Send WG-InfoSharing mailing list submissions to
wg-infosharing@kantarainitiative.org
To subscribe or unsubscribe via the World Wide Web, visit
https://kantarainitiative.org/mailman/listinfo/wg-infosharing
or, via email, send a message with subject or body 'help' to
wg-infosharing-request@kantarainitiative.org
You can reach the person managing the list at
wg-infosharing-owner@kantarainitiative.org
When replying, please edit your Subject line so it is more specific
than "Re: Contents of WG-InfoSharing digest..."
Today's Topics:
1. Re: W3C Workshop - Data Privacy Controls and Vocabularies
(Mark Lizar)
----------------------------------------------------------------------
Message: 1
Date: Wed, 21 Feb 2018 15:31:34 +0000
From: Mark Lizar <ma...@openconsent.com>
To: Mark Lizar <ma...@openconsent.com>
Cc: "wg-infosharing@kantarainitiative.org"
<wg-infosharing@kantarainitiative.org>
Subject: Re: [WG-InfoSharing] W3C Workshop - Data Privacy Controls and
Vocabularies
Message-ID: <03248CBA-D405-4C5B-8F6D-F887FE...@openconsent.com>
Content-Type: text/plain; charset="utf-8"
HI All,
I have progressed this input from the CISWG to this conference (see below for latest version). This input has evolved to make clear that the CR is about people interoperability and that we (CISWG) advocate that specs and tech, use the CR as an output format for people.
In this regard, the final output here is a proposal for CISWG to explore with other community efforts (and specifications) how to support the mapping of these efforts to the Consent Receipt work.
Please Review, comment and support - for call tomorrow.
Best Regards,
Mark
Input From Kantara CISWG: For Data Privacy Controls & Vocabularies
https://lists.w3.org/Archives/Public/public-new-work/2018Jan/0017.html <https://lists.w3.org/Archives/Public/public-new-work/2018Jan/0017.html>
Consent and Information Sharing WG (CISWG) at Kantara is focused on creating an open machine and human readable privacy record format for people that maps to international standards and consent based legal notice requirements that vary from jurisdiction to jurisdiction.
In the CISWG work is developed from the perspective that privacy, is not primarily about companies compliance, but about personal control of data and data processing transparency. The consent receipt format captures; the identity of the privacy controllers and processors, maps the purpose to personal data categories and to data types, then uses this specified purpose transparency to map what data is disclosed to 3rd parties.
The Consent Receipt specification is intended to be usable and extensible by ?Vocabularies to link privacy policies, regulations and involved (business) processes?, to a privacy record format which we have called a consent receipt. For example the COEL specification at OASIS and work is under way with UMA.
With the GDPR, privacy by default/design is the expectation removing the burden from people to organisations to make privacy the default. The Consent Receipt specification is being adopted by people facing technologies and infrastructure to provide a point of interoperability amongst records.
From this context of interoperable privacy transparency that is usable for people, the CISWG would also like to explore links and synergies using Linked Data vocabularies in the context of related efforts such as those listed by W3C.
Consent Receipt Update
Consent Receipt Specification ?has now reached a v1.1 <https://kantarainitiative.org/confluence/download/attachments/76447870/Consent%20Receipt%20Specification%201_1_0%20DRAFT%208%20-%20clean.docx?version=1&modificationDate=1519153788000&api=v2> as this has gone through a 45 day public IPR review and 3 rounds of public comments, so it is getting quite stable.
The receipt is an open specification for the technical output people should receive when providing consent. In terms of interoperability the CISWG proposes that as a common privacy record output that a consent based privacy vocabulary is of great value for linking data vocabularies to a single format. For privacy, this means linking laws and legal (privacy and contract) vocabularies to technical lexicons and identity management protocols.
The Consent Receipt specification V1.1 is becoming an internationally applicable specification for consent records; It is unique because it memorialises an action made by the individual in regard to the policies of an organisations. This makes the organisation accountable to that policy and enables more than privacy compliance, by enabling semi-automated privacy rights/rights and preferences.
> On 19 Feb 2018, at 16:04, Mark Lizar <ma...@openconsent.com> wrote:
>
> Thanks Julian,
>
> Great comments !!
>
> Mark
>
>> On 18 Feb 2018, at 15:16, Mark Lizar <ma...@openconsent.com <mailto:ma...@openconsent.com>> wrote:
>>
>> HI,
>>
>> Due to some good advice and for ease of editing/commenting and contributing I have pasted the text into an open Google Doc,? <https://docs.google.com/document/d/1cxsFEvwZEUZa8bGF0sN7DpaaKk1qAn1wrCituyrdyGo/edit?usp=sharing>
>>
>> (Full link ?> https://docs.google.com/document/d/1cxsFEvwZEUZa8bGF0sN7DpaaKk1qAn1wrCituyrdyGo/edit?usp=sharing <https://docs.google.com/document/d/1cxsFEvwZEUZa8bGF0sN7DpaaKk1qAn1wrCituyrdyGo/edit?usp=sharing>)
>>
>> Best,
>>
>> Mark
>>
>>
>>> On 18 Feb 2018, at 11:34, Mark Lizar <ma...@openconsent.com <mailto:ma...@openconsent.com>> wrote:
>>>
>>> Input From Kantara CISWG:
>>>
>>> Consent Receipt Specification v1.1 is a significant development for privacy as it is a technical format designed for the purpose of standardising the technical output people receive when engaging with the privacy notice infrastructure of organisations.
>>>
>>> A Consent Receipt is a record of the privacy notices provided for an explicit consent and is provided/generated at the time of consent to provide a record of privacy to a person. The consent receipt is comprised of the information required in what is called a Subject Access Request and this is provided to the individual up front to enable people to withdraw consent as easy as they have provided it.
>>>
>>> The consent receipt is being rapidly adopted by people facing technologies and infrastructure and is intended to provide a point of interoperability for people. As privacy, is not only about companies compliance, its personal and its about transparency over what privacy people do or do not have. The Consent Receipt assists the individual to self regulate their behaviour and act autonomously.
>>>
>>> Transparency over privacy is a critical requirement to enable people with the tools to be autonomous in the digital age. The V1.1 specification from the Kantara Consent & Information Sharing WG is the result of 4 years of work from a group of volunteers that are passionate about enabling people with tools to control their own personal information. The specification has been taken up by many other organisations, standards efforts and specifications.
>>>
>>> The V1.1 is an internationally applicable specification for consent records, it has been reviewed extensively as a format for making privacy transparency and personal data control interoperable for people. It is unique because it memorialises an action made by the individual in regard to the policies of an organisations. This makes the organisation accountable to that policy and enables more than privacy compliance, by enabling semi-automated privacy infrastructure so that the privacy rights around consent become more usable.
>>>
>>> Already there are a lot of organisations that have picked up the consent receipt for consent management solutions. The field format in the consent receipt align with international standards like that from the ISO 29100, 29184, and contains the explicit consent notice requirements that are consistent globally.
>>>
>>> The receipt has a specified field format that can be extended for any privacy notice receipt and is intended to go beyond the use of explicit consent as a privacy receipt applies to 'implied consent transparency', no consent transparency, and even privacy notices about no privacy transparency, as is required for privacy in the EU.
>>>
>>> CISWG would support a cross standards organisation effort to build interoperable privacy notice transparency that maps to efforts in W3C and the web of trust, bridging efforts in this space.
>>
>> _______________________________________________
>> WG-InfoSharing mailing list
>> WG-InfoSharing@kantarainitiative.org <mailto:WG-InfoSharing@kantarainitiative.org>
>> https://kantarainitiative.org/mailman/listinfo/wg-infosharing
>
> _______________________________________________
> WG-InfoSharing mailing list
> WG-InfoSharing@kantarainitiative.org
> https://kantarainitiative.org/mailman/listinfo/wg-infosharing
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://kantarainitiative.org/pipermail/wg-infosharing/attachments/20180221/af72d7a1/attachment.html>
------------------------------
Subject: Digest Footer
_______________________________________________
WG-InfoSharing mailing list
WG-InfoSharing@kantarainitiative.org
https://kantarainitiative.org/mailman/listinfo/wg-infosharing
------------------------------
End of WG-InfoSharing Digest, Vol 99, Issue 8
*********************************************
_______________________________________________
WG-InfoSharing mailing list
WG-Info...@kantarainitiative.org
https://kantarainitiative.org/mailman/listinfo/wg-infosharing
On 22 Feb 2018, at 19:57, Mark Lizar <ma...@openconsent.com> wrote:Thanks Tom,Will update and re-post - does anyone else have any comments before I do?- Mark
On 22 Feb 2018, at 19:29, Tom Jones <thomascli...@gmail.com> wrote:To be clear this problem could be fixed with a few weasel words. The following is particularly bad.
Consent Receipt is a record of the privacy notices provided for an explicit consent and is provided/generated at the time of consent to provide a record of privacy to a person. The consent receipt is comprised of the information required in what is called a Subject Access Request and this is provided to the individual up front to enable people to withdraw consent as easy as they have provided it.
thx ..Tom (mobile)
Hi Tom,
Message-ID: <03248CBA-D405-4C5B-8F6D-F887FE6E...@openconsent.com>
_______________________________________________
WG-InfoSharing mailing list
WG-InfoSharing@kantarainitiative.org
https://kantarainitiative.org/mailman/listinfo/wg-infosharing
Note that the term Individual here means a human being. That should not be considered to prevent the RP from also supporting non human users.
Andrew Hughes CISM CISSP
In Turn Information Management Consulting
o +1 650.209.7542
m +1 250.888.9474
1249 Palmer Road, Victoria, BC V8P 2H8
AndrewHu...@gmail.com
ca.linkedin.com/pub/andrew-hughes/a/58/682/
Identity Management | IT Governance | Information Security
On 24 Feb 2018, at 17:48, Tom Jones <thomascli...@gmail.com> wrote: