mental health of a natural person, including the provision of health care services, which reveal information about his or her health status | ||
Date Created | 2024-12-17 | ||
Date Modified | 2025-07-28 | ||
Contributors | Harshvardhan J. Pandit | ||
See More: | section MISC-CONCEPTS in EU-GDPR |
Term | IndirectDataCollectionNotice | Prefix | eu-gdpr |
---|---|---|---|
Label | Indirect Data Collection Notice | ||
IRI | https://w3id.org/dpv/legal/eu/gdpr#IndirectDataCollectionNotice | ||
Type | rdfs:Class, skos:Concept, dpv:OrganisationalMeasure | ||
Broader/Parent types | dpv:RightFulfilmentNotice → dpv:RightExerciseNotice → dpv:RightNotice → dpv:Notice → dpv:OrganisationalMeasure → dpv:TechnicalOrganisationalMeasure | ||
Object of relation | dpv:hasNotice, dpv:hasOrganisationalMeasure, dpv:hasTechnicalOrganisationalMeasure, dpv:isExercisedAt | ||
Definition | A Notice provided in fulfilment of GDPR's Art.14 regarding information to be provided where personal data are not collected from the data subject | ||
Date Created | 2022-11-09 | ||
Contributors | Beatriz Esteves, Georg P. Krog, Harshvardhan J. Pandit | ||
See More: | section RIGHTS in EU-GDPR |
Term | InformationSocietyService | Prefix | eu-gdpr |
---|---|---|---|
Label | Information Society Service | ||
IRI | https://w3id.org/dpv/legal/eu/gdpr#InformationSocietyService | ||
Type | rdfs:Class, skos:Concept | ||
Broader/Parent types | dpv:Service → dpv:Process | ||
Object of relation | dpv:hasProcess, dpv:hasService | ||
Definition | Information Society Service’ means a service as defined in point (b) of Article 1(1) of Directive (EU) 2015/1535 of the European Parliament and of the Council | ||
Date Created | 2024-12-17 | ||
Date Modified | 2025-07-30 | ||
Contributors | Harshvardhan J. Pandit | ||
See More: | section MISC-CONCEPTS in EU-GDPR |
Term | IntegrityBreach | Prefix | eu-gdpr |
---|---|---|---|
Label | Integrity Breach | ||
IRI | https://w3id.org/dpv/legal/eu/gdpr#IntegrityBreach | ||
Type | rdfs:Class, skos:Concept | ||
Broader/Parent types | eu-gdpr:DataBreach → risk:Incident → dpv:RiskConcept | ||
Object of relation | risk:avoids, risk:contains, risk:controls, risk:detects, risk:eliminates, risk:hasIncident, risk:identifies, risk:interrupts, risk:intervenes, risk:investigates, risk:logs, risk:mitigates, risk:modifies, risk:monitors, risk:overrides, risk:recovers, risk:reduces, risk:remedies, risk:resolves, risk:reverses, risk:shares, risk:substitutes, risk:transfers | ||
Definition | A data breach where there is an unauthorised or accidental alteration of personal data | ||
Source | EDPB Guidelines 9/2022 on personal data breach notification under GDPR | ||
Date Created | 2024-05-19 | ||
See More: | section DATA-BREACH in EU-GDPR |
Term | IntegrityConfidentialityPrinciple | Prefix | eu-gdpr |
---|---|---|---|
Label | Integrity Confidentiality Principle | ||
IRI | https://w3id.org/dpv/legal/eu/gdpr#IntegrityConfidentialityPrinciple | ||
Type | rdfs:Class, skos:Concept, dpv:OrganisationalMeasure | ||
Broader/Parent types | dpv:Principle → dpv:GuidelinesPrinciple → dpv:OrganisationalMeasure → dpv:TechnicalOrganisationalMeasure | ||
Object of relation | dpv:hasOrganisationalMeasure, dpv:hasTechnicalOrganisationalMeasure | ||
Definition | Principle stating personal data must be processed in a manner that ensures appropriate security of the personal data, including protection against unauthorised or unlawful processing and against accidental loss, destruction or damage, using appropriate technical or organisational measures | ||
Source | GDPR Art.5-1f | ||
Date Created | 2024-05-12 | ||
Contributors | Georg P. Krog | ||
See More: | section PRINCIPLES in EU-GDPR |
Term | JustificationA12Complexity | Prefix | eu-gdpr |
---|---|---|---|
Label | Justification A12 - Complexity | ||
IRI | https://w3id.org/dpv/legal/eu/gdpr#JustificationA12Complexity | ||
Type | rdfs:Class, skos:Concept, dpv:Justification | ||
Broader/Parent types | justifications:ComplexityOfProcess → justifications:DelayJustification → dpv:Justification → dpv:Context | ||
Broader/Parent types | eu-gdpr:JustificationA12Delay → justifications:DelayJustification → dpv:Justification → dpv:Context | ||
Object of relation | dpv:hasContext, dpv:hasJustification | ||
Definition | Justification that the request under A15-A22 is delayed due to complexity in fulfilling it | ||
Source | GDPR Art.12-3 | ||
Date Created | 2024-12-17 | ||
Contributors | Beatriz Esteves, Georg P. Krog, Harshvardhan J. Pandit | ||
See More: | section RIGHTS-JUSTIFICATIONS in EU-GDPR |
Term | JustificationA12Delay | Prefix | eu-gdpr |
---|---|---|---|
Label | Justification A12 - Delay | ||
IRI | https://w3id.org/dpv/legal/eu/gdpr#JustificationA12Delay | ||
Type | rdfs:Class, skos:Concept, dpv:Justification | ||
Broader/Parent types | justifications:DelayJustification → dpv:Justification → dpv:Context | ||
Object of relation | dpv:hasContext, dpv:hasJustification | ||
Definition | Justification that the request under A15-A22 is delayed | ||
Usage Note | The justification is for when the initial process, which is to be completed within one month of receipt of the request, is delayed with Art.12-3 stating a duration of two further months where necessary taking into account the complexity and number of the requests. In such cases, the controller is needed to inform the data subject of the extension within one month of receipt of the request together with the reasons for the delay - which is done through this extension. Information about expected duration of response can be provided through use of dpv:hasDuration. The specific nature of delay can be expressed through use of eu-gdpr:A12ComplexityOfRequest or eu-gdpr:A12HighVolumeOfRequest | ||
Source | GDPR Art.12-3 | ||
Date Created | 2024-12-17 | ||
Contributors | Beatriz Esteves, Georg P. Krog, Harshvardhan J. Pandit | ||
See More: | section RIGHTS-JUSTIFICATIONS in EU-GDPR |
Term | JustificationA12HighVolume | Prefix | eu-gdpr |
---|---|---|---|
Label | Justification A12 - High Volume | ||
IRI | https://w3id.org/dpv/legal/eu/gdpr#JustificationA12HighVolume | ||
Type | rdfs:Class, skos:Concept, dpv:Justification | ||
Broader/Parent types | justifications:HighVolumeOfProcesses → justifications:DelayJustification → dpv:Justification → dpv:Context | ||
Broader/Parent types | eu-gdpr:JustificationA12Delay → justifications:DelayJustification → dpv:Justification → dpv:Context | ||
Object of relation | dpv:hasContext, dpv:hasJustification | ||
Definition | Justification that the request under A15-A22 is delayed due to high volume of similar requestes required to be fulfilled | ||
Source | GDPR Art.12-3 | ||
Date Created | 2024-12-17 | ||
Contributors | Beatriz Esteves, Georg P. Krog, Harshvardhan J. Pandit | ||
See More: | section RIGHTS-JUSTIFICATIONS in EU-GDPR |
Term | JustificationA12IdentityFailure | Prefix | eu-gdpr |
---|---|---|---|
Label | Justification A12 - Identity Failure | ||
IRI | https://w3id.org/dpv/legal/eu/gdpr#JustificationA12IdentityFailure | ||
Type | rdfs:Class, skos:Concept, dpv:Justification | ||
Broader/Parent types | justifications:IdentityVerificationFailure → justifications:LegalProcessImpaired → justifications:NonFulfilmentJustification → dpv:Justification → dpv:Context | ||
Broader/Parent types | justifications:IdentityVerificationFailure → justifications:SecurityImpaired → justifications:NonFulfilmentJustification → dpv:Justification → dpv:Context | ||
Object of relation | dpv:hasContext, dpv:hasJustification | ||
Definition | Justification that a request under A14-21 could not be fulfilled due to lack of identity verification | ||
Usage Note | For justifications where identity cannot be verified and requires additional information, eu-gdpr:A12IdentityVerificationRequired should be used | ||
Source | GDPR Art.12-6 | ||
Date Created | 2024-12-17 | ||
Contributors | Beatriz Esteves, Georg P. Krog, Harshvardhan J. Pandit | ||
See More: | section RIGHTS-JUSTIFICATIONS in EU-GDPR |
Term | JustificationA12IdentityRequired | Prefix | eu-gdpr |
---|---|---|---|
Label | Justification A12 - Identity Required | ||
IRI | https://w3id.org/dpv/legal/eu/gdpr#JustificationA12IdentityRequired | ||
Type | rdfs:Class, skos:Concept, dpv:Justification | ||
Broader/Parent types | justifications:IdentityVerificationRequired → justifications:DelayJustification → dpv:Justification → dpv:Context | ||
Object of relation | dpv:hasContext, dpv:hasJustification | ||
Definition | Justification that a request under A14-21 could not be fulfilled due to lack of identity verification, and therefore requires additional information to complete the identity verification request | ||
Usage Note | If the purpose of this justification is to ask for identity verification, then it requires information on what information is considered as an acceptable form of identity, which can ideally be expressed through dpv:Process and relevant dpv:PersonalData categories, or through a comment or description for the justification | ||
Source | GDPR Art.12-6 | ||
Date Created | 2024-12-17 | ||
Contributors | Beatriz Esteves, Georg P. Krog, Harshvardhan J. Pandit | ||
See More: | section RIGHTS-JUSTIFICATIONS in EU-GDPR |
Term | JustificationA12InformationRequired | Prefix | eu-gdpr |
---|---|---|---|
Label | Justification A12 - Information Required | ||
IRI | https://w3id.org/dpv/legal/eu/gdpr#JustificationA12InformationRequired | ||
Type | rdfs:Class, skos:Concept, dpv:Justification | ||
Broader/Parent types | justifications:InformationRequired → justifications:DelayJustification → dpv:Justification → dpv:Context | ||
Object of relation | dpv:hasContext, dpv:hasJustification | ||
Definition | Justification that the request under A14-21 could not be fulfilled due to additional information being required | ||
Usage Note | If the purpose of this justification is to ask for identity verification, then eu-gdpr:A12IdentityVerificationRequired should be used. The information required can be expressed using dpv:Process, which allows also expressing the purpose for why it is required and relevant dpv:PersonalData categories, or through a comment or description for the justification | ||
Source | GDPR Art.12-6 | ||
Date Created | 2024-12-17 | ||
Contributors | Beatriz Esteves, Georg P. Krog, Harshvardhan J. Pandit | ||
See More: | section RIGHTS-JUSTIFICATIONS in EU-GDPR |
Term | JustificationA12LackOfIntent | Prefix | eu-gdpr |
---|---|---|---|
Label | Justification A12 - Lack Of Intent | ||
IRI | https://w3id.org/dpv/legal/eu/gdpr#JustificationA12LackOfIntent | ||
Type | rdfs:Class, skos:Concept, dpv:Justification | ||
Broader/Parent types | eu-gdpr:JustificationA12ManifestlyUnfounded → justifications:ProcessUnfounded → justifications:ProcessRejected → justifications:NonFulfilmentJustification → dpv:Justification → dpv:Context | ||
Broader/Parent types | justifications:LackOfIntent → justifications:NonFulfilmentJustification → dpv:Justification → dpv:Context | ||
Object of relation | dpv:hasContext, dpv:hasJustification | ||
Definition | Justification that a request under A13-A22 and A34 is manifestly unfounded - in particular due to a lack of intent - and therefore is being charged a fee or is being refused | ||
Usage Note | This justification requires information on why or how the lack of intent was assessed, which can be provided as a description of comment | ||
Source | GDPR Art.12-5 | ||
Date Created | 2024-12-17 | ||
Contributors | Beatriz Esteves, Georg P. Krog, Harshvardhan J. Pandit | ||
See More: | section RIGHTS-JUSTIFICATIONS in EU-GDPR |
Term | JustificationA12MaliciousIntent | Prefix | eu-gdpr |
---|---|---|---|
Label | Justification A12 - Malicious Intent | ||
IRI | https://w3id.org/dpv/legal/eu/gdpr#JustificationA12MaliciousIntent | ||
Type | rdfs:Class, skos:Concept, dpv:Justification | ||
Broader/Parent types | eu-gdpr:JustificationA12ManifestlyUnfounded → justifications:ProcessUnfounded → justifications:ProcessRejected → justifications:NonFulfilmentJustification → dpv:Justification → dpv:Context | ||
Broader/Parent types | justifications:ProcessMalicious → justifications:ProcessRejected → justifications:NonFulfilmentJustification → dpv:Justification → dpv:Context | ||
Object of relation | dpv:hasContext, dpv:hasJustification | ||
Definition | Justification that a request under A13-A22 and A34 is manifestly unfounded - in particular due to malicious intent - and therefore is being charged a fee or is being refused | ||
Usage Note | This justification requires information on why or how the malicious intent was assessed, which can be provided as a description of comment | ||
Source | GDPR Art.12-5 | ||
Date Created | 2024-12-17 | ||
Contributors | Beatriz Esteves, Georg P. Krog, Harshvardhan J. Pandit | ||
See More: | section RIGHTS-JUSTIFICATIONS in EU-GDPR |
Term | JustificationA12ManifestlyExcessive | Prefix | eu-gdpr |
---|---|---|---|
Label | Justification A12 - Manifestly Excessive | ||
IRI | https://w3id.org/dpv/legal/eu/gdpr#JustificationA12ManifestlyExcessive | ||
Type | rdfs:Class, skos:Concept, dpv:Justification | ||
Broader/Parent types | justifications:ProcessExcessive → justifications:ProcessRejected → justifications:NonFulfilmentJustification → dpv:Justification → dpv:Context | ||
Object of relation | dpv:hasContext, dpv:hasJustification | ||
Definition | Justification that a request under A13-A22 and A34 is manifestly excessive and therefore is being charged a fee or is being refused | ||
Usage Note | This justification requires information on why or how the assessment of manifestly excessive was made, which can be provided as a description of comment | ||
Source | GDPR Art.12-5 | ||
Date Created | 2024-12-17 | ||
Contributors | Beatriz Esteves, Georg P. Krog, Harshvardhan J. Pandit | ||
See More: | section RIGHTS-JUSTIFICATIONS in EU-GDPR |
Term | JustificationA12ManifestlyUnfounded | Prefix | eu-gdpr |
---|---|---|---|
Label | Justification A12 - Manifestly Unfounded | ||
IRI | https://w3id.org/dpv/legal/eu/gdpr#JustificationA12ManifestlyUnfounded | ||
Type | rdfs:Class, skos:Concept, dpv:Justification | ||
Broader/Parent types | justifications:ProcessUnfounded → justifications:ProcessRejected → justifications:NonFulfilmentJustification → dpv:Justification → dpv:Context | ||
Object of relation | dpv:hasContext, dpv:hasJustification | ||
Definition | Justification that a process under A13-A22 and A34 is manifestly unfounded and therefore is being charged a fee or is being refused | ||
Usage Note | This justification requires information on why the process was considered manifestly unfounded which can be expressed through the additional concepts provided such as eu-gdpr:A12LackOfIntent or eu-gdpr:A12MaliciousIntent, or which can be provided as a description of comment | ||
Source | GDPR Art.12-5 | ||
Date Created | 2024-12-17 | ||
Contributors | Beatriz Esteves, Georg P. Krog, Harshvardhan J. Pandit | ||
See More: | section RIGHTS-JUSTIFICATIONS in EU-GDPR |
Term | JustificationA13EntityAlreadyInformed | Prefix | eu-gdpr |
---|---|---|---|
Label | Justification A13 - Entity Already Informed | ||
IRI | https://w3id.org/dpv/legal/eu/gdpr#JustificationA13EntityAlreadyInformed | ||
Type | rdfs:Class, skos:Concept, dpv:Justification | ||
Broader/Parent types | justifications:EntityAlreadyInformed → justifications:DisproportionateEffortRequired → justifications:NonFulfilmentJustification → dpv:Justification → dpv:Context | ||
Object of relation | dpv:hasContext, dpv:hasJustification | ||
Definition | Justification that A13 obligations for providing information do not apply as the data subject already has the information | ||
Usage Note | This justification requires information on how the data subject was provided the information to satisfy the assertion, which can be provided as a description of comment | ||
Source | GDPR Art.13-4 | ||
Date Created | 2024-12-17 | ||
Contributors | Beatriz Esteves, Georg P. Krog, Harshvardhan J. Pandit | ||
See More: | section RIGHTS-JUSTIFICATIONS in EU-GDPR |
Term | JustificationA14ConfidentialityCompromised | Prefix | eu-gdpr |
---|---|---|---|
Label | Justification A14 - Confidentiality Compromised | ||
IRI | https://w3id.org/dpv/legal/eu/gdpr#JustificationA14ConfidentialityCompromised | ||
Type | rdfs:Class, skos:Concept, dpv:Justification | ||
Broader/Parent types | justifications:ConfidentialityObligationCompromised → justifications:LegalProcessImpaired → justifications:NonFulfilmentJustification → dpv:Justification → dpv:Context | ||
Object of relation | dpv:hasContext, dpv:hasJustification | ||
Definition | Justification that A14 obligations for providing information cannot be fulfilled as the personal data must remain confidential subject to an obligation of professional secrecy regulated by Union or Member State law, including a statutory obligation of secrecy | ||
Usage Note | This justification requires information on which legal provision provides the confidentiality obligation, which can be provided as a description of comment, or ideally through dpv:hasApplicableLaw to refer to the specific law or through dpv:hasLegalBasis to refer to the specific legal basis enabling this justification | ||
Source | GDPR Art.14-5d | ||
Date Created | 2024-12-17 | ||
Contributors | Beatriz Esteves, Georg P. Krog, Harshvardhan J. Pandit | ||
See More: | section RIGHTS-JUSTIFICATIONS in EU-GDPR |
Term | JustificationA14DisproportionateEffort | Prefix | eu-gdpr |
---|---|---|---|
Label | Justification A14 - Disproportionate Effort | ||
IRI | https://w3id.org/dpv/legal/eu/gdpr#JustificationA14DisproportionateEffort | ||
Type | rdfs:Class, skos:Concept, dpv:Justification | ||
Broader/Parent types | justifications:DisproportionateEffortRequired → justifications:NonFulfilmentJustification → dpv:Justification → dpv:Context | ||
Object of relation | dpv:hasContext, dpv:hasJustification | ||
Definition | Justification that A14 obligations for providing information will require a disproportionate effort to fulfill | ||
Usage Note | This justification requires information on why the effort is considered disproportionate, such as the amount of time or resources required, which can be provided as a description of comment | ||
Source | GDPR Art.14-5b | ||
Date Created | 2024-12-17 | ||
Contributors | Beatriz Esteves, Georg P. Krog, Harshvardhan J. Pandit | ||
See More: | section RIGHTS-JUSTIFICATIONS in EU-GDPR |
Term | JustificationA14EntityAlreadyInformed | Prefix | eu-gdpr |
---|---|---|---|
Label | Justification A14 - Entity Already Informed | ||
IRI | https://w3id.org/dpv/legal/eu/gdpr#JustificationA14EntityAlreadyInformed | ||
Type | rdfs:Class, skos:Concept, dpv:Justification | ||
Broader/Parent types | justifications:EntityAlreadyInformed → justifications:DisproportionateEffortRequired → justifications:NonFulfilmentJustification → dpv:Justification → dpv:Context | ||
Object of relation | dpv:hasContext, dpv:hasJustification | ||
Definition | Justification that A14 obligations for providing information do not apply as the data subject already has the information | ||
Usage Note | This justification requires information on how the data subject was provided the information to satisfy the assertion, which can be provided as a description of comment | ||
Source | GDPR Art.14-5a | ||
Date Created | 2024-12-17 | ||
Contributors | Beatriz Esteves, Georg P. Krog, Harshvardhan J. Pandit | ||
See More: | section RIGHTS-JUSTIFICATIONS in EU-GDPR |
Term | JustificationA14FulfilmentImpossible | Prefix | eu-gdpr |
---|---|---|---|
Label | Justification A14 - Fulfilment Impossible | ||
IRI | https://w3id.org/dpv/legal/eu/gdpr#JustificationA14FulfilmentImpossible | ||
Type | rdfs:Class, skos:Concept, dpv:Justification | ||
Broader/Parent types | justifications:FulfilmentImpossible → justifications:NonFulfilmentJustification → dpv:Justification → dpv:Context | ||
Object of relation | dpv:hasContext, dpv:hasJustification | ||
Definition | Justification that A14 obligations for providing information are impossible to fulfill | ||
Usage Note | This justification requires information for why the fulfilment is impossible, such as technical impossibility, which can be provided as a description of comment | ||
Source | GDPR Art.14-5b | ||
Date Created | 2024-12-17 | ||
Contributors | Beatriz Esteves, Georg P. Krog, Harshvardhan J. Pandit | ||
See More: | section RIGHTS-JUSTIFICATIONS in EU-GDPR |
Term | JustificationA14LegallyExempted | Prefix | eu-gdpr |
---|---|---|---|
Label | Justification A14 - Legally Exempted | ||
IRI | https://w3id.org/dpv/legal/eu/gdpr#JustificationA14LegallyExempted | ||
Type | rdfs:Class, skos:Concept, dpv:Justification | ||
Broader/Parent types | justifications:LegallyExempted → justifications:LegalProcessImpaired → justifications:NonFulfilmentJustification → dpv:Justification → dpv:Context | ||
Object of relation | dpv:hasContext, dpv:hasJustification | ||
Definition | Justification that A14 obligations for providing information is legally exempted | ||
Usage Note | This justification requires information on which legal provision provides the exemption, which can be provided as a description of comment, or ideally through dpv:hasApplicableLaw to refer to the specific law or through dpv:hasLegalBasis to refer to the specific legal basis enabling this justification | ||
Source | GDPR Art.14-5c | ||
Date Created | 2024-12-17 | ||
Contributors | Beatriz Esteves, Georg P. Krog, Harshvardhan J. Pandit | ||
See More: | section RIGHTS-JUSTIFICATIONS in EU-GDPR |
Term | JustificationA14ObjectivesImpaired | Prefix | eu-gdpr |
---|---|---|---|
Label | Justification A14 - Objectives Impaired | ||
IRI | https://w3id.org/dpv/legal/eu/gdpr#JustificationA14ObjectivesImpaired | ||
Type | rdfs:Class, skos:Concept, dpv:Justification | ||
Broader/Parent types | justifications:ObjectivesImpaired → justifications:NonFulfilmentJustification → dpv:Justification → dpv:Context | ||
Object of relation | dpv:hasContext, dpv:hasJustification | ||
Definition | Justification that A14 obligations for providing information will (seriously) impair the objectives of the processing | ||
Usage Note | This justification requires information on what objectives are being impaired and the nature of impairment, which can be provided as a description of comment | ||
Source | GDPR Art.14-5b | ||
Date Created | 2024-12-17 | ||
Contributors | Beatriz Esteves, Georg P. Krog, Harshvardhan J. Pandit | ||
See More: | section RIGHTS-JUSTIFICATIONS in EU-GDPR |
Term | JustificationA17Archiving | Prefix | eu-gdpr |
---|---|---|---|
Label | Justification A17 - Archiving | ||
IRI | https://w3id.org/dpv/legal/eu/gdpr#JustificationA17Archiving | ||
Type | rdfs:Class, skos:Concept, dpv:Justification | ||
Broader/Parent types | justifications:PublicInterestArchivingImpaired → justifications:LegalProcessImpaired → justifications:NonFulfilmentJustification → dpv:Justification → dpv:Context | ||
Object of relation | dpv:hasContext, dpv:hasJustification | ||
Definition | Justification that the A17 right to erasure or to be forgotten could not be completed due to | ||
Source | GDPR Art.17- | ||
Date Created | 2024-12-17 | ||
Contributors | Harshvardhan J. Pandit | ||
See More: | section RIGHTS-JUSTIFICATIONS in EU-GDPR |
Term | JustificationA17ChildData | Prefix | eu-gdpr |
---|---|---|---|
Label | Justification A17 - Child Data | ||
IRI | https://w3id.org/dpv/legal/eu/gdpr#JustificationA17ChildData | ||
Type | rdfs:Class, skos:Concept, dpv:Justification | ||
Broader/Parent types | justifications:InformationSocietyServicesOffer → justifications:ExerciseJustification → dpv:Justification → dpv:Context | ||
Object of relation | dpv:hasContext, dpv:hasJustification | ||
Definition | Justification that the A17 right to erasure or to be forgotten is being exercised as the personal data of a child have been collected for information society services referred to in A8(1) | ||
Source | GDPR Art.17- | ||
Date Created | 2024-12-17 | ||
Contributors | Beatriz Esteves, Harshvardhan J. Pandit | ||
See More: | section RIGHTS-JUSTIFICATIONS in EU-GDPR |
Term | JustificationA17FreedomOfExpression | Prefix | eu-gdpr |
---|---|---|---|
Label | Justification A17 - Freedom Of Expression | ||
IRI | https://w3id.org/dpv/legal/eu/gdpr#JustificationA17FreedomOfExpression | ||
Type | rdfs:Class, skos:Concept, dpv:Justification | ||
Broader/Parent types | justifications:FreedomOfExpressionImpaired → justifications:LegalProcessImpaired → justifications:NonFulfilmentJustification → dpv:Justification → dpv:Context | ||
Object of relation | dpv:hasContext, dpv:hasJustification | ||
Definition | Justification that the A17 right to erasure or to be forgotten could not be completed as the processing is necessary for exercising the right of freedom of expression and information | ||
Source | GDPR Art.17- | ||
Date Created | 2024-12-17 | ||
Contributors | Harshvardhan J. Pandit | ||
See More: | section RIGHTS-JUSTIFICATIONS in EU-GDPR |
Term | JustificationA17LegalClaims | Prefix | eu-gdpr |
---|---|---|---|
Label | Justification A17 - Legal Claims | ||
IRI | https://w3id.org/dpv/legal/eu/gdpr#JustificationA17LegalClaims | ||
Type | rdfs:Class, skos:Concept, dpv:Justification | ||
Broader/Parent types | justifications:LegalClaimImpaired → justifications:LegalProcessImpaired → justifications:NonFulfilmentJustification → dpv:Justification → dpv:Context | ||
Object of relation | dpv:hasContext, dpv:hasJustification | ||
Definition | Justification that the A17 right to erasure or to be forgotten could not be completed due to | ||
Source | GDPR Art.17- | ||
Date Created | 2024-12-17 | ||
Contributors | Harshvardhan J. Pandit | ||
See More: | section RIGHTS-JUSTIFICATIONS in EU-GDPR |
Term | JustificationA17LegalErasure | Prefix | eu-gdpr |
---|---|---|---|
Label | Justification A17 - Legal Erasure | ||
IRI | https://w3id.org/dpv/legal/eu/gdpr#JustificationA17LegalErasure | ||
Type | rdfs:Class, skos:Concept, dpv:Justification | ||
Broader/Parent types | justifications:LegalObligation → justifications:ExerciseJustification → dpv:Justification → dpv:Context | ||
Object of relation | dpv:hasContext, dpv:hasJustification | ||
Definition | Justification that the A17 right to erasure or to be forgotten is being exercised as the personal data have to be erased for compliance with a legal obligation in Union or Member State law to which the controller is subject | ||
Source | GDPR Art.17- | ||
Date Created | 2024-12-17 | ||
Contributors | Beatriz Esteves, Harshvardhan J. Pandit | ||
See More: | section RIGHTS-JUSTIFICATIONS in EU-GDPR |
Term | JustificationA17LegallyRequired | Prefix | eu-gdpr |
---|---|---|---|
Label | Justification A17 - Legally Required | ||
IRI | https://w3id.org/dpv/legal/eu/gdpr#JustificationA17LegallyRequired | ||
Type | rdfs:Class, skos:Concept, dpv:Justification | ||
Broader/Parent types | justifications:LegalObligationImpaired → justifications:LegalProcessImpaired → justifications:NonFulfilmentJustification → dpv:Justification → dpv:Context | ||
Object of relation | dpv:hasContext, dpv:hasJustification | ||
Definition | Justification that the A17 right to erasure or to be forgotten could not be completed as the processing is required for compliance with a legal obligation | ||
Source | GDPR Art.17- | ||
Date Created | 2024-12-17 | ||
Contributors | Harshvardhan J. Pandit | ||
See More: | section RIGHTS-JUSTIFICATIONS in EU-GDPR |
Term | JustificationA17NoLegalBasis | Prefix | eu-gdpr |
---|---|---|---|
Label | Justification A17 - No Legal Basis | ||
IRI | https://w3id.org/dpv/legal/eu/gdpr#JustificationA17NoLegalBasis | ||
Type | rdfs:Class, skos:Concept, dpv:Justification | ||
Broader/Parent types | justifications:LegalityLackingObjection → justifications:Objection → justifications:ExerciseJustification → dpv:Justification → dpv:Context | ||
Object of relation | dpv:hasContext, dpv:hasJustification | ||
Definition | Justification that the A17 right to erasure or to be forgotten is being exercised as the corresponding consent has been withdrawn and there is no other legal basis for the processing | ||
Source | GDPR Art.17- | ||
Date Created | 2024-12-17 | ||
Contributors | Beatriz Esteves, Harshvardhan J. Pandit | ||
See More: | section RIGHTS-JUSTIFICATIONS in EU-GDPR |
Term | JustificationA17NonNecessity | Prefix | eu-gdpr |
---|---|---|---|
Label | Justification A17 - Non-Necessity | ||
IRI | https://w3id.org/dpv/legal/eu/gdpr#JustificationA17NonNecessity | ||
Type | rdfs:Class, skos:Concept, dpv:Justification | ||
Broader/Parent types | justifications:NonNecessityObjection → justifications:Objection → justifications:ExerciseJustification → dpv:Justification → dpv:Context | ||
Object of relation | dpv:hasContext, dpv:hasJustification | ||
Definition | Justification that the A17 right to erasure or to be forgotten is being exercised as the personal data are no longer necessary in relation to the purposes for which they were collected or otherwise processed | ||
Source | GDPR Art.17- | ||
Date Created | 2024-12-17 | ||
Contributors | Beatriz Esteves, Harshvardhan J. Pandit | ||
See More: | section RIGHTS-JUSTIFICATIONS in EU-GDPR |
Term | JustificationA17ObjectA21 | Prefix | eu-gdpr |
---|---|---|---|
Label | Justification A17 - Object A21 | ||
IRI | https://w3id.org/dpv/legal/eu/gdpr#JustificationA17ObjectA21 | ||
Type | rdfs:Class, skos:Concept, dpv:Justification | ||
Broader/Parent types | justifications:Objection → justifications:ExerciseJustification → dpv:Justification → dpv:Context | ||
Object of relation | dpv:hasContext, dpv:hasJustification | ||
Definition | Justification that the A17 right to erasure or to be forgotten is being exercised through A21 right to object where there are no overriding legitimate grounds for the processing (A21-1) or as an objection to direct marketing (A21-2) | ||
Source | GDPR Art.17- | ||
Date Created | 2024-12-17 | ||
Contributors | Beatriz Esteves, Harshvardhan J. Pandit | ||
See More: | section RIGHTS-JUSTIFICATIONS in EU-GDPR |
Term | JustificationA17OfficialAuthority | Prefix | eu-gdpr |
---|---|---|---|
Label | Justification A17 - Official Authority | ||
IRI | https://w3id.org/dpv/legal/eu/gdpr#JustificationA17OfficialAuthority | ||
Type | rdfs:Class, skos:Concept, dpv:Justification | ||
Broader/Parent types | justifications:OfficialAuthorityExerciseImpaired → justifications:LegalProcessImpaired → justifications:NonFulfilmentJustification → dpv:Justification → dpv:Context | ||
Object of relation | dpv:hasContext, dpv:hasJustification | ||
Definition | Justification that the A17 right to erasure or to be forgotten could not be completed due to | ||
Source | GDPR Art.17- | ||
Date Created | 2024-12-17 | ||
Contributors | Harshvardhan J. Pandit | ||
See More: | section RIGHTS-JUSTIFICATIONS in EU-GDPR |
Term | JustificationA17PublicHealth | Prefix | eu-gdpr |
---|---|---|---|
Label | Justification A17 - Public Health | ||
IRI | https://w3id.org/dpv/legal/eu/gdpr#JustificationA17PublicHealth | ||
Type | rdfs:Class, skos:Concept, dpv:Justification | ||
Broader/Parent types | justifications:PublicHealthCompromised → justifications:LegalProcessImpaired → justifications:NonFulfilmentJustification → dpv:Justification → dpv:Context | ||
Object of relation | dpv:hasContext, dpv:hasJustification | ||
Definition | Justification that the A17 right to erasure or to be forgotten could not be completed due to | ||
Source | GDPR Art.17- | ||
Date Created | 2024-12-17 | ||
Contributors | Harshvardhan J. Pandit | ||
See More: | section RIGHTS-JUSTIFICATIONS in EU-GDPR |
Term | JustificationA17PublicInterest | Prefix | eu-gdpr |
---|---|---|---|
Label | Justification A17 - Public Interest | ||
IRI | https://w3id.org/dpv/legal/eu/gdpr#JustificationA17PublicInterest | ||
Type | rdfs:Class, skos:Concept, dpv:Justification | ||
Broader/Parent types | justifications:PublicInterestCompromised → justifications:LegalProcessImpaired → justifications:NonFulfilmentJustification → dpv:Justification → dpv:Context | ||
Object of relation | dpv:hasContext, dpv:hasJustification | ||
Definition | Justification that the A17 right to erasure or to be forgotten could not be completed due to | ||
Source | GDPR Art.17- | ||
Date Created | 2024-12-17 | ||
Contributors | Harshvardhan J. Pandit | ||
See More: | section RIGHTS-JUSTIFICATIONS in EU-GDPR |
Term | JustificationA17UnlawfulProcessing | Prefix | eu-gdpr |
---|---|---|---|
Label | Justification A17 - Unlawful Processing | ||
IRI | https://w3id.org/dpv/legal/eu/gdpr#JustificationA17UnlawfulProcessing | ||
Type | rdfs:Class, skos:Concept, dpv:Justification | ||
Broader/Parent types | justifications:UnlawfulActivityObjection → justifications:Objection → justifications:ExerciseJustification → dpv:Justification → dpv:Context | ||
Object of relation | dpv:hasContext, dpv:hasJustification | ||
Definition | Justification that the A17 right to erasure or to be forgotten is being exercised as the personal data have been unlawfully processed | ||
Source | GDPR Art.17- | ||
Date Created | 2024-12-17 | ||
Contributors | Beatriz Esteves, Harshvardhan J. Pandit | ||
See More: | section RIGHTS-JUSTIFICATIONS in EU-GDPR |
Term | JustificationA33BreachedDataIneffective | Prefix | eu-gdpr |
---|---|---|---|
Label | Justification A33 - Breached Data Ineffective | ||
IRI | https://w3id.org/dpv/legal/eu/gdpr#JustificationA33BreachedDataIneffective | ||
Type | rdfs:Class, skos:Concept, dpv:Justification | ||
Broader/Parent types | eu-gdpr:DataBreachJustification → dpv:Justification → dpv:Context | ||
Broader/Parent types | justifications:ProcessSafeguarded → justifications:NotRequiredJustification → dpv:Justification → dpv:Context | ||
Object of relation | dpv:hasContext, dpv:hasJustification | ||
Definition | Justification that the personal data breach was not communicated to the data subject as the controller has implemented appropriate technical and organisational protection measures, and those measures were applied to the personal data affected by the personal data breach, in particular those that render the personal data unintelligible to any person who is not authorised to access it, such as encryption i.e. the breached data cannot be effectively used | ||
Source | GDPR Article33(3a) | ||
Date Created | 2024-12-17 | ||
Contributors | Beatriz Esteves, Georg P. Krog, Harshvardhan J. Pandit | ||
See More: | section DATA-BREACH in EU-GDPR |
Term | JustificationA33DisproportionateEffort | Prefix | eu-gdpr |
---|---|---|---|
Label | Justification A33 - Disproportionate Effort | ||
IRI | https://w3id.org/dpv/legal/eu/gdpr#JustificationA33DisproportionateEffort | ||
Type | rdfs:Class, skos:Concept, dpv:Justification | ||
Broader/Parent types | eu-gdpr:DataBreachJustification → dpv:Justification → dpv:Context | ||
Broader/Parent types | justifications:DisproportionateEffortRequired → justifications:NonFulfilmentJustification → dpv:Justification → dpv:Context | ||
Object of relation | dpv:hasContext, dpv:hasJustification | ||
Definition | Justification that the personal data breach was not communicated to the data subject as it would involve disproportionate effort, and that a public communication or similar measure whereby the data subjects are informed in an equally effective manner has been deployed | ||
Source | GDPR Article33(3c) | ||
Date Created | 2024-12-17 | ||
Contributors | Beatriz Esteves, Georg P. Krog, Harshvardhan J. Pandit | ||
See More: | section DATA-BREACH in EU-GDPR |
Term | JustificationA33NotificationDelay | Prefix | eu-gdpr |
---|---|---|---|
Label | Justification A33 - Notification Delay | ||
IRI | https://w3id.org/dpv/legal/eu/gdpr#JustificationA33NotificationDelay | ||
Type | rdfs:Class, skos:Concept, dpv:Justification | ||
Broader/Parent types | eu-gdpr:DataBreachJustification → dpv:Justification → dpv:Context | ||
Broader/Parent types | justifications:DelayJustification → dpv:Justification → dpv:Context | ||
Object of relation | dpv:hasContext, dpv:hasJustification | ||
Definition | Justification for why the notification about personal data breach to the authority was not communicated within 72 hours after having become aware of it | ||
Source | GDPR Article33(1) | ||
Date Created | 2024-12-17 | ||
Contributors | Beatriz Esteves, Georg P. Krog, Harshvardhan J. Pandit | ||
See More: | section DATA-BREACH in EU-GDPR |
Term | JustificationA33RiskMitigated | Prefix | eu-gdpr |
---|---|---|---|
Label | Justification A33 - Risk Mitigated | ||
IRI | https://w3id.org/dpv/legal/eu/gdpr#JustificationA33RiskMitigated | ||
Type | rdfs:Class, skos:Concept, dpv:Justification | ||
Broader/Parent types | eu-gdpr:DataBreachJustification → dpv:Justification → dpv:Context | ||
Broader/Parent types | justifications:RiskMitigated → justifications:NotRequiredJustification → dpv:Justification → dpv:Context | ||
Object of relation | dpv:hasContext, dpv:hasJustification | ||
Definition | Justification that the personal data breach was not communicated to the data subject as the controller has taken subsequent measures which ensure that the high risk to the rights and freedoms of data subjects is no longer likely to materialise | ||
Source | GDPR Article33(3b) | ||
Date Created | 2024-12-17 | ||
Contributors | Beatriz Esteves, Georg P. Krog, Harshvardhan J. Pandit | ||
See More: | section DATA-BREACH in EU-GDPR |
Term | JustificationA33RiskUnlikely | Prefix | eu-gdpr |
---|---|---|---|
Label | Justification A33 - Risk Unlikely | ||
IRI | https://w3id.org/dpv/legal/eu/gdpr#JustificationA33RiskUnlikely | ||
Type | rdfs:Class, skos:Concept, dpv:Justification | ||
Broader/Parent types | eu-gdpr:DataBreachJustification → dpv:Justification → dpv:Context | ||
Broader/Parent types | justifications:RightsFreedomsImpactUnlikely → justifications:NotRequiredJustification → dpv:Justification → dpv:Context | ||
Object of relation | dpv:hasContext, dpv:hasJustification | ||
Definition | Justification that the notification about personal data breach was not communicated to the authority as it is unlikely to result in a risk to the rights and freedoms of natural persons | ||
Source | GDPR Article33(1) | ||
Date Created | 2024-12-17 | ||
Contributors | Beatriz Esteves, Georg P. Krog, Harshvardhan J. Pandit | ||
See More: | section DATA-BREACH in EU-GDPR |
Term | LawfulnessPrinciple | Prefix | eu-gdpr |
---|---|---|---|
Label | Lawfulness Principle | ||
IRI | https://w3id.org/dpv/legal/eu/gdpr#LawfulnessPrinciple | ||
Type | rdfs:Class, skos:Concept, dpv:OrganisationalMeasure | ||
Broader/Parent types | dpv:Principle → dpv:GuidelinesPrinciple → dpv:OrganisationalMeasure → dpv:TechnicalOrganisationalMeasure | ||
Object of relation | dpv:hasOrganisationalMeasure, dpv:hasTechnicalOrganisationalMeasure | ||
Definition | Principle stating personal data must be processed processed in a lawful manner in relation to the data subject | ||
Source | GDPR Art.5-1a | ||
Date Created | 2024-05-12 | ||
Contributors | Georg P. Krog | ||
See More: | section PRINCIPLES in EU-GDPR |
Term | MainEstablishment | Prefix | eu-gdpr |
---|---|---|---|
Label | Main Establishment | ||
IRI | https://w3id.org/dpv/legal/eu/gdpr#MainEstablishment | ||
Type | rdfs:Class, skos:Concept | ||
Broader/Parent types | eu-gdpr:Establishment → dpv:Organisation → dpv:LegalEntity → dpv:Entity | ||
Object of relation | dpv:hasActiveEntity, dpv:hasEntity, dpv:hasNonInvolvedEntity, dpv:hasParty, dpv:hasPassiveEntity, dpv:hasResponsibleEntity, dpv:hasSubsidiary, dpv:isDeterminedByEntity, dpv:isImplementedByEntity, dpv:isIndicatedBy, dpv:isOrganisationalUnitOf, dpv:isRepresentativeFor, dpv:isSubsidiaryOf, eu-gdpr:hasEstablishment, eu-gdpr:hasMainEstablishment, eu-gdpr:isMainEstablishmentFor | ||
Definition | Main Establishment' means as regards a controller with establishments in more than one Member State, the place of its central administration in the Union, unless the decisions on the purposes and means of the processing of personal data are taken in another establishment of the controller in the Union and the latter establishment has the power to have such decisions implemented, in which case the establishment having taken such decisions is to be considered to be the main establishment; as regards a processor with establishments in more than one Member State, the place of its central administration in the Union, or, if the processor has no central administration in the Union, the establishment of the processor in the Union where the main processing activities in the context of the activities of an establishment of the processor take place to the extent that the processor is subject to specific obligations under this Regulation; | ||
Source | GDPR Art.56, Guidelines 3/2018 on the territorial scope of the GDPR (Article 3) Version 2.1, GDPR Art.4-16 | ||
Date Created | 2024-02-14 | ||
Contributors | Georg P. Krog, Harshvardhan J. Pandit | ||
See More: | section ENTITIES in EU-GDPR |
Term | PersonalData | Prefix | eu-gdpr |
---|---|---|---|
Label | Personal Data | ||
IRI | https://w3id.org/dpv/legal/eu/gdpr#PersonalData | ||
Type | rdfs:Class, skos:Concept | ||
Broader/Parent types | dpv:PersonalData → dpv:Data | ||
Object of relation | dpv:hasData, dpv:hasPersonalData | ||
Definition | Personal Data' means any information relating to an identified or identifiable natural person (‘Data Subject’) | ||
Date Created | 2024-12-17 | ||
Date Modified | 2025-07-22 | ||
Contributors | Harshvardhan J. Pandit | ||
See More: | section MISC-CONCEPTS in EU-GDPR |
Term | Processing | Prefix | eu-gdpr |
---|---|---|---|
Label | Processing | ||
IRI | https://w3id.org/dpv/legal/eu/gdpr#Processing | ||
Type | rdfs:Class, skos:Concept | ||
Broader/Parent types | dpv:Processing | ||
Object of relation | dpv:hasProcessing | ||
Definition | ‘Processing’ means any operation or set of operations which is performed on personal data or on sets of personal data, whether or not by automated means, such as collection, recording, organisation, structuring, storage, adaptation or alteration, retrieval, consultation, use, disclosure by transmission, dissemination or otherwise making available, alignment or combination, restriction, erasure or destruction | ||
Date Created | 2024-12-17 | ||
Date Modified | 2025-07-23 | ||
Contributors | Harshvardhan J. Pandit | ||
See More: | section MISC-CONCEPTS in EU-GDPR |
Term | Processor | Prefix | eu-gdpr |
---|---|---|---|
Label | Processor | ||
IRI | https://w3id.org/dpv/legal/eu/gdpr#Processor | ||
Type | rdfs:Class, skos:Concept | ||
Broader/Parent types | dpv:DataProcessor → dpv:Recipient → dpv:LegalEntity → dpv:Entity | ||
Object of relation | dpv:hasActiveEntity, dpv:hasDataProcessor, dpv:hasEntity, dpv:hasNonInvolvedEntity, dpv:hasParty, dpv:hasPassiveEntity, dpv:hasRecipient, dpv:hasResponsibleEntity, dpv:isDeterminedByEntity, dpv:isImplementedByEntity, dpv:isIndicatedBy, dpv:isOrganisationalUnitOf, dpv:isRepresentativeFor, eu-gdpr:hasEstablishment, eu-gdpr:hasMainEstablishment, eu-gdpr:isMainEstablishmentFor | ||
Definition | ‘Processor’ means a natural or legal person, public authority, agency or other body which processes personal data on behalf of the controller | ||
Source | GDPR Art.4-8 | ||
Date Created | 2024-12-17 | ||
Contributors | Harshvardhan J. Pandit | ||
See More: | section ENTITIES in EU-GDPR |
Term | ProcessorBreachNotice | Prefix | eu-gdpr |
---|---|---|---|
Label | Processor Breach Notice | ||
IRI | https://w3id.org/dpv/legal/eu/gdpr#ProcessorBreachNotice | ||
Type | rdfs:Class, skos:Concept, eu-gdpr:DataBreachNotice | ||
Broader/Parent types | eu-gdpr:DataBreachNotice → dpv:DataBreachNotice → dpv:SecurityIncidentNotice → dpv:Notice → dpv:OrganisationalMeasure → dpv:TechnicalOrganisationalMeasure | ||
Object of relation | dpv:hasNotice, dpv:hasOrganisationalMeasure, dpv:hasTechnicalOrganisationalMeasure | ||
Definition | Notice regarding a data breach to the Processor | ||
Source | GDPR Article 33 | ||
Date Created | 2024-05-19 | ||
See More: | section DATA-BREACH in EU-GDPR |
Term | ProcessorBreachNotificationNeeded | Prefix | eu-gdpr |
---|---|---|---|
Label | Processor Breach Notification Needed | ||
IRI | https://w3id.org/dpv/legal/eu/gdpr#ProcessorBreachNotificationNeeded | ||
Type | rdfs:Class, skos:Concept, eu-gdpr:DataBreachNoticeRequirement | ||
Broader/Parent types | eu-gdpr:DataBreachNoticeRequirement → dpv:AuditStatus → dpv:Status → dpv:Context | ||
Object of relation | dpv:hasAuditStatus, dpv:hasContext, dpv:hasStatus | ||
Definition | Data Breach notification to the Processor is required | ||
Source | GDPR Article 33 | ||
Date Created | 2024-05-19 | ||
See More: | section DATA-BREACH in EU-GDPR |
Term | Profiling | Prefix | eu-gdpr |
---|---|---|---|
Label | Profiling | ||
IRI | https://w3id.org/dpv/legal/eu/gdpr#Profiling | ||
Type | rdfs:Class, skos:Concept, eu-gdpr:Processing | ||
Broader/Parent types | dpv:Profiling → dpv:Use → dpv:Processing | ||
Object of relation | dpv:hasProcessing | ||
Definition | ‘Profiling’ means any form of automated processing of personal data consisting of the use of personal data to evaluate certain personal aspects relating to a natural person, in particular to analyse or predict aspects concerning that natural person’s performance at work, economic situation, health, personal preferences, interests, reliability, behaviour, location or movements | ||
Date Created | 2024-12-17 | ||
Date Modified | 2025-07-24 | ||
Contributors | Harshvardhan J. Pandit | ||
See More: | section MISC-CONCEPTS in EU-GDPR |
Term | Pseudonymisation | Prefix | eu-gdpr |
---|---|---|---|
Label | Pseudonymisation | ||
IRI | https://w3id.org/dpv/legal/eu/gdpr#Pseudonymisation | ||
Type | rdfs:Class, skos:Concept, dpv:TechnicalMeasure | ||
Broader/Parent types | dpv:Pseudonymisation → dpv:Deidentification → dpv:DataSanitisationTechnique → dpv:TechnicalMeasure → dpv:TechnicalOrganisationalMeasure | ||
Object of relation | dpv:hasTechnicalMeasure, dpv:hasTechnicalOrganisationalMeasure | ||
Definition | Pseudonymisation’ means the processing of personal data in such a manner that the personal data can no longer be attributed to a specific data subject without the use of additional information, provided that such additional information is kept separately and is subject to technical and organisational measures to ensure that the personal data are not attributed to an identified or identifiable natural person | ||
Date Created | 2024-12-17 | ||
Date Modified | 2025-07-25 | ||
Contributors | Harshvardhan J. Pandit | ||
See More: | section MISC-CONCEPTS in EU-GDPR |
Term | PurposeLimitationPrinciple | Prefix | eu-gdpr |
---|---|---|---|
Label | Purpose Limitation Principle | ||
IRI | https://w3id.org/dpv/legal/eu/gdpr#PurposeLimitationPrinciple | ||
Type | rdfs:Class, skos:Concept, dpv:OrganisationalMeasure | ||
Broader/Parent types | dpv:Principle → dpv:GuidelinesPrinciple → dpv:OrganisationalMeasure → dpv:TechnicalOrganisationalMeasure | ||
Object of relation | dpv:hasOrganisationalMeasure, dpv:hasTechnicalOrganisationalMeasure | ||
Definition | Principle stating personal data collected for specified, explicit and legitimate purposes and not further processed in a manner that is incompatible with those purposes; further processing for archiving purposes in the public interest, scientific or historical research purposes or statistical purposes shall, in accordance with Article 89(1), not be considered to be incompatible with the initial purposes | ||
Source | GDPR Art.5-1b | ||
Date Created | 2024-05-12 | ||
Contributors | Georg P. Krog | ||
See More: | section PRINCIPLES in EU-GDPR |
Term | Recipient | Prefix | eu-gdpr |
---|---|---|---|
Label | Recipient | ||
IRI | https://w3id.org/dpv/legal/eu/gdpr#Recipient | ||
Type | rdfs:Class, skos:Concept | ||
Broader/Parent types | dpv:Recipient → dpv:LegalEntity → dpv:Entity | ||
Object of relation | dpv:hasActiveEntity, dpv:hasEntity, dpv:hasNonInvolvedEntity, dpv:hasParty, dpv:hasPassiveEntity, dpv:hasRecipient, dpv:hasResponsibleEntity, dpv:isDeterminedByEntity, dpv:isImplementedByEntity, dpv:isIndicatedBy, dpv:isOrganisationalUnitOf, dpv:isRepresentativeFor, eu-gdpr:hasEstablishment, eu-gdpr:hasMainEstablishment, eu-gdpr:isMainEstablishmentFor | ||
Definition | ‘Recipient’ means a natural or legal person, public authority, agency or another body, to which the personal data are disclosed, whether a third party or not | ||
Source | GDPR Art.4-9 | ||
Date Created | 2024-12-17 | ||
Contributors | Harshvardhan J. Pandit | ||
See More: | section ENTITIES in EU-GDPR |
Term | Representative | Prefix | eu-gdpr |
---|---|---|---|
Label | Representative | ||
IRI | https://w3id.org/dpv/legal/eu/gdpr#Representative | ||
Type | rdfs:Class, skos:Concept | ||
Broader/Parent types | dpv:Representative → dpv:LegalEntity → dpv:Entity | ||
Object of relation | dpv:hasActiveEntity, dpv:hasEntity, dpv:hasNonInvolvedEntity, dpv:hasParty, dpv:hasPassiveEntity, dpv:hasRepresentative, dpv:hasResponsibleEntity, dpv:isDeterminedByEntity, dpv:isImplementedByEntity, dpv:isIndicatedBy, dpv:isOrganisationalUnitOf, dpv:isRepresentativeFor, eu-gdpr:hasEstablishment, eu-gdpr:hasMainEstablishment, eu-gdpr:isMainEstablishmentFor | ||
Definition | Representative’ means a natural or legal person established in the Union who, designated by the controller or processor in writing pursuant to Article 27, represents the controller or processor with regard to their respective obligations under this Regulation | ||
Source | GDPR Art.4-17 | ||
Date Created | 2024-12-17 | ||
Contributors | Harshvardhan J. Pandit | ||
See More: | section ENTITIES in EU-GDPR |
Term | RightsRecipientsNotice | Prefix | eu-gdpr |
---|---|---|---|
Label | Rights Recipients Notice | ||
IRI | https://w3id.org/dpv/legal/eu/gdpr#RightsRecipientsNotice | ||
Type | rdfs:Class, skos:Concept, dpv:OrganisationalMeasure | ||
Broader/Parent types | dpv:RightFulfilmentNotice → dpv:RightExerciseNotice → dpv:RightNotice → dpv:Notice → dpv:OrganisationalMeasure → dpv:TechnicalOrganisationalMeasure | ||
Object of relation | dpv:hasNotice, dpv:hasOrganisationalMeasure, dpv:hasTechnicalOrganisationalMeasure, dpv:isExercisedAt | ||
Definition | A Notice provided in fulfilment of GDPR's Art.19 regarding Recipients to whom a rights exercise has been communicated, such as regarding rectification (A.16) or erasure of personal data (A.17) or restriction of processing (A.18) | ||
Date Created | 2022-11-09 | ||
Contributors | Beatriz Esteves, Georg P. Krog, Harshvardhan J. Pandit | ||
See More: | section RIGHTS in EU-GDPR |
Term | SARNotice | Prefix | eu-gdpr |
---|---|---|---|
Label | SAR Notice | ||
IRI | https://w3id.org/dpv/legal/eu/gdpr#SARNotice | ||
Type | rdfs:Class, skos:Concept, dpv:OrganisationalMeasure | ||
Broader/Parent types | dpv:RightFulfilmentNotice → dpv:RightExerciseNotice → dpv:RightNotice → dpv:Notice → dpv:OrganisationalMeasure → dpv:TechnicalOrganisationalMeasure | ||
Object of relation | dpv:hasNotice, dpv:hasOrganisationalMeasure, dpv:hasTechnicalOrganisationalMeasure, dpv:isExercisedAt | ||
Definition | A Notice provided in fulfilment of GDPR's Art.15 regarding information to be provided for Right of Access or Subject Access Request (SAR) | ||
Date Created | 2022-11-09 | ||
Contributors | Beatriz Esteves, Georg P. Krog, Harshvardhan J. Pandit | ||
See More: | section RIGHTS in EU-GDPR |
Term | SCCByCommission | Prefix | eu-gdpr |
---|---|---|---|
Label | SCCs adopted by Commission | ||
IRI | https://w3id.org/dpv/legal/eu/gdpr#SCCByCommission | ||
Type | rdfs:Class, skos:Concept, dpv:OrganisationalMeasure | ||
Broader/Parent types | eu-gdpr:StandardContractualClauses → dpv:Contract → dpv:LegalBasis | ||
Broader/Parent types | eu-gdpr:StandardContractualClauses → eu-gdpr:DataTransferTool → dpv:OrganisationalMeasure → dpv:TechnicalOrganisationalMeasure | ||
Object of relation | dpv:hasLegalBasis, dpv:hasOrganisationalMeasure, dpv:hasTechnicalOrganisationalMeasure | ||
Definition | Standard contractual clauses adopted by the Commission in accordance with the examination procedure referred to in GDPR Article 93(2) | ||
Source | GDPR Art.46-2c | ||
Date Created | 2021-09-22 | ||
Contributors | David Hickey, Georg P. Krog, Harshvardhan J. Pandit, Paul Ryan | ||
See More: | section DATA-TRANSFERS in EU-GDPR |
Term | SCCBySupervisoryAuthority | Prefix | eu-gdpr |
---|---|---|---|
Label | SCCs adopted by Supervisory Authority | ||
IRI | https://w3id.org/dpv/legal/eu/gdpr#SCCBySupervisoryAuthority | ||
Type | rdfs:Class, skos:Concept, dpv:OrganisationalMeasure | ||
Broader/Parent types | eu-gdpr:StandardContractualClauses → dpv:Contract → dpv:LegalBasis | ||
Broader/Parent types | eu-gdpr:StandardContractualClauses → eu-gdpr:DataTransferTool → dpv:OrganisationalMeasure → dpv:TechnicalOrganisationalMeasure | ||
Object of relation | dpv:hasLegalBasis, dpv:hasOrganisationalMeasure, dpv:hasTechnicalOrganisationalMeasure | ||
Definition | Standard data protection clauses adopted by a supervisory authority and approved by the Commission pursuant to the examination procedure referred to in GDPR Article 93(2) | ||
Source | GDPR Art.46-2d | ||
Date Created | 2021-09-22 | ||
Contributors | David Hickey, Georg P. Krog, Harshvardhan J. Pandit, Paul Ryan | ||
See More: | section DATA-TRANSFERS in EU-GDPR |
Term | SingleEstablishment | Prefix | eu-gdpr |
---|---|---|---|
Label | Single Establishment | ||
IRI | https://w3id.org/dpv/legal/eu/gdpr#SingleEstablishment | ||
Type | rdfs:Class, skos:Concept | ||
Broader/Parent types | eu-gdpr:Establishment → dpv:Organisation → dpv:LegalEntity → dpv:Entity | ||
Object of relation | dpv:hasActiveEntity, dpv:hasEntity, dpv:hasNonInvolvedEntity, dpv:hasParty, dpv:hasPassiveEntity, dpv:hasResponsibleEntity, dpv:hasSubsidiary, dpv:isDeterminedByEntity, dpv:isImplementedByEntity, dpv:isIndicatedBy, dpv:isOrganisationalUnitOf, dpv:isRepresentativeFor, dpv:isSubsidiaryOf, eu-gdpr:hasEstablishment, eu-gdpr:hasMainEstablishment, eu-gdpr:isMainEstablishmentFor | ||
Definition | A legal entity that is established in only one Member State | ||
Source | GDPR Art.23 | ||
Date Created | 2024-02-14 | ||
Contributors | Georg P. Krog, Harshvardhan J. Pandit | ||
See More: | section ENTITIES in EU-GDPR |
Term | StandardContractualClauses | Prefix | eu-gdpr |
---|---|---|---|
Label | Standard Contractual Clauses (SCC) | ||
IRI | https://w3id.org/dpv/legal/eu/gdpr#StandardContractualClauses | ||
Type | rdfs:Class, skos:Concept, dpv:OrganisationalMeasure | ||
Broader/Parent types | dpv:Contract → dpv:LegalBasis | ||
Broader/Parent types | eu-gdpr:DataTransferTool → dpv:OrganisationalMeasure → dpv:TechnicalOrganisationalMeasure | ||
Object of relation | dpv:hasLegalBasis, dpv:hasOrganisationalMeasure, dpv:hasTechnicalOrganisationalMeasure | ||
Definition | Standard Contractual Clauses (SCCs) are pre-approved clauses by the EU for ensuring appropriate data protection safeguards intended for data transfers from the EU to third countries | ||
Source | Implementing Decision on SCC for Data Transfers | ||
Date Created | 2021-09-22 | ||
Contributors | David Hickey, Georg P. Krog, Harshvardhan J. Pandit, Paul Ryan | ||
See More: | section DATA-TRANSFERS in EU-GDPR |
Term | StorageLimitationPrinciple | Prefix | eu-gdpr |
---|---|---|---|
Label | Storage Limitation Principle | ||
IRI | https://w3id.org/dpv/legal/eu/gdpr#StorageLimitationPrinciple | ||
Type | rdfs:Class, skos:Concept, dpv:OrganisationalMeasure | ||
Broader/Parent types | dpv:Principle → dpv:GuidelinesPrinciple → dpv:OrganisationalMeasure → dpv:TechnicalOrganisationalMeasure | ||
Object of relation | dpv:hasOrganisationalMeasure, dpv:hasTechnicalOrganisationalMeasure | ||
Definition | Principle stating personal data must be kept in a form which permits identification of data subjects for no longer than is necessary for the purposes for which the personal data are processed; personal data may be stored for longer periods insofar as the personal data will be processed solely for archiving purposes in the public interest, scientific or historical research purposes or statistical purposes in accordance with Article 89(1) subject to implementation of the appropriate technical and organisational measures required by this Regulation in order to safeguard the rights and freedoms of the data subject | ||
Source | GDPR Art.5-1e | ||
Date Created | 2024-05-12 | ||
Contributors | Georg P. Krog | ||
See More: | section PRINCIPLES in EU-GDPR |
Term | SupplementaryMeasure | Prefix | eu-gdpr |
---|---|---|---|
Label | Supplementary Measure | ||
IRI | https://w3id.org/dpv/legal/eu/gdpr#SupplementaryMeasure | ||
Type | rdfs:Class, skos:Concept, dpv:OrganisationalMeasure | ||
Broader/Parent types | eu-gdpr:DataTransferTool → dpv:OrganisationalMeasure → dpv:TechnicalOrganisationalMeasure | ||
Object of relation | dpv:hasOrganisationalMeasure, dpv:hasTechnicalOrganisationalMeasure | ||
Definition | Supplementary measures are intended to additionally provide safeguards or guarantees to bring the resulting protection in line with EU requirements | ||
Source | EDPB Recommendations 01/2020 on Supplementary Measures and Transfer Tools | ||
Date Created | 2021-09-22 | ||
Contributors | David Hickey, Georg P. Krog, Harshvardhan J. Pandit | ||
See More: | section DATA-TRANSFERS in EU-GDPR |
Term | ThirdParty | Prefix | eu-gdpr |
---|---|---|---|
Label | Third Party | ||
IRI | https://w3id.org/dpv/legal/eu/gdpr#ThirdParty | ||
Type | rdfs:Class, skos:Concept | ||
Broader/Parent types | dpv:ThirdParty → dpv:LegalEntity → dpv:Entity | ||
Object of relation | dpv:hasActiveEntity, dpv:hasEntity, dpv:hasNonInvolvedEntity, dpv:hasParty, dpv:hasPassiveEntity, dpv:hasRecipientThirdParty, dpv:hasResponsibleEntity, dpv:hasThirdParty, dpv:isDeterminedByEntity, dpv:isImplementedByEntity, dpv:isIndicatedBy, dpv:isOrganisationalUnitOf, dpv:isRepresentativeFor, eu-gdpr:hasEstablishment, eu-gdpr:hasMainEstablishment, eu-gdpr:isMainEstablishmentFor | ||
Definition | ‘Third Party’ means a natural or legal person, public authority, agency or body other than the data subject, controller, processor and persons who, under the direct authority of the controller or processor, are authorised to process personal data | ||
Source | GDPR Art.4-10 | ||
Date Created | 2024-12-17 | ||
Contributors | Harshvardhan J. Pandit | ||
See More: | section ENTITIES in EU-GDPR |
Term | TransparencyPrinciple | Prefix | eu-gdpr |
---|---|---|---|
Label | Transparency Principle | ||
IRI | https://w3id.org/dpv/legal/eu/gdpr#TransparencyPrinciple | ||
Type | rdfs:Class, skos:Concept, dpv:OrganisationalMeasure | ||
Broader/Parent types | dpv:Principle → dpv:GuidelinesPrinciple → dpv:OrganisationalMeasure → dpv:TechnicalOrganisationalMeasure | ||
Object of relation | dpv:hasOrganisationalMeasure, dpv:hasTechnicalOrganisationalMeasure | ||
Definition | Principle stating personal data must be processed processed in a transparent manner in relation to the data subject | ||
Source | GDPR Art.5-1a | ||
Date Created | 2024-05-12 | ||
Contributors | Georg P. Krog | ||
See More: | section PRINCIPLES in EU-GDPR |
Term | hasConcernedSA | Prefix | eu-gdpr |
---|---|---|---|
Label | has concerned supervisory authority | ||
IRI | https://w3id.org/dpv/legal/eu/gdpr#hasConcernedSA | ||
Type | rdf:Property, skos:Concept | ||
Broader/Parent types | dpv:hasEntity | ||
Sub-property of | dpv:hasEntity | ||
Range includes | dpv:DataProtectionAuthority | ||
Definition | Indicates a concerned supervisory authority | ||
Source | Guidelines 3/2018 on the territorial scope of the GDPR (Article 3) Version 2.1, GDPR Art.56 | ||
Date Created | 2024-02-14 | ||
Contributors | Georg P. Krog, Harshvardhan J. Pandit | ||
See More: | section ENTITIES in EU-GDPR |
Term | hasEstablishment | Prefix | eu-gdpr |
---|---|---|---|
Label | has establishment | ||
IRI | https://w3id.org/dpv/legal/eu/gdpr#hasEstablishment | ||
Type | rdf:Property, skos:Concept | ||
Broader/Parent types | dpv:hasEntity | ||
Sub-property of | dpv:hasEntity | ||
Domain includes | dpv:LegalEntity | ||
Range includes | dpv:LegalEntity | ||
Definition | Indicates an establishment associated with a legal entity | ||
Source | Guidelines 3/2018 on the territorial scope of the GDPR (Article 3) Version 2.1, GDPR Art.56 | ||
Date Created | 2024-02-14 | ||
Contributors | Georg P. Krog, Harshvardhan J. Pandit | ||
See More: | section ENTITIES in EU-GDPR |
Term | hasLeadSA | Prefix | eu-gdpr |
---|---|---|---|
Label | has lead supervisory authority | ||
IRI | https://w3id.org/dpv/legal/eu/gdpr#hasLeadSA | ||
Type | rdf:Property, skos:Concept | ||
Broader/Parent types | dpv:hasEntity | ||
Sub-property of | dpv:hasEntity | ||
Range includes | dpv:DataProtectionAuthority | ||
Definition | Indicates the lead supervisory authority | ||
Source | Guidelines 3/2018 on the territorial scope of the GDPR (Article 3) Version 2.1, GDPR Art.56 | ||
Date Created | 2024-02-14 | ||
Contributors | Georg P. Krog, Harshvardhan J. Pandit | ||
See More: | section ENTITIES in EU-GDPR |
Term | hasLocalSA | Prefix | eu-gdpr |
---|---|---|---|
Label | has local supervisory authority | ||
IRI | https://w3id.org/dpv/legal/eu/gdpr#hasLocalSA | ||
Type | rdf:Property, skos:Concept | ||
Broader/Parent types | dpv:hasEntity | ||
Sub-property of | dpv:hasEntity | ||
Range includes | dpv:DataProtectionAuthority | ||
Definition | Indicates the local supervisory authority | ||
Source | Guidelines 3/2018 on the territorial scope of the GDPR (Article 3) Version 2.1, GDPR Art.56 | ||
Date Created | 2024-02-14 | ||
Contributors | Georg P. Krog, Harshvardhan J. Pandit | ||
See More: | section ENTITIES in EU-GDPR |
Term | hasMainEstablishment | Prefix | eu-gdpr |
---|---|---|---|
Label | has main establishment | ||
IRI | https://w3id.org/dpv/legal/eu/gdpr#hasMainEstablishment | ||
Type | rdf:Property, skos:Concept | ||
Broader/Parent types | dpv:hasEntity | ||
Sub-property of | dpv:hasEntity | ||
Domain includes | dpv:LegalEntity | ||
Range includes | dpv:LegalEntity | ||
Definition | Indicates the legal entity has specified establishment as its main establishment | ||
Source | Guidelines 3/2018 on the territorial scope of the GDPR (Article 3) Version 2.1, GDPR Art.56 | ||
Date Created | 2024-02-14 | ||
Contributors | Georg P. Krog, Harshvardhan J. Pandit | ||
See More: | section ENTITIES in EU-GDPR |
Term | isMainEstablishmentFor | Prefix | eu-gdpr |
---|---|---|---|
Label | is main establishment for | ||
IRI | https://w3id.org/dpv/legal/eu/gdpr#isMainEstablishmentFor | ||
Type | rdf:Property, skos:Concept | ||
Broader/Parent types | dpv:hasEntity | ||
Sub-property of | dpv:hasEntity | ||
Domain includes | dpv:LegalEntity | ||
Range includes | dpv:LegalEntity | ||
Definition | Indicates the main establishment for specific legal entity | ||
Source | Guidelines 3/2018 on the territorial scope of the GDPR (Article 3) Version 2.1, GDPR Art.56 | ||
Date Created | 2024-02-14 | ||
Contributors | Georg P. Krog, Harshvardhan J. Pandit | ||
See More: | section ENTITIES in EU-GDPR |
DPV uses the following terms from [RDF] and [RDFS] with their defined meanings:
The following external concepts are re-used within DPV:
Term | dcat:Resource | Prefix | dcat |
---|---|---|---|
Label | dcat:Resource | ||
IRI | http://www.w3.org/ns/dcat#Resource | ||
Type | rdfs:Class, skos:Concept | ||
Usage Note | A dataset or catalogue or any other resource provided in fulfilment of a Right Exercise, such as for GDPR's Art.15 regarding Right of Access or Art.20 regarding Right to Data Portability. The associated properties from DCAT and DCMI DCT vocabularies provide convenient means to express metadata such as URL for accessing the data, its temporal validity and access restrictions, and specific datasets present along with their schemas. | ||
Usage Note | A dataset, data service, or any other resource associated with Right Exercise - such as for providing a copy of data | ||
Date Created | 2022-11-02 | ||
Contributors | Beatriz Esteves, Georg P. Krog, Harshvardhan J. Pandit | ||
See More: | section RIGHTS in DPV |
Term | dct:conformsTo | Prefix | dct |
---|---|---|---|
Label | dct:conformsTo | ||
IRI | http://purl.org/dc/terms/conformsTo | ||
Type | rdf:Property, skos:Concept | ||
Usage Note | For expressing an existing standard, guideline, or requirements to which the DPIA document or process will be conforming to. This could be external guidelines published by an Authority, or internal guidelines established by the organisation | ||
See More: | section DPIA in EU-GDPR |
Term | dct:coverage | Prefix | dct |
---|---|---|---|
Label | dct:coverage | ||
IRI | http://purl.org/dc/terms/coverage | ||
Type | rdf:Property, skos:Concept | ||
Usage Note | For expressing coverage (e.g. jurisdictions, products, services) of the DPIA document or process. For temporal coverage, please see dct:temporal. The coverage can be expressed using dpv:Process, or using another concept, or even be a link or reference to a document, or a textual description | ||
See More: |
Term | dct:created | Prefix | dct |
---|---|---|---|
Label | dct:created | ||
IRI | http://purl.org/dc/terms/created | ||
Type | rdf:Property, skos:Concept | ||
Usage Note | For expressing when the documentation (e.g. DPIA Necessity Assessment, or DPIA Procedure, or DPIA outcome) was created | ||
See More: |
Term | dct:dateAccepted | Prefix | dct |
---|---|---|---|
Label | dct:dateAccepted | ||
IRI | http://purl.org/dc/terms/dateAccepted | ||
Type | rdf:Property, skos:Concept | ||
Usage Note | For expressing when the documentation (e.g. DPIA Necessity Assessment, or DPIA Procedure, or DPIA outcome) was accepted through audit or approval | ||
See More: | section DPIA in EU-GDPR |
Term | dct:dateSubmitted | Prefix | dct |
---|---|---|---|
Label | dct:dateSubmitted | ||
IRI | http://purl.org/dc/terms/dateSubmitted | ||
Type | rdf:Property, skos:Concept | ||
Usage Note | For expressing when the documentation (e.g. DPIA Necessity Assessment, or DPIA Procedure, or DPIA outcome) was submitted for audit or approval | ||
See More: | section DPIA in EU-GDPR |
Term | dct:description | Prefix | dct |
---|---|---|---|
Label | dct:description | ||
IRI | http://purl.org/dc/terms/description | ||
Type | rdf:Property, skos:Concept | ||
Usage Note | Indicates a description of the DPIA for human comprehension | ||
See More: | section DPIA in EU-GDPR |
Term | dct:hasPart | Prefix | dct |
---|---|---|---|
Label | dct:hasPart | ||
IRI | http://purl.org/dc/terms/hasPart | ||
Type | rdf:Property, skos:Concept | ||
Domain includes | dpv:RightExerciseRecord | ||
Range includes | dpv:RightExerciseActivity | ||
Usage Note | Also used for specifying a RightExerciseRecord has RightExerciseActivity as part of its records | ||
Usage Note | For expressing something contains a DPIA document or process contains as a part. For example, as some dpv:DPIA dct:hasPart DPIANecessityAssessment | ||
See More: | section RIGHTS in DPV |
Term | dct:identifier | Prefix | dct |
---|---|---|---|
Label | dct:identifier | ||
IRI | http://purl.org/dc/terms/identifier | ||
Type | rdf:Property, skos:Concept | ||
Usage Note | Indicates an identifier associated with the DPIA documentation or process. Identifiers may be reused from existing systems, or created for the purposes of record management | ||
See More: | section DPIA in EU-GDPR |
Term | dct:isPartOf | Prefix | dct |
---|---|---|---|
Label | dct:isPartOf | ||
IRI | http://purl.org/dc/terms/isPartOf | ||
Type | rdf:Property, skos:Concept | ||
Domain includes | dpv:RightExerciseActivity | ||
Range includes | dpv:RightExerciseRecord | ||
Usage Note | Also used for specifying a RightExerciseActivity is part of a RightExerciseRecord | ||
Usage Note | For expressing a DPIA document or process is part of another. For example, as some DPIANecessityAssessment dct:isPartOf some dpv:DPIA | ||
See More: | section RIGHTS in DPV |
Term | dct:isVersionOf | Prefix | dct |
---|---|---|---|
Label | dct:isVersionOf | ||
IRI | http://purl.org/dc/terms/isVersionOf | ||
Type | rdf:Property, skos:Concept | ||
Usage Note | For expressing prior versions or iterations of the DPIA document or process | ||
See More: | section DPIA in EU-GDPR |
Term | dct:modified | Prefix | dct |
---|---|---|---|
Label | dct:modified | ||
IRI | http://purl.org/dc/terms/modified | ||
Type | rdf:Property, skos:Concept | ||
Usage Note | For expressing when the documentation (e.g. DPIA Necessity Assessment, or DPIA Procedure, or DPIA outcome) was last modified | ||
See More: |
Term | dct:subject | Prefix | dct |
---|---|---|---|
Label | dct:subject | ||
IRI | http://purl.org/dc/terms/subject | ||
Type | rdf:Property, skos:Concept | ||
Usage Note | For expressing the subject of the DPIA document or process, where subject refers to the point of focus. For expressing what is affected or included within the DPIA, please see dct:coverage | ||
See More: |
Term | dct:temporal | Prefix | dct |
---|---|---|---|
Label | dct:temporal | ||
IRI | http://purl.org/dc/terms/temporal | ||
Type | rdf:Property, skos:Concept | ||
Usage Note | For expressing the temporal coverage of the DPIA document or process | ||
See More: |
Term | dct:title | Prefix | dct |
---|---|---|---|
Label | dct:title | ||
IRI | http://purl.org/dc/terms/title | ||
Type | rdf:Property, skos:Concept | ||
Usage Note | Indicates a title of the DPIA for human comprehension | ||
See More: |
Term | dct:valid | Prefix | dct |
---|---|---|---|
Label | dct:valid | ||
IRI | http://purl.org/dc/terms/valid | ||
Type | rdf:Property, skos:Concept | ||
Usage Note | Also used for specifying the temporal validity of an activity associated with Right Exercise. For example, limits on duration for providing or accessing provided information | ||
Usage Note | For expressing the temporal date or range of validity of the DPIA document or process. This refers to the time period for which the DPIA is considered valid, and does not refer to the temporal period associated with processing (see dct:temporal instead). The assumption is that after this period, the DPIA should be re-evaluated or some process should be triggered | ||
See More: | section RIGHTS in DPV |
Term | dpv:hasStatus | Prefix | dpv |
---|---|---|---|
Label | has status | ||
IRI | https://w3id.org/dpv#hasStatus | ||
Type | rdf:Property, skos:Concept | ||
Domain includes | dpv:RightExerciseActivity | ||
Range includes | dpv:Status | ||
Definition | Indicates the status of specified concept | ||
Usage Note | Also used to Indicate the status of a Right Exercise Activity | ||
Usage Note | For expressing the status of the DPIA document or process. Here different statuses are used to convey different contextual meanings. For example, dpv:ActivityStatus expresses the state of the activity in terms of whether it is ongoing or completed, and dpv:AuditStatus expresses the state of the audit process in terms of being required, approved, or rejected. These are applied over each step of the DPIA i.e. DPIANecessityAssessment, DPIAProcedure, and DPIAOutcome. Similarly, a process also uses hasStatus with DPIAConformity to indicate adherence to the results of the DPIA process. | ||
Examples | dex:E0069 :: Using DPV and RISK extension to represent incidents |
||
Date Created | 2022-05-18 | ||
Contributors | Harshvardhan J. Pandit | ||
See More: | section CONTEXT-STATUS in DEX , section RIGHTS in DEX |
The DPVCG was established as part of the SPECIAL H2020 Project, which received funding from the European Union’s Horizon 2020 research and innovation programme under grant agreement No. 731601 from 2017 to 2019. Continued developments have been funded under: RECITALS Project funded under the EU's Horizon program with grant agreement No. 101168490.
Harshvardhan J. Pandit was funded to work on DPV from 2020 to 2022 by the Irish Research Council's Government of Ireland Postdoctoral Fellowship Grant#GOIPD/2020/790.
The ADAPT SFI Centre for Digital Media Technology is funded by Science Foundation Ireland through the SFI Research Centres Programme and is co-funded under the European Regional Development Fund (ERDF) through Grant#13/RC/2106 (2018 to 2020) and Grant#13/RC/2106_P2 (2021 onwards).
The contributions of Axel Polleres, Javier Fernandez, Piero Bonatti, and Luigi Sauro to the DPVCG have been funded by the European Union’s Horizon 2020 research and innovation programme under grant agreement N. 731601 (project SPECIAL) until 2019, and that for Piero Bonatti and Luigi Sauro were under grant agreement N. 883464 (project TRAPEZE) from 2020 until 2023.
The contributions of Beatriz Esteves have received funding through the PROTECT ITN Project from the European Union’s Horizon 2020 research and innovation programme under the Marie Skłodowska-Curie grant agreement No 813497. Beatriz Esteves is funded by SolidLab Vlaanderen (Flemish Government, EWI and RRF project VV023/10), and by the imec.icon project PACSOI (HBC.2023.0752) which was co-financed by imec and VLAIO.
The contributions of Harshvardhan J. Pandit have been made with the financial support of Science Foundation Ireland under Grant Agreement No. 13/RC/2106_P2 at the ADAPT SFI Research Centre; and the AI Accountability Lab (AIAL) which is supported by grants from following groups: the AI Collaborative, an Initiative of the Omidyar Group; Luminate; the Bestseller Foundation; and the John D. and Catherine T. MacArthur Foundation.
The EU-GDPR Article 35 requires a "Data Protection Impact Assessment" (DPIA) assessing the impact of processing activities involving personal data on the data subject's rights and freedoms. This requires maintaining information about whether such a DPIA is required, and if yes, then how it was conducted and what were its findings, and based on which whether processing activities were justified or were halted or not conducted. This GUIDE-GDPR-DPIA will provide guidance to implement machine-readable DPIA using the DPV.
The scope of this guide would be to create machine-readable DPIAs that can provide the information as required for implementing DPIA according to GDPR requirements. The scope as of now does not include providing tools or libraries for the creation of DPIA or interfaces or other means to work with this information. This will be based on the peer-reviewed article A Semantic Specification for Data Protection Impact Assessments (DPIA) and will incorporate work being developed in #183
The GDPR Article 30 requires keeping records of processing activities (ROPA) involving personal data, where the information to be maintained in such records includes purpose, personal data categories, technical and organisational measures utilised, and others. This GUIDE-GDPR-ROPA will provide guidance to implement machine-readable ROPAs using the DPV. The scope as of now does not include providing tools or libraries for the creation of ROPA or interfaces or other means to work with this information.
This will be based on existing specifications developed using DPV called Data Processing Catalogue (DPCat) - see peer-reviewed article by DPVCG members Paul Ryan, Rob Brennan, and Harshvardhan J. Pandit.
The GDPR Article 33 and 34 requires keeping records associated with suspicion or occurrence of a data breach and its impacts, including any communications to the data subjects or authorities regarding it. This GUIDE-GDPR-DataBreach will provide guidance to implement machine-readable Data Breach records and notifications using the DPV. The scope of this guide would be to create machine-readable records and notices that can provide the information as required for implementing data breach records, assessments, and notifications according to GDPR requirements. The scope as of now does not include providing tools or libraries for the creation of data breach assessment or notification tools or interfaces or other means to work with this information.
The peer-reviewed article - Towards a Semantic Specification for GDPR Data Breach Reporting authored by DPVCG members Harshvardhan J. Pandit, Paul Ryan, Georg P. Krog, and Rob Brennan is the basis for this work. This will include work conducted in #64 and #100, and the existing draft at https://w3id.org/dpv/guides/data-breach will be updated for new concepts developed in DPV v2.1 and v2.2.
Specs
New Concept(s)
The EU-GDPR extension should provide information on which processing activities require a DPIA. This work will be led by @TyttiRintamaki and will be based on High-Risk Categorisations in GDPR vs AI Act: Overlaps and Implications
Proposal from Prinon Das: Create a mapping between GDPR clauses and DPV concepts.
Regulations such as the GDPR, amongst others across the globe, provide specific rights (to data subjects) through which they can avail of information regarding the processing of their personal data, object to it, or obtain a copy of their given personal data. The GUIDE-Rights will provide guidance on how to implement machine-actionable rights using the DPV.
The scope of this guide would be to create machine-readable records that can provide the information as required for demonstrating rights exercise, its fulfilment or non-fulfilment, and the communications, and provide specific guidance for implementing GDPR rights. The scope as of now does not include providing tools or libraries for exercise or management of rights, or interfaces or other means to work with this information.
This work will be based on Rights Exercising with DPV developed by DPVCG members Beatriz Esteves, Harshvardhan J. Pandit, Georg P. Krog, and Paul Ryan, and described in the peer-reviewed article. A working draft is present at https://w3id.org/dpv/guides/rights
RISK, EU-GDPR, EU-Rights
See #184-comment with concepts proposed for each impact on right to be expressed as granular concepts:
And in addition to these, to interpret the right as a series of requirements or actions and create impacts based on that e.g. something is not fulfilled or something occurs (that wasn't supposed to). These concepts are proposed for EU-GDPR and EU-Rights extensions - but also for any rights concepts in DPV that can be accompanied by Rights Impact concepts.
No response
Other, DPV, EU-GDPR
Proposed by Stratis Koulierakis from PhD Thesis, see presentation to group on MAR-27 https://lists.w3.org/Archives/Public/public-dpvcg/2025Mar/0005.html
This complements the existing data privacy vocabulary by providing specific details about notification requirements under the GDPR.
INCIDENT: Personal data breach (defined in Article 4(12))
NOTIFICATION TO: Supervisory authority (defined in Article 4(21)) (Article 33(1))
TIMELINE: Without undue delay, when feasible within 72 hours (Article 33(1))
TRIGGER: Upon becoming aware of the personal data breach, unless unlikely to result in a risk to individuals (Article 33(1))
INCIDENT: Personal data breach (defined in Article 4(12))
NOTIFICATION TO: Data subject (defined in Article 4(1)) (Articles 34(1) and 34(4))
TIMELINE: Without undue delay (Article 34(1))
TRIGGER: If the personal data breach is likely to result in a high risk to individuals, with exceptions when:
INCIDENT: Personal data breach (defined in Article 4(12))
NOTIFICATION TO: Controller (Article 33(2))
TIMELINE: Without undue delay (Article 33(2))
TRIGGER: Upon becoming aware of the personal data breach (Article 33(2))
This complements the existing data privacy vocabulary by providing specific details about notification requirements under the Law Enforcement Directive.
INCIDENT: Personal data breach (defined in Article 3(11))
NOTIFICATION TO: Supervisory authority (defined in Article 3(15)) (Article 30(1))
TIMELINE: Without undue delay, where feasible within 72 hours (Article 30(1))
TRIGGER: Upon becoming aware of the personal data breach, unless unlikely to result in a risk to individuals (Article 30(1))
INCIDENT: Personal data breach (defined in Article 3(11))
NOTIFICATION TO: Data subject (defined in Article 3(1)) (Articles 31(1) and 31(4))
TIMELINE: Without undue delay (may be delayed, restricted or omitted in specific circumstances, per Article 31(5)) (Article 31(1))
TRIGGER: If the personal data breach is likely to result in a high risk to individuals, with exceptions when:
INCIDENT: Personal data breach (defined in Article 3(11))
NOTIFICATION TO: Controller of another member state by or to whom the personal data breached has been transmitted (Article 30(6))
TIMELINE: Without undue delay (Article 30(6))
TRIGGER: If the personal data breach involves personal data that have been transmitted by or to the controller of another member state (Article 30(6))
INCIDENT: Personal data breach (defined in Article 3(11))
NOTIFICATION TO: Controller (Article 30(2))
TIMELINE: Without undue delay (Article 30(2))
TRIGGER: Upon becoming aware of the personal data breach (Article 30(2))
This complements the existing data privacy vocabulary by providing specific details about notification requirements under the E-Privacy Directive.
INCIDENT: Personal data breach (defined in Article 2(i))
NOTIFICATION TO: Competent national authority (Article 4(3-5))
TIMELINE: Without undue delay (Article 4(3))
TRIGGER: A personal data breach (Article 4(3))
INCIDENT: Personal data breach (defined in Article 2(i))
NOTIFICATION TO: Subscriber or individual (Article 4(3-5))
TIMELINE: Without undue delay (Article 4(3))
TRIGGER: If the personal data breach is likely to adversely affect the personal data or privacy of a subscriber or individual, with exception when:
INCIDENT: Particular risk of a breach of the security of the network
NOTIFICATION TO: Subscribers (Article 4(2)(2))
TIMELINE: Not specified in the law
TRIGGER: A particular risk of a breach of the security of the network (Article 4(2)(2))
This complements the existing data privacy vocabulary by providing specific details about notification requirements under the Data Governance Act.
INCIDENT: Unauthorized transfer, access or use of shared nonpersonal data
NOTIFICATION TO: Data holders (defined in Article 2(8)) (Articles 12(k) and 21(5))
TIMELINE: Without delay (Articles 12(k) and 21(5))
TRIGGER: Unauthorized transfer, access or use of shared nonpersonal data (Articles 12(k) and 21(5))
INCIDENT: Unauthorized transfer, access or use of shared nonpersonal data
NOTIFICATION TO: Data holders (defined in Article 2(8)) (Articles 12(k) and 21(5))
TIMELINE: Without delay (Articles 12(k) and 21(5))
TRIGGER: Unauthorized transfer, access or use of shared nonpersonal data (Articles 12(k) and 21(5))
INCIDENT: Unauthorized re-use (defined in Article 2(2)) of nonpersonal data
NOTIFICATION TO: Legal persons whose rights and interests may be affected (Article 5(5))
TIMELINE: Without delay (Article 5(5))
TRIGGER: Unauthorized re-use of nonpersonal data (Article 5(5))
INCIDENT: Data breach resulting in the re-identification of the data subject
NOTIFICATION TO: Public sector body (Article 5(5))
TIMELINE: Not specified in the law (Article 5(5))
TRIGGER: Data breach resulting in the re-identification of the data subject (Article 5(5))
This complements the existing data privacy vocabulary by providing specific details about notification requirements under the Data Act.
INCIDENT: Unauthorized use or disclosure of data under circumstances defined in Article 11(3)
NOTIFICATION TO: User of a connected product (defined in Article 2(12)) (Article 11(2)(c))
TIMELINE: Without undue delay (Article 11(2))
TRIGGER: If requested by the data holder (defined in Article 2(13)) or the trade secret holder (defined in Article 2(19)) (Article 11(2))
This complements the existing data privacy vocabulary by providing specific details about notification requirements under the NIS2 Directive.
INCIDENT: Significant Incident (defined in Articles 6(6), 23(3) and 23(11))
NOTIFICATION TO: CSIRT (defined in Article 10) (Article 23(1))
*The majority of essential and important entities will have to notify the authority(ies) of the member state(s) where the incident occurred or where they provide their services, while the Digital Infrastructure entities will have to notify the authority of the member state where they have their main establishment, per Article 26
TIMELINE: Early warning without undue delay, within 24 hours (Article 23(4)(a)); Notification without undue delay, within 72 hours, or 24 hours for trusted service providers (Article 23(4)(b)); Intermediate report at request of CSIRT or competent authority (Article 23(4)(c)); Final report within one month after notification (Article 23(4)(d)); Final report within one month of incident handling (Article 23(4)(e)); Progress report within one month if incident ongoing (Article 23(4)(e))
TRIGGER: Upon becoming aware of the significant incident (Article 23(4))
INCIDENT: Significant Incident (defined in Articles 6(6), 23(3) and 23(11))
NOTIFICATION TO: Recipients of their services (Article 23(1))
TIMELINE: Without undue delay (Article 23(1))
TRIGGER: When appropriate, if the provision of these services is likely to be adversely affected by the significant incident (Article 23(1))
INCIDENT: Significant Incident (defined in Articles 6(6), 23(3) and 23(11))
NOTIFICATION TO: Law enforcement authorities (Article 23(5))
TIMELINE: Without undue delay (Article 23(2))
TRIGGER: If the significant incident is suspected to be of criminal nature (Article 23(5))
INCIDENT: Significant Incident (defined in Articles 6(6), 23(3) and 23(11))
NOTIFICATION TO: The public (Article 23(7))
TIMELINE: According to the guidance from the CSIRT of the competent authority (Article 23(5))
TRIGGER: If required by CSIRT or competent authority (Article 23(7))
INCIDENT: Significant cyber threat (defined in Articles 6(10) and 6(11))
NOTIFICATION TO: Recipients of their services (Article 23(2))
TIMELINE: Without undue delay (Article 23(2))
TRIGGER: When appropriate, if these services are potentially affected by the significant cyber threat (Article 23(2))
INCIDENT: Incidents, cyber threats and near misses (defined in Article 6(5))
NOTIFICATION TO: CSIRT (defined in Article 10) or competent authority (defined in Article 8) (Article 23(1))
TIMELINE: Not explicitly specified for in the law
TRIGGER: Not explicitly specified for in the law
INCIDENT: Incidents, cyber threats and near misses (defined in Article 6(5))
NOTIFICATION TO: CSIRT or competent authority (Article 30(1))
TIMELINE: Not specified in the law
TRIGGER: Not specified in the law
This complements the existing data privacy vocabulary by providing specific details about information sharing requirements under the NIS2 Directive.
TO: Entities that fall within the scope of the NIS2 Directive and other relevant entities (Article 29(1))
WHAT INFORMATION: Relevant cybersecurity information, e.g. information relating to cyber threats, near misses, vulnerabilities, techniques and procedures, indicators of compromise and adversarial tactics (Article 29(1))
TIMELINE: Not specified in the law
TRIGGER: When such information sharing aims to prevent, detect, respond to or recover from incidents or to mitigate their impacts or enhances the level of cybersecurity (Article 29(1))
TO: CSIRT (Article 23(1))
WHAT INFORMATION: The notification of a significant incident received from an essential or important entity (Article 23(1))
TIMELINE: Upon receipt of the notification (Article 23(1))
TRIGGER: When an essential or important entity notifies the competent authority of a significant incident (Article 23(1))
TO: Competent authorities under the Critical Entities Resilience Directive (Article 23(10))
WHAT INFORMATION: Information about notified significant incidents, incidents, cyber threats and near misses (Article 23(10))
TIMELINE: Not specified in the law
TRIGGER: When significant incidents, incidents, cyber threats and near misses are notified by entities identified as critical entities under the Critical Entities Resilience Directive (Article 23(10))
TO: Single point of contact (defined in Article 8(3)) (Article 23(1))
WHAT INFORMATION: Relevant information notified by essential and important entities (Article 23(1))
TIMELINE: In due time (Article 23(1))
TRIGGER: In case of a cross-border or cross-sectoral significant incident (Article 23(1))
TO: Single point of contact (defined in Article 8(3)) (Article 30(2))
WHAT INFORMATION: Information about voluntary notifications of incidents, significant incidents, cyber threats and near misses (Article 30(2))
TIMELINE: Not specified in the law (Article 30(2))
TRIGGER: When necessary (Article 30(2))
TO: Other affected member states and ENISA (Article 23(6))
WHAT INFORMATION: Information about the notified significant incident (Article 23(6))
TIMELINE: Without undue delay (Article 23(6))
TRIGGER: When a significant incident concerns two or more member states and when otherwise appropriate (Article 23(6))
TO: The public (Article 23(7))
WHAT INFORMATION: About the significant incident (Article 23(7))
TIMELINE: After consulting the entity concerned (Article 23(7))
TRIGGER: When public awareness is necessary to prevent a significant incident or to deal with an ongoing significant incident, or when its disclosure is otherwise in the public interest (Article 23(7))
TO: Other affected member states and ENISA (Article 23(6))
WHAT INFORMATION: Information about the notified significant incident (Article 23(6))
TIMELINE: Without undue delay (Article 23(6))
TRIGGER: When a significant incident concerns two or more member states and when otherwise appropriate (Article 23(6))
TO: Single points of contact of other affected member states (Article 23(8))
WHAT INFORMATION: Notifications received (Article 23(8))
TIMELINE: Not specified in the law
TRIGGER: When it is requested by CSIRT or the competent authority (Article 23(8))
TO: ENISA (Article 23(9))
WHAT INFORMATION: A summary report, including anonymized and aggregated data on significant incidents, incidents, cyber threats and near misses notified, including voluntarily (Article 23(9))
TIMELINE: Every three months (Article 23(9))
TRIGGER: Not specified in the law
TO: The public (Article 23(7))
WHAT INFORMATION: About the significant incident (Article 23(7))
TIMELINE: After consulting the entity concerned (Article 23(7))
TRIGGER: When public awareness is necessary to prevent a significant incident or to deal with an ongoing significant incident, or when its disclosure is otherwise in the public interest (Article 23(7))
TO: Data protection authority of own member state (Article 35(1))
WHAT INFORMATION: That an infringement by an essential or important entity of their obligations under the NIS2 Directive can entail a personal data breach as defined in the GDPR (Article 35(1))
TIMELINE: Without undue delay (Article 35(1))
TRIGGER: When an infringement by an essential or important entity of their obligations under the NIS2 Directive can entail a personal data breach as defined in the GDPR (Article 35(1))
TO: CSIRTs network and the Cooperation Group (defined in Article 14) (Article 23(9))
WHAT INFORMATION: Its findings on notifications received (Article 23(9))
TIMELINE: Every six months (Article 23(9))
TRIGGER: Not specified in the law
This complements the existing data privacy vocabulary by providing specific details about notification requirements under DORA.
INCIDENT: Major information communication technology-related incident (defined in Article 3(10))
NOTIFICATION TO: Relevant competent authority (defined in Article 46) (Article 19(1))
TIMELINE: Initial notification four hours from the moment of classification of the incident as major, but no later than 24 hours from becoming aware of the incident; Intermediate report within 72 hours from the submission of the initial notification; Updated notifications every time a relevant status update is available or upon a request from the competent authority; Final report when the root cause analysis is complete, or within one month from the submission of the latest updated intermediate report (per draft Regulatory Technical Standard, subject to change)
TRIGGER: Upon becoming aware of the incident (Article 19(3))
INCIDENT: Major information communication technology-related incident (defined in Article 3(10))
NOTIFICATION TO: Competent authorities or CSIRTs under the NIS2 Directive, if required by a member state (Article 19(1))
TIMELINE: Initial notification four hours from the moment of classification of the incident as major, but no later than 24 hours from becoming aware of the incident; Intermediate report within 72 hours from the submission of the initial notification; Updated notifications every time a relevant status update is available or upon a request from the competent authority; Final report when the root cause analysis is complete, or within one month from the submission of the latest updated intermediate report (per draft Regulatory Technical Standard, subject to change)
TRIGGER: Not specified in the law
INCIDENT: Major information communication technology-related incident (defined in Article 3(10))
NOTIFICATION TO: Clients (Article 19(3))
TIMELINE: Without undue delay upon becoming aware of the incident (Article 19(3))
TRIGGER: When the incident has an impact on the financial interests of clients (Article 19(3))
INCIDENT: Significant cyber threat (defined in Article 3(13))
NOTIFICATION TO: Relevant competent authority (defined in Article 46) (Article 19(2))
TIMELINE: Not specified in the law
TRIGGER: If the financial entity deems the threat to be of relevance to the financial system, service users or clients (Article 19(2))
INCIDENT: Significant cyber threat (defined in Article 3(13))
NOTIFICATION TO: CSIRTs under the NIS2 Directive, if permitted by a member state (Article 19(2))
TIMELINE: Not specified in the law
TRIGGER: If the financial entity deems the threat to be of relevance to the financial system, service users or clients (Article 19(2))
INCIDENT: Significant cyber threat (defined in Article 3(13))
NOTIFICATION TO: Potentially affected clients (Article 19(3))
TIMELINE: Not specified in the law
TRIGGER: Where applicable (Article 19(3))
INFORMATION TO: Other relevant authorities, based on their respective competences (Article 19(6))
INFORMATION SHARED: Details of the major ICT-related incident (Article 19(6))
TIMELINE: In a timely manner (Article 19(6))
TRIGGER: Upon receipt of the initial notification and of each report about the major ICT-related incident (Article 19(6))
INFORMATION TO: Other relevant authorities, defined in Article 19(6) (Article 19(2))
INFORMATION SHARED: Information about significant cyber threats notified by financial entities (Article 19(2))
TIMELINE: Not specified in the law
TRIGGER: Not specified in the law (Article 19(2))
INFORMATION TO: Members of the European System of Central Banks (Article 19(7))
INFORMATION SHARED: On issues relevant to the payment system, in connection to the major ICT-related incident (Article 19(7))
TIMELINE: Not specified in the law
TRIGGER: If there are issues relevant to the payment system in connection to the major ICT-related incident (Article 19(7))
INFORMATION TO: Relevant competent authorities in other member states (Article 19(7))
INFORMATION SHARED: Not specified in the law
TIMELINE: As soon as possible following the assessment that the major ICT-related incident is relevant for competent authorities in other member states (Article 19(7))
TRIGGER: Upon receipt of information in relation to the major ICT-related incident from the competent authority, if it is determined that the major ICT-related incident is relevant for competent authorities in other member states (Article 19(7))
This complements the existing data privacy vocabulary by providing specific details about notification requirements under PSD2.
INCIDENT: Major operational or security incident
NOTIFICATION TO: Competent authority (defined in Article 100) in the home member state (defined in Article 4(1)) of the payment service provider (Article 96(1))
TIMELINE: Without undue delay (Article 96(1))
TRIGGER: Major operational or security incident (Article 96(1))
INCIDENT: Major operational or security incident
NOTIFICATION TO: Payment service users (defined in Article 4(10)) (Article 96(1))
TIMELINE: Without undue delay (Article 96(1))
TRIGGER: If the incident has or may have an impact on the financial interests of its payment service users (Article 96(1))
INFORMATION TO: Other relevant authorities in its member state (Article 96(2))
INFORMATION SHARED: Not specified in the law
TIMELINE: After assessing the relevance of the notified incident to other relevant authorities in its member state (Article 96(2))
TRIGGER: If notified incident is relevant to other relevant authorities in its member state (Article 96(2))
INFORMATION TO: European Banking Authority and European Central Bank (Article 96(2))
INFORMATION SHARED: Relevant details of the notified incident (Article 96(2))
TIMELINE: Without undue delay (Article 96(2))
TRIGGER: Receipt of the notification of the incident from the payment service provider (Article 96(2))
INFORMATION TO: Other relevant EU and national authorities (Article 96(2))
INFORMATION SHARED: Not specified in the law (Article 96(2))
TIMELINE: Not specified in the law
TRIGGER: If notified incident is relevant to other relevant EU and national authorities (Article 96(2))
INFORMATION TO: Members of the European System of Central Banks (Article 96(2))
INFORMATION SHARED: Issues relevant to the payment system (defined in Article 4(7)) in connection to the notified incident (Article 96(2))
TIMELINE: Not specified in the law
TRIGGER: If there are issues relevant to the payment system in connection to the notified incident (Article 96(2))
DPV, Personal Data (PD), Technical (TECH), Locations (LOC), RISK, Other
After analysing the processing activities that require a DPIA across all 30 EU /EEA member states, I identified several conditions that highlight the need for additional concepts in the DPV to fully represent all DPIA-required criteria.
The proposal of the concepts can be found here: https://docs.google.com/spreadsheets/d/1_xj4D_3lppqIWQIWbQeDVKMOC5iWItqJpz1qbCNovk4/edit?usp=sharing or DPIA concepts for DPV Final - DPIA high-risk processing activity concepts-2.csv.
The "identifier" column consists of the identifiers assigned to each processing activity, and if you want to find out what overall processing statement is being represented, this can be found in Appendix A. of the preprint of our paper: https://osf.io/preprints/osf/6qhzj_v2.
Below are three examples of how these concepts could be used to represent DPIA required conditions:
ex:DPIARequiredC8 a eu-gdpr:DPIARequiredProcess ;
dpv:hasAutomationLevel dpv:Automated; # Automated proposed
dpv:hasConsequence risk:LegalEffect ; # LegalEffect proposed
dpv:hasStatus eu-gdpr:DPIARequired ;
skos:prefLabel "DPIA Required Process # 8" ;
skos:definition "A process that has automated decision making and/or automated processing with legal or similar effect, , due to which it requires a DPIA"@en ;
dct:source "GDPR, EDPB, AT, BE, BG, HR, CY, CZ, DK, EE, FI, FR, DE, GR, HU, IS, IE, IT, LV, LI, LT, LU, MT, NL, NO, PL, PT, RO, SK, SI, ES, SE" .
ex:DPIARequiredC21 a eu-gdpr:DPIARequiredProcess ;
dpv:hasDataSubject dpv:AsylumSeeker, dpv:Immigrant ;
dpv:hasStatus eu-gdpr:DPIARequired ;
skos:prefLabel "DPIA Required Process # 21" ;
skos:definition "A processing activity using data concerning asylum seekers and immigrants, due to which it requires a DPIA"@en ;
dct:source "AT, CY, IE, IT, LV, MT, SI, SE" .
ex:DPIARequiredC76 a eu-gdpr:DPIARequiredProcess ;
dpv:hasProcessing dpv:Monitoring ;
dpv:isImplementedUsingTechnology tech:SmartMeter; # SmartMeter proposed
dpv:hasDataController dpv:UtilityProvider ; # UtilityProvider proposed
dpv:hasStatus eu-gdpr:DPIARequired ;
skos:prefLabel "DPIA Required Process # 76" ;
skos:definition "A processing activity that uses data from the application of smart meters set up by public utility providers (for monitoring of consumption habits), which requires a DPIA."@en ;
dct:source "BE, HR, GR, HU, NL, PL, RO" .
Based on discussions in #283 the dpv:ReuseCompatibility
concept should be extended as eu-gdpr:PurposeCompatibility
to represent the compatibility of purposes as defined and interpreted within the EU GDPR. The specific concepts modelling these are:
PurposeCompatible
: An assessment that the specified use or purpose is compatible with the Purpose of processing personal data as defined and interpreted under the GDPRPurposeIncompatible
: An assessment that the specified use or purpose is incompatible with the Purpose of processing personal data as defined and interpreted under the GDPRThese concepts should be accompanied with guidelines on how the interpretation of compatibility works by using DPV concepts, e.g. to test for compatibility, which DPV concepts should be compared.
The GDPR involves assessment of proportionality and necessity, which should be modelled as concepts in the EU-GDPR extension. Proposal by @StrKoulierakis
total terms: 245 ; added: 0 ; removed: 1
The changelog provides more information on concepts that have been added/removed in this version. Below is a summary of the changes.
Fixed typo A6-1-d-natual-person
.
Referenced in:
Referenced in:
Referenced in:
Referenced in: