News

May 24th, 2018 - Cross Community Liaison Event: Day Before GDPR

OC-Liaison-May24.png

Advertised Event: May 25th (the day after this event) marks the day new data privacy rules become enforceable across the EU. It represents a shift to a new privacy paradigm more equipped for digital information society. This includes new performance requirements, like being able to demonstrate consent for processing personal data, granting free access to personal data “in a structured, commonly used and machine readable format” and transferring it “without hindrance” to other services, as well as providing explanations and “meaningful information” in relation to the logic, significance and consequences of automated decision-making.

Objective: Cross community workshop to connect projects and efforts that are related to each other to build liaisons and collaboration on best practice between efforts and communities (and celebrate GDPR)

Report Aim: to list projects and efforts that are active and overlapping. Provide this report as way for projects to connect over the summer, leading up to MyData’s conference in Helsinki.

At The Workshop

IMG_0087.png

The event was broken down into 3 sessions, 1. Standards 2. Data Portability 3. AI -Right to an Explanation

This event also had a sister event “​GDPRHackDay​” co-hosted with MIT Media Labs. The 3rd Session, featured a presentation from Dr. Thomas Hardjono from MIT in London, with the remaining presentation broadcasted ​live and recorded​ for posterity here. For a summary about the Hackday see the HackDay Appendix.

The event started with standards efforts presenting on BSI PIM’s Standard - BS 10012:2017 ,W3C Data Privacy Vocabularies and Controls​, Kantara CISWG ​Consent Receipt V.1.1(approved for release May 25) and interestingly both CISWG and BSI are providing input to ​ISO 29184​, which will drive interoperability in notice and consent internationally (more below).

Go here for full OC Report

Kantara: Consent Receipt v.1 Published

Kantara_CIS_logo2-300x254-300x254.png

In the Kantara Initiative community, the Kantara Consent & Information Sharing WG (CISWG) has been engineering consent transparency for the,Identity Management industry.  The Work Group, is excited to announce the publication of the Consent Receipt Specification, which is a project led to create a global specification for minimum viable consent element to capture a mutual state of privacy.   Expert volunteers have come together to build through consensus a specification to guide industry in capturing the privacy state people have when using identity attributes.

The Consent Receipt V.1 is  an output comprised of many engagements acorss standards communities, beginning with a conference called  IIW and a community called Identity Commons. These communities have been critical in the incubation of this work which started in 2006.  This has resulted in outputs that are helping to shape the global Identity Management community. Influencing privacy regulators and supporting industry champions to what has resulted in the work now called the Consent Receipt.

Consent is a fundamental component of new laws that are coming into force on May 25th, 2018.  At the time the V.1 Specification has been approved by the Kantara Community, the General Data Protection Regulation has come into force. Providing an important guide to the identity management industry, providing a vision of how  identity management can evolve to include privacy.

The Consent Receipt is now implemented in numerous industries and is  aligned with the international ISO 29100 Privacy Risk Framework as an approach to international interoperability of privacy notice and consent.    

Kantara Initiative Consent Receipt v.1 specification can be found on the CISWG home page.