Skip to content

Commit 56cd5cb

Browse files
committed
Update vCon Lifecycle Management draft to include acknowledgment section and refine text for clarity and readability, enhancing the document's focus on privacy compliance and consent management.
1 parent d0b278a commit 56cd5cb

File tree

2 files changed

+22
-592
lines changed

2 files changed

+22
-592
lines changed

draft-howe-vcon-lifecycle.md

Lines changed: 22 additions & 9 deletions
Original file line numberDiff line numberDiff line change
@@ -44,6 +44,7 @@ author:
4444
email: thomas.howe@strolid.com
4545
-
4646
fullname: S. Lasker
47+
organization: Independent
4748
email: stevenlasker@hotmail.com
4849
-
4950
fullname: Diana James
@@ -189,8 +190,10 @@ These relying parties can then use this information to make decisions
189190
based on the current state and context of the vCon to account for changes
190191
in consent, updates in the accuracy of the content, or amendments of the
191192
information it might contain.
192-
SCITT, the Supply Chain, Integrity, Transparency, and Trust protocol, enables clients to register statements about events, physical or virtual, such as when things are created or used.
193-
These statements are immutable and are useful to support auditing,
193+
SCITT, the Supply Chain, Integrity, Transparency, and Trust protocol,
194+
enables clients to register statements about events, physical or virtual,
195+
such as when things are created or used.
196+
These statements are immutable and are useful to support auditing,
194197
governance, and coordination between various distributed systems.
195198

196199
When using vCons to define a conversation, and SCITT to record the
@@ -212,14 +215,15 @@ principles, multijurisdictional business operations, and the ever-changing
212215
privacy laws. Please see the [privacy-primer-vcon] for more information on
213216
consent and other data subject protection concepts.
214217

215-
In all of these cases, the ability to define and express the processing of conversations depends on the ability to authoritatively define the lifecycle of a vCon:
218+
In all of these cases, the ability to define and express the processing of
219+
conversations depends on the ability to authoritatively define the lifecycle of a vCon:
216220

217-
* who originated the vCon in the first place to establish provenance
218-
* how it was analyzed and amended, to accurately respond to right-to-know requests
219-
* the authenticity both of the original document for downstream workflow
220-
* and authenticity of the redactions that come from the original, in service of data minimization efforts
221-
* the various expressions of digital rights
222-
* the sharing or deletion in response to the same digital rights
221+
- who originated the vCon in the first place to establish provenance
222+
- how it was analyzed and amended, to accurately respond to right-to-know requests
223+
- the authenticity both of the original document for downstream workflow
224+
- and authenticity of the redactions that come from the original, in service of data minimization efforts
225+
- the various expressions of digital rights
226+
- the sharing or deletion in response to the same digital rights
223227

224228
For this document and for purposes of illustration, consent will be used as an example use case.
225229
Proper consent management is fundamental to the responsible protection of data and the ability
@@ -675,3 +679,12 @@ This document has no IANA actions.
675679
[GDPR]: https://gdpr.eu/
676680
[HIPAA]: https://www.hhs.gov/hipaa/index.html
677681
[privacy-primer-vcon]: https://datatracker.ietf.org/doc/draft-james-privacy-primer-vcon/
682+
683+
--- back
684+
685+
# Acknowledgments
686+
687+
{:numbered="false"}
688+
689+
- Thank you to Allistair Woodman for connecting the first dots between VCon and SCITT
690+
- Thank you to Jeff Pulver and Cody Launius for their collaboration and support

0 commit comments

Comments
 (0)