Metadata vocabulary · 2.3 · stable release · 2026-02-28

W3C Data Privacy Vocabulary

Maintained by W3C Data Privacy Vocabularies and Controls Community Group

What it helps you do

DPV supports machine-readable concepts for data and processing, purposes, legal bases, parties, recipients, rights, risks, controls, technologies, AI, and jurisdiction-specific laws.

  • Clinical
  • Omics
  • AI / ML
  • Cross-cutting
PlanAcquireHarmonizeExchangeLearn + reuse

01

Where it fits and where it does not

Use these four checks before committing implementation time.

Use it when
Privacy and data-protection context for human, genomic, clinical, real-world, and AI datasets where DUO alone is too narrow.
Limits
DPV is a vocabulary, not legal advice or an enforcement engine; local authority, consent, contracts, and jurisdiction-specific interpretation remain controlling.
Best for
Clinical and Omics and AI / ML and Cross-cutting teams working across Plan → Acquire → Harmonize → Exchange → Learn + reuse.
Maturity
ScalingUsable now, but adoption or tooling is still developing. Pilot the exact stack first.

02

See it in the workflow

This view shows the input, the change the standard introduces, and the resulting output.

  1. InputWhat starts

    Clinical and Omics and AI / ML and Cross-cutting source data, metadata, and local mappings

  2. DPVWhat changes

    Use DPV as a pinned metadata vocabulary across Plan → Acquire → Harmonize → Exchange → Learn + reuse

  3. OutputWhat becomes possible

    A handoff the next system or team can validate against the same release

Readiness gateDPV is a vocabulary, not legal advice or an enforcement engine; local authority, consent, contracts, and jurisdiction-specific interpretation remain controlling.

03

A concrete example

A governed dataset record pins DPV 2.3 and describes personal-data categories, processing purposes, legal basis, controllers and processors, recipients, retention, risks, measures, and applicable legal context.

Why it matters: Enables automated privacy and permitted-processing screening, but cannot itself establish lawful processing, valid consent, adequate safeguards, or fairness.

04

What it fits with

Can supply domain concepts to ODRL policies and complement DUO, PROV-O, DCAT, RO-Crate, and Croissant metadata.

05

Implementation starter

Start with one bounded handoff. Pin, test, and review it before scaling.

  1. Define one handoff, its accountable owner, and the decision DPV must support.

  2. Pin the exact version and companion artifacts: 2.3 · stable release · 2026-02-28.

  3. Map one representative input to the required metadata vocabulary artifacts.

  4. Test the result against the canonical source and record every exception.

  5. Preserve the source data, mappings, and review evidence before scaling.

06

Test the main limitation

Risk

DPV is a vocabulary, not legal advice or an enforcement engine; local authority, consent, contracts, and jurisdiction-specific interpretation remain controlling.

Test

Run one representative end-to-end pilot and record exactly where DPV loses context, needs an extension, or depends on another standard.

Risk

Machine-readable output may still be unfit for analysis or ML.

Test

Test the output for missing context, provenance, terminology alignment, time leakage, and the intended downstream decision. Enables automated privacy and permitted-processing screening, but cannot itself establish lawful processing, valid consent, adequate safeguards, or fairness.

07

Official resources

Specifications, diagrams, examples, and guides from the organizations that maintain them.

  • Primary source2.3 · stable release · 2026-02-28

    DPV 2.3 specification

    Official publisher or steward guidance for this metadata vocabulary profile.

    Publisher
    W3C Data Privacy Vocabularies and Controls Community Group
    Open official source

Next action

Put this profile in context

Compare its role with adjacent standards or place it inside an end-to-end data pathway before choosing an implementation.