W3C

DPVCG Meeting Call

12 NOV 2025

Attendees

Present
ArthitSuriyawongkul, HarshPandit, JulianFlake, PaulRyan, StratisKoulierakis
Regrets
BeatrizEsteves, DelaramGolpayegani, JulioHernandez
Chair
HarshPandit
Scribe
HarshPandit

Meeting minutes

Repository: w3c/dpv

Agenda: https://www.w3.org/events/meetings/ce42ad87-3040-4f82-a341-7cb7c699a1a4/20251112T133000/

Meeting minutes: https://w3id.org/dpv/meetings

Persistent ID for current minutes: https://w3id.org/dpv/meetings/meeting-2025-11-12

Previous minutes: https://w3id.org/dpv/meetings/meeting-2025-11-05

Admin

DPVCG co-chairs

See https://lists.w3.org/Archives/Public/public-dpvcg/2025Sep/0005.html

<ghurlbot> Issue 389 DPVCG chair nomination (discussion) (by coolharsh55)

Confirmation of DPVCG co-chairs: Harsh and Beatriz https://lists.w3.org/Archives/Public/public-dpvcg/2025Nov/0000.html and responses (tracking issue https://github.com/w3c/dpv/issues/389)

HarshPandit: confirm (no objections registered on mailing list or elsewhere)

no objections raised; accepted to have new co-chairs

DPVCG Charter

<ghurlbot> Issue 399 Establish DPVCG Charter (by coolharsh55)

HarshPandit: Working document: https://docs.google.com/document/d/1poo7rYNBlkd4Ag0YHB_il2Xe2hwtHWfROgl5WgrNgyc

HarshPandit: is the structure/approach okay?

JulianFlake: +1

PaulRyan: +1 used the template which is good, and its good that its focused on what we are and what we are not doing, and having a concrete set of deliverables

ArthitSuriyawongkul: contribution mechanics section - some groups mention about a process for archival e.g. works should be in github; so for DPVCG should we specify where it goes e.g. to Zenodo with a DOI.

HarshPandit: w3c reports is the official "archival" as they are committed to maintain this

ArthitSuriyawongkul: meant as a permalink to the report; maybe this should be in the charter or contribution guidelines?

HarshPandit: maybe we should mention that we produce works and this is official only when published by w3c?

ArthitSuriyawongkul: we mention this is the official artefact etc. this is the url

HarshPandit: we mention w3id.org/dpv is the official urls for work published by DPVCG and then we submit these by w3c for publication; agree this would be good for the deliverables section

ArthitSuriyawongkul: Make sure the contribution guidelines at https://github.com/w3c/dpv/wiki/Contribution-Guide is up to date before mentioning it in the charter

HarshPandit: agreed

agreed with the structure of the draft; Harsh will restructure the draft based on this discussion and then circulate it on the mailing list for further feedback/comments and then next week we will work on this. The goal is to have the draft be circulated for approval and then to have the charter be ready by next year so we are in a good position to talk about standardisation.

W3C reports

HarshPandit: working on submitting the v2.2.1 and changes to prior versions (red box saying this is outdated) to the w3c for publishing our outputs. The w3id issues for some purls have been fixed.

Improve Documentation

<ghurlbot> Issue 395 Revise DPV main spec page for ease of access (by coolharsh55)

Harsh initial simplification proposal at https://harshp.com/dpv-x/dpv-simplification/dpv.html

HarshPandit: being implemented, next week will go live for 2.3-dev; still room for improvement, feedback until publication of v2.3

Examples, Use-Cases

HarshPandit: We need more examples, need to register use-cases for new concepts as agreed previous. For these, are there any good examples / good practices we should follow? Otherwise we have existing examples, and use-cases is a separate document that we can continue with https://dev.dpvcg.org/use-cases/

no new suggestions recorded, will continue with existing methods

HarshPandit: For new concepts such as proportionality and AI agents etc. will draft examples and use-cases and these will be discussed async directly with the relevant contributors

Updates

HarshPandit: For the below topics, there will be dedicated meetings with people who have expressed interest (let me know if you are interested in being involved). We will report back proposals and findings with consensus. This will allow us to move forward with concepts faster than taking things up one by one in the meetings.

EHDS

<ghurlbot> Issue 238 Update EHDS extension with practical concepts (by coolharsh55)

HarshPandit: Beatriz and Georg have proposed concepts, Harsh is reviewing until end of Nov.

AI Act

<ghurlbot> Issue 229 Update EU-AIAct extension with practical concepts (by coolharsh55)

HarshPandit: Delaram, Georg, and Harsh working on list of topics with a focus on coverage (i.e. more of AI Act) than depth (i.e. specific article or obligation)

DE-GDNG

<ghurlbot> Issue 387 Extension for the German GDNG (by chhdraeger)

JulianFlake: updates - next: discussion of a selection of a minimal set of identified concepts to describe a synthetic use case: next Monday. After that: proposal for addition.

NIS2

<ghurlbot> Issue 222 Update NIS2 extension with practical concepts (by coolharsh55)

HarshPandit: Georg and Harsh working on incident reporting

AOB

EU Omnibus

HarshPandit: EU's "simplification" and "omnibus" proposals are leaked as drafts for the GDPR and AI Act. We are expecting full proposals on NOV-19. They change key criteria such as personal data, special categories, and others. These are changes in definitions which we have modelled into the DPV. So if this goes through we will need to revisit what it means for DPV.

ISO 29151

<ghurlbot> Issue 26 DPV-ISO providing concepts from ISO terminology and standards (by coolharsh55)

HarshPandit: ISO/IEC FDIS 29151 Information security, cybersecurity and privacy protection — Controls, requirements, and guidance for personally identifiable information protection https://www.iso.org/standard/88151.html is being developed and is currently in the final draft stage. It contains lots of concepts that are relevant for the DPV's tech/org measures. This is a good resource we should look at.

HarshPandit: Stratis, do standards like these also feature / are relevant for the proposals made in your thesis?

StratisKoulierakis: Yes, but I'm doubtful we can add them directly. We should add to existing extensions - that makes sense, adding new vocabularies for each standard doesn't make sense. Interested in participanting in meetings on this topic.

HarshPandit: Delaram was also of the same opinion, so I think we have alignment on how to work on standards for improving DPV and then those that offer certification or evidence. Focus is on GDPR certifications, like the one from Luxembourg featured in your thesis. I will organise a meeting for standards (also GDPR certifications).

StratisKoulierakis: For proposals made regarding codes of conduct will need technical expertise for formalisation of the legal part in to the concepts etc.

Next Meeting

The next meeting will be on NOV-19 Wednesday 13:30WET/14:30CET

Minutes manually created (not a transcript), formatted by scribe.perl version 217 (Fri Apr 7 17:23:01 2023 UTC).