Existing policy languages such as the eXtensible Access Control Markup Language (XACML) 3.0~\cite{xacml} and the W3C Open Digital Rights Language (ODRL) 2.2~\cite{odrl-im}\cite{odrl-voc} provide syntactic interoperability but only basic conflict-handling. XACML relies on combining algorithms (e.g., deny-overrides, permit-overrides, first-applicable) to choose a single outcome if rules disagree. Similarly, the built-in conflict resolution strategy of ODRL relies on a static conflict property (perm, prohibit, or invalid) and is insufficient for handling complex rule conflicts in dynamic environments~\cite{kebede2021}. These limitations are inherited by approaches leveraging ODRL for conflict resolution, such as the Open Digital Rights Enforcement framework (ODRE)~\cite{Cimmino2025}, or the one proposed by Gaia-X~\cite{Vanwambeke2023}. 
A recent survey~\cite{Akaichi2025} has reviewed more than twenty policy languages and confirms that only a handful support semantic conflict resolution, i.e., the ability to explain or repair clashes rather than merely flag them. 
Fostering to allow for negotiation in consent banners (cookies) on the Web, the work in~\cite{Slabbinck2025} builds upon ODRL and introduces a Compliance Report Model to denote the result of an ODRL evaluation in an interoperable manner and test suite for letting different evaluators agree on the result of a policy check, but their engine still flags conflicts rather than merging or rewriting rules.
Recent work on the challenges of policy consistency checking~\cite{Hochstenbach2025} throws light on logic-driven approaches such as the framework described in~\cite{Costantino2018}; however, the presented DSA-Analyser outputs either the confirmation that no conflicts arise among
the evaluated rules or the complete list of conflicts, each of them associated to the
related context, with no mechanisms for conflict resolution. 

Several initiatives have started to align ontologies related to usage control. The W3C DPVCG, that develops and maintains the Data Privacy Vocabulary (DPV)~\cite{pandit2024}, recently published a draft mapping between DPV and ODRL~\cite{mapping-dpv-odrl}, so that privacy concepts can be reused inside ODRL policies. The work in \cite{pandit2025} extends the Data Use Ontology (DUO)~\cite{Lawson2021} for genomic data by encoding ODRL rules and DPV annotations, demonstrating better matchmaking, also comprehensively dealing with conflict resolution, based on the work conceived in~\cite{estevez2021}, without however considering the \textit{lex posterior} principle, which is an innovative aspect of our work.

The paper advances the state-of-the-art in policy-based access and usage control, by providing innovative contributions focusing on interoperability and collaboration. It provides the means for aligning proprietary models with standardised ontologies such as ODRL and DPV, and bridges the gap between ODRL and attribute-based access control, thereby allowing for comprehensive resolution of conflicts arising between policies specified by different parties leveraging advanced conflict resolution strategies beyond the static approach of ODRL.
