This document provides a mapping from core or foundational ISO standards to DPV concepts to assist implementations using both of them together. Currently, this activity is a work in progress and the DPVCG welcomes contributions and participation for it.

DPV Specifications: The [[DPV]] is the core specification that is extended by specific extensions. A [[PRIMER]] introduces the concepts and modelling of DPV specifications, and [[GUIDES]] describe application of DPV for specific applications and use-cases. The Search Index page provides a searchable hierarchy of all concepts. The Data Privacy Vocabularies and Controls Community Group (DPVCG) develops and manages these specifications through GitHub. For meetings, see the DPVCG calendar.

The peer-reviewed article "Data Privacy Vocabulary (DPV) - Version 2.0" (2024) describes the current state of DPV and extensions from version 2.0 onwards, with an earlier article (2019) covering how the DPV was developed (open access versions here, here, and here).

Contributing: The DPVCG welcomes participation to improve the DPV and associated resources, including expansion or refinement of concepts, requesting information and applications, and addressing open issues. See contributing guide for further information.

Introduction

The DPV and other specifications produced by the DPVCG have utilised terms from various sources -- such as ISO standards, regulations such as GDPR, as well as original concepts developed by the community. To support the use of DPV with ISO standards, this document provides a mapping between the concepts provided in DPV with those defined in core or foundational ISO standards. The goal of this exercise is to provide sufficient information on how DPV concepts align with the core ISO standards, and to enable the further use of DPV in their implementations. This mapping is also provided in RDF and CSV form for convenience.

Mapping

The following is a mapping between concepts defined in ISO/IEC 29100:2024 Information technology — Security techniques — Privacy framework with those provided in [[[DPV]]].

External Concept DPV Concept Mapping Type
Personally Identifiable Information (PII) dpv:PersonalData skos:narrower
PII Controller dpv:DataController skos:exactMatch
PII Principal dpv:DataSubject skos:exactMatch
PII Processor dpv:DataProcessor skos:exactMatch
Consent dpv:InformedConsent skos:exactMatch

Funding Acknowledgements

Funding Sponsors

The DPVCG was established as part of the SPECIAL H2020 Project, which received funding from the European Union’s Horizon 2020 research and innovation programme under grant agreement No. 731601 from 2017 to 2019. Continued developments have been funded under: RECITALS Project funded under the EU's Horizon program with grant agreement No. 101168490.

Harshvardhan J. Pandit was funded to work on DPV from 2020 to 2022 by the Irish Research Council's Government of Ireland Postdoctoral Fellowship Grant#GOIPD/2020/790.

The ADAPT SFI Centre for Digital Media Technology is funded by Science Foundation Ireland through the SFI Research Centres Programme and is co-funded under the European Regional Development Fund (ERDF) through Grant#13/RC/2106 (2018 to 2020) and Grant#13/RC/2106_P2 (2021 onwards).

The contributions of Harshvardhan J. Pandit have been made with the financial support of Science Foundation Ireland under Grant Agreement No. 13/RC/2106_P2 at the ADAPT SFI Research Centre; and the AI Accountability Lab (AIAL) which is supported by grants from following groups: the AI Collaborative, an Initiative of the Omidyar Group; Luminate; the Bestseller Foundation; and the John D. and Catherine T. MacArthur Foundation.