SlideShare a Scribd company logo
1 of 13
Download to read offline
CONSENT & INFORMATION SHARING
Kantara Initiative
Consent Receipt v0.8: The Alpha
@kantaraCISWG
Mark Lizar
2
A consent receipt is the first layer of a privacy notice and links to
the rest of the layers and policy notices
It is being designed to reduce friction and improves the customer
experience around personal information sharing.
What is a Consent Receipt?
To enable high value flows of volunteered personal information between
individuals and organisations that merit their trust.
Step 2Step 1
3
I Agree
Your receipt has been sent to you: Download another?
Click
Presentation Options :
• Display on screen
• email
• direct to PDS
• Download to local device
Benefits
-Opens Consent - people have a record and are able to
use it in the future to manage digital rights.
-organisations have proof of consent
-uses a common meta-format for recording consent so
that consent can be managed on aggregate
Alpha - v0.8 —> 2 Step Receipt
Kantara respects your privacy
To Send with Email
To deliver Goods
Trusted Services
Y/N
Y/N Sensitive Personal Information
Link
Link
Link
Trusted Services
Data Categories Collected
Link to Policies
Privacy Policy
Link To
Kantara
Website
https://
kantarainitiat
This consent receipt is provided by the Kantara Initiative, this receipt
can be used to access, rectify PII and manage consent
Purpose List
Minimum (or Simple) Consent Receipt
To charge Credit Card
To Advertise
Linked Trusted
Services Icons
privacy-controller@kanatarainitiative.org
123 AR St. London, WC2X 1NG
Data Controller Contact
Information
Date & Time
Name
Email
Credit Card
Stamped
V
Minimum Viable Consent Receipt
Kantara respects your privacy
To Send with Email
To deliver Goods
Trusted Services
Y/N
Y/N Sensitive Personal Information
Link
Link
Link
Trusted Services
Data Categories Collected
To charge Credit Card
To Advertise
privacy-controller@kanatarainitiative.org
123 AR St. London, WC2X 1NG
Date & Time
Machine Readable: JWT
Integrity
eyJhbGciOiJSUzI1NiIsInR5cCI6IkpXVCJ
9.eyJqdXJpc2RpY3Rpb24iOiJVUyIsInN1
YiI6Im1hcmtAc21hcnRzcGVjaWVzLmNv
bSIsInN2YyI6WyJLYW50YXJhIiwiQ29uc
2VudCAmIEluZm9ybWF0aW9uIFNoYXJ
pbmcgV29yayBHcm91cCJdLCJub3RpY2
UiOiJEYXRhIGlzIGNvbGxlY3RlZCBmb3I
gbWVtYmVyc2hpcCBhbmQgYWRtaW5p
c3RhcnRpdmUgIHB1cnBvc2UiLCJwb2xp
Y3lfdXJpIjoiaHR0cDovL3d3dy5rYW50YX
This consent receipt is provided by the Kantara Initiative, this receipt
can be used to access, rectify PII and manage consent
WHEN FULLY EVOLVED THE STANDARD
BECOMES A VEHICLE FOR TRUST MARKS
Membership Priv.
IPR TRACKING
YES
4
Stakeholder Benefits
Stakeholder/
Development
Stage
Alpha - v0.8
V1. Consent Receipt
Specification
Standard Candidate - ISO
Fast Track
1
Individuals
(data subjects)
Provides people with a
record of consent and
information to manually
manage
Reduces friction around
personal information sharing.
focused on human centric
approach a clear and simple
standard to bridge the legal
and technical divide
2
Kantara
Implementation
(orgs)
Demonstrate that consent
has been provided and
people can use receipt to
manage
Improves customer
experience.
Simplify data protection, data
control, negotiation of terms
3
Regulators
(education)
Proof of consent and useful
to demonstrate compliance
or lack thereof
Enable good personal
information management
practices for data controllers
and processors. Provides proof
of compliance.
Use for Market Self-
Regulation
4
Trust Services
(education)
Used to demonstrate value
to trust services
core format for binding
protocols and trust services
needed an missing standard
to channel trust services and
create interoperability in trust
8
General Data Protection Revision
Article 7
1. Where Article 6(1)(a) applies the controller shall bear
the burden of proof for the data subject's be able to
demonstrate that unambiguous consent to the processing
of their personal data for specified purposes was given by
the data subject.
1a. Where article 9(2)(a) applies, the controller shall be
able to demonstrate that explicit consent was given by the
data subject.
9
General Data Protection Revision
Article 7
2. If the data subject's consent is to be given in the
context of a written declaration which also concerns
another matter, the requirement to request consent must
be presented in a manner which is clearly
distinguishable in its appearance, in an intelligible and
easily accessible form, using clear and plain language.
10
General Data Protection Revision
Article 7
3. The data subject shall have the right to withdraw his
or her consent at any time. The withdrawal of consent
shall not affect the lawfulness of processing based on
consent before its withdrawal. Prior to giving consent,
the data subject thereof shall be informed
11
There should be no doubt on the elements establishing consent and
the intention of the data subject to consent.
Even though it can be expressed in many different ways, for instance
through a statement or an affirmative action, the essential requirement
is that such statement or action must clearly signify the data subject’s
agreement to personal data relating to them being processed. There has
to be a clear distinction between opt-in and opt-out.
Therefore, the notion of unambiguous consent foreseen by the Council of
the EU in Recital 25 may create some confusion with respect to the
aim of the proposed text especially on the Internet where there is now
too much improper use of consent. Requiring it to be explicit is an
important clarification, truly enabling data subjects the exercise of their
rights.
Furthermore consent should be informed and concern a specific purpose,
any ́broad consent ́ would therefore not be acceptable.
Article 29 WP - Consent 17 June 2015
12
To Get Involved
We are looking for use cases for the v.1 specification that represent
different identity relationships in the “Connected Life” ecosystem:
The Individual: Managing Consent
Organisations: Dealing with managing identities with consent
Service Providers: using rich consent to deliver services
Health Care: consent directors and portability
Government: Open Consent
IOT: Dynamic Consent
CONSENT & INFORMATION SHARING WG
If you would like to chat, or get a copy of
this presentation
If you would like to get involved in
developing the receipt infrastructure – join
us at CISWG https://kantarainitiative.org/
confluence/display/infosharing/Home
To keep Track: Follow us on Twitter
@kantaraCISWG

More Related Content

What's hot

Iiw east openidentityforopengovfinal
Iiw east openidentityforopengovfinalIiw east openidentityforopengovfinal
Iiw east openidentityforopengovfinal
MaryIIW
 
Oix local government mydex platform overview 2nd july 2013
Oix local government mydex platform overview 2nd july 2013Oix local government mydex platform overview 2nd july 2013
Oix local government mydex platform overview 2nd july 2013
Mydex CIC
 

What's hot (20)

Managing identity for the future how everybody can win - david alexander - ...
Managing identity for the future   how everybody can win - david alexander - ...Managing identity for the future   how everybody can win - david alexander - ...
Managing identity for the future how everybody can win - david alexander - ...
 
Introduction to Mydex CIC Personal Data Stores - 7th March 2013
Introduction to Mydex CIC Personal Data Stores -  7th March 2013Introduction to Mydex CIC Personal Data Stores -  7th March 2013
Introduction to Mydex CIC Personal Data Stores - 7th March 2013
 
The role of the individual in "digital by default" public services
The role of the individual in "digital by default" public servicesThe role of the individual in "digital by default" public services
The role of the individual in "digital by default" public services
 
Iiw east openidentityforopengovfinal
Iiw east openidentityforopengovfinalIiw east openidentityforopengovfinal
Iiw east openidentityforopengovfinal
 
Oix local government mydex platform overview 2nd july 2013
Oix local government mydex platform overview 2nd july 2013Oix local government mydex platform overview 2nd july 2013
Oix local government mydex platform overview 2nd july 2013
 
Kantara trust frameworks 2016 05-08
Kantara trust frameworks 2016 05-08Kantara trust frameworks 2016 05-08
Kantara trust frameworks 2016 05-08
 
Identity Summit 2015: 2Keys Canadian Digital Identity
Identity Summit 2015: 2Keys Canadian Digital Identity Identity Summit 2015: 2Keys Canadian Digital Identity
Identity Summit 2015: 2Keys Canadian Digital Identity
 
Exploring the Possibilities of Blockchain in Healthcare
Exploring the Possibilities of Blockchain in HealthcareExploring the Possibilities of Blockchain in Healthcare
Exploring the Possibilities of Blockchain in Healthcare
 
Future of digital identity initial perspective - final lr
Future of digital identity   initial perspective - final lrFuture of digital identity   initial perspective - final lr
Future of digital identity initial perspective - final lr
 
180926 ihan webinar 2
180926 ihan webinar 2180926 ihan webinar 2
180926 ihan webinar 2
 
HR Blockchain User Experience
HR Blockchain User ExperienceHR Blockchain User Experience
HR Blockchain User Experience
 
Blockchain in HR
Blockchain in HRBlockchain in HR
Blockchain in HR
 
Various blockchain specialization domains
Various blockchain specialization domainsVarious blockchain specialization domains
Various blockchain specialization domains
 
Identity 101: Boot Camp for Identity North 2016
Identity 101: Boot Camp for Identity North 2016Identity 101: Boot Camp for Identity North 2016
Identity 101: Boot Camp for Identity North 2016
 
Kantara orientation april 2020
Kantara orientation april 2020Kantara orientation april 2020
Kantara orientation april 2020
 
Bring Your Own Identity
Bring Your Own IdentityBring Your Own Identity
Bring Your Own Identity
 
Virtual Interactive Working Environments
Virtual Interactive Working EnvironmentsVirtual Interactive Working Environments
Virtual Interactive Working Environments
 
2016 04-26 webinar - consumer-focused identity management
2016 04-26 webinar - consumer-focused identity management2016 04-26 webinar - consumer-focused identity management
2016 04-26 webinar - consumer-focused identity management
 
Protecting Personal Data in a IoT Network with UMA
Protecting Personal Data in a IoT Network with UMAProtecting Personal Data in a IoT Network with UMA
Protecting Personal Data in a IoT Network with UMA
 
The Future of Identity - OpenID Summit 2020
The Future of Identity - OpenID Summit 2020The Future of Identity - OpenID Summit 2020
The Future of Identity - OpenID Summit 2020
 

Viewers also liked

Framework and Product Comparison for Big Data Log Analytics and ITOA
Framework and Product Comparison for Big Data Log Analytics and ITOA Framework and Product Comparison for Big Data Log Analytics and ITOA
Framework and Product Comparison for Big Data Log Analytics and ITOA
Kai Wähner
 
РИФ 2016, Будущее за дуальным образованием, микроформатами и проектированием ...
РИФ 2016, Будущее за дуальным образованием, микроформатами и проектированием ...РИФ 2016, Будущее за дуальным образованием, микроформатами и проектированием ...
РИФ 2016, Будущее за дуальным образованием, микроформатами и проектированием ...
Тарасов Константин
 
The road to go to school
The road to go to schoolThe road to go to school
The road to go to school
Kostas Tampakis
 
איך להפיק את המטיב מהערכת ביצועים 3
איך להפיק את המטיב מהערכת ביצועים   3איך להפיק את המטיב מהערכת ביצועים   3
איך להפיק את המטיב מהערכת ביצועים 3
yossi koren
 
Lb spektakulare seebilde
Lb spektakulare seebildeLb spektakulare seebilde
Lb spektakulare seebilde
Kostas Tampakis
 
η αρχή του 90 10
η αρχή του 90 10η αρχή του 90 10
η αρχή του 90 10
Kostas Tampakis
 

Viewers also liked (20)

Mobile Device and Attribute Validation (MDAV)
Mobile Device and Attribute Validation (MDAV)Mobile Device and Attribute Validation (MDAV)
Mobile Device and Attribute Validation (MDAV)
 
Framework and Product Comparison for Big Data Log Analytics and ITOA
Framework and Product Comparison for Big Data Log Analytics and ITOA Framework and Product Comparison for Big Data Log Analytics and ITOA
Framework and Product Comparison for Big Data Log Analytics and ITOA
 
РИФ 2016, Будущее за дуальным образованием, микроформатами и проектированием ...
РИФ 2016, Будущее за дуальным образованием, микроформатами и проектированием ...РИФ 2016, Будущее за дуальным образованием, микроформатами и проектированием ...
РИФ 2016, Будущее за дуальным образованием, микроформатами и проектированием ...
 
РИФ 2016, Особенности влияния топ-блогеров на имидж территорий
РИФ 2016, Особенности влияния топ-блогеров на имидж территорийРИФ 2016, Особенности влияния топ-блогеров на имидж территорий
РИФ 2016, Особенности влияния топ-блогеров на имидж территорий
 
РИФ 2016, Размер не имеет значения: маленький бюджет на маркетинг - не повод ...
РИФ 2016, Размер не имеет значения: маленький бюджет на маркетинг - не повод ...РИФ 2016, Размер не имеет значения: маленький бюджет на маркетинг - не повод ...
РИФ 2016, Размер не имеет значения: маленький бюджет на маркетинг - не повод ...
 
Promociones
PromocionesPromociones
Promociones
 
РИФ 2016, Стратегическое планирование в digital. Опыт БИНБАНКа
РИФ 2016, Стратегическое планирование в digital. Опыт БИНБАНКаРИФ 2016, Стратегическое планирование в digital. Опыт БИНБАНКа
РИФ 2016, Стратегическое планирование в digital. Опыт БИНБАНКа
 
РИФ 2016, Как выдерживать высокие нагрузки без rocket science
РИФ 2016, Как выдерживать высокие нагрузки без rocket scienceРИФ 2016, Как выдерживать высокие нагрузки без rocket science
РИФ 2016, Как выдерживать высокие нагрузки без rocket science
 
РИФ 2016, Кластер электронной коммерции РАЭК
РИФ 2016, Кластер электронной коммерции РАЭКРИФ 2016, Кластер электронной коммерции РАЭК
РИФ 2016, Кластер электронной коммерции РАЭК
 
The road to go to school
The road to go to schoolThe road to go to school
The road to go to school
 
РИФ 2016, Видео-контент и видео-реклама
РИФ 2016, Видео-контент и видео-рекламаРИФ 2016, Видео-контент и видео-реклама
РИФ 2016, Видео-контент и видео-реклама
 
РИФ 2016, Wi-Fi в метро – результаты первого года работы, мы знаем о вас боль...
РИФ 2016, Wi-Fi в метро – результаты первого года работы, мы знаем о вас боль...РИФ 2016, Wi-Fi в метро – результаты первого года работы, мы знаем о вас боль...
РИФ 2016, Wi-Fi в метро – результаты первого года работы, мы знаем о вас боль...
 
איך להפיק את המטיב מהערכת ביצועים 3
איך להפיק את המטיב מהערכת ביצועים   3איך להפיק את המטיב מהערכת ביצועים   3
איך להפיק את המטיב מהערכת ביצועים 3
 
Lb spektakulare seebilde
Lb spektakulare seebildeLb spektakulare seebilde
Lb spektakulare seebilde
 
Rif13.18apr s42--timchenko
Rif13.18apr s42--timchenkoRif13.18apr s42--timchenko
Rif13.18apr s42--timchenko
 
РИФ 2016, SEO: Ошибки влияющие на результат
РИФ 2016, SEO: Ошибки влияющие на результатРИФ 2016, SEO: Ошибки влияющие на результат
РИФ 2016, SEO: Ошибки влияющие на результат
 
Se vuoi vedere impara ad agire
Se vuoi vedere impara ad agireSe vuoi vedere impara ad agire
Se vuoi vedere impara ad agire
 
Salento Italy
Salento ItalySalento Italy
Salento Italy
 
η αρχή του 90 10
η αρχή του 90 10η αρχή του 90 10
η αρχή του 90 10
 
РИФ 2016, Как обнять 2 000 коллег за день и не умереть от усталости
РИФ 2016, Как обнять 2 000 коллег за день и не умереть от усталостиРИФ 2016, Как обнять 2 000 коллег за день и не умереть от усталости
РИФ 2016, Как обнять 2 000 коллег за день и не умереть от усталости
 

Similar to Kantara - Consent & Information Sharing WG Update

25 Ways the Consumer Data Right Can Create Smoother and Smarter Customer Expe...
25 Ways the Consumer Data Right Can Create Smoother and Smarter Customer Expe...25 Ways the Consumer Data Right Can Create Smoother and Smarter Customer Expe...
25 Ways the Consumer Data Right Can Create Smoother and Smarter Customer Expe...
PemaDoma1
 
The Pulse of Liquid Health Data
The Pulse of Liquid Health DataThe Pulse of Liquid Health Data
The Pulse of Liquid Health Data
Brian Ahier
 
2015-0318 GAC Presentation - BCR - 05052015
2015-0318 GAC Presentation - BCR - 050520152015-0318 GAC Presentation - BCR - 05052015
2015-0318 GAC Presentation - BCR - 05052015
Jan Dhont
 
Procurement Of Software And Information Technology Services
Procurement Of Software And Information Technology ServicesProcurement Of Software And Information Technology Services
Procurement Of Software And Information Technology Services
Peister
 
Technology Services RM1058 Customer Guidance
Technology Services RM1058 Customer GuidanceTechnology Services RM1058 Customer Guidance
Technology Services RM1058 Customer Guidance
Ben Morrison
 
Martino Maggio - Cape_v1.0.pdf
Martino Maggio -  Cape_v1.0.pdfMartino Maggio -  Cape_v1.0.pdf
Martino Maggio - Cape_v1.0.pdf
FIWARE
 
Agenda21 eu cookie seminar - dominic trigg - rocket fuel
Agenda21   eu cookie seminar - dominic trigg - rocket fuelAgenda21   eu cookie seminar - dominic trigg - rocket fuel
Agenda21 eu cookie seminar - dominic trigg - rocket fuel
agenda21
 
Reasons to consider Binding Corporate Rules
Reasons to consider Binding Corporate RulesReasons to consider Binding Corporate Rules
Reasons to consider Binding Corporate Rules
Jan Dhont
 

Similar to Kantara - Consent & Information Sharing WG Update (20)

California Consumer Privacy Act (CCPA)
California Consumer Privacy Act (CCPA)California Consumer Privacy Act (CCPA)
California Consumer Privacy Act (CCPA)
 
CIS 2015- User-centric Privacy of Identity- Jenn Behrens
CIS 2015- User-centric Privacy of Identity- Jenn BehrensCIS 2015- User-centric Privacy of Identity- Jenn Behrens
CIS 2015- User-centric Privacy of Identity- Jenn Behrens
 
Take Control with Consent Management
Take Control with Consent ManagementTake Control with Consent Management
Take Control with Consent Management
 
Salesforce Wellington Data Privacy Act 2020 Presentation Feb 2021
Salesforce Wellington Data Privacy Act 2020 Presentation Feb 2021Salesforce Wellington Data Privacy Act 2020 Presentation Feb 2021
Salesforce Wellington Data Privacy Act 2020 Presentation Feb 2021
 
25 Ways the Consumer Data Right Can Create Smoother and Smarter Customer Expe...
25 Ways the Consumer Data Right Can Create Smoother and Smarter Customer Expe...25 Ways the Consumer Data Right Can Create Smoother and Smarter Customer Expe...
25 Ways the Consumer Data Right Can Create Smoother and Smarter Customer Expe...
 
NHIN Workgroup
NHIN WorkgroupNHIN Workgroup
NHIN Workgroup
 
Cloud Services As An Enabler
Cloud Services As An EnablerCloud Services As An Enabler
Cloud Services As An Enabler
 
The Pulse of Liquid Health Data
The Pulse of Liquid Health DataThe Pulse of Liquid Health Data
The Pulse of Liquid Health Data
 
DATA Working Group - Consumer Best Practices
DATA Working Group - Consumer Best PracticesDATA Working Group - Consumer Best Practices
DATA Working Group - Consumer Best Practices
 
Golden Gekko, 10 burning questions on privacy
Golden Gekko, 10 burning questions on privacyGolden Gekko, 10 burning questions on privacy
Golden Gekko, 10 burning questions on privacy
 
BSL Fintech special / english-french
BSL Fintech special / english-frenchBSL Fintech special / english-french
BSL Fintech special / english-french
 
2015-0318 GAC Presentation - BCR - 05052015
2015-0318 GAC Presentation - BCR - 050520152015-0318 GAC Presentation - BCR - 05052015
2015-0318 GAC Presentation - BCR - 05052015
 
Sookman law society_6_min_business_law
Sookman law society_6_min_business_lawSookman law society_6_min_business_law
Sookman law society_6_min_business_law
 
10 07-14 hosting con europe 2014 presentation unannotated
10 07-14 hosting con europe 2014 presentation unannotated10 07-14 hosting con europe 2014 presentation unannotated
10 07-14 hosting con europe 2014 presentation unannotated
 
Procurement Of Software And Information Technology Services
Procurement Of Software And Information Technology ServicesProcurement Of Software And Information Technology Services
Procurement Of Software And Information Technology Services
 
Technology Services RM1058 Customer Guidance
Technology Services RM1058 Customer GuidanceTechnology Services RM1058 Customer Guidance
Technology Services RM1058 Customer Guidance
 
201804 idento.one v3
201804 idento.one v3201804 idento.one v3
201804 idento.one v3
 
Martino Maggio - Cape_v1.0.pdf
Martino Maggio -  Cape_v1.0.pdfMartino Maggio -  Cape_v1.0.pdf
Martino Maggio - Cape_v1.0.pdf
 
Agenda21 eu cookie seminar - dominic trigg - rocket fuel
Agenda21   eu cookie seminar - dominic trigg - rocket fuelAgenda21   eu cookie seminar - dominic trigg - rocket fuel
Agenda21 eu cookie seminar - dominic trigg - rocket fuel
 
Reasons to consider Binding Corporate Rules
Reasons to consider Binding Corporate RulesReasons to consider Binding Corporate Rules
Reasons to consider Binding Corporate Rules
 

More from kantarainitiative

More from kantarainitiative (20)

Kantara initiative - AGM 2022
Kantara initiative - AGM 2022Kantara initiative - AGM 2022
Kantara initiative - AGM 2022
 
2021 Annual General Meeting
2021 Annual General Meeting2021 Annual General Meeting
2021 Annual General Meeting
 
2020 Annual General Meeting Executive Summary
2020 Annual General Meeting Executive Summary2020 Annual General Meeting Executive Summary
2020 Annual General Meeting Executive Summary
 
2020 Annual General Meeting
2020 Annual General Meeting2020 Annual General Meeting
2020 Annual General Meeting
 
AARC Assurance Profiles for Kantara Initiative
AARC Assurance Profiles for Kantara InitiativeAARC Assurance Profiles for Kantara Initiative
AARC Assurance Profiles for Kantara Initiative
 
Kantara uma webinar july 2020
Kantara uma webinar   july 2020Kantara uma webinar   july 2020
Kantara uma webinar july 2020
 
Kantara webinar 800 63-3 approval 2020-07-15
Kantara webinar 800 63-3 approval 2020-07-15Kantara webinar 800 63-3 approval 2020-07-15
Kantara webinar 800 63-3 approval 2020-07-15
 
Kantara webinar 800 63-3 approval 2020-07-15
Kantara webinar 800 63-3 approval 2020-07-15Kantara webinar 800 63-3 approval 2020-07-15
Kantara webinar 800 63-3 approval 2020-07-15
 
Kantara Initiative orientation 2019 (incl. 10th Anniversary video)
Kantara Initiative orientation 2019 (incl. 10th Anniversary video)Kantara Initiative orientation 2019 (incl. 10th Anniversary video)
Kantara Initiative orientation 2019 (incl. 10th Anniversary video)
 
Kantara Initiative orientation 2019 (incl. 10th Anniversary video)
Kantara Initiative orientation 2019 (incl. 10th Anniversary video)Kantara Initiative orientation 2019 (incl. 10th Anniversary video)
Kantara Initiative orientation 2019 (incl. 10th Anniversary video)
 
Kantara Initiative orientation 2019 (incl. 10th Anniversary video)
Kantara Initiative orientation 2019 (incl. 10th Anniversary video)Kantara Initiative orientation 2019 (incl. 10th Anniversary video)
Kantara Initiative orientation 2019 (incl. 10th Anniversary video)
 
Kantara orientation 2018
Kantara orientation 2018Kantara orientation 2018
Kantara orientation 2018
 
Kantara Overview 2017
Kantara Overview 2017Kantara Overview 2017
Kantara Overview 2017
 
The state of uma 2014 11-03
The state of uma 2014 11-03The state of uma 2014 11-03
The state of uma 2014 11-03
 
Laws of relationships v7
Laws of relationships v7Laws of relationships v7
Laws of relationships v7
 
Protecting Personal Data in a IoT Network with UMA
 Protecting Personal Data in a IoT Network with UMA Protecting Personal Data in a IoT Network with UMA
Protecting Personal Data in a IoT Network with UMA
 
IDoT: How to find a thing - Discovery in IoT
IDoT: How to find a thing - Discovery in IoTIDoT: How to find a thing - Discovery in IoT
IDoT: How to find a thing - Discovery in IoT
 
IDoT: Challenges from the IDentities of Things Landscape
IDoT: Challenges from the IDentities of Things LandscapeIDoT: Challenges from the IDentities of Things Landscape
IDoT: Challenges from the IDentities of Things Landscape
 
Uma webinar 2014 06-19
Uma webinar 2014 06-19Uma webinar 2014 06-19
Uma webinar 2014 06-19
 
Uma webinar 2014 03-20
Uma webinar 2014 03-20Uma webinar 2014 03-20
Uma webinar 2014 03-20
 

Recently uploaded

Finding Java's Hidden Performance Traps @ DevoxxUK 2024
Finding Java's Hidden Performance Traps @ DevoxxUK 2024Finding Java's Hidden Performance Traps @ DevoxxUK 2024
Finding Java's Hidden Performance Traps @ DevoxxUK 2024
Victor Rentea
 
Cloud Frontiers: A Deep Dive into Serverless Spatial Data and FME
Cloud Frontiers:  A Deep Dive into Serverless Spatial Data and FMECloud Frontiers:  A Deep Dive into Serverless Spatial Data and FME
Cloud Frontiers: A Deep Dive into Serverless Spatial Data and FME
Safe Software
 
Modular Monolith - a Practical Alternative to Microservices @ Devoxx UK 2024
Modular Monolith - a Practical Alternative to Microservices @ Devoxx UK 2024Modular Monolith - a Practical Alternative to Microservices @ Devoxx UK 2024
Modular Monolith - a Practical Alternative to Microservices @ Devoxx UK 2024
Victor Rentea
 

Recently uploaded (20)

MINDCTI Revenue Release Quarter One 2024
MINDCTI Revenue Release Quarter One 2024MINDCTI Revenue Release Quarter One 2024
MINDCTI Revenue Release Quarter One 2024
 
Decarbonising Commercial Real Estate: The Role of Operational Performance
Decarbonising Commercial Real Estate: The Role of Operational PerformanceDecarbonising Commercial Real Estate: The Role of Operational Performance
Decarbonising Commercial Real Estate: The Role of Operational Performance
 
How to Troubleshoot Apps for the Modern Connected Worker
How to Troubleshoot Apps for the Modern Connected WorkerHow to Troubleshoot Apps for the Modern Connected Worker
How to Troubleshoot Apps for the Modern Connected Worker
 
Less Is More: Utilizing Ballerina to Architect a Cloud Data Platform
Less Is More: Utilizing Ballerina to Architect a Cloud Data PlatformLess Is More: Utilizing Ballerina to Architect a Cloud Data Platform
Less Is More: Utilizing Ballerina to Architect a Cloud Data Platform
 
Finding Java's Hidden Performance Traps @ DevoxxUK 2024
Finding Java's Hidden Performance Traps @ DevoxxUK 2024Finding Java's Hidden Performance Traps @ DevoxxUK 2024
Finding Java's Hidden Performance Traps @ DevoxxUK 2024
 
WSO2 Micro Integrator for Enterprise Integration in a Decentralized, Microser...
WSO2 Micro Integrator for Enterprise Integration in a Decentralized, Microser...WSO2 Micro Integrator for Enterprise Integration in a Decentralized, Microser...
WSO2 Micro Integrator for Enterprise Integration in a Decentralized, Microser...
 
Rising Above_ Dubai Floods and the Fortitude of Dubai International Airport.pdf
Rising Above_ Dubai Floods and the Fortitude of Dubai International Airport.pdfRising Above_ Dubai Floods and the Fortitude of Dubai International Airport.pdf
Rising Above_ Dubai Floods and the Fortitude of Dubai International Airport.pdf
 
AI in Action: Real World Use Cases by Anitaraj
AI in Action: Real World Use Cases by AnitarajAI in Action: Real World Use Cases by Anitaraj
AI in Action: Real World Use Cases by Anitaraj
 
API Governance and Monetization - The evolution of API governance
API Governance and Monetization -  The evolution of API governanceAPI Governance and Monetization -  The evolution of API governance
API Governance and Monetization - The evolution of API governance
 
Connector Corner: Accelerate revenue generation using UiPath API-centric busi...
Connector Corner: Accelerate revenue generation using UiPath API-centric busi...Connector Corner: Accelerate revenue generation using UiPath API-centric busi...
Connector Corner: Accelerate revenue generation using UiPath API-centric busi...
 
Cloud Frontiers: A Deep Dive into Serverless Spatial Data and FME
Cloud Frontiers:  A Deep Dive into Serverless Spatial Data and FMECloud Frontiers:  A Deep Dive into Serverless Spatial Data and FME
Cloud Frontiers: A Deep Dive into Serverless Spatial Data and FME
 
Repurposing LNG terminals for Hydrogen Ammonia: Feasibility and Cost Saving
Repurposing LNG terminals for Hydrogen Ammonia: Feasibility and Cost SavingRepurposing LNG terminals for Hydrogen Ammonia: Feasibility and Cost Saving
Repurposing LNG terminals for Hydrogen Ammonia: Feasibility and Cost Saving
 
Simplifying Mobile A11y Presentation.pptx
Simplifying Mobile A11y Presentation.pptxSimplifying Mobile A11y Presentation.pptx
Simplifying Mobile A11y Presentation.pptx
 
Understanding the FAA Part 107 License ..
Understanding the FAA Part 107 License ..Understanding the FAA Part 107 License ..
Understanding the FAA Part 107 License ..
 
Polkadot JAM Slides - Token2049 - By Dr. Gavin Wood
Polkadot JAM Slides - Token2049 - By Dr. Gavin WoodPolkadot JAM Slides - Token2049 - By Dr. Gavin Wood
Polkadot JAM Slides - Token2049 - By Dr. Gavin Wood
 
Exploring Multimodal Embeddings with Milvus
Exploring Multimodal Embeddings with MilvusExploring Multimodal Embeddings with Milvus
Exploring Multimodal Embeddings with Milvus
 
Modular Monolith - a Practical Alternative to Microservices @ Devoxx UK 2024
Modular Monolith - a Practical Alternative to Microservices @ Devoxx UK 2024Modular Monolith - a Practical Alternative to Microservices @ Devoxx UK 2024
Modular Monolith - a Practical Alternative to Microservices @ Devoxx UK 2024
 
Strategies for Landing an Oracle DBA Job as a Fresher
Strategies for Landing an Oracle DBA Job as a FresherStrategies for Landing an Oracle DBA Job as a Fresher
Strategies for Landing an Oracle DBA Job as a Fresher
 
AWS Community Day CPH - Three problems of Terraform
AWS Community Day CPH - Three problems of TerraformAWS Community Day CPH - Three problems of Terraform
AWS Community Day CPH - Three problems of Terraform
 
Choreo: Empowering the Future of Enterprise Software Engineering
Choreo: Empowering the Future of Enterprise Software EngineeringChoreo: Empowering the Future of Enterprise Software Engineering
Choreo: Empowering the Future of Enterprise Software Engineering
 

Kantara - Consent & Information Sharing WG Update

  • 1. CONSENT & INFORMATION SHARING Kantara Initiative Consent Receipt v0.8: The Alpha @kantaraCISWG Mark Lizar
  • 2. 2 A consent receipt is the first layer of a privacy notice and links to the rest of the layers and policy notices It is being designed to reduce friction and improves the customer experience around personal information sharing. What is a Consent Receipt? To enable high value flows of volunteered personal information between individuals and organisations that merit their trust.
  • 3. Step 2Step 1 3 I Agree Your receipt has been sent to you: Download another? Click Presentation Options : • Display on screen • email • direct to PDS • Download to local device Benefits -Opens Consent - people have a record and are able to use it in the future to manage digital rights. -organisations have proof of consent -uses a common meta-format for recording consent so that consent can be managed on aggregate Alpha - v0.8 —> 2 Step Receipt
  • 4. Kantara respects your privacy To Send with Email To deliver Goods Trusted Services Y/N Y/N Sensitive Personal Information Link Link Link Trusted Services Data Categories Collected Link to Policies Privacy Policy Link To Kantara Website https:// kantarainitiat This consent receipt is provided by the Kantara Initiative, this receipt can be used to access, rectify PII and manage consent Purpose List Minimum (or Simple) Consent Receipt To charge Credit Card To Advertise Linked Trusted Services Icons privacy-controller@kanatarainitiative.org 123 AR St. London, WC2X 1NG Data Controller Contact Information Date & Time Name Email Credit Card Stamped
  • 5. V Minimum Viable Consent Receipt Kantara respects your privacy To Send with Email To deliver Goods Trusted Services Y/N Y/N Sensitive Personal Information Link Link Link Trusted Services Data Categories Collected To charge Credit Card To Advertise privacy-controller@kanatarainitiative.org 123 AR St. London, WC2X 1NG Date & Time Machine Readable: JWT Integrity eyJhbGciOiJSUzI1NiIsInR5cCI6IkpXVCJ 9.eyJqdXJpc2RpY3Rpb24iOiJVUyIsInN1 YiI6Im1hcmtAc21hcnRzcGVjaWVzLmNv bSIsInN2YyI6WyJLYW50YXJhIiwiQ29uc 2VudCAmIEluZm9ybWF0aW9uIFNoYXJ pbmcgV29yayBHcm91cCJdLCJub3RpY2 UiOiJEYXRhIGlzIGNvbGxlY3RlZCBmb3I gbWVtYmVyc2hpcCBhbmQgYWRtaW5p c3RhcnRpdmUgIHB1cnBvc2UiLCJwb2xp Y3lfdXJpIjoiaHR0cDovL3d3dy5rYW50YX This consent receipt is provided by the Kantara Initiative, this receipt can be used to access, rectify PII and manage consent
  • 6. WHEN FULLY EVOLVED THE STANDARD BECOMES A VEHICLE FOR TRUST MARKS Membership Priv. IPR TRACKING YES
  • 7. 4 Stakeholder Benefits Stakeholder/ Development Stage Alpha - v0.8 V1. Consent Receipt Specification Standard Candidate - ISO Fast Track 1 Individuals (data subjects) Provides people with a record of consent and information to manually manage Reduces friction around personal information sharing. focused on human centric approach a clear and simple standard to bridge the legal and technical divide 2 Kantara Implementation (orgs) Demonstrate that consent has been provided and people can use receipt to manage Improves customer experience. Simplify data protection, data control, negotiation of terms 3 Regulators (education) Proof of consent and useful to demonstrate compliance or lack thereof Enable good personal information management practices for data controllers and processors. Provides proof of compliance. Use for Market Self- Regulation 4 Trust Services (education) Used to demonstrate value to trust services core format for binding protocols and trust services needed an missing standard to channel trust services and create interoperability in trust
  • 8. 8 General Data Protection Revision Article 7 1. Where Article 6(1)(a) applies the controller shall bear the burden of proof for the data subject's be able to demonstrate that unambiguous consent to the processing of their personal data for specified purposes was given by the data subject. 1a. Where article 9(2)(a) applies, the controller shall be able to demonstrate that explicit consent was given by the data subject.
  • 9. 9 General Data Protection Revision Article 7 2. If the data subject's consent is to be given in the context of a written declaration which also concerns another matter, the requirement to request consent must be presented in a manner which is clearly distinguishable in its appearance, in an intelligible and easily accessible form, using clear and plain language.
  • 10. 10 General Data Protection Revision Article 7 3. The data subject shall have the right to withdraw his or her consent at any time. The withdrawal of consent shall not affect the lawfulness of processing based on consent before its withdrawal. Prior to giving consent, the data subject thereof shall be informed
  • 11. 11 There should be no doubt on the elements establishing consent and the intention of the data subject to consent. Even though it can be expressed in many different ways, for instance through a statement or an affirmative action, the essential requirement is that such statement or action must clearly signify the data subject’s agreement to personal data relating to them being processed. There has to be a clear distinction between opt-in and opt-out. Therefore, the notion of unambiguous consent foreseen by the Council of the EU in Recital 25 may create some confusion with respect to the aim of the proposed text especially on the Internet where there is now too much improper use of consent. Requiring it to be explicit is an important clarification, truly enabling data subjects the exercise of their rights. Furthermore consent should be informed and concern a specific purpose, any ́broad consent ́ would therefore not be acceptable. Article 29 WP - Consent 17 June 2015
  • 12. 12 To Get Involved We are looking for use cases for the v.1 specification that represent different identity relationships in the “Connected Life” ecosystem: The Individual: Managing Consent Organisations: Dealing with managing identities with consent Service Providers: using rich consent to deliver services Health Care: consent directors and portability Government: Open Consent IOT: Dynamic Consent
  • 13. CONSENT & INFORMATION SHARING WG If you would like to chat, or get a copy of this presentation If you would like to get involved in developing the receipt infrastructure – join us at CISWG https://kantarainitiative.org/ confluence/display/infosharing/Home To keep Track: Follow us on Twitter @kantaraCISWG