1 of 39

Inputs and outputs of ODRL evaluators

Beatriz Esteves

Postdoctoral Researcher at KNoWS

Policy Evaluation and Enforcement on the Web with ODRL

Tutorial colocated with ESWC 2026, May 10th 2026

2 of 39

Short Bio

  • Postdoctoral Researcher at the Knowledge on Web Scale Group (KNoWS), IDLab, Ghent University – imec
  • Research focused on
    • Deployment of access and usage control policies in decentralised systems
    • Alignment of policy systems with legal requirements related to data protection
  • Active contributor of the W3C ODRL CG since 2020
    • Focus on formal semantics and alignment with DPV
  • Co-chair of W3C Data Privacy Vocabularies and Controls CG
    • Focus on GDPR, Data Governance Act and European Health Data Spaces
  • Other standards
    • IEEE 7012-2025 - IEEE Standard for Machine Readable Personal Privacy Terms

3 of 39

4 of 39

5 of 39

6 of 39

Health data sharing

My GP

Read

Blood Test Results

During consultation;

For clinical diagnosis

7 of 39

Financial data sharing

My bank

Read

Bank account statements

For loan

assessment

8 of 39

Rule

Permission

Prohibition

Obligation

Party

Action

Asset

Constraint

function

action

target

constraint

Open Digital Rights Language (ODRL)

9 of 39

Open Digital Rights Language (ODRL)

10 of 39

How to interoperably enforce ODRL policies?

Standardised

ODRL Policy

11 of 39

How to interoperably enforce ODRL policies?

Standardised

ODRL Policy

Not standardised

Input

Can I do some action?

Output

12 of 39

How to interoperably enforce ODRL policies?

Standardised

ODRL Policy

Input

ODRL evaluator

Output

Formalising

Not standardised

13 of 39

ODRL evaluator

This document specifies the expected behaviour of an ODRL Evaluator, a piece of software that performs computations based on a set of policies, a request and a certain state of the world.

14 of 39

ODRL evaluator

15 of 39

If they are to behave deterministically & interoperate,

ODRL evaluators lack a common vocabulary to represent contextual inputs

16 of 39

Input models of other policy languages

  • [Priebe et al. 2006] context information for the XACML standard
  • [Mustafa et al. 2014] OJADEAC (Ontology-based Access Control Model for the JADE Platform)
  • [Kayes et al. 2015] OntCAAC (Ontology-based Context-Aware Access Control) framework
  • [Brewster et al. 2020] OBAC (Ontology-Based Access Control for FAIR data)

17 of 39

How to interoperably enforce ODRL policies?

Standardised

ODRL Policy

Evaluation Request

ODRL evaluator

Output

Formalising

Not standardised

State of the world

Esteves, Beatriz, Wout Slabbinck, Yassir Sellami, Andrea Cimmino, Víctor Rodríguez-Doncel, and Ruben Verborgh. ‘Capturing Requests and Context for ODRL-Based Access and Usage Control’. Joint Proceedings of the 16th Workshop on Ontology Design and Patterns and the 1st Workshop on Bridging Hybrid Intelligence and the Semantic Web (WOP-HAIBRIDGE 2025) Co-Located with the 24th International Semantic Web Conference (ISWC 2025), 2025. https://ceur-ws.org/Vol-4093/paper5.pdf.

18 of 39

Contextual Inputs for ODRL Evaluators

19 of 39

Evaluation Request

20 of 39

Evaluation Request

21 of 39

Evaluation Request – Example

For instance, if Billie, i.e., http://example.com/party/billie, requests to play the asset http://example.com/music/1999.mp3, the EvaluationRequest in the example above must be presented to an ODRL evaluator to determine whether this request is permitted or not.

22 of 39

State of the world

23 of 39

State of the world

24 of 39

State of the world – Example

For instance, to demonstrate that Billie, i.e., http://example.com/party/billie, paid Sony, i.e., http://example.com/party/sony, to play http://example.com/music/1999.mp3, the SotW in the example above must be presented to an ODRL evaluator to have contextual information about the performed payments. Furthermore, each payment is linked with the corresponding duty that originated the payment, i.e., using the conditionID property.

25 of 39

How to interoperably enforce ODRL policies?

Standardised

ODRL Policy

Evaluation Request

ODRL evaluator

Formalising

State of the world

Compliance Report

Slabbinck, Wout, Julián Rojas Meléndez, Beatriz Esteves, Pieter Colpaert, and Ruben Verborgh. ‘Interoperable Interpretation and Evaluation of ODRL Policies’. In The Semantic Web, edited by Edward Curry, Maribel Acosta, Maria Poveda-Villalón, et al. Springer Nature Switzerland, 2025. https://doi.org/10.1007/978-3-031-94578-6_11.

26 of 39

Compliance report as output of an ODRL Evaluator

  • Transparency & Auditability:
    • When was the policy evaluated?
    • Were there any violations?
  • Explainability:
    • Which policy?
    • Which rule of the policy?
    • Which premises?
      • What is the evaluation state of the constraints and party/action/asset matching?
    • Which Request?

27 of 39

Compliance Report Model

28 of 39

Deontic State Calculation

29 of 39

Report – Example

30 of 39

Test Suite

31 of 39

Company X allows employees to access documents during weekdays only, from the EU

32 of 39

Company X allows employees to access documents during weekdays only, from the EU

Policy

33 of 39

Request

Company X allows employees to access documents during weekdays only, from the EU

34 of 39

State of the World

Company X allows employees to access documents during weekdays only, from the EU

35 of 39

Compliance Report

Company X allows employees to access documents during weekdays only, from the EU

36 of 39

Challenges

  • Representing values that may change over time, i.e., dynamic values, related to certain policy constraints, e.g., current time or the GPS coordinates of a party who is moving
    • Introducing a meta-language on top of the ODRL policies to represent variables that are injected on the fly during the evaluation
    • Adopting ODRL dynamic constraint extension

37 of 39

Challenges – Dynamic Right Operands

38 of 39

Challenges

  • Behaviour of the system in case a requested or attempted action is neither permitted nor prohibited by the Policy being evaluated
    • Open: in case of an open system, anything that is not prohibited is permitted
    • Closed: in case of a closed system, anything that is not permitted is prohibited

39 of 39

Challenges – Behaviour

Open

ALLOWED

Closed

DENIED

Evaluation