Contributors: (ordered alphabetically) Arthit Suriyawongkul (ADAPT Centre, Trinity College Dublin), Axel Polleres (Vienna University of Economics and Business), Beatriz Esteves (IDLab, IMEC, Ghent University), Bud Bruegger (Unabhängige Landeszentrum für Datenschutz Schleswig-Holstein), Damien Desfontaines (No affiliation provided), Danielle Welter (University of Luxembourg), David Hickey (Dublin City University), Delaram Golpayegani (ADAPT Centre, Trinity College Dublin), Elmar Kiesling (Vienna University of Technology), Fajar Ekaputra (Vienna University of Technology), Georg P. Krog (Signatu AS), Harshvardhan J. Pandit (AI Accountability Lab (AIAL), Trinity College Dublin), Iain Henderson (JLINC Labs), Javier Fernández (Vienna University of Economics and Business), Julian Flake (University of Koblenz), Julio Hernandez (Dublin City University), Mark Lizar (OpenConsent/Kantara Initiative), Maya Borges (Danish Agency for Digitisation), Paul Ryan (Uniphar PLC), Piero Bonatti (Università di Napoli Federico II), Rana Saniei (Universidad Politécnica de Madrid), Rob Brennan (University College Dublin), Rudy Jacob (Proximus), Simon Steyskal (Siemens), Steve Hickman (Epistimis LLC), Tytti Rintamaki (ADAPT Centre, Dublin City University). NOTE: The affiliations are informative, do not represent formal endorsements, and may be outdated as this list is generated automatically from existing data.

The Data Privacy Vocabulary [[DPV]] enables expressing machine-readable metadata about the use and processing of (personal or otherwise) data and technologies, and supports legislative requirements such as the General Data Protection Regulation [[GDPR]]. This document describes the DPV specification along with its data model. The canonical URL for DPV is https://w3id.org/dpv which contains (this) specification. The namespace for DPV terms is https://w3id.org/dpv#, the suggested prefix is dpv, and this document along with source and releases are available at https://github.com/w3c/dpv. A changelog this version is provided in the appendix.

DPV Specifications: The [[DPV]] is the core specification that is extended by specific extensions. A [[PRIMER]] introduces the concepts and modelling of DPV specifications, and [[GUIDES]] describe application of DPV for specific applications and use-cases. The Search Index page provides a searchable hierarchy of all concepts. The Data Privacy Vocabularies and Controls Community Group (DPVCG) develops and manages these specifications through GitHub. For meetings, see the DPVCG calendar.

The peer-reviewed article "Data Privacy Vocabulary (DPV) - Version 2.0" (2024) describes the current state of DPV and extensions from version 2.0 onwards, with an earlier article (2019) covering how the DPV was developed (open access versions here, here, and here).

Contributing: The DPVCG welcomes participation to improve the DPV and associated resources, including expansion or refinement of concepts, requesting information and applications, and addressing open issues. See contributing guide for further information.

Introduction

The motivation of DPV is to provide a 'data model' or an 'ontology' of concepts for interoperable representation and exchange of information about processing of (personal) data and the use of technologies. For this, the DPV specification defines concepts and relationships using the [[RDF]] standard, and which can additionally be implemented and applied using technologies appropriate to a use-case's specific requirements.

The DPV specification contains several distinct groups of concepts, some of which are provided with a taxonomy of concepts to support practical use-cases. In addition to these, 'extensions' to the DPV are also provided which further extend one or more DPV concepts or enable separation of concepts - such as for distinguishing between different jurisdictions and laws. The figure below shows an overview of the DPV concepts along with its extensions.

Overview showing core concepts and relations in DPV with their further expansion as taxonomies and as extensions

DPV and its extensions (collectively DPV vocabularies) consists of certain 'core concepts' that are intended to be independent representations of specific information, and are distinct from other core concepts. For example, the [=Purpose=] refers only to the purpose of why personal data is processed and is independent as a concept from the other concepts (e.g. [=PersonalData=] or [=LegalBasis=]). The structuring of DPV is based on providing rich and comprehensive taxonomies that group concepts together based on each core concept, e.g. taxonomy of purposes, taxonomy of legal basis. 'Extensions' are a separate group of concepts that expand the 'core' vocabulary or provide concepts focused on a particular topic e.g. [[PD]] for personal data categories and [[RISK]] for risk management. Extensions allow allow modelling legally relevant but jurisdictionally applicable concepts e.g. [[EU-GDPR]] for concepts from EU's GDPR.

DPV

The Data Privacy Vocabulary (DPV) provides the following core concepts which have been grouped into 'modules'. Each module has its own documentation page which provides the full definition for involved concepts, provides guidance and examples, and illustrates ongoing discussions on future additions and changes. The modules in DPV are:

Extensions

Extensions reflect additional concepts that extend the core concepts present in DPV and also provide a way to group related concepts that relate to the same topic. Currently, the following extensions are provided. A 'draft' status represents evolving modelling and concepts as they are actively being refined.

[[[PD]]] ([[PD]]) provides additional concepts that extend the DPV's personal data taxonomy based on an opinionated structure contributed by R. Jason Cronk from EnterPrivacy. This separation is to enable adopters to decide whether the extension's concepts are useful to them, or to use other external vocabularies, or define their own.

[[[LOC]]] ([[LOC]]) provides additional concepts regarding locations such as countries and regions based on the ISO 3166 standards.

[[[RISK]]] ([[RISK]]) extends [[DPV]]'s risk assessment concepts based on ISO standards and provides taxonomies relevant to impact assessments.

[[[TECH]]] ([[TECH]]) extends the DPV's terms to represent further specific details regarding technologies, their management, and relevance to actual real-world tools and systems. The [[[AI]]] ([[AI]]) extension further extends [[TECH]] to provide concepts specifically regarding AI techniques, capabilities, risks, data and documentation.

[[[JUSTIFICATIONS]]] ([[JUSTIFICATIONS]]) provides concepts for use as 'justifications' with DPV. For example, where a right cannot be fulfilled, a justification such as 'identity could not be verified' is represented using a specific concept.

[[[LEGAL]]] ([[LEGAL]]) provides concepts to represent laws, authorities, and other legal concepts in various jurisdictions. It is structured to create a separate namespace for each country or jurisdiction by using the ISO 3166-2 code, for example IE represents Ireland and EU represents the European Union. Within this namespace, the specific laws and authorities for that jurisdiction are defined.

Within [[LEGAL]], the following Members States of the European Union are defined in their individual namespaces, with [[LEGAL-EU]] as an additional namespace for representing laws and concepts at EU-level: [[LEGAL-AT]] for Austria, [[LEGAL-BE]] for Belgium, [[LEGAL-BG]] for Bulgaria, [[LEGAL-CY]] for Cyprus, [[LEGAL-CZ]] for Czech Republic, [[LEGAL-DE]] for Germany, [[LEGAL-DK]] for Denmark, [[LEGAL-EE]] for Estonia, [[LEGAL-ES]] for Spain, [[LEGAL-FI]] for Finland, [[LEGAL-FR]] for France, [[LEGAL-GR]] for Greece, [[LEGAL-HR]] for Croatia, [[LEGAL-HU]] for Hungary, [[LEGAL-IE]] for Ireland, [[LEGAL-IS]] for Iceland, [[LEGAL-IT]] for Italy, [[LEGAL-LI]] for Liechtenstein, [[LEGAL-LT]] for Lithuania, [[LEGAL-LU]] for Luxembourg, [[LEGAL-LV]] for Latvia, [[LEGAL-MT]] for Malta, [[LEGAL-NL]] for Netherlands, [[LEGAL-NO]] for Norway, [[LEGAL-PL]] for Poland, [[LEGAL-PT]] for Portugal, [[LEGAL-RO]] for Romania, [[LEGAL-SE]] for Sweden, [[LEGAL-SI]] for Slovenia, [[LEGAL-SK]] for Slovakia. [[LEGAL]] also contains the following jurisdictions: [[LEGAL-GB]] for Great Britain and Northern Ireland, [[LEGAL-HK]] for Hong Kong, [[LEGAL-IN]] for India, [[LEGAL-JP]] for Japan, [[LEGAL-KR]] for Republic of Korea, [[LEGAL-MO]] for Macao, [[LEGAL-MY]] for Malaysia, [[LEGAL-PH]] for the Philippines, [[LEGAL-SG]] for Singapore, [[LEGAL-TH]] for Thailand, [[LEGAL-TW]] for Taiwan, [[LEGAL-US]] for United States of America.

Laws are modelled as extensions within the namespace of their respective jurisdictions. The following are extensions part of [[LEGAL-EU]]: [[[EU-GDPR]]] ([[EU-GDPR]]), [[[EU-DGA]]] ([[EU-DGA]]), [[[EU-NIS2]]] ([[EU-NIS2]]), [[[EU-AIAct]]] ([[EU-AIAct]]), [[[EU-EHDS]]] ([[EU-EHDS]]), [[[EU-RIGHTS]]] ([[EU-RIGHTS]]).

[[SECTOR]] provides extensions modelling specific sectors by using those sector-specific concepts, terms, and modelling which extends the concepts in other DPV extensions. These extensions include: [[SECTOR-EDUCATION]] for Education Sector, [[SECTOR-FINANCE]] for Finance Sector, [[SECTOR-HEALTH]] for Health Sector, [[SECTOR-INFRA]] for (Critical) Infrastructure Sector, [[SECTOR-LAW]] for Law Enforcement & Justice Sector, [[SECTOR-PUBLICSERVICES]] for Public Services Sector.

The [[STANDARDS]] extensions model the core terminologies defined and used within specific forums such as ISO, CEN/CENELEC, NIST, and IEEE so that they can be used with DPV. Currently it provides the extension [[STANDARD-IEEE-7012]] to support the implementation of [[[IEEE-7012]]].

Guidance

Guides

The [[[GUIDE-Consent-27560]]] [[GUIDE-Consent-27560]] provides implementation of machine-readable consent records and receipts as defined in [[ISO-27560]] by using the Data Privacy Vocabulary (DPV). Additionally, it also provides guidance on using [[ISO-27560]] for meeting [[GDPR]] requirements regarding consent.

As the default semantics in DPV use RDFS and SKOS, the [[[GUIDE-OWL2]]] [[GUIDE-OWL2]] provides guidance for the use of DPV as an OWL2 ontology, and explains how DPV can be easily encoded in a low-complexity profile of OWL2 called OWL2-PL to perform efficient semantic reasoning.

Planned guides in the near future include: ISO-29184 Privacy Notices, GDPR Record of Processing Activities (ROPA), GDPR Data Protection Impact Assessment (DPIA), Data Breach Records and Notifications, Rights Management. Also planned is the [[GUIDE-ODRL]] to provide guidance for the use of DPV concepts with [[[ODRL-MODEL]]] and [[[ODRL-VOCAB]]] which are W3C standards for machine-readable representations of policies and agreements.

Applications

This section provides brief examples of how various DPV concepts and extensions are relevant to specific applications.

Vocabulary Index

AcademicResearch Purposes associated with conducting or assisting with research conducted in an academic context e.g. within universities. See full definition in purposes module AcademicScientificOrganisation Organisations related to academia or scientific pursuits e.g. Universities, Schools, Research Bodies. See full definition in entities module AcceptableRule A rule that is acceptable where it is either desirable if it occurs or it is not unacceptable if it does. See full definition in rules module AcceptableUsePolicy Acceptable Use Policy (AUP) refers to conditions, contexts, or uses which are considered acceptable with the implication that those not covered by such a policy are to be considered unacceptable. See full definition in TOM module AcceptContract Control for accepting a contract. See full definition in legal_basis module Access to access data. See full definition in processing module AccessControlMethod Methods which restrict access to a place or resource. See full definition in TOM module AccountManagement Account Management refers to purposes associated with account management, such as to create, provide, maintain, and manage accounts. See full definition in purposes module Acquire to come into possession or control of the data. See full definition in processing module ActivelyInvolved Status indicating the specified context is 'actively' involved. See full definition in context module ActiveRight The right(s) applicable, provided, or expected that need to be (actively) exercised. See full definition in rights module ActivityCompleted State of an activity that has completed i.e. is fully in the past. See full definition in context module ActivityHalted State of an activity that was occurring in the past, and has been halted or paused or stopped. See full definition in context module ActivityMonitoring Monitoring of activities including assessing whether they have been successfully initiated and completed. See full definition in TOM module ActivityNotCompleted State of an activity that could not be completed, but has reached some end state. See full definition in context module ActivityOngoing State of an activity occurring in continuation i.e. currently ongoing. See full definition in context module ActivityPlanned State of an activity being planned with concrete plans for implementation. See full definition in context module ActivityProposed State of an activity being proposed without any concrete plans for implementation. See full definition in context module ActivityStatus Status associated with activity operations and lifecycles. See full definition in context module Adapt to modify the data, often rewritten into a new form for a new use. See full definition in processing module Adult A natural person that is not a child i.e. has attained some legally specified age of adulthood. See full definition in entities module Advertising Purposes associated with conducting advertising i.e. process or artefact used to call attention to a product, service, etc. through announcements, notices, or other forms of communication. See full definition in purposes module Agent An Agent is a dpv:Entity that is (a) acting on behalf of another Entity; and (b) is authorised to do so by that Entity. See full definition in entities module AgeVerification Purposes associated with verifying or authenticating age or age related information as a form of security. See full definition in purposes module Aggregate to aggregate data. See full definition in processing module AIGovernance Procedures related to governance of AI, including its procurement, development, deployment, and assessments. See full definition in TOM module AILiteracy Providing skills, knowledge, and understanding to enable reading, writing, analysing, reasoning, and communicating regarding AI. See full definition in TOM module AINotice A notice providing information regarding the particulars of an AI system such as its intended purpose and proper use. See full definition in TOM module AlgorithmicLogic The algorithmic logic applied or used. See full definition in processing module Align to adjust the data to be in relation to another data. See full definition in processing module Alter to change the data without changing it into something else. See full definition in processing module AmbulanceProvider An organisation that that offers transportation and medical care to patients requiring urgent medical attention. See full definition in entities module Analyse to study or examine the data in detail. See full definition in processing module Anonymisation Anonymisation is the process by which data is irreversibly altered in such a way that a data subject can no longer be identified directly or indirectly, either by the entity holding the data alone or in collaboration with other entities and information sources. See full definition in TOM module Anonymise to irreversibly alter personal data in such a way that an unique data subject can no longer be identified directly or indirectly or in combination with other data. See full definition in processing module AnonymisedData Personal Data that has been (fully and completely) anonymised so that it is no longer considered Personal Data. See full definition in personal_data module Applicability Concept provided to represent indication of cases where the information or context is not applicable (N/A) or not available or this is not known or determined yet. If the information is applicable and available, this concept should not be used.. See full definition in context module Applicant Humans that are applicants in some context. See full definition in entities module ApprovalProcedure A procedure or process for determining and managing approvals for activities as part of governance. See full definition in TOM module Assess to assess data for some criteria. See full definition in processing module Assessment The document, plan, or process for assessment or determination towards a purpose e.g. assessment of legality or impact assessments. See full definition in TOM module AssetManagementProcedures Procedures related to management of assets. See full definition in TOM module AssistiveAutomation Level of automation corresponding to Level 1 in ISO/IEC 22989:2022 where automation is limited to parts of the system or a specific part of the system in a manner that does not change the control of the human in using/driving the system. See full definition in processing module AsylumSeeker Humans that are asylum seekers. See full definition in entities module AsymmetricCryptography Use of public-key cryptography or asymmetric cryptography involving a public and private pair of keys. See full definition in TOM module AsymmetricEncryption Use of asymmetric cryptography to encrypt data. See full definition in TOM module Audit An audit is a systematic examination or evaluation of records, processes, or systems towards a specific objective such as to assess accuracy, compliance, effectiveness, or performance. See full definition in TOM module AuditApproved State of being approved through the audit. See full definition in context module AuditConditionallyApproved State of being conditionally approved through the audit. See full definition in context module AuditNotRequired State where an audit is determined as not being required. See full definition in context module AuditRejected State of not being approved or being rejected through the audit. See full definition in context module AuditRequested State of an audit being requested whose outcome is not yet known. See full definition in context module AuditRequired State where an audit is determined as being required but has not been conducted. See full definition in context module AuditStatus Status associated with Auditing or Investigation. See full definition in context module Authentication-ABC Use of Attribute Based Credentials (ABC) to perform and manage authentication. See full definition in TOM module Authentication-PABC Use of Privacy-enhancing Attribute Based Credentials (ABC) to perform and manage authentication. See full definition in TOM module AuthenticationProtocols Protocols involving validation of identity i.e. authentication of a person or information. See full definition in TOM module AuthorisationProcedure Procedures for determining authorisation through permission or authority. See full definition in TOM module AuthorisationProtocols Protocols involving authorisation of roles or profiles to determine permission, rights, or privileges. See full definition in TOM module Authority An authority with the power to create or enforce laws, or determine their compliance.. See full definition in entities module AuthorityInformed Status indicating Authority has been informed about the specified context. See full definition in context module AuthorityUninformed Status indicating Authority is uninformed i.e. has not been informed about the specified context. See full definition in context module AutomatedDecisionMaking Processing that involves automated decision making. See full definition in processing module AutomatedScoringOfIndividuals Processing that involves automated scoring of individuals. See full definition in processing module AutomationLevel Indication of degree or level of automation associated with specified context. See full definition in processing module Autonomous Level of automation corresponding to Level 6 in ISO/IEC 22989:2022 where the automation in system is capable of modifying its operation domain or its goals without external intervention, control or oversight. See full definition in processing module B2B2CContract A contract between two businesses who partner together to provide services to a consumer. See full definition in legal_basis module B2BContract A contract between two businesses. See full definition in legal_basis module B2CContract A contract between a business and a consumer where the business provides goods or services to the consumer. See full definition in legal_basis module BackgroundChecks Procedure where the background of an entity is assessed to identity vulnerabilities and threats due to their current or intended role. See full definition in TOM module BiometricAuthentication Use of biometric data for authentication. See full definition in TOM module C2BContract A contract between a consumer and a business where the business purchases goods or services from the consumer. See full definition in legal_basis module C2CContract A contract between two consumers. See full definition in legal_basis module CannotChallengeProcess Involvement where entity cannot challenge the process of specified context. See full definition in processing module CannotChallengeProcessInput Involvement where entity cannot challenge input of specified context. See full definition in processing module CannotChallengeProcessOutput Involvement where entity cannot challenge the output of specified context. See full definition in processing module CannotCorrectProcess Involvement where entity cannot correct the process of specified context. See full definition in processing module CannotCorrectProcessInput Involvement where entity cannot correct input of specified context. See full definition in processing module CannotCorrectProcessOutput Involvement where entity cannot correct the output of specified context. See full definition in processing module CannotObjectToProcess Involvement where entity cannot object to process of specified context. See full definition in processing module CannotOptInToProcess Involvement where entity cannot opt-in to specified context. See full definition in processing module CannotOptOutFromProcess Involvement where entity cannot opt-out from specified context. See full definition in processing module CannotReverseProcessEffects Involvement where entity cannot reverse effects of specified context. See full definition in processing module CannotReverseProcessInput Involvement where entity cannot reverse input of specified context. See full definition in processing module CannotReverseProcessOutput Involvement where entity cannot reverse output of specified context. See full definition in processing module CannotWithdrawFromProcess Involvement where entity cannot withdraw a previously given assent from specified context. See full definition in processing module Certification Certification mechanisms, seals, and marks for the purpose of demonstrating compliance. See full definition in TOM module CertificationSeal Certifications, seals, and marks indicating compliance to regulations or practices. See full definition in TOM module ChallengingProcess Involvement where entity can challenge the process of specified context. See full definition in processing module ChallengingProcessInput Involvement where entity can challenge input of specified context. See full definition in processing module ChallengingProcessOutput Involvement where entity can challenge the output of specified context. See full definition in processing module CharityOrganisation A nonprofit entity dedicated to providing assistance or raising funds for social, educational, religious, or other philanthropic purposes. See full definition in entities module Child A 'child' is a natural legal person who is below a certain legal age depending on the legal jurisdiction.. See full definition in entities module Citizen Humans that are citizens (for a jurisdiction). See full definition in entities module City A region consisting of urban population and commerce. See full definition in context module Client Humans that are clients or recipients of services. See full definition in entities module Clinic An organisation that is a smaller healthcare facility offering outpatient medical services for diagnosis and treatment. See full definition in entities module CloudLocation Location that is in the 'cloud' i.e. a logical location operated over the internet. See full definition in context module CodeOfConduct A set of rules or procedures outlining the norms and practices for conducting activities. See full definition in TOM module Collect to gather data from someone. See full definition in processing module CollectedData Data that has been obtained by collecting it from a source. See full definition in personal_data module CollectedPersonalData Personal Data that has been collected from another source such as the Data Subject. See full definition in personal_data module CombatClimateChange Purposes associated with combating the causes and consequences of climate change, including reducing gas emissions and fighting emergencies such as floods or wildfires. See full definition in purposes module Combine to join or merge data. See full definition in processing module CommerciallyConfidentialData Data that is considered confidential due to business/trade secrets, confidentiality agreements, or company secrets. See full definition in personal_data module CommercialPurpose Purposes associated with processing activities performed in a commercial setting or with intention to commercialise. See full definition in purposes module CommercialResearch Purposes associated with conducting research in a commercial setting or with intention to commercialise e.g. in a company or sponsored by a company. See full definition in purposes module CommunicationForCustomerCare Customer Care Communication refers to purposes associated with communicating with customers for assisting them, resolving issues, ensuring satisfaction, etc. in relation to services provided. See full definition in purposes module CommunicationManagement Communication Management refers to purposes associated with providing or managing communication activities e.g. to send an email for notifying some information. See full definition in purposes module CompatibilityUnknown Status indicating the compatibility of the context with an earlier context is currently unknown. See full definition in context module ComplianceAssessment Assessment regarding compliance (e.g. internal policy, regulations). See full definition in TOM module ComplianceIndeterminate State where the status of compliance has not been fully assessed, evaluated, or determined. See full definition in context module ComplianceMonitoring Monitoring of compliance (e.g. internal policy, regulations). See full definition in TOM module ComplianceStatus Status associated with Compliance with some norms, objectives, or requirements. See full definition in context module ComplianceUnknown State where the status of compliance is unknown. See full definition in context module ComplianceViolation State where compliance cannot be achieved due to requirements being violated. See full definition in context module Compliant State of being fully compliant. See full definition in context module ConditionalAutomation Level of automation corresponding to Level 3 in ISO/IEC 22989:2022 where the automation is sufficient to perform most tasks of the system with the human present to take over where necessary. See full definition in processing module ConfidentialData Data deemed confidential. See full definition in personal_data module ConfidentialityAgreement Agreements that enforce confidentiality for e.g. to protect business, professional, or company secrets. See full definition in TOM module ConformanceAssessment Assessment regarding conformance with standards or norms or guidelines or similar instruments. See full definition in TOM module ConformanceStatus Status associated with conformance to a standard, guideline, code, or recommendation. See full definition in context module Conformant State of being conformant. See full definition in context module Consent Consent of the Data Subject for specified process or activity. See full definition in legal_basis module ConsentControl The control or activity associated with obtaining, providing, withdrawing, or reaffirming consent. See full definition in legal_basis module ConsentExpired The state where the temporal or contextual validity of consent has 'expired'. See full definition in legal_basis module ConsentGiven The state where consent has been given. See full definition in legal_basis module ConsentInvalidated The state where consent has been deemed to be invalid. See full definition in legal_basis module ConsentManagement Methods to obtain, provide, modify, and withdraw consent along with maintaining a record of consent, retrieving records, and processing changes in consent states. See full definition in TOM module ConsentNotice A Notice for information provision associated with Consent. See full definition in TOM module ConsentReceipt A record of consent or consent related activities that is provided to another entity. See full definition in TOM module ConsentRecord A Record of Consent or Consent related activities. See full definition in TOM module ConsentRefused The state where consent has been refused. See full definition in legal_basis module ConsentRequestDeferred State where a request for consent has been deferred without a decision. See full definition in legal_basis module ConsentRequested State where a request for consent has been made and is awaiting a decision. See full definition in legal_basis module ConsentRevoked The state where the consent is revoked by an entity other than the data subject and which prevents it from being further used as a valid state. See full definition in legal_basis module ConsentStatus The state or status of 'consent' that provides information reflecting its operational status and validity for processing data. See full definition in legal_basis module ConsentStatusInvalidForProcessing States of consent that cannot be used as valid justifications for processing data. See full definition in legal_basis module ConsentStatusValidForProcessing States of consent that can be used as valid justifications for processing data. See full definition in legal_basis module ConsentUnknown State where information about consent is not available or is unknown. See full definition in legal_basis module ConsentWithdrawn The state where the consent is withdrawn or revoked specifically by the data subject and which prevents it from being further used as a valid state. See full definition in legal_basis module Consequence The consequence(s) possible or arising from specified context. See full definition in risk module ConsequenceAsSideEffect The consequence(s) possible or arising as a side-effect of specified context. See full definition in risk module ConsequenceOfFailure The consequence(s) possible or arising from failure of specified context. See full definition in risk module ConsequenceOfSuccess The consequence(s) possible or arising from success of specified context. See full definition in risk module Consult to consult or query data. See full definition in processing module Consultation Consultation is a process of receiving feedback, advice, or opinion from an external agency. See full definition in TOM module ConsultationWithAuthority Consultation with an authority or authoritative entity. See full definition in TOM module ConsultationWithDataSubject Consultation with data subject(s) or their representative(s). See full definition in TOM module ConsultationWithDataSubjectRepresentative Consultation with representative of data subject(s). See full definition in TOM module ConsultationWithDPO Consultation with Data Protection Officer(s). See full definition in TOM module Consumer Humans that consume goods or services for direct use. See full definition in entities module ConsumerStandardFormContract A contract where the terms and conditions are determined by parties in the role of a 'consumer' - whether an entity or an individual, and the other parties have negligible or no ability to negotiate the terms and conditions. See full definition in legal_basis module Context Contextually relevant information. See full definition in context module ContextuallyAnonymisedData Data that can be considered as being fully anonymised within the context but in actuality is not fully anonymised and is still personal data as it can be de-anonymised outside that context. See full definition in personal_data module ContinuousFrequency Frequency where occurrences are continuous. See full definition in context module Contract Creation, completion, fulfilment, or performance of a contract involving specified processing of data or technologies. See full definition in legal_basis module ContractActivationStatus Status associated with activation of a contract i.e. whether its terms are active and are required to be performed. See full definition in legal_basis module ContractActive Status representing contract that has been fully executed and whose terms are considered active i.e. they are applicable and are required to be performed. See full definition in legal_basis module ContractAmended Status representing contract that has been fully executed and whose terms have been amended through mutual agreement or other means such that the contract is still required to be performed. See full definition in legal_basis module ContractAmendmentClause A provision describing how changes or modifications to the contract can be made and the process for implementing them. See full definition in legal_basis module ContractApproved Status representing contract has been approved and can be used for signing. See full definition in legal_basis module ContractBeingPerformed Status representing contract that has been fully executed and whose terms are being carried out i.e. the contract is being performed. See full definition in legal_basis module ContractBreached Status representing contract being breached where its terms are not fulfilled or are violated with legal consequences. See full definition in legal_basis module ContractByDomain A generic concept representing contracts categorised by specific domains which dictate the drafting and interpretation of contracts. See full definition in legal_basis module ContractByEntityType A generic concept representing contracts categorised by the type of entities involved - such as Businesses (B), Consumers (C), and Governments (G). See full definition in legal_basis module ContractByNegotiationType A generic concept representing contracts categorised based on their use or absence of negotiation in the contract forming process. See full definition in legal_basis module ContractConfidentialityClause A provision requiring parties to keep certain information confidential and not disclose it to third parties. See full definition in legal_basis module ContractControl The control or activity associated with accepting, refusing, and other actions associated with a contract. See full definition in legal_basis module ContractDefinitions A section specifying the meanings of key terms and phrases used throughout the contract. See full definition in legal_basis module ContractDisputed Status representing contract being disputed where one or more parties have an issue regarding the interpretation and performance of the contract. See full definition in legal_basis module ContractDisputeResolutionClause A provision detailing the methods and procedures for resolving disagreements or conflicts arising from the contract. See full definition in legal_basis module ContractDrafted Status representing the drafting of contract text has been completed and it can now be offered for signing. See full definition in legal_basis module ContractExecutionStatus Status associated with execution of a contract (i.e. signing and procedural aspects before the contract terms come in to effect). See full definition in legal_basis module ContractExpired Status representing reaching the expiry defined in the contract, such as when the stated duration or the stated obligations have been completed. See full definition in legal_basis module ContractExtended Status representing the duration associated with a contract being extended through mutual agreement or by a party. See full definition in legal_basis module ContractFulfilled Status representing contract where all its terms have been fulfilled in a manner that does not constitute a violation or breach of the contract. See full definition in legal_basis module ContractFulfilmentStatus Status associated with fulfilment of a contract. See full definition in legal_basis module ContractFullyExecuted Status representing contract has been fully executed i.e. it has been signed by all parties and all other procedural aspects such as exchange of signed contract copies have been completed. See full definition in legal_basis module ContractFullySigned Status representing contract has been signed by all concerned parties. See full definition in legal_basis module ContractInactive Status representing contract that has been fully executed and whose terms are not yet active i.e. they need to be performed at a later time. See full definition in legal_basis module ContractJurisdictionClause A provision specifying the legal jurisdiction or court where disputes related to the contract will be resolved. See full definition in legal_basis module ContractNegotiated Status representing contract has been successfully negotiated by involved parties. See full definition in legal_basis module ContractNotFulfilled Status representing contract where none of its terms have been fulfilled in a manner that does not constitute a violation or breach of the contract i.e. there is still time and opportunity to complete the terms. See full definition in legal_basis module ContractOffered Status representing contract has been offered to a party or to parties for reviewing and signing. See full definition in legal_basis module ContractPartiallyFulfilled Status representing contract where some of its terms have been fulfilled, and others are yet to be fulfilled in a manner that does not constitute a violation or breach of the contract i.e. there is still time and opportunity to complete the terms. See full definition in legal_basis module ContractPartiallySigned Status representing contract has been partially signed by parties i.e. some parties have signed the contract and others are yet to make a decision to sign it. See full definition in legal_basis module ContractPerformance Fulfilment or performance of a contract involving specified processing of data or technologies. See full definition in legal_basis module ContractPerformanceStatus Status associated with performance of a contract. See full definition in legal_basis module ContractPreamble An introductory section outlining the background, context, and purpose of the contract. See full definition in legal_basis module ContractPreparationStatus Status associated with preparation of contracts before they are signed or accepted or executed. See full definition in legal_basis module ContractRejected Status representing contract has been rejected and cannot be used for signing. See full definition in legal_basis module ContractRenewed Status representing contract being renewed with new duration and/or applicability where the contract has been fully executed in the past. See full definition in legal_basis module ContractSignedByParty Status representing contract has been signed by the indicated signing party. See full definition in legal_basis module ContractStatus Status associated with a contract. See full definition in legal_basis module ContractTemporarilySuspended Status representing contract that has been temporarily suspended through mutual agreement or by some parties. See full definition in legal_basis module ContractTerminated Status representing contract being terminated by one or more parties. See full definition in legal_basis module ContractTerminationClause A provision outlining the conditions under which the contract can be terminated before its completion, including any penalties or obligations. See full definition in legal_basis module ContractTerminationStatus Status associated with termination of a contract. See full definition in legal_basis module ContractualClause A part or component within a contract that outlines its specifics. See full definition in legal_basis module ContractualClauseFulfilled Status indicating the terms of the contractual clause are fulfilled i.e. they have been successfully completed without violation. See full definition in legal_basis module ContractualClauseFulfilmentStatus Status associated with fulfilment of a contractual clause. See full definition in legal_basis module ContractualClauseNotFulfilled Status indicating the terms of the contractual clause have not yet been fulfilled in a manner that does not constitute a violation i.e. there is still an opportunity to complete them. See full definition in legal_basis module ContractualClausePartiallyFulfilled Status indicating some of the terms of the contractual clause have been fulfilled, and others have not yet been fulfilled in a manner that does not constitute a violation i.e. there is still an opportunity to complete them. See full definition in legal_basis module ContractualClauseViolated Status indicating the terms of the contractual clause have been violated. See full definition in legal_basis module ContractualTerms Contractual terms governing data handling within or with an entity. See full definition in TOM module ContractUnderNegotiation Status representing contract is under negotiation between parties. See full definition in legal_basis module ContractUnderReview Status representing contract is under review and is being considered for signing. See full definition in legal_basis module ContractViolated Status representing contract where one or more terms have not been fulfilled or have been fulfilled, where either is considered a violation of the terms. See full definition in legal_basis module ControllerDataSubjectAgreement An agreement outlining conditions, criteria, obligations, responsibilities, and specifics for carrying out processing of data between a Data Controller and a Data Subject. See full definition in legal_basis module ControllerInformed Status indicating Controller has been informed about the specified context. See full definition in context module ControllerProcessorAgreement An agreement outlining conditions, criteria, obligations, responsibilities, and specifics for carrying out processing of data between a Data Controller and a Data Processor. See full definition in legal_basis module ControllerUninformed Status indicating Controller is uninformed i.e. has not been informed about the specified context. See full definition in context module Copy to produce an exact reproduction of the data. See full definition in processing module CorrectingProcess Involvement where entity can correct the process of specified context. See full definition in processing module CorrectingProcessInput Involvement where entity can correct input of specified context. See full definition in processing module CorrectingProcessOutput Involvement where entity can correct the output of specified context. See full definition in processing module CounterMoneyLaundering Purposes associated with detection, prevention, and mitigation of mitigate money laundering. See full definition in purposes module Counterterrorism Purposes associated with activities that detect, prevent, mitigate, or otherwise perform activities to combat or eliminate terrorism (also referred to as anti-terrorism). See full definition in purposes module Country A political entity indicative of a sovereign or non-sovereign territorial state comprising of distinct geographical areas. See full definition in context module CredentialManagement Management of credentials and their use in authorisations. See full definition in TOM module CrossBorderTransfer to move data from one jurisdiction (border) to another. See full definition in processing module CryptographicAuthentication Use of cryptography for authentication. See full definition in TOM module CryptographicKeyManagement Management of cryptographic keys, including their generation, storage, assessment, and safekeeping. See full definition in TOM module CryptographicMethods Use of cryptographic methods to perform tasks. See full definition in TOM module Customer Humans that purchase goods or services. See full definition in entities module CustomerCare Customer Care refers to purposes associated with purposes for providing assistance, resolving issues, ensuring satisfaction, etc. in relation to services provided. See full definition in purposes module CustomerClaimsManagement Customer Claims Management refers to purposes associated with managing claims, including repayment of monies owed. See full definition in purposes module CustomerManagement Customer Management refers to purposes associated with managing activities related with past, current, and future customers. See full definition in purposes module CustomerOrderManagement Customer Order Management refers to purposes associated with managing customer orders i.e. processing of an order related to customer's purchase of good or services. See full definition in purposes module CustomerRelationshipManagement Customer Relationship Management refers to purposes associated with managing and analysing interactions with past, current, and potential customers. See full definition in purposes module CustomerSolvencyMonitoring Customer Solvency Monitoring refers to purposes associated with monitor solvency of customers for financial diligence. See full definition in purposes module CybersecurityAssessment Assessment of cybersecurity capabilities in terms of vulnerabilities and effectiveness of controls. See full definition in risk module CybersecurityTraining Training methods related to cybersecurity. See full definition in TOM module DashboardNotice A notice that is provided within a dashboard also used for other purposes. See full definition in TOM module Data A broad concept representing 'data' or 'information'. See full definition in personal_data module DataAltruism Purposes associated with the voluntary sharing of data for the general interest of the public, such as healthcare or combating climate change. See full definition in purposes module DataAvailabilityAssessment Measures associated with assessment of availability of data for specific task(s). See full definition in TOM module DataBackupProtocols Protocols or plans for backing up of data. See full definition in TOM module DataBreachImpactAssessment Impact Assessment concerning the consequences and impacts of a data breach. See full definition in risk module DataBreachNotice A notice providing information about data breach(es) i.e. unauthorised transfer, access, use, or modification of data. See full definition in TOM module DataBreachNotification Notification of information about data breach(es) i.e. unauthorised transfer, access, use, or modification of data. See full definition in TOM module DataBreachRecord Record of a data breach incident. See full definition in TOM module DataController The individual or organisation that decides (or controls) the purpose(s) of processing personal data.. See full definition in entities module DataControllerContract Creation, completion, fulfilment, or performance of a contract, with Data Controllers as parties being Joint Data Controllers, and involving specified processing of data or technologies. NOTE: This concept is being deprecated - use dpv:JointDataControllersAgreement which has a more explicit definition of the entities involved and the intent of the contract. See full definition in legal_basis module DataControllerDataSource Data Sourced from Data Controller(s), e.g. a Controller inferring data or generating data. See full definition in processing module DataDeletionPolicy Policy regarding deletion of data. See full definition in TOM module DataErasurePolicy Policy regarding erasure of data. See full definition in TOM module DataExporter An entity that 'exports' data where exporting is considered a form of data transfer. See full definition in entities module DataGovernance Measures associated with topics typically considered to be part of 'Data Governance'. See full definition in TOM module DataHandlingClause Contractual clauses governing handling of data within or by an entity. See full definition in TOM module DataImporter An entity that 'imports' data where importing is considered a form of data transfer. See full definition in entities module DataInteroperabilityAssessment Measures associated with assessment of data interoperability. See full definition in TOM module DataInteroperabilityImprovement Measures associated with improvement of data interoperability. See full definition in TOM module DataInteroperabilityManagement Measures associated with management of data interoperability. See full definition in TOM module DataInventoryManagement Measures associated with management of data inventory or a data asset list. See full definition in TOM module DataJurisdictionPolicy Policy specifying jurisdictional requirements for data processing. See full definition in TOM module DataLiteracy Providing skills, knowledge, and understanding to enable reading, writing, analysing, reasoning, and communicating regarding data. See full definition in TOM module DataProcessingAgreement An agreement outlining conditions, criteria, obligations, responsibilities, and specifics for carrying out processing of data. See full definition in legal_basis module DataProcessingPolicy Policy regarding data processing activities. See full definition in TOM module DataProcessingRecord Record of data processing, whether ex-ante or ex-post. See full definition in TOM module DataProcessor A ‘processor’ means a natural or legal person, public authority, agency or other body which processes data on behalf of the controller.. See full definition in entities module DataProcessorContract Creation, completion, fulfilment, or performance of a contract, with the Data Controller and Data Processor as parties, and involving specified processing of data or technologies. NOTE: This concept is being deprecated - use dpv:ControllerProcessorAgreement which has a more explicit definition of the entities involved and the intent of the contract. See full definition in legal_basis module DataProtectionAuthority An authority tasked with overseeing legal compliance regarding privacy and data protection laws.. See full definition in entities module DataProtectionOfficer An entity within or authorised by an organisation to monitor internal compliance, inform and advise on data protection obligations and act as a contact point for data subjects and the supervisory authority.. See full definition in entities module DataProtectionTraining Training intended to increase knowledge regarding data protection. See full definition in TOM module DataPublishedByDataSubject Data is published by the data subject. See full definition in processing module DataQualityAssessment Measures associated with assessment of data quality. See full definition in TOM module DataQualityImprovement Measures associated with improvement of data quality. See full definition in TOM module DataQualityManagement Measures associated with management of data quality. See full definition in TOM module DataRedaction Removal of sensitive information from a data or document. See full definition in TOM module DataRestorationPolicy Policy regarding restoration of data. See full definition in TOM module DataReusePolicy Policy regarding reuse of data i.e. using data for purposes other than its initial purpose. See full definition in TOM module DataSanitisationTechnique Cleaning or any removal or re-organisation of elements in data based on selective criteria. See full definition in TOM module DataSecurityManagement Measures associated with management of data security. See full definition in TOM module DataSource The source or origin of data. See full definition in processing module DataStoragePolicy Policy regarding storage of data, including the manner, duration, location, and conditions for storage. See full definition in TOM module DataSubject The individual (or category of individuals) whose personal data is being processed. See full definition in entities module DataSubjectContract Creation, completion, fulfilment, or performance of a contract, with the Data Controller and Data Subject as parties, and involving specified processing of data or technologies. NOTE: This concept is being deprecated - use dpv:ControllerDataSubjectAgreement which has a more explicit definition of the entities involved and the intent of the contract. See full definition in legal_basis module DataSubjectDataSource Data Sourced from Data Subject(s), e.g. when data is collected via a form or observed from their activities. See full definition in processing module DataSubjectInformed Status indicating DataSubject has been informed about the specified context. See full definition in context module DataSubjectRight The rights applicable or provided to a Data Subject. See full definition in rights module DataSubjectRightsManagement Methods to provide, implement, and exercise data subjects' rights. See full definition in TOM module DataSubjectScale Scale of Data Subject(s). See full definition in processing module DataSubjectUninformed Status indicating DataSubject is uninformed i.e. has not been informed about the specified context. See full definition in context module DataSubProcessor A 'sub-processor' is a processor engaged by another processor. See full definition in entities module DataSuitabilityAssessment Measures associated with assessment of suitability of data for specific task(s). See full definition in TOM module DataTransferImpactAssessment Impact Assessment for conducting data transfers. See full definition in risk module DataTransferLegalBasis Specific or special categories and instances of legal basis intended for justifying data transfers. See full definition in legal_basis module DataTransferNotice Notice for the legal entity for the transfer of its data. See full definition in TOM module DataTransferRecord Record of data transfer activities. See full definition in TOM module DataVolume Volume or Scale of Data. See full definition in processing module DecentralisedLocations Location that is spread across multiple separate areas with no distinction between their importance. See full definition in context module DecisionMaking Processing that involves decision making. See full definition in processing module Deidentification Removal of identity or information to reduce identifiability. See full definition in TOM module Delete to remove data in a logical fashion i.e. with the possibility of retrieval. See full definition in processing module DeliveryOfGoods Purposes associated with delivering goods and services requested or asked by consumer. See full definition in purposes module Derive to create new derivative data from the original data. See full definition in processing module DerivedData Data that has been obtained through derivations of other data. See full definition in personal_data module DerivedPersonalData Personal Data that is obtained or derived from other data. See full definition in personal_data module DesignStandard A set of rules or guidelines outlining criterias for design. See full definition in TOM module Destruct to process data in a way it no longer exists or cannot be repaired. See full definition in processing module DeterministicPseudonymisation Pseudonymisation achieved through a deterministic function. See full definition in TOM module Deterrence A rule describing a deterrence for performing an activity. See full definition in rules module DeterrenceFollowed Status indicating a deterrence has been followed i.e. the activity stated as being deterred has not been carried out. See full definition in rules module DeterrenceNotFollowed Status indicating a deterrence has not been followed i.e. the activity stated as being deterred has been carried out. See full definition in rules module DeviceNotice A notice provided using the functionality provided by a device e.g. using the popup or alert feature. See full definition in TOM module DifferentialPrivacy Utilisation of differential privacy where information is shared as patterns or groups to withhold individual elements. See full definition in TOM module DigitalLiteracy Providing skills, knowledge, and understanding to enable reading, writing, analysing, reasoning, and communicating regarding digital technologies and their implications. See full definition in TOM module DigitalRightsManagement Management of access, use, and other operations associated with digital content. See full definition in TOM module DigitalSignatures Expression and authentication of identity through digital information containing cryptographic signatures. See full definition in TOM module DirectMarketing Purposes associated with conducting direct marketing i.e. marketing communicated directly to the individual. See full definition in purposes module DisasterRecoveryProcedures Procedures related to management of disasters and recovery. See full definition in TOM module Disclose to make data known. See full definition in processing module DiscloseByTransmission to disclose data by means of transmission. See full definition in processing module Display to present or show data. See full definition in processing module DisputeManagement Purposes associated with activities that manage disputes by natural persons, private bodies, or public authorities relevant to organisation. See full definition in purposes module Disseminate to spread data throughout. See full definition in processing module DistributedSystemSecurity Security implementations provided using or over a distributed system. See full definition in TOM module DistributionAgreement A contract regarding supply of data or technologies between a distributor and a supplier. See full definition in legal_basis module DocumentRandomisedPseudonymisation Use of randomised pseudonymisation where the same elements are assigned different values in the same document or database. See full definition in TOM module DocumentSecurity Security measures enacted over documents to protect against tampering or restrict access. See full definition in TOM module Download to provide a copy or to receive a copy of data over a network or internet. See full definition in processing module DPIA Impact assessment determining the potential and actual impact of processing activities on individuals or groups of individuals and taking into account the impacts of activities on their rights and freedoms. See full definition in risk module Duration The duration or temporal limitation. See full definition in context module EconomicUnion A political union of two or more countries based on economic or trade agreements. See full definition in context module EducationalOrganisation An organisation focused on delivering formal or informal education, training, or research. See full definition in entities module EducationalTraining Training methods that are intended to provide education on topic(s). See full definition in TOM module EffectivenessDeterminationProcedures Procedures intended to determine effectiveness of other measures. See full definition in TOM module ElderlyDataSubject Data subjects that are considered elderly (i.e. based on age). See full definition in entities module ElderlyHuman Humans that are considered elderly (i.e. based on age). See full definition in entities module EmergencyHealthcareProvider An organisation that is an emergency service provider focused on delivering immediate medical care to patients in critical or life-threatening situations. See full definition in entities module EmergencyServiceProvider An organisation tasked with providing emergency services such as by responding rapidly to urgent situations to protect lives, property, and the environment. See full definition in entities module Employee Humans that are employees. See full definition in entities module EmploymentContract A contract regarding employment between an employer and an employee. See full definition in legal_basis module Encryption Technical measures consisting of encryption. See full definition in TOM module EncryptionAtRest Encryption of data when being stored (persistent encryption). See full definition in TOM module EncryptionInTransfer Encryption of data in transit e.g. when being transferred from one location to another, including sharing. See full definition in TOM module EncryptionInUse Encryption of data when it is being used. See full definition in TOM module EndlessDuration Duration that is (known or intended to be) open ended or without an end. See full definition in context module EndToEndEncryption Encrypted communications where data is encrypted by the sender and decrypted by the intended receiver to prevent access to any third party. See full definition in TOM module EnforceAccessControl Purposes associated with conducting or enforcing access control as a form of security. See full definition in purposes module EnforceSecurity Purposes associated with ensuring and enforcing security for data, personnel, or other related matters. See full definition in purposes module EnterIntoContract Processing necessary to enter into contract. See full definition in legal_basis module Entity A human or non-human 'thing' that constitutes as an entity. See full definition in entities module EntityActiveInvolvement Involvement where entity is 'actively' involved. See full definition in processing module EntityInformed Status indicating entity has been informed about specified context. See full definition in context module EntityInformedStatus Status indicating whether an entity is informed or uninformed about specified context. See full definition in context module EntityIntendedInvolvement Status indicating the involvement of the entity is intended. See full definition in processing module EntityInvolved Status indicating the entity is involved. See full definition in processing module EntityInvolvement Involvement of an entity in specific context. See full definition in processing module EntityInvolvementStatus Status indicating whether an entity is involved. See full definition in processing module EntityNonInvolvement Indicating entity is not involved. See full definition in processing module EntityNonPermissiveInvolvement Involvement of an entity in specific context where it is not permitted or able to do something. See full definition in processing module EntityNotInvolved Status indicating the entity is not involved. See full definition in processing module EntityPassiveInvolvement Involvement where entity is 'passively' or 'not actively' involved. See full definition in processing module EntityPermissiveInvolvement Involvement of an entity in specific context where it is permitted or able to do something. See full definition in processing module EntityUninformed Status indicating entity is uninformed i.e. has been not been informed about specified context. See full definition in context module EntityUnintendedInvolvement Status indicating the involvement of the entity is not intended. See full definition in processing module EnvironmentalProtection Physical protection against environmental threats such as fire, floods, storms, etc.. See full definition in TOM module Erase to remove data from existence i.e. without the possibility of retrieval. See full definition in processing module EstablishContractualAgreement Purposes associated with carrying out data processing to establish an agreement, such as for entering into a contract. See full definition in purposes module EULA End User License Agreement is a contract entered into between a software (or service) developer or provider with the (end-)user. See full definition in legal_basis module EvaluationOfIndividuals Processing that involves evaluation of individuals. See full definition in processing module EvaluationScoring Processing that involves evaluation and scoring of individuals. See full definition in processing module ExpectationStatus Status indicating whether the specified context was intended or unintended. See full definition in context module Expected Status indicating the specified context was expected. See full definition in context module ExplicitlyExpressedConsent Consent that is expressed through an explicit action solely conveying a consenting decision. See full definition in legal_basis module Export to provide a copy of data from one system to another. See full definition in processing module ExpressedConsent Consent that is expressed through an action intended to convey a consenting decision. See full definition in legal_basis module FailSafeProtocols Use of fail-safe measures and protocols. See full definition in TOM module FederatedLocations Location that is federated across multiple separate areas with designation of a primary or central location. See full definition in context module FeeNotRequired Concept indicating a fee is not required. This is distinct from a Fee of zero as it indicates a fee is not applicable in the context. See full definition in context module FeeRequired Concept indicating a fee is required. The value of the fee should be specified using rdf:value or an another relevant means. See full definition in context module FeeRequirement Concept indicating whether a fee is required. See full definition in context module FileSystemSecurity Security implemented over a file system. See full definition in TOM module Filter to filter or keep data for some criteria. See full definition in processing module FireDepartment An organisation that is an emergency service provider for fire prevention, firefighting, and rescue services. See full definition in entities module FixedLocation Location that is fixed i.e. known to occur at a specific place. See full definition in context module FixedMultipleLocations Location that is fixed with multiple places e.g. multiple cities. See full definition in context module FixedOccurrencesDuration Duration that takes place a fixed number of times e.g. 3 times. See full definition in context module FixedSingularLocation Location that is fixed at a specific place e.g. a city. See full definition in context module Format to arrange or structure data in a specific form. See full definition in processing module ForProfitOrganisation An organisation that aims to achieve profit as its primary goal. See full definition in entities module FraudPreventionAndDetection Purposes associated with fraud detection, prevention, and mitigation. See full definition in purposes module Frequency The frequency or information about periods and repetitions in terms of recurrence.. See full definition in context module FRIA Impact assessment which assesses the potential and actual impact on fundamental rights occurring due to processing activities. See full definition in risk module FulfilmentOfContractualObligation Purposes associated with carrying out data processing to fulfill a contractual obligation. See full definition in purposes module FulfilmentOfObligation Purposes associated with carrying out data processing to fulfill an obligation. See full definition in purposes module FullAutomation Level of automation corresponding to Level 5 in ISO/IEC 22989:2022 where the automation in system is capable of performing all its tasks regardless of the conditions without human involvement. See full definition in processing module FullyRandomisedPseudonymisation Use of randomised pseudonymisation where the same elements are assigned different values each time they occur. See full definition in TOM module G2BContract A contract between a government and a business. See full definition in legal_basis module G2CContract A contract between a government and consumers. See full definition in legal_basis module G2GContract A contract between two governments or government departments or units. See full definition in legal_basis module Generate to generate or create data. See full definition in processing module GeneratedData Data that is generated or brought into existence without relation to existing data i.e. it is not derived or inferred from other data. See full definition in personal_data module GeneratedPersonalData Personal Data that is generated or brought into existence without relation to existing data i.e. it is not derived or inferred from other data. See full definition in personal_data module GeographicCoverage Indicate of scale in terms of geographic coverage. See full definition in processing module GlobalScale Geographic coverage spanning the entire globe. See full definition in processing module GovernanceProcedures Procedures related to governance (e.g. organisation, unit, team, process, system). See full definition in TOM module GovernmentalOrganisation An organisation managed or part of government. See full definition in entities module GraphicalNotice A notice that uses graphical elements such as visualisations and icons. See full definition in TOM module GuardianOfDataSubject Guardian(s) of data subjects such as children. See full definition in entities module GuardianOfHuman Guardian(s) of humans. See full definition in entities module Guideline Practices that specify how activities must be conducted. See full definition in TOM module GuidelinesPrinciple Guidelines or Principles regarding processing and operational measures. See full definition in TOM module HardwareSecurityProtocols Security protocols implemented at or within hardware. See full definition in TOM module hasActiveEntity indicates the entity is actively involved in specified context. See full definition in processing module hasActivityStatus Indicates the status of activity of specified concept. See full definition in context module hasAddress Specifies address of a legal entity such as street address or pin code. See full definition in entities module hasAlgorithmicLogic Indicates the logic used in processing such as for automated decision making. See full definition in processing module hasApplicability Indicates situations where the context is not applicable, information is not available, or this is unknown. An appropriate instance of dpv:Applicability should be used with this relation to express the situation. See full definition in context module hasApplicableLaw Indicates applicability of a Law. See full definition in context module hasAssessment Indicates a relevant assessment associated with the specific context. See full definition in TOM module hasAuditStatus Indicates the status of audit associated with specified concept. See full definition in context module hasAuthority Indicates applicability of authority for a jurisdiction. See full definition in entities module hasAutomationLevel Indicates the level of automation involved in implementation of the specified context. See full definition in processing module hasComplianceStatus Indicates the status of compliance of specified concept. See full definition in context module hasConformanceStatus Indicates the status of being conformant or non-conformant. See full definition in context module hasConsentControl Specific a control associated with consent. See full definition in legal_basis module hasConsentStatus Specifies the state or status of consent. See full definition in legal_basis module hasConsequence Indicates consequence(s) possible or arising from specified concept. See full definition in risk module hasConsequenceOn Indicates the thing (e.g. plan, process, or entity) affected by a consequence. See full definition in risk module hasContact Specifies contact details of a legal entity such as phone or email. See full definition in entities module hasContext Indicates a purpose is restricted to the specified context(s). See full definition in context module hasContractControl Indicates the contract to be used with a contract. See full definition in legal_basis module hasContractStatus Indicates the status of the contract. See full definition in legal_basis module hasContractualClause Indicates the association or involvement of specified contractual clause. See full definition in legal_basis module hasContractualFulfilmentStatus Indicates the fulfilment status of a contract or a contractual clause. See full definition in legal_basis module hasCountry Indicates applicability of specified country. See full definition in context module hasData Indicates associated with Data (may or may not be personal). See full definition in personal_data module hasDataController Indicates association with Data Controller. See full definition in entities module hasDataExporter Indicates inclusion or applicability of a LegalEntity in the role of Data Exporter. See full definition in entities module hasDataImporter Indicates inclusion or applicability of a LegalEntity in the role of Data Importer. See full definition in entities module hasDataProcessor Indicates inclusion or applicability of a Data Processor. See full definition in entities module hasDataProtectionOfficer Specifies an associated data protection officer. See full definition in entities module hasDataSource Indicates the source or origin of data being processed. See full definition in processing module hasDataSubject Indicates association with Data Subject. See full definition in entities module hasDataSubjectScale Indicates the scale of data subjects. See full definition in processing module hasDataVolume Indicates the volume of data. See full definition in processing module hasDeterrence Specifies applicability or inclusion of a deterrence rule within specified context. See full definition in rules module hasDuration Indicates information about duration. See full definition in context module hasEntity Indicates inclusion or applicability of an entity to some concept. See full definition in entities module hasEntityControl Indicates a control or measure provided for an entity to perform the specified action. See full definition in TOM module hasEntityInvolvement Indicates involvement of an entity in specified context. See full definition in processing module hasExpectation Indicates whether the specified context was expected or unexpected. See full definition in context module hasFee Indicates whether a fee is required for the specified context. See full definition in context module hasFrequency Indicates the frequency with which something takes place. See full definition in context module hasFulfilmentStatus Specifies the fulfillment status associated with a rule. See full definition in rules module hasGeographicCoverage Indicates the geographic coverage (of specified context). See full definition in processing module HashFunctions Use of hash functions to map information or to retrieve a prior categorisation. See full definition in TOM module HashMessageAuthenticationCode Use of HMAC where message authentication code (MAC) utilise a cryptographic hash function and a secret cryptographic key. See full definition in TOM module hasHumanInvolvement Indicates Involvement of humans in processing such as within automated decision making process. See full definition in processing module hasHumanSubject Indicates association with Human Subject. See full definition in entities module hasIdentifier Indicates an identifier associated for identification or reference. See full definition in context module hasImpact Indicates impact(s) possible or arising as consequences from specified concept. See full definition in risk module hasImpactAssessment Indicates an impact assessment associated with the specific context. See full definition in risk module hasImpactOn Indicates the thing (e.g. plan, process, or entity) affected by an impact. See full definition in risk module hasImportance Indicates the importance for specified context or criteria. See full definition in context module hasIndicationMethod Specifies the method by which an entity has indicated the specific context. See full definition in legal_basis module hasInformedStatus Indicates whether an entity was informed or uninformed. See full definition in context module hasIntention Indicates whether the specified context was intended or unintended. See full definition in context module hasInverseJurisdiction Indicates the inverse jurisdiction for a given jurisdiction. See full definition in context module hasInvolvement Indicates the involvement status for the specified context. See full definition in context module hasJointDataControllers Indicates inclusion or applicability of a Joint Data Controller. See full definition in entities module hasJurisdiction Indicates applicability of specified jurisdiction. See full definition in context module hasJustification Indicates a justification for specified concept or context. See full definition in context module hasLawfulness Indicates the status of being lawful or legally compliant. See full definition in context module hasLegalBasis Indicates use or applicability of a Legal Basis. See full definition in legal_basis module hasLegalMeasure Indicates use or applicability of Legal measure. See full definition in TOM module hasLikelihood Indicates the likelihood associated with a concept. See full definition in risk module hasLocation Indicates information about location. See full definition in context module hasName Specifies name of a legal entity. See full definition in entities module hasNecessity Indicates the necessity for specified context or criteria. See full definition in context module hasNonInvolvedEntity indicates the entity is not involved in specified context. See full definition in processing module hasNonPersonalDataProcess Indicates association with a Non-Personal Data Process. See full definition in process module hasNotice Indicates the use or applicability of a Notice for the specified context. See full definition in TOM module hasNoticeIcon Indicates the concept can be represented graphically using the specified icon. See full definition in TOM module hasNoticeLayer Indicates the use of a notice layer within a notice or to associate a layer with another layer. See full definition in TOM module hasNoticeStatus Indicates the status of the associated notice. See full definition in TOM module hasNotificationStatus Indicates the status associated with a notice. See full definition in context module hasObligation Specifies applicability or inclusion of an obligation rule within specified context. See full definition in rules module hasOrganisationalMeasure Indicates use or applicability of Organisational measure. See full definition in TOM module hasOrganisationalUnit Indicates the specified entity is a unit of the organisation. See full definition in entities module hasOutcome Indicates an outcome of specified concept or context. See full definition in context module hasParty Indicates a legal entity involved as a party in a contract. See full definition in legal_basis module hasPassiveEntity indicates the entity is passively involved in specified context. See full definition in processing module hasPermission Specifies applicability or inclusion of a permission rule within specified context. See full definition in rules module hasPersonalData Indicates association with Personal Data. See full definition in personal_data module hasPersonalDataHandling Indicates association with Personal Data Handling. See full definition in process module hasPersonalDataProcess Indicates association with a Personal Data Process. See full definition in process module hasPhysicalMeasure Indicates use or applicability of Physical measure. See full definition in TOM module hasPolicy Indicates policy applicable or used. See full definition in TOM module hasProcess Indicates association with a Process. See full definition in process module hasProcessing Indicates association with Processing. See full definition in processing module hasProcessingCondition Indicates information about processing condition. See full definition in processing module hasProcessingScale Indicates the scale of processing operations. See full definition in processing module hasProhibition Specifies applicability or inclusion of a prohibition rule within specified context. See full definition in rules module hasPurpose Indicates association with Purpose. See full definition in purposes module hasRecipient Indicates Recipient of Data. See full definition in entities module hasRecipientDataController Indicates inclusion or applicability of a Data Controller as a Recipient of personal data. See full definition in entities module hasRecipientThirdParty Indicates inclusion or applicability of a Third Party as a Recipient of personal data. See full definition in entities module hasRecommendation Specifies applicability or inclusion of a recommendation rule within specified context. See full definition in rules module hasRecordOfActivity Indicates a relevant record of activity. See full definition in TOM module hasRelationWithDataSubject Indicates the relation between specified Entity and Data Subject. See full definition in entities module hasRepresentative Specifies representative of the legal entity. See full definition in entities module hasRequestStatus Indicates the status associated with a request. See full definition in context module hasResidualRisk Indicates the associated risk is the remaining or residual risk from applying mitigation measures or treatments to this risk. See full definition in risk module hasResponsibleEntity Specifies the indicated entity is responsible within some context. See full definition in entities module hasReuseCompatibility Indicates the reuse compatibility for the specified context. See full definition in context module hasRight Indicates use or applicability of Right. See full definition in rights module hasRisk Indicates applicability of Risk for this concept. See full definition in risk module hasRiskAssessment Indicates an associated risk assessment. See full definition in risk module hasRiskLevel Indicates the associated risk level associated with a risk. See full definition in risk module hasRule Specifies applicability or inclusion of a rule within specified context. See full definition in rules module hasScale Indicates the scale of specified concept. See full definition in processing module hasScope Indicates the scope of specified concept or context. See full definition in context module hasSector Indicates the purpose is associated with activities in the indicated (Economic) Sector(s). See full definition in purposes module hasSensitivityLevel Indicates the associated level of sensitivity. See full definition in risk module hasService Indicates associated with the specified service. See full definition in process module hasServiceConsumer Indicates the entity that consumes or receives the associated service. See full definition in entities module hasServiceProvider Indicates the entity that provides the associated service. See full definition in entities module hasSeverity Indicates the severity associated with a concept. See full definition in risk module hasStatus Indicates the status of specified concept. See full definition in context module hasStorageCondition Indicates information about storage condition. See full definition in processing module hasSubsidiary Indicates this entity has the specified entity as its subsidiary. See full definition in entities module hasTechnicalMeasure Indicates use or applicability of Technical measure. See full definition in TOM module hasTechnicalOrganisationalMeasure Indicates use or applicability of Technical or Organisational measure. See full definition in TOM module hasThirdCountry Indicates applicability or relevance of a 'third country'. See full definition in context module hasThirdParty Indicates association with Third Party. See full definition in entities module hasUncategorisedData Indicates association with the specified uncategorised data. See full definition in personal_data module hasUnstructuredData Indicates association with the specified unstructured data. See full definition in personal_data module HealthcareOrganisation An organisation that delivers medical services, promotes health, and provides care for individuals and communities. See full definition in entities module HighAutomation Level of automation corresponding to Level 4 in ISO/IEC 22989:2022 where the automation in system is capable of performing all its tasks within specific controlled conditions without human involvement. See full definition in processing module HomomorphicEncryption Use of Homomorphic encryption that permits computations on encrypted data without decrypting it. See full definition in TOM module Hospital An organisation that provides comprehensive medical treatment, including emergency care, surgeries, and inpatient services. See full definition in entities module HugeDataVolume Data volume that is considered huge or more than large within the context. See full definition in processing module HugeScaleOfDataSubjects Scale of data subjects considered huge or more than large within the context. See full definition in processing module HumanInvolved Humans are involved in the specified context. See full definition in processing module HumanInvolvement The involvement of humans in specified context. See full definition in processing module HumanInvolvementForControl Human involvement for the purposes of exercising control over the specified operations in context. See full definition in processing module HumanInvolvementForDecision Human involvement for the purposes of exercising decisions over the specified operations in context. See full definition in processing module HumanInvolvementForInput Human involvement for the purposes of providing inputs to the specified context. See full definition in processing module HumanInvolvementForIntervention Human involvement for the purposes of exercising interventions over the specified operations in context. See full definition in processing module HumanInvolvementForOversight Human involvement for the purposes of having oversight over the specified context regarding its operations, inputs, or outputs. See full definition in processing module HumanInvolvementForVerification Human involvement for the purposes of verification of specified context to ensure its operations, inputs, or outputs are correct or are acceptable.. See full definition in processing module HumanNotInvolved Humans are not involved in the specified context. See full definition in processing module HumanOversight Procedures related to implementing and ensuring human oversight, which includes ability for humans to oversee, understand, control, and reverse processes, and to have sufficient monitoring capability to detect and address anomalies, dysfunctions, or unexpected performance. See full definition in TOM module HumanResourceManagement Purposes associated with managing humans and 'human resources' within the organisation for effective and efficient operations.. See full definition in purposes module HumanSubject The individual (or category of individuals) that is the subject within some context such as personal data (dpv:DataSubject) or technology (tech:Subject). See full definition in entities module HybridPublicPrivateSpace A space that is a hybrid space i.e it has both public and private components - such as by having part of it be a private space or which is operated privately. See full definition in context module IdentifyingPersonalData Personal Data that explicitly and by itself is sufficient to identify a person. See full definition in personal_data module IdentityAuthentication Purposes associated with performing authentication based on identity as a form of security. See full definition in purposes module IdentityManagementMethod Management of identity and identity-based processes. See full definition in TOM module IdentityVerification Purposes associated with verifying or authenticating identity as a form of security. See full definition in purposes module Immigrant Humans that are immigrants (for a jurisdiction). See full definition in entities module Impact The impact(s) possible or arising as a consequence from specified context. See full definition in risk module ImpactAssessment Calculating or determining the likelihood of impact of an existing or proposed process, which can involve risks or detriments.. See full definition in risk module ImpliedConsent Consent that is implied indirectly through an action not associated solely with conveying a consenting decision. See full definition in legal_basis module Importance An indication of 'importance' within a context. See full definition in context module ImproveExistingProductsAndServices Purposes associated with improving existing products and services. See full definition in purposes module ImproveHealthcare Purposes associated with improving healthcare systems such as for personalised treatments and curing chronic diseases. See full definition in purposes module ImproveInternalCRMProcesses Purposes associated with improving customer-relationship management (CRM) processes. See full definition in purposes module ImprovePublicServices Purposes associated with improving the provision of public services, such as public safety, education or law enforcement. See full definition in purposes module ImproveTransportMobility Purposes associated with improving traffic, public transport systems or costs for drivers. See full definition in purposes module IncidentManagementProcedures Procedures related to management of incidents. See full definition in TOM module IncidentReportingCommunication Procedures related to management of incident reporting. See full definition in TOM module IncorrectData Data that is known to be incorrect or inconsistent with some requirements. See full definition in personal_data module IncreaseServiceRobustness Purposes associated with improving robustness and resilience of services. See full definition in purposes module IndeterminateDuration Duration that is indeterminate or cannot be determined. See full definition in context module IndustryConsortium A consortium established and comprising on industry organisations. See full definition in entities module Infer to infer data from existing data. See full definition in processing module InferredData Data that has been obtained through inferences of other data. See full definition in personal_data module InferredPersonalData Personal Data that is obtained through inference from other data. See full definition in personal_data module InformationAudit An audit that systematically examines the existence and use of information along with its associated resources (e.g. where it is stored) and flows (e.g. where it originates and with whom it is being shared). See full definition in TOM module InformationFlowControl Use of measures to control information flows. See full definition in TOM module InformationSecurityPolicy Policy regarding security of information. See full definition in TOM module InformedConsent Consent that is informed i.e. with the requirement to provide sufficient information to make a consenting decision. See full definition in legal_basis module InnovativeUseOfExistingTechnology Involvement of existing technologies used in an innovative manner. See full definition in processing module InnovativeUseOfNewTechnologies Involvement of a new (innovative) technologies. See full definition in processing module InnovativeUseOfTechnology Indicates that technology is being used in an innovative manner. See full definition in processing module IntellectualPropertyData Data protected by Intellectual Property rights and regulations. See full definition in personal_data module Intended Status indicating the specified context was intended. See full definition in context module IntentionStatus Status indicating whether the specified context was intended or unintended. See full definition in context module InternalResourceOptimisation Purposes associated with optimisation of internal resource availability and usage for organisation. See full definition in purposes module InternationalOrganisation An organisation and its subordinate bodies governed by public international law, or any other body which is set up by, or on the basis of, an agreement between two or more countries. See full definition in entities module IntrusionDetectionSystem Use of measures to detect intrusions and other unauthorised attempts to gain access to a system. See full definition in TOM module InverseJurisdiction An inverse jurisdiction for a specific jurisdiction is the set of all other jurisdictions that are not part of the specific jurisdiction. See full definition in context module InvolvementStatus Status indicating whether the involvement of specified context. See full definition in context module IPRManagement Management of Intellectual Property Rights with a view to identify and safeguard and enforce them. See full definition in TOM module isAfter Indicates the specified concepts is 'after' this concept in some context. See full definition in context module isApplicableFor Indicates the concept or information is applicable for specified context. See full definition in context module isAuthorityFor Indicates area, scope, or applicability of an Authority. See full definition in entities module isBefore Indicates the specified concepts is 'before' this concept in some context. See full definition in context module isDeterminedByEntity Indicates the context is determined by the specified entity. See full definition in processing module isDuring Indicates the specified concepts occur 'during' this concept in some context. See full definition in context module isExercisedAt Indicates context or information about exercising a right. See full definition in rights module isImplementedByEntity Indicates implementation details such as entities or agents. See full definition in processing module isImplementedUsingTechnology Indicates implementation details such as technologies or processes. See full definition in processing module isIndicatedAtTime Specifies the temporal information for when the entity has indicated the specific context. See full definition in legal_basis module isIndicatedBy Specifies entity who indicates the specific context. See full definition in legal_basis module isMitigatedByMeasure Indicate a risk is mitigated by specified measure. See full definition in risk module isNotApplicableFor Indicates the concept or information is not applicable for specified context. See full definition in context module isOrganisationalUnitOf Indicates this entity is an organisational unit of the specified entity. See full definition in entities module isOutsideOfLocation Indicates the interpretation where the location being referenced is outside of the indicated concept. See full definition in context module isPolicyFor Indicates the context or application of policy. See full definition in TOM module isRepresentativeFor Indicates the entity is a representative for specified entity. See full definition in entities module isResidualRiskOf Indicates this risk is the remaining or residual risk from applying mitigation measures or treatments to specified risk. See full definition in risk module isSubsidiaryOf Indicates this entity is the subsidiary of the specified entity. See full definition in entities module JITNotice A notice that is provided "just in time" when collecting information or performing an activity. See full definition in TOM module JobApplicant Humans that apply for jobs or employments. See full definition in entities module JointDataControllers A group of Data Controllers that jointly determine the purposes and means of processing. See full definition in entities module JointDataControllersAgreement An agreement outlining conditions, criteria, obligations, responsibilities, and specifics for carrying out processing of data between Controllers within a Joint Controllers relationship. See full definition in legal_basis module JudicialOrganisation An organisation involved in interpreting and applying the law, resolving disputes, and administering justice as part of the judicial system. See full definition in entities module Jurisdiction A jurisdiction represents the locations that define the extent of authority (or control) claimed, granted, or asserted by a legal entity (in particular a legal authority) to govern or enforce rules. See full definition in context module Justification A form of documentation providing reasons, explanations, or justifications. See full definition in context module LargeDataVolume Data volume that is considered large within the context. See full definition in processing module LargeScaleOfDataSubjects Scale of data subjects considered large within the context. See full definition in processing module LargeScaleProcessing Processing that takes place at large scales (as specified by some criteria). See full definition in processing module Law A law is a set of rules created by government or authorities. See full definition in context module LawEnforcementOrganisation An organisation that is an agency responsible for enforcing laws, maintaining public order, and ensuring public safety. See full definition in entities module Lawful State of being lawful or legally compliant. See full definition in context module Lawfulness Status associated with expressing lawfulness or legal compliance. See full definition in context module LawfulnessUnknown State of the lawfulness not being known. See full definition in context module LayeredNotice A notice that contains layered elements. See full definition in TOM module LegalAgent A Legal Agent is a Legal Entity that is authorised to act on behalf of another entity. See full definition in entities module LegalAgreement A legally binding agreement. See full definition in TOM module LegalBasis Legal basis used to justify processing of data or use of technology in accordance with a law. See full definition in legal_basis module LegalCompliance Purposes associated with carrying out data processing to fulfill a legal or statutory obligation. See full definition in purposes module LegalComplianceAssessment Assessment regarding legal compliance. See full definition in TOM module LegalComplianceAudit An audit that systematically examines the state of legal compliance by reviewing policies and procedures related to obligations and compliance requirements for specific laws and regulations. See full definition in TOM module LegalEntity A human or non-human 'thing' that constitutes as an entity and which is recognised and defined in law. See full definition in entities module LegalMeasure Legal measures used to safeguard and ensure good practices in connection with data and technologies. See full definition in TOM module LegalObligation Legal Obligation to conduct the specified activities. See full definition in legal_basis module LegalObligationCompleted Status where the legal obligation has been completed. See full definition in legal_basis module LegalObligationOngoing Status where the legal obligation is being fulfilled. See full definition in legal_basis module LegalObligationPending Status where the legal obligation has not been started. See full definition in legal_basis module LegalObligationStatus Status associated with use of Legal Obligation as a legal basis. See full definition in legal_basis module LegitimateInterest Legitimate Interests of a Party as justification for specified activities. See full definition in legal_basis module LegitimateInterestAssessment Indicates an assessment regarding the use of legitimate interest as a lawful basis by the data controller. See full definition in TOM module LegitimateInterestInformed Status where the Legitimate Interest was informed to the data subject or other relevant entities. See full definition in legal_basis module LegitimateInterestNotObjected Status where the use of Legitimate Interest was not objected to. See full definition in legal_basis module LegitimateInterestObjected Status where the use of Legitimate Interest was objected to. See full definition in legal_basis module LegitimateInterestOfController Legitimate Interests of a Data Controller in conducting specified activities. See full definition in legal_basis module LegitimateInterestOfDataSubject Legitimate Interests of the Data Subject in conducting specified activities. See full definition in legal_basis module LegitimateInterestOfThirdParty Legitimate Interests of a Third Party in conducting specified activities. See full definition in legal_basis module LegitimateInterestStatus Status associated with use of Legitimate Interest as a legal basis. See full definition in legal_basis module LegitimateInterestUninformed Status where the Legitimate Interest was not informed to the data subject or other relevant entities. See full definition in legal_basis module LicenseAgreement A Legal Document providing permission to utilise data or resource and outlining the conditions under which such use is considered valid. See full definition in legal_basis module Likelihood The likelihood or probability or chance of something taking place or occurring. See full definition in risk module LocalEnvironmentScale Geographic coverage spanning a specific environment within the locality. See full definition in processing module LocalityScale Geographic coverage spanning a specific locality. See full definition in processing module LocalLocation Location is local. See full definition in context module Location A location is a position, site, or area where something is located. See full definition in context module LocationFixture The fixture of location refers to whether the location is fixed. See full definition in context module LocationLocality Locality refers to whether the specified location is local within some context, e.g. for the user. See full definition in context module LoggingPolicy Policy for logging of information. See full definition in TOM module MaintainFraudDatabase Purposes associated with maintaining a database related to identifying and identified fraud risks and fraud incidents. See full definition in purposes module MakeAvailable to transform or publish data to be used. See full definition in processing module ManageConsent Control for managing a given consent in terms of providing, reaffirming, or withdrawing it. See full definition in legal_basis module ManagementStandard A management standard is a standard that establishes norms or requirements regarding the management operations and processes e.g. in an organisation. See full definition in TOM module Marketing Purposes associated with conducting marketing in relation to organisation or products or services e.g. promoting, selling, and distributing. See full definition in purposes module Match to combine, compare, or match data from different sources. See full definition in processing module MediumDataVolume Data volume that is considered medium i.e. neither large nor small within the context. See full definition in processing module MediumScaleOfDataSubjects Scale of data subjects considered medium i.e. neither large nor small within the context. See full definition in processing module MediumScaleProcessing Processing that takes place at medium scales (as specified by some criteria). See full definition in processing module Member Humans that are members of a group, organisation, or other collectives. See full definition in entities module MemberPartnerManagement Purposes associated with maintaining a registry of shareholders, members, or partners for governance, administration, and management functions. See full definition in purposes module MentallyVulnerableDataSubject Data subjects that are considered mentally vulnerable. See full definition in entities module MentallyVulnerableHuman Humans that are considered mentally vulnerable within the context. See full definition in entities module MessageAuthenticationCodes Use of cryptographic methods to authenticate messages. See full definition in TOM module MetadataManagement Measures associated with management of metadata. See full definition in TOM module MisusePreventionAndDetection Prevention and Detection of Misuse or Abuse of services. See full definition in purposes module mitigatesRisk Indicates risks mitigated by this concept. See full definition in risk module MobilePlatformSecurity Security implemented over a mobile platform. See full definition in TOM module Modify to modify or change data. See full definition in processing module Monitor to monitor data for some criteria. See full definition in processing module MonitoringPolicy Policy for monitoring (e.g. progress, performance). See full definition in TOM module MonotonicCounterPseudonymisation A simple pseudonymisation method where identifiers are substituted by a number chosen by a monotonic counter. See full definition in TOM module Move to move data from one location to another including deleting the original copy. See full definition in processing module MultiFactorAuthentication An authentication system that uses two or more methods to authenticate. See full definition in TOM module MultiNationalScale Geographic coverage spanning multiple nations. See full definition in processing module NationalAuthority An authority tasked with overseeing legal compliance for a nation. See full definition in entities module NationalScale Geographic coverage spanning a nation. See full definition in processing module NaturalPerson A human. See full definition in entities module NDA Non-disclosure Agreements e.g. preserving confidentiality of information. See full definition in TOM module NearlyGlobalScale Geographic coverage nearly spanning the entire globe. See full definition in processing module Necessity An indication of 'necessity' within a context. See full definition in context module NegotiateContract Control for negotiating a contract. See full definition in legal_basis module NegotiatedContract A contract where the terms and conditions are determined with all parties having the ability to negotiate the terms and conditions. See full definition in legal_basis module NetworkProxyRouting Use of network routing using proxy. See full definition in TOM module NetworkSecurityProtocols Security implemented at or over networks protocols. See full definition in TOM module NonCitizen Humans that are not citizens (for a jurisdiction). See full definition in entities module NonCommercialPurpose Purposes associated with processing activities performed in a non-commercial setting or without intention to commercialise. See full definition in purposes module NonCommercialResearch Purposes associated with conducting research in a non-commercial setting e.g. for a non-profit-organisation (NGO). See full definition in purposes module NonCompliant State of non-compliance where objectives have not been met, but have not been violated. See full definition in context module NonConformant State of being non-conformant. See full definition in context module NonGovernmentalOrganisation An organisation not part of or independent from the government. See full definition in entities module NonPersonalData Data that is not Personal Data. See full definition in personal_data module NonPersonalDataProcess An action, activity, or method involving non-personal data, and asserting that no personal data is involved. See full definition in process module NonProfitOrganisation An organisation that does not aim to achieve profit as its primary goal. See full definition in entities module NonPublicDataSource A source of data that is not publicly accessible or available. See full definition in processing module NotApplicable Concept indicating the information or context is not applicable. See full definition in context module NotAutomated Level of automation corresponding to Level 0 in ISO/IEC 22989:2022 where there is no automation in the system. See full definition in processing module NotAvailable Concept indicating the information or context is applicable but information is not yet available. See full definition in context module Notice A notice is an artefact for providing information, choices, or controls. See full definition in TOM module NoticeCommunicated Status indicating the notice has been communicated. See full definition in TOM module NoticeGenerated Status indicating the notice has been generated. See full definition in TOM module NoticeIcon An icon within a notice associated with specific information or elements. See full definition in TOM module NoticeLatest Status indicating the notice is currently at its latest iteration. See full definition in TOM module NoticeLayer A layer within a layered notice where the layer can be used for providing specific information or controls. See full definition in TOM module NoticeStale Status indicating the notice is stale or not up to date or not the latest version. See full definition in TOM module NoticeStatus Status associated with notice provision, use, and management. See full definition in TOM module NoticeUnused Status indicating the notice has been communicated but has not yet been used e.g. the recipient has not acknowledged it or has not taken the intended action. See full definition in TOM module NoticeUpdated Status indicating the notice has been updated and its contents or implications have changed. See full definition in TOM module NoticeUsed Status indicating the notice has been communicated and has been used e.g. the recipient has acknowledged it or taken the intended action. See full definition in TOM module Notification Notification represents the provision of a notice i.e. notifying. See full definition in TOM module NotificationCompleted Status indicating notification(s) are completed. See full definition in context module NotificationFailed Status indicating notification(s) could not be completed due to a failure. See full definition in context module NotificationNotNeeded Status indicating notification(s) are not needed. See full definition in context module NotificationOngoing Status indicating notification(s) are ongoing. See full definition in context module NotificationPlanned Status indicating notification(s) are planned. See full definition in context module NotificationStatus Status indicating whether notification(s) are planned, completed, or failed. See full definition in context module NotInvolved Status indicating the specified context is 'not' involved. See full definition in context module NotRequired Indication of neither being required nor optional i.e. not relevant or needed. See full definition in context module ObjectingToProcess Involvement where entity can object to process of specified context. See full definition in processing module Obligation A rule describing an obligation for performing an activity. See full definition in rules module ObligationFulfilled Status indicating an obligation has been fulfilled i.e. the activity stated as being required to be carried out has been successfully completed. See full definition in rules module ObligationUnfulfilled Status indicating an obligation has not been fulfilled i.e. the activity stated as being required to be carried out has not been carried out but this is not considered as a violation e.g. there is still time to conduct the activity. See full definition in rules module ObligationViolated Status indicating an obligation has been violated i.e. the activity stated as being required to be carried out has not been carried out and this is considered as a violation i.e. the activity can no longer be carried out to fulfil the obligation. See full definition in rules module Observe to obtain data through observation. See full definition in processing module ObservedData Data that has been obtained through observations of a source. See full definition in personal_data module ObservedPersonalData Personal Data that has been collected through observation of the Data Subject(s). See full definition in personal_data module Obtain to solicit or gather data from someone. See full definition in processing module ObtainConsent Control for obtaining consent. See full definition in legal_basis module OfferContract Control for offering a contract. See full definition in legal_basis module OfficialAuthorityExerciseCompleted Status where the official authority has been exercised to completion. See full definition in legal_basis module OfficialAuthorityExerciseOngoing Status where the official authority is being exercised. See full definition in legal_basis module OfficialAuthorityExercisePending Status where the official authority has not been exercised. See full definition in legal_basis module OfficialAuthorityExerciseStatus Status associated with use of Official Authority as a legal basis. See full definition in legal_basis module OfficialAuthorityOfController Activities are necessary or authorised through the official authority granted to or vested in the Data Controller. See full definition in legal_basis module OftenFrequency Frequency where occurrences are often or frequent, but not continuous. See full definition in context module OperatingSystemSecurity Security implemented at or through operating systems. See full definition in TOM module OptimisationForConsumer Purposes associated with optimisation of activities and services for consumer or user. See full definition in purposes module OptimisationForController Purposes associated with optimisation of activities and services for provider or controller. See full definition in purposes module OptimiseUserInterface Purposes associated with optimisation of interfaces presented to the user. See full definition in purposes module OptingInToProcess Involvement where entity can opt-in to specified context. See full definition in processing module OptingOutFromProcess Involvement where entity can opt-out from specified context. See full definition in processing module Optional Indication of 'optional' or 'voluntary'. See full definition in context module OralNotice A notice provided orally or verbally. See full definition in TOM module Organisation A general term reflecting a company or a business or a group acting as a unit. See full definition in entities module OrganisationalMeasure Organisational measures used to safeguard and ensure good practices in connection with data and technologies. See full definition in TOM module OrganisationalUnit Entity within an organisation that does not constitute as a separate legal entity. See full definition in entities module OrganisationComplianceManagement Purposes associated with managing compliance for organisation in relation to internal policies. See full definition in purposes module OrganisationGovernance Purposes associated with conducting activities and functions for governance of an organisation. See full definition in purposes module OrganisationRiskManagement Purposes associated with managing risk for organisation's activities. See full definition in purposes module Organise to organize data for arranging or classifying. See full definition in processing module ParentLegalEntity A legal entity that has one or more subsidiary entities operating under it. See full definition in entities module ParentOfDataSubject Parent(s) of data subjects such as children. See full definition in entities module ParentOfHuman Parent(s) of humans. See full definition in entities module PartialAutomation Level of automation corresponding to Level 2 in ISO/IEC 22989:2022 where the automation is present in multiple parts of the system or in a manner that does not require the human to control/use these parts while still retaining control over the system. See full definition in processing module PartiallyCompliant State of partially being compliant i.e. only some objectives have been met, and others have not been in violation. See full definition in context module Participant Humans that participate in some context such as volunteers in a function. See full definition in entities module PassivelyInvolved Status indicating the specified context is 'passively' involved. See full definition in context module PassiveRight The right(s) applicable, provided, or expected that are always (passively) applicable. See full definition in rights module PasswordAuthentication Use of passwords to perform authentication. See full definition in TOM module Patient Humans that receive medical attention, treatment, care, advice, or other health related services. See full definition in entities module PaymentManagement Purposes associated with processing and managing payment in relation to service, including invoicing and records. See full definition in purposes module PenetrationTestingMethods Use of penetration testing to identify weaknesses and vulnerabilities through simulations. See full definition in TOM module Permission A rule describing a permission to perform an activity. See full definition in rules module PermissionManagement Methods to obtain, provide, modify, and withdraw permissions along with maintaining a record of permissions, retrieving records, and processing changes in permission states. See full definition in TOM module PermissionNotUtilised Status indicating a permission has not been utilised i.e. the activity stated as being permitted has not been carried out. See full definition in rules module PermissionUtilised Status indicating a permission has been utilised i.e. the activity stated as being permitted has been carried out. See full definition in rules module PersonalData Data directly or indirectly associated or related to an individual. See full definition in personal_data module PersonalDataAudit An audit that systematically examines the existence and use of personal data along with its associated resources (e.g. where it is stored) and flows (e.g. where it originates and with whom it is being shared). See full definition in TOM module PersonalDataHandling An abstract concept describing 'personal data handling'. See full definition in process module PersonalDataProcess An action, activity, or method involving personal data. See full definition in process module Personalisation Purposes associated with creating and providing customisation based on attributes and/or needs of person(s) or context(s).. See full definition in purposes module PersonalisedAdvertising Purposes associated with creating and providing personalised advertising. See full definition in purposes module PersonalisedBenefits Purposes associated with creating and providing personalised benefits for a service. See full definition in purposes module PersonalSpace A private space associated with an individual in a personal capacity - such as their home or the space around their physical person e.g. my home or my room. See full definition in context module PersonnelBehaviourMonitoring Purposes associated with monitoring behaviour of personnel. See full definition in purposes module PersonnelHiring Purposes associated with management and execution of hiring processes of personnel. See full definition in purposes module PersonnelManagement Purposes associated with management of personnel associated with the organisation e.g. evaluation and management of employees and intermediaries. See full definition in purposes module PersonnelMonitoring Purposes associated with monitoring of personnel. See full definition in purposes module PersonnelOffboarding Purposes associated with offboarding of personnel i.e. activities and processes carried out when the person is exiting the company or role. See full definition in purposes module PersonnelOnboarding Purposes associated with onboarding and integration of personnel within an organisation. See full definition in purposes module PersonnelPayment Purposes associated with management and execution of payment of personnel. See full definition in purposes module PersonnelPerformanceEvaluation Purposes associated with evaluation or assessment of performance of employees. See full definition in purposes module PersonnelPerformanceManagement Purposes associated with management of performance of personnel. See full definition in purposes module PersonnelPerformanceMonitoring Purposes associated with monitoring of performance of personnel. See full definition in purposes module PersonnelPerformancePrediction Purposes associated with prediction of performance of personnel. See full definition in purposes module PersonnelPromotionManagement Purposes associated with determination and management of promotion of personnel. See full definition in purposes module PersonnelTerminationManagement Purposes associated with determination and management of termination of personnel. See full definition in purposes module PersonnelWorkloadManagement Purposes assocaited with determination, scheduling, planning, and carrying out workload management of personnel. See full definition in purposes module PhysicalAccessControlMethod Access control applied for physical access e.g. premises or equipment. See full definition in TOM module PhysicalAuthentication Physical implementation of authentication e.g. by matching the person to their ID card. See full definition in TOM module PhysicalAuthorisation Physical implementation of authorisation e.g. by stamping a visitor pass. See full definition in TOM module PhysicalDeviceSecurity Physical protection for devices and equipment. See full definition in TOM module PhysicalInterceptionProtection Physical protection against interception e.g. by posting a guard. See full definition in TOM module PhysicalInterruptionProtection Physical protection against interruptions e.g. electrical supply interruption. See full definition in TOM module PhysicalMeasure Physical measures used to safeguard and ensure good practices in connection with data and technologies. See full definition in TOM module PhysicalNetworkSecurity Physical protection for networks and networking related infrastructure e.g. by isolating networking equipments. See full definition in TOM module PhysicalSecureStorage Physical protection for storage of information or equipment e.g. secure storage for files. See full definition in TOM module PhysicalSupplySecurity Physically securing the supply of resources. See full definition in TOM module PhysicalSurveillance Physically monitoring areas via surveillance. See full definition in TOM module PIA Impact assessment regarding privacy risks. See full definition in risk module Policy A guidance document outlining any of: procedures, plans, principles, decisions, intent, or protocols.. See full definition in TOM module PoliticalCampaign Purposes associated with political campaign activities related to promotion and advertisement of positions and candidates in elections at local, state or regional, or national and international levels. See full definition in purposes module PostedNotice A notice that is posted as a sign or banner. See full definition in TOM module PostQuantumCryptography Use of algorithms that are intended to be secure against cryptanalytic attack by a quantum computer. See full definition in TOM module PrimaryImportance Indication of 'primary' or 'main' or 'core' importance. See full definition in context module PrimaryUse Status indicating compatibility based on the use being either the original context or something that is compatible with it. See full definition in context module Principle A representation of values or norms that must be taken into consideration when conducting activities. See full definition in TOM module PrintedNotice A notice that is provided in a printed form on or along with a device. See full definition in TOM module PrivacyByDefault Practices regarding setting the default configurations of information and services to implement data protection and privacy (synonymous with Data Protection by Default). See full definition in TOM module PrivacyByDesign Practices regarding incorporating data protection and privacy in the design of information and services (synonymous with Data Protection by Design). See full definition in TOM module PrivacyNotice Represents a notice or document outlining information regarding privacy. See full definition in TOM module PrivacyPreservingProtocol Use of protocols designed with the intention of provided additional guarantees regarding privacy. See full definition in TOM module PrivateCommunalSpace A space that is accessible to a group or a community within a private space and where members of the public do not have access to it e.g. society amenities such as gyms and pools. See full definition in context module PrivateInformationRetrieval Use of cryptographic methods to retrieve a record from a system without revealing which record is retrieved. See full definition in TOM module PrivateLocation Location that is not or cannot be accessed by the public and is controlled as a private space. See full definition in context module PrivatelyOperatedPublicSpace A space that is operated or managed by a private entity but which is accessible to the public e.g. a public bus station operated by a specific company. See full definition in context module PrivatelyOwnedPublicSpace A space that is privately owned but which is accessible and usable by the public - whether freely or through a process which is open to all members of the public e.g. hotel lobby, shopping mall atriums. See full definition in context module PrivatelyOwnedSpace A place that is privately owned e.g. offices, malls. See full definition in context module PrivateSectorBody An organisation owned and operated by private individuals or companies. See full definition in entities module PrivateSpace A space that is owned or controlled by a private entity and where access to members of the public is restricted. See full definition in context module Process An action, activity, or method. See full definition in process module Processing Operations or 'processing' performed on data. See full definition in processing module ProcessingCondition Conditions required or followed regarding processing of data or use of technologies. See full definition in processing module ProcessingContext Context or conditions within which processing takes place. See full definition in processing module ProcessingDuration Conditions regarding duration or temporal limitation for processing. See full definition in processing module ProcessingLocation Conditions regarding location or geospatial scope where processing takes places. See full definition in processing module ProcessingScale Scale of Processing. See full definition in processing module ProfessionalConfidentialData Data protected by professional secrecy or confidentiality, including but not limited to data covered by professional privilege or secrecy obligations such as that covered by lawyer or doctor-patient confidentiality and other forms of recognised professional confidentiality obligations. See full definition in personal_data module ProfessionalTraining Training methods that are intended to provide professional knowledge and expertise. See full definition in TOM module Profiling to create a profile that describes or represents a person. See full definition in processing module Prohibition A rule describing a prohibition to perform an activity. See full definition in rules module ProhibitionUnviolated Status indicating a prohibition has not been violated i.e. the activity stated as being prohibited has not been carried out. See full definition in rules module ProhibitionViolated Status indicating a prohibition has been violated i.e. the activity stated as being prohibited has been carried out. See full definition in rules module ProtectionOfIPR Purposes associated with the protection of intellectual property rights. See full definition in purposes module ProtectionOfNationalSecurity Purposes associated with the protection of national security. See full definition in purposes module ProtectionOfPublicSecurity Purposes associated with the protection of public security. See full definition in purposes module ProvideConsent Control for providing consent. See full definition in legal_basis module ProvidedData Data that has been provided by an entity. See full definition in personal_data module ProvidedPersonalData Personal Data that has been provided by an entity such as the Data Subject. See full definition in personal_data module ProvideEventRecommendations Purposes associated with creating and providing personalised recommendations for events. See full definition in purposes module ProvideOfficialStatistics Purposes associated with facilitating the development, production and dissemination of reliable official statistics. See full definition in purposes module ProvidePersonalisedRecommendations Purposes associated with creating and providing personalised recommendations. See full definition in purposes module ProvideProductRecommendations Purposes associated with creating and providing product recommendations e.g. suggest similar products. See full definition in purposes module ProviderStandardFormContract A contract where the terms and conditions are determined by parties in the role of a 'provider', and the other parties have negligible or no ability to negotiate the terms and conditions. See full definition in legal_basis module Pseudonymisation Pseudonymisation means the processing of personal data in such a manner that the personal data can no longer be attributed to a specific data subject without the use of additional information, provided that such additional information is kept separately and is subject to technical and organisational measures to ensure that the personal data are not attributed to an identified or identifiable natural person;. See full definition in TOM module Pseudonymise to replace personal identifiable information by artificial identifiers. See full definition in processing module PseudonymisedData Pseudonymised Data is data that has gone a partial or incomplete anonymisation process by replacing the identifiable information with artificial identifiers or 'pseudonyms', and is still considered as personal data. See full definition in personal_data module PublicBenefit Purposes undertaken and intended to provide benefit to public or society. See full definition in purposes module PublicDataSource A source of data that is publicly accessible or available. See full definition in processing module PublicInterest Activities are necessary or beneficial for interest of the public or society at large. See full definition in legal_basis module PublicInterestCompleted Status where the public interest activity has been completed. See full definition in legal_basis module PublicInterestObjected Status where the public interest activity was objected to by the Data Subject or another relevant entity. See full definition in legal_basis module PublicInterestOngoing Status where the public interest activity is ongoing. See full definition in legal_basis module PublicInterestPending Status where the public interest activity has not started. See full definition in legal_basis module PublicInterestStatus Status associated with use of Public Interest as a legal basis. See full definition in legal_basis module PublicLocation Location that is or can be accessed by the public. See full definition in context module PubliclyAccessibleSpace A space that is accessible to all members of the public e.g. parks, malls, train stations. See full definition in context module PubliclyOwnedSpace A space that is owned by the public e.g. national parks, forests. See full definition in context module PublicPolicyMaking Purposes associated with public policy making, such as the development of new laws. See full definition in purposes module PublicRegisterOfEntities A publicly available list of entities e.g. to indicate which entities perform a certain activity within a certain location or jurisdiction. See full definition in entities module PublicRelations Purposes associated with managing and conducting public relations processes, including creating goodwill for the organisation. See full definition in purposes module PublicSectorBody A government-controlled organisation that provides services or goods to the public. See full definition in entities module PublicSpace Any space that is accessible to the public or is owned by the public. See full definition in context module Purpose Purpose or (broader) Goal associated with data or technology. See full definition in purposes module QuantumCryptography Cryptographic methods that utilise quantum mechanical properties to perform cryptographic tasks. See full definition in TOM module Query to query or make enquiries over data. See full definition in processing module RandomLocation Location that is random or unknown. See full definition in context module ReaffirmConsent Control for affirming consent. See full definition in legal_basis module RecertificationPolicy Policy regarding repetition or renewal of existing certification(s). See full definition in TOM module Recipient Entities that receive data or technologies. See full definition in entities module RecipientInformed Status indicating Recipient has been informed about the specified context. See full definition in context module RecipientUninformed Status indicating Recipient is uninformed i.e. has not been informed about the specified context. See full definition in context module Recommendation A rule describing a recommendation for performing an activity. See full definition in rules module RecommendationFollowed Status indicating a recommendation has been followed i.e. the activity stated as being recommended has been carried out. See full definition in rules module RecommendationNotFollowed Status indicating a recommendation has not been followed i.e. the activity stated as being recommended has not been carried out. See full definition in rules module Record to make a record (especially media). See full definition in processing module RecordManagement Purposes associated with manage creation, storage, and use of records relevant to operations, events, and processes e.g. to store logs or access requests. See full definition in purposes module RecordsOfActivities Records of activities within some context such as maintenance tasks or governance functions. See full definition in TOM module RecruitmentAdvertising Purposes associated with advertisement for Recruitments and personnel hiring. See full definition in purposes module RecruitmentApplicantBackgroundCheck Purposes assocaited with conducting background checks for prospective and current job applicants for recruitment. See full definition in purposes module RecruitmentApplicantCriminalBackgroundCheck Purposes associated with conducting criminal background assessment for prospective and current job applicants for recruitment. See full definition in purposes module RecruitmentApplicantInformationAuthentication Purposes associated with authentication and verification of information as part of recruitment. See full definition in purposes module RecruitmentApplicantSelection Purposes associated with determination or selection of candidates, whether for a specific job or job pool, or for a specific stage as part of recruitment. See full definition in purposes module RecruitmentApplicationAnalysis Purposes assocaited with analysis of job applications or job candidates for recruitment. See full definition in purposes module RecruitmentApplicationManagement Purposes associated with managing job applications for recruitment. See full definition in purposes module RecruitmentApplicationScreening Purposes associated with screening and filtering of job applications or job candidates for recruitment. See full definition in purposes module RecruitmentInterviewAnalysis Purposes associated with analysis of interviews, including the people and involved, for recruitment. See full definition in purposes module RecruitmentInterviewAssessment Purposes associated with assessment of interviews, including assessment of people and information, for recruitment. See full definition in purposes module RecruitmentInterviewManagement Purposes associated conducting and managing interviews for recruitment. See full definition in purposes module RecruitmentInterviewScheduling Purposes associated with scheduling interviews for recruitment. See full definition in purposes module RecruitmentManagement Purposes assocaited with recruitment of personnel, which includes identifying, sourcing, screening, filtering, shortlisting, and interviewing candidates. See full definition in purposes module RecruitmentTargetedAdvertising Purposes associated with targeted advertisement for Recruitments and personnel hiring. See full definition in purposes module Reformat to rearrange or restructure data to change its form. See full definition in processing module RefuseConsent Control for refusing consent. See full definition in legal_basis module RefuseContract Control for refusing a contract. See full definition in legal_basis module Region A region is an area or site that is considered a location. See full definition in context module RegionalAuthority An authority tasked with overseeing legal compliance for a region. See full definition in entities module RegionalScale Geographic coverage spanning a specific region or regions. See full definition in processing module RegulatorySandbox Mechanism used by regulators and businesses for gauging the compatibility of regulations and innovative products, particularly in the context of digitalisation, in a controlled real-world environment with appropriate safeguards in place. See full definition in TOM module ReligiousAssociations An organisations that supports the practice, promotion, and management of religious activities and beliefs. See full definition in entities module RemoteLocation Location is remote i.e. not local. See full definition in context module Remove to destruct or erase data. See full definition in processing module RenewedConsentGiven The state where a previously given consent has been 'renewed' or 'refreshed' or 'reaffirmed' to form a new instance of given consent. See full definition in legal_basis module RepairImpairments Purposes associated with identifying, rectifying, or otherwise undertaking activities intended to fix or repair impairments to existing functionalities. See full definition in purposes module Representative A representative of a legal entity. See full definition in entities module RequestAccepted State of a request being accepted towards fulfilment. See full definition in context module RequestAcknowledged State of a request being acknowledged. See full definition in context module RequestActionDelayed State of a request being delayed towards fulfilment. See full definition in context module RequestedServiceProvision Purposes associated with delivering services as requested by user or consumer. See full definition in purposes module RequestFulfilled State of a request being fulfilled. See full definition in context module RequestInitiated State of a request being initiated. See full definition in context module RequestRejected State of a request being rejected towards non-fulfilment. See full definition in context module RequestRequiredActionPerformed State of a request's required action having been performed by the other party. See full definition in context module RequestRequiresAction State of a request requiring an action to be performed from another party. See full definition in context module RequestStatus Status associated with requests. See full definition in context module RequestStatusQuery State of a request's status being queried. See full definition in context module RequestUnfulfilled State of a request being unfulfilled. See full definition in context module Required Indication of 'required' or 'necessary'. See full definition in context module ResearchAndDevelopment Purposes associated with conducting research and development for new methods, products, or services. See full definition in purposes module ResidualRisk Risk remaining after treatment or mitigation. See full definition in risk module Restrict to apply a restriction on the processing of specific records. See full definition in processing module Retrieve to retrieve data, often in an automated manner. See full definition in processing module ReuseCompatibility Status indicating whether the specified context is compatible with another earlier context. See full definition in context module ReversingProcessEffects Involvement where entity can reverse effects of specified context. See full definition in processing module ReversingProcessInput Involvement where entity can reverse input of specified context. See full definition in processing module ReversingProcessOutput Involvement where entity can reverse output of specified context. See full definition in processing module ReviewImpactAssessment Procedures to review impact assessments in terms of continued validity, adequacy for intended purposes, and conformance of processes with findings. See full definition in TOM module ReviewProcedure A procedure or process that reviews the correctness and validity of other procedures and policies e.g. to ensure continued validity, adequacy for intended purposes, and conformance of processes with findings. See full definition in TOM module Right The right(s) applicable, provided, or expected. See full definition in rights module RightExerciseActivity An activity representing an exercising of an active right. See full definition in rights module RightExerciseNotice Information associated with exercising of an active right such as where and how to exercise the right, information required for it, or updates on an exercised rights request. See full definition in rights module RightExerciseRecord Record of a Right being exercised. See full definition in rights module RightFulfilmentNotice Notice provided regarding fulfilment of a right. See full definition in rights module RightNonFulfilmentNotice Notice provided regarding non-fulfilment of a right. See full definition in rights module RightNotice Information associated with rights, such as which rights exist, when and where they are applicable, and other relevant information. See full definition in rights module RightsFulfilment Purposes associated with the fulfillment of rights specified in law. See full definition in purposes module RightsImpactAssessment Impact assessment which involves determining the impact on rights and freedoms. See full definition in risk module RightsManagement Methods associated with rights management where 'rights' refer to controlling who can do what with a resource. See full definition in TOM module Risk A risk or possibility or uncertainty of negative effects, impacts, or consequences. See full definition in risk module RiskAssessment Assessment involving identification, analysis, and evaluation of risk. See full definition in risk module RiskConcept Parent concept for combining concepts associated with risk assessment such as actual and potential Risk, Risk Source, Consequences, and Impacts. See full definition in risk module RiskLevel The magnitude of a risk expressed as an indication to aid in its management. See full definition in risk module RiskMitigationMeasure Measures intended to mitigate, minimise, or prevent risk.. See full definition in risk module RNGPseudonymisation A pseudonymisation method where identifiers are substituted by a number chosen by a Random Number Generator (RNG). See full definition in TOM module ROPA A Record of Processing Activities (ROPA) is a document detailing processing activities. See full definition in TOM module Rule A rule describing a process or control that directs or determines if and how an activity should be conducted. See full definition in rules module RuleFulfilled Status indicating a rule has been fulfilled, completed, or satisfied. See full definition in rules module RuleFulfilmentStatus Status associated with a rule for indicating whether it is applicable, or has been utilised, and whether the requirements of the rule have been fulfilled or violated. See full definition in rules module RuleUnfulfilled Status indicating a rule has not been fulfilled nor violated. See full definition in rules module RuleViolated Status indicating a rule has been violated, breached, broken, or infracted. See full definition in rules module Safeguard A safeguard is a precautionary measure for the protection against or mitigation of negative effects. See full definition in TOM module SafeguardForDataTransfer Represents a safeguard used for data transfer. Can include technical or organisational measures.. See full definition in TOM module Scale A measurement along some dimension. See full definition in processing module ScientificResearch Purposes associated with scientific research. See full definition in purposes module Scope Indication of the extent or range or boundaries associated with(in) a context. See full definition in context module ScoringOfIndividuals Processing that involves scoring of individuals. See full definition in processing module Screen to remove data for some criteria. See full definition in processing module Seal A seal or a mark indicating proof of certification to some certification or standard. See full definition in TOM module SearchFunctionalities Purposes associated with providing searching, querying, or other forms of information retrieval related functionalities. See full definition in purposes module SecondaryImportance Indication of 'secondary' or 'minor' or 'auxiliary' importance. See full definition in context module SecondaryUse Status indicating incompatibility based on the use not being compatible with an earlier context. See full definition in context module SecretSharingSchemes Use of secret sharing schemes where the secret can only be reconstructed through combination of sufficient number of individuals. See full definition in TOM module Sector Sector describes the area of application or domain that indicates or restricts scope for interpretation and application of purpose e.g. Agriculture, Banking. See full definition in purposes module SecureMultiPartyComputation Use of cryptographic methods for entities to jointly compute functions without revealing inputs. See full definition in TOM module SecureProcessingEnvironment A physical or virtual environment supported by organisational means that integrates security and compliance requirements and allows supervising data processing actions. See full definition in TOM module SecurityAssessment Assessment of security intended to identify gaps, vulnerabilities, risks, and effectiveness of controls. See full definition in risk module SecurityAudit An audit that systematically examines the existence and use of security risks and measures within information systems, networks, and security policies to identify vulnerabilities, risks, and gaps. See full definition in TOM module SecurityIncidentNotice A notice providing information about security incident(s). See full definition in TOM module SecurityIncidentNotification Notification of information about security incident(s). See full definition in TOM module SecurityIncidentRecord Record of a security incident. See full definition in TOM module SecurityKnowledgeTraining Training intended to increase knowledge regarding security. See full definition in TOM module SecurityMethod Methods that relate to creating and providing security. See full definition in TOM module SecurityProcedure Procedures associated with assessing, implementing, and evaluating security. See full definition in TOM module SecurityRoleProcedures Procedures related to security roles. See full definition in TOM module SellDataToThirdParties Purposes associated with selling or sharing data or information to third parties. See full definition in purposes module SellInsightsFromData Purposes associated with selling or sharing insights obtained from analysis of data. See full definition in purposes module SellProducts Purposes associated with selling products or services. See full definition in purposes module SellProductsToDataSubject Purposes associated with selling products or services to the user, consumer, or data subjects. See full definition in purposes module SemiPrivateSpace A private space that acts as a shared space with other entities but which is still essentially private for the individuals e.g. a semi-private hospital room shared with another patient. See full definition in context module SensitiveData Data deemed sensitive. See full definition in personal_data module SensitiveNonPersonalData Non-personal data deemed sensitive. See full definition in personal_data module SensitivePersonalData Personal data that is considered 'sensitive' in terms of privacy and/or impact, and therefore requires additional considerations and/or protection. See full definition in personal_data module SensitivityLevel Sensitivity' reflects the risk of impact if not secured or utilised with appropriate measures and controls e.g. for sensitive data. See full definition in risk module Service A service is a process where one entity provides some benefit or assistance to another entity. See full definition in process module ServiceAccessDetermination Purposes associated with the determination of whether specific conditions or criteria are met for accessing, using, or gaining access to a service. See full definition in purposes module ServiceConsumer The entity that consumes or receives the service. See full definition in entities module ServiceLevelAgreement A contract regarding the provision of a service which outlines the acceptable metrics and performance of the service for the consumer. See full definition in legal_basis module ServiceManagement Purposes associated with the management of services or products. See full definition in purposes module ServiceMonitoring Purposes associated with the monitoring of services or products to understand their performance and utilisation with a view to inform their management. See full definition in purposes module ServiceOptimisation Purposes associated with optimisation of services or activities. See full definition in purposes module ServicePersonalisation Purposes associated with providing personalisation within services or product or activities. See full definition in purposes module ServiceProvider The entity that provides a service. See full definition in entities module ServiceProvision Purposes associated with providing service or product or activities. See full definition in purposes module ServiceRegistration Purposes associated with registering users and collecting information required for providing a service. See full definition in purposes module ServiceUsageAnalytics Purposes associated with conducting analysis and reporting related to usage of services or products. See full definition in purposes module Severity The magnitude of being unwanted or having negative effects such as harmful impacts. See full definition in risk module Share to give data (or a portion of it) to others. See full definition in processing module SingleSignOn Use of credentials or processes that enable using one set of credentials to authenticate multiple contexts.. See full definition in TOM module SingularDataVolume Data volume that is considered singular i.e. a specific instance or single item. See full definition in processing module SingularFrequency Frequency where occurrences are singular i.e. they take place only once. See full definition in context module SingularScaleOfDataSubjects Scale of data subjects considered singular i.e. a specific data subject. See full definition in processing module SmallDataVolume Data volume that is considered small or limited within the context. See full definition in processing module SmallScaleOfDataSubjects Scale of data subjects considered small or limited within the context. See full definition in processing module SmallScaleProcessing Processing that takes place at small scales (as specified by some criteria). See full definition in processing module SMEOrganisation An organisation that is characterised as a Small or Medium-sized Enterprise based on limited staff and revenue. See full definition in entities module SocialMediaMarketing Purposes associated with conducting marketing through social media. See full definition in purposes module SpecialCategoryPersonalData Sensitive Personal Data whose use requires specific additional legal permission or justification. See full definition in personal_data module SporadicDataVolume Data volume that is considered sporadic or sparse within the context. See full definition in processing module SporadicFrequency Frequency where occurrences are sporadic or infrequent or sparse. See full definition in context module SporadicScaleOfDataSubjects Scale of data subjects considered sporadic or sparse within the context. See full definition in processing module StaffTraining Practices and policies regarding training of staff members. See full definition in TOM module Standard A set of requirements or norms that are agreed upon i.e. they are considered a 'standard'. See full definition in TOM module StandardFormContract A contract where the terms and conditions are determined by one or more of the parties, and the other parties have negligible or no ability to negotiate the terms and conditions. See full definition in legal_basis module StandardsConformance Purposes associated with activities undertaken to ensure or achieve conformance with standards. See full definition in TOM module StartupOrganisation An organisation that is newly established and is nascent in terms of available resources. See full definition in entities module StatisticalConfidentialityAgreement An agreement outlining conditions, criteria, obligations, responsibilities, and specifics for classification and management of 'confidential data' based on a statistical framework. See full definition in TOM module StatisticallyConfidentialData Data protected through Statistical Confidentiality regulations and agreements. See full definition in personal_data module Status The status or state of something. See full definition in context module StorageCondition Conditions required or followed regarding storage of data. See full definition in processing module StorageDeletion Deletion or Erasure of data including any deletion guarantees. See full definition in processing module StorageDuration Duration or temporal limitation on storage of data. See full definition in processing module StorageLocation Location or geospatial scope where the data is stored. See full definition in processing module StorageRestoration Regularity and temporal span of data restoration/backup mechanisms that guarantee that data is preserved. See full definition in processing module Store to keep data for future use. See full definition in processing module Structure to arrange data according to a structure. See full definition in processing module Student Humans that are students. See full definition in entities module SubProcessorAgreement An agreement outlining conditions, criteria, obligations, responsibilities, and specifics for carrying out processing of data between a Data Processor and a Data (Sub-)Processor. See full definition in legal_basis module Subscriber Humans that subscribe to service(s). See full definition in entities module SubsidiaryLegalEntity A legal entity that operates as a subsidiary of another legal entity. See full definition in entities module SupportContractNegotiation Supporting entities, including individuals, with negotiating a contract and its terms and conditions. See full definition in TOM module SupportEntityDecisionMaking Supporting entities, including individuals, in making decisions. See full definition in TOM module SupportExchangeOfViews Supporting individuals and entities in exchanging views e.g. regarding data processing purposes for their best interests. See full definition in TOM module SupportInformedConsentDecision Supporting individuals with making a decision regarding their informed consent. See full definition in TOM module supportsComplianceWith Indicate the measure is required for meeting specified requirement or satisfying specified condition/constraint. See full definition in TOM module SupraNationalAuthority An authority tasked with overseeing legal compliance for a supra-national union e.g. EU. See full definition in entities module SupraNationalUnion A political union of two or more countries with an establishment of common authority. See full definition in context module SymmetricCryptography Use of cryptography where the same keys are utilised for encryption and decryption of information. See full definition in TOM module SymmetricEncryption Use of symmetric cryptography to encrypt data. See full definition in TOM module SyntheticData Synthetic data refers to artificially created data such that it is intended to resemble real data (personal or non-personal), but does not refer to any specific identified or identifiable individual, or to the real measure of an observable parameter in the case of non-personal data. See full definition in personal_data module SystematicMonitoring Processing that involves systematic monitoring of individuals. See full definition in processing module TargetedAdvertising Purposes associated with creating and providing personalised advertisement where the personalisation is targeted to a specific individual or group of individuals. See full definition in purposes module TechnicalMeasure Technical measures used to safeguard and ensure good practices in connection with data and technologies. See full definition in TOM module TechnicalOrganisationalMeasure Technical and Organisational measures used to safeguard and ensure good practices in connection with data and technologies. See full definition in TOM module TechnicalServiceProvision Purposes associated with managing and providing technical processes and functions necessary for delivering services. See full definition in purposes module TechnicalStandard A technical standard is a standard that establishes norms or requirements regarding technology or technical processes. See full definition in TOM module Technology The technology, technological implementation, or any techniques, skills, methods, and processes used or applied. See full definition in processing module TemporalDuration Duration that has a fixed temporal duration e.g. 6 months. See full definition in context module TerminateContract Control for terminating a contract. See full definition in legal_basis module TermsOfService Contractual clauses outlining the terms and conditions regarding the provision of a service, typically between a service provider and a service consumer, also know as 'Terms of Use' and 'Terms and Conditions' and commonly abbreviated as TOS, ToS, ToU, or T&C. See full definition in legal_basis module ThirdCountry Represents a country outside applicable or compatible jurisdiction as outlined in law. See full definition in context module ThirdParty A ‘third party’ means any natural or legal person other than - the entities directly involved or operating under those directly involved in a process. See full definition in entities module ThirdPartyAgreement An agreement outlining conditions, criteria, obligations, responsibilities, and specifics for carrying out processing of data between a Data Controller or Processor and a Third Party. See full definition in legal_basis module ThirdPartyContract Creation, completion, fulfilment, or performance of a contract, with the Data Controller and Third Party as parties, and involving specified processing of data or technologies. NOTE: This concept is being deprecated - use dpv:ThirdPartyAgreement which has a more explicit definition of the entities involved and the intent of the contract. See full definition in legal_basis module ThirdPartyDataSource Data Sourced from a Third Party, e.g. when data is collected from an entity that is neither the Controller nor the Data Subject. See full definition in processing module ThirdPartySecurityProcedures Procedures related to security associated with Third Parties. See full definition in TOM module Tourist Humans that are tourists i.e. not citizens and not immigrants. See full definition in entities module Tracking to use data to track a specific factor (e.g. a human or their activities) across multiple distinct contexts. See full definition in processing module TrackingByFirstParty to perform tracking where the performing entity is a first party within the context. See full definition in processing module TrackingByThirdParty to perform tracking where the performing entity is a third party within the context. See full definition in processing module Transfer to move data from one place to another. See full definition in processing module Transform to change the form or nature of data. See full definition in processing module Transmit to send out data. See full definition in processing module TrustedComputing Use of cryptographic methods to restrict access and execution to trusted parties and code. See full definition in TOM module TrustedExecutionEnvironment Use of cryptographic methods to restrict access and execution to trusted parties and code within a dedicated execution environment. See full definition in TOM module UnacceptableRule A rule that is unacceptable where it is not desirable if it occurs. See full definition in rules module UncategorisedData Data whose categorisation is not known e.g. whether it is personal or non-personal data. See full definition in personal_data module Unexpected Status indicating the specified context was unexpected i.e. not expected. See full definition in context module UninformedConsent Consent that is uninformed i.e. without requirement to provide sufficient information to make a consenting decision. See full definition in legal_basis module Unintended Status indicating the specified context was unintended i.e. not intended. See full definition in context module UnknownApplicability Concept indicating information or context availability is unknown i.e. it is not known if the information exists or is applicable and therefore statements about its availability cannot be made (yet). See full definition in context module Unlawful State of being unlawful or legally non-compliant. See full definition in context module UnstructuredData Data that is without a predefined data model or is not organised in a pre-defined manner. See full definition in personal_data module UntilEventDuration Duration that takes place until a specific event occurs e.g. Account Closure. See full definition in context module UntilTimeDuration Duration that has a fixed end date e.g. 2022-12-31. See full definition in context module UnverifiedData Data that has not been verified in terms of accuracy, inconsistency, or quality. See full definition in personal_data module UsageControl Management of usage, which is intended to be broader than access control and may cover trust, digital rights, or other relevant controls. See full definition in TOM module Use to use data. See full definition in processing module User Humans that use service(s). See full definition in entities module UserInterfacePersonalisation Purposes associated with personalisation of interfaces presented to the user. See full definition in purposes module UseSyntheticData Use of synthetic data to preserve privacy, security, or other effects and side-effects. See full definition in TOM module VariableLocation Location that is known but is variable e.g. somewhere within a given area. See full definition in context module VendorManagement Purposes associated with manage orders, payment, evaluation, and prospecting related to vendors. See full definition in purposes module VendorPayment Purposes associated with managing payment of vendors. See full definition in purposes module VendorRecordsManagement Purposes associated with managing records and orders related to vendors. See full definition in purposes module VendorSelectionAssessment Purposes associated with managing selection, assessment, and evaluation related to vendors. See full definition in purposes module Verification Purposes association with verification e.g. information, identity, integrity. See full definition in purposes module VerifiedData Data that has been verified in terms of accuracy, consistency, or quality. See full definition in personal_data module VirtualisationSecurity Security implemented at or through virtualised environments. See full definition in TOM module Visitor Humans that are temporary visitors. See full definition in entities module VitalInterest Activities are necessary or required to protect vital interests of a data subject or other natural person. See full definition in legal_basis module VitalInterestCompleted Status where the vital interest activity has been completed. See full definition in legal_basis module VitalInterestObjected Status where the vital interest activity was objected to by the Data Subject or another relevant entity. See full definition in legal_basis module VitalInterestOfDataSubject Activities are necessary or required to protect vital interests of a data subject. See full definition in legal_basis module VitalInterestOfNaturalPerson Activities are necessary or required to protect vital interests of a natural person. See full definition in legal_basis module VitalInterestOngoing Status where the vital interest activity is ongoing. See full definition in legal_basis module VitalInterestPending Status where the vital interest activity has not started. See full definition in legal_basis module VitalInterestStatus Status associated with use of Vital Interest as a legal basis. See full definition in legal_basis module VulnerabilityTestingMethods Methods that assess or discover vulnerabilities in a system. See full definition in TOM module VulnerableDataSubject Humans which should be considered 'vulnerable' and therefore would require additional measures and safeguards. See full definition in entities module VulnerableHuman Human(s) which should be considered 'vulnerable' within the context. See full definition in entities module WebBrowserSecurity Security implemented at or over web browsers. See full definition in TOM module WebSecurityProtocols Security implemented at or over web-based protocols. See full definition in TOM module WirelessSecurityProtocols Security implemented at or over wireless communication protocols. See full definition in TOM module WithdrawConsent Control for withdrawing consent. See full definition in legal_basis module WithdrawingFromProcess Involvement where entity can withdraw a previously given assent from specified context. See full definition in processing module WithinDevice Location is local and entirely within a device, such as a smartphone. See full definition in context module WithinPhysicalEnvironment Location is local and entirely within a physical environment, such as a room. See full definition in context module WithinVirtualEnvironment Location is local and entirely within a virtual environment, such as a software system. See full definition in context module ZeroKnowledgeAuthentication Authentication using Zero-Knowledge proofs. See full definition in TOM module

As DPV contains a large number of concepts (1259 in this version), additional documentation with guidance and examples is provided in the specific module pages. to display the full index.

Funding Acknowledgements

Funding Sponsors

The DPVCG was established as part of the SPECIAL H2020 Project, which received funding from the European Union’s Horizon 2020 research and innovation programme under grant agreement No. 731601 from 2017 to 2019. Continued developments have been funded under: RECITALS Project funded under the EU's Horizon program with grant agreement No. 101168490.

Harshvardhan J. Pandit was funded to work on DPV from 2020 to 2022 by the Irish Research Council's Government of Ireland Postdoctoral Fellowship Grant#GOIPD/2020/790.

The ADAPT SFI Centre for Digital Media Technology is funded by Science Foundation Ireland through the SFI Research Centres Programme and is co-funded under the European Regional Development Fund (ERDF) through Grant#13/RC/2106 (2018 to 2020) and Grant#13/RC/2106_P2 (2021 onwards).

Funding Acknowledgements for Contributors

The contributions of Piero Bonatti and Luigi Sauro to the DPVCG have been funded by the European Union’s Horizon 2020 research and innovation programme under grant agreement N. 731601 (project SPECIAL) until 2019, and under grant agreement N. 883464 (project TRAPEZE) from 2020 until 2023.

The contributions of Beatriz Esteves, Delaram Golpayegani, and Rana Saniei have received funding through the PROTECT ITN Project from the European Union’s Horizon 2020 research and innovation programme under the Marie Skłodowska-Curie grant agreement No 813497, in particular through the development of AI Risk Ontology (AIRO) and Vocabulary of AI Risks (VAIR) which have been integrated in to this extension. Beatriz Esteves also received funding from the INESData project - Infrastructure to Investigate Data Spaces in Distributed Environments at UPM, (TSI-063100-2022-0001), a project funded under the UNICO I+D CLOUD call by the Ministry for Digital Transformation and the Civil Service, in the framework of the recovery plan PRTR financed by the European Union (NextGenerationEU); and from SolidLab Vlaanderen (Flemish Government, EWI and RRF project VV023/10), and by the imec.icon project PACSOI (HBC.2023.0752) which was co-financed by imec and VLAIO. Julian Flake received funding from the TITAN project funded under European Union’s Horizon Europe Framework Programme grant#101129822 and from the European Union’s Digital Europe Programme grant#101123471 (EDGE-Skills).

The contributions of Harshvardhan J. Pandit, Arthit Suriyawongkul, Delaram Golpayegani, and Rob Brennan have been made with the financial support of Science Foundation Ireland under Grant Agreement No. 13/RC/2106_P2 at the ADAPT SFI Research Centre. The contributions of Harshvardhan J. Pandit have been made with the AI Accountability Lab (AIAL) which is supported by grants from following groups: the AI Collaborative, an Initiative of the Omidyar Group; Luminate; the Bestseller Foundation; and the John D. and Catherine T. MacArthur Foundation.

Semantics & Scope

Semantics

DPV's terms are defined using [[RDFS]] & [[SKOS]] semantics where all 'classes' and 'properties' are defined as skos:Concept in addition to rdfs:Class and rdf:Property respectively. For taxonomies or hierarchies, concepts are defined as 'instances' of a top-concept, and relationships within the hierarchy are defined using skos:broader/skos:narrower. For example, [=Purpose=] is the top concept within the purposes taxonomy, and all concepts in the purpose taxonomy are instances of it, and are related to each other using skos:broader/narrower relations, such as [=ServiceProvision=] and its more specific form [=RequestedServiceProvision=] are both instances of [=Purpose=] while being related to each other using skos:broader/narrower.

[[[DPV-OWL]]] is an alternate serialisation of DPV that contains the same concepts but is provided under a different namespace with the semantics defined using [[OWL]]. The conversion from SKOS to OWL follows the best practices and concerns outlined in [[[SKOS-OWL]]], e.g. by replacing skos:Concept with owl:Class, and using rdfs:subClassOf instead of skos:broader/skos:narrower. See the example showing implications of using SKOS vs OWL in the [[PRIMER]].

The table provides an overview of the expression of concepts across the three DPV serialisations. These may be expanded in the future, including to non-semantic-web serialisations.

Concept Default OWL
Semantics [[RDF]], [[RDFS]], [[SKOS]] [[RDF]], [[RDFS]], [[OWL]]
Concept/Term skos:Concept owl:Class
subtype relation skos:broader owl:subClassOf
instance/type relation rdf:type rdf:type
relations/association rdf:Property owl:ObjectProperty
relation domain rdfs:domain rdfs:domain
relation range rdfs:range rdfs:range

Scope Change in v2.0

In DPV v1.0, the scope of the DPV and the DPVCG was limited to 'privacy', 'data protection', and the 'processing of personal data', including technologies used to perform it. Under this scope, the DPVCG discussed and modelled regulations such as the [[EU-GDPR]] which also share the same scope. Newer laws such as the [[EU-DGA]] and [[EU-AIAct]] share a significant overlap with this scope and necessitate their inclusion in DPVCG activities. However, such laws utilise the same legal framework to model both personal and non-personal data (for DGA) or regulate a technology that goes beyond 'personal data' (DGA and AI Act). To enable their inclusion and representation as extensions to the DPV, and to enable adopters to utilise a single consistent framework to represent information, the scope of DPVCG and the DPV was expanded in v2.0 as follows:

  1. Expansion of scope to include 'data' and 'technologies' instead of only 'personal data' - this means concepts such as [=Purpose=] which were defined as purpose associated with 'personal data' are now defined as purpose associated with 'data or technologies'.
  2. Creation of concepts to represent expanded scope - such as [=Data=] as the broader concept for both [=PersonalData=] and [=NonPersonalData=].
  3. Changing the scope of associated extensions such as [[TECH]] and [[RISK]] to be useful for any technology and activities and not just personal data related technologies and activities.
  4. Creating [[AI]] as a new extension to specifically provide concepts associated with AI technologies.
  5. Creating extensions to represent concepts from laws regarding 'data and technologies' based on the new concepts and extensions created e.g. [[EU-DGA]] and [[EU-AIAct]] extensions.
  6. Creating new namespaces such as /legal/eu/gdpr instead of /dpv-gdpr to enable consisting and unambiguous representation of legal extensions
  7. Restructuring the GitHub repository to accommodate the changed structure of DPV extensions

In addition to the above, the v2.0 scope change also includes removal of the bespoke 'DPV serialisation' which was based on a custom extension of [[SKOS]]. Instead, the RDFS+SKOS serialisation has been made the default serialisation, and the alternate OWL2 serialisation is continued as before.

Changelog for v2.3

total terms: 1165 ; added: 47 ; removed: 11

The changelog provides more information on concepts that have been added/removed in this version. Below is a summary of the changes.

This document is based on inspiration from the following: