Child pages
  • DRAFT 2017-05-18 Meeting Notes (CR)

Versions Compared

Key

  • This line was added.
  • This line was removed.
  • Formatting was changed.

...

Attendees

Voting

 

Non-Voting

  • David Turner

Info
titleQuorum Status
quorum STATUSMeeting was not quorate

 

 

Info
titleVoting participants

Participant Roster (2016) - Quorum is 4 of 7 as of 2016-10-06

Iain Henderson, Mary Hodder, Harri Honko, MarkLizarMark Lizar, Jim Pasquale, John Wunderlich, Andrew Hughes

...

TimeItemWhoNotes
4 mins
  • Roll call
  • Agenda bashing
Andrew Hughes 
1 min
  • Organization updates
All

Please review these blogs offline for current status on Kantara and all the DG/WG:

1 min
  • Status of Consent Receipt Specification v1
Andrew Hughes
  • Congratulations!
  • The Consent Receipt Specification v1.0 is now formally approved as a Kantara Recommendation
  • Final touches to the document happening now before posting to the downloads page and promotion
40 minDiscuss work backlog priorities for CR v1.1All

Consent Receipt v1.1 Work Backlog

On Wed, May 10, 2017 at 1:56 PM, David Turner <david.turner@voltagegate.com> wrote:

I’ve been reviewing the input for v1.1 and I’ve grouped the issues into 5 broad categories to help focus discussions.

  • Terminology
    • Reconcile terms from various ISO specs (e.g., 29100, 29184) with other significant sources (e.g., GDPR).
    • We need to be clear that the CR spec is not the authoritative source for definitions and be clear that implementers must follow the appropriate definitions according to their relevant jurisdictions.
  • Data model
    • What is the proper relationship between different fields? For example, in the v1 spec there is only one dataController; and purpose, purposeCategory and piiCategory are subordinate to a service. What happens when we allow multiple dataControllers? Do we then make services subordinate to dataControllers, or the other way around? I’ve attached two views of the current JSON schema. One is pseudo-ERP and the other an expandable tree graph.
  • New fields
    • E.g., duration of consent, retention period
    • Some of these suggested fields raise the question of how much of a policy’s details should be repeated in the CR. What is the reason for including the field? Is it just for the implementer, for interchange/interop, for the end user, for regulatory compliance?
  • Field semantics/syntax
    • Some fields need more guidance and possibly specific data types. (e.g., jurisdiction, policyURL, termination)
  • Purpose, purposeCategory, piiCategory, primaryPurpose
    • A big ol’ discussion all by itself.

From David: CR Schema v1_0_0.html

From David: CR-1_0_0 data model v1 (1).gif

 General discussion 
  • There is a need to clarify the existence of a 'Record of Consent' as distinct from the 'Consent Receipt'
  • There is a need to define 'parameters' that an implementer or assessor would need to use to be compliant with any particular regulation or law
  • Discussed the path forward. Mark has contributions on the way on several topics - he commited committed to send small samples to help the WG plan.
  • David described his categorization of the backlog items
    • Security of the Receipt section needs clarification
  • Discussed the concept of creating "Implementer's Guidance for xxx" - to explain how terminology in the specification translates into whatever local regulation is applicable
  • Discussed what the source of defined terms is: ISO 29184

...