<div dir="ltr">Sorry - my understanding is this. The Article 29 WG is NOT a regulator, therefore is not a suitable authority. It is a guidance provider and not anything more than this. <div><br></div><div>Its website makes this clear. </div>
<div><br></div><div><span style="color:rgb(52,65,70);font-family:Verdana,Geneva,Helvetica,Arial,sans-serif;font-size:12px;font-weight:bold;line-height:16px;background-color:rgb(244,244,244)">"The material (opinions, working documents, letters etc.) issued by the Article 29 Working Party (Art. 29 WP), available on this website reflect the views only of the Art. 29 WP which has an advisory status and acts independently. They do not reflect the position of the European Commission."</span><br>
</div><div><span style="color:rgb(52,65,70);font-family:Verdana,Geneva,Helvetica,Arial,sans-serif;font-size:12px;font-weight:bold;line-height:16px;background-color:rgb(244,244,244)"><br></span></div><div><a href="http://ec.europa.eu/justice/data-protection/article-29/" target="_blank">http://ec.europa.eu/justice/data-protection/article-29/</a><span style="color:rgb(52,65,70);font-family:Verdana,Geneva,Helvetica,Arial,sans-serif;font-size:12px;font-weight:bold;line-height:16px;background-color:rgb(244,244,244)"><br>
</span></div><div><span style="color:rgb(52,65,70);font-family:Verdana,Geneva,Helvetica,Arial,sans-serif;font-size:12px;font-weight:bold;line-height:16px;background-color:rgb(244,244,244)"><br></span></div><div><span style="background-color:rgb(244,244,244)"><font color="#344146" face="Verdana, Geneva, Helvetica, Arial, sans-serif"><span style="font-size:12px;line-height:16px"><b>Therefore, the regulators that make up part of the Article 29 working party have more authority separately than when acting in the capacity of the Article 29 WG. </b></span></font></span></div>
</div><div class="gmail_extra"><br clear="all"><div><div dir="ltr"><div><br></div>
<div> </div>
<div> </div>
<div>Mark Leiser</div>
<div> </div>
<div><div style="background-color:rgb(255,255,255)"><div><font color="#222222" face="arial, sans-serif">Mark R. Leiser, Phd Student</font></div><div><font color="#222222" face="arial, sans-serif">School of Law, Humanities & Social Sciences Faculty</font></div>
<div><font color="#222222" face="arial, sans-serif">PGR Room, Lord Hope Building</font></div><div><font color="#222222" face="arial, sans-serif">University of Strathclyde</font></div><div><font color="#222222" face="arial, sans-serif">141 St James Road,</font></div>
<div><font color="#222222" face="arial, sans-serif">Glasgow G4 0LT </font>Scotland </div><div><br></div><div>Mobile: +44 (0) 7719739090</div><div><font color="#222222" face="arial, sans-serif">Email: <a href="mailto:markleiser@gmail.com" target="_blank">markleiser@gmail.com</a> </font></div>
<div><font color="#222222" face="arial, sans-serif">Twitter: <a href="http://twitter.com/#!/mleiser" target="_blank">http://twitter.com/#!/mleiser</a></font></div><div><font color="#222222" face="arial, sans-serif">LinkedIN: <a href="http://www.linkedin.com/profile/view?id=189149411&trk=tab_pro" target="_blank">http://www.linkedin.com/profile/view?id=189149411&trk=tab_pro</a> </font></div>
<div><font color="#222222" face="arial, sans-serif">Google+: <a href="https://plus.google.com/u/0/105289982691060086995/posts" target="_blank">https://plus.google.com/u/0/105289982691060086995/posts</a></font></div></div>
</div><div><br></div></div></div>
<br><br><div class="gmail_quote">On Tue, Jul 16, 2013 at 1:52 AM, Andrew A. Adams <span dir="ltr"><<a href="mailto:aaa@meiji.ac.jp" target="_blank">aaa@meiji.ac.jp</a>></span> wrote:<br><blockquote class="gmail_quote" style="margin:0 0 0 .8ex;border-left:1px #ccc solid;padding-left:1ex">
<div class="im">Milton wrote:<br>
> Is there any way that EPIC or other privacy organizations with<br>
> litigation experience can advise us on or European colleagues on how<br>
> to sue ICANN to show that it does have legal effect?<br>
<br>
</div>There is no way really to premptively bring this to a court. If ICANN does<br>
not regard the Art 29 WP as a suitable authority, then it may also not<br>
recognise the individual regulators as competent authorities. In its current<br>
form, i.e. the data protection directive, it is up to individual member<br>
states to set up appropriate legislation in each country to implement the<br>
directive. (As a side-note the proposed new regulation is much simpler in<br>
that regulations pretty much get direct effect in member states.) We'd have<br>
to know what ICANN would regard as sufficient legal authority. Perhaps they<br>
would regard individual rulings by each regulator as having sufficient effect<br>
(since this appears to have been a unanimous decision by the ART29WP which<br>
includes representatives of all the regulators as well as some other<br>
advisors, that actually should be feasible). However, ICANN could just as<br>
easily then turn around and say that this is still not sufficient, in which<br>
case we'd have to wait for:<br>
<br>
An EU-based registrar to comply with thick whois, and make the information<br>
available as per the ICANN rules;<br>
someone subject to that registry to make a complaint to the regulator in<br>
their country; OR for the relevant DPA to intervene on their own recognisance<br>
to order the registrar to stop such activity;<br>
the registrar to appeal to the relevant tribunal or court;<br>
the relevant tribunal or court to rule that the data protection authority is<br>
correct;<br>
further appeals up the chain to the member state top court, and for them to<br>
refer the matter to the ECJ (European Court of Justice) for an EU-level<br>
opinion binding on all EU jurisdictions.<br>
<br>
THat would take, on conservative estimates, about five years to complete. In<br>
the meantime all registrars in EU member states would be caught between the<br>
rock of ICANN rules and the hard place of their own regulators'<br>
interpretations of EU rules.<br>
<br>
Plus, in the meantime, the new EU DP Regulations will probably become EU law<br>
this year or next. Luckily for us, this wouldn't then have any further delay<br>
in transposition into member states laws.<br>
<br>
<br>
<br>
We need to know whether ICANN would regard individual statements from<br>
relevant DPAs in the various EU member states would be regarded as<br>
sufficient, or whether they would push registrars into the ridiculous<br>
position of having to ignore the advice of their DP authority (which opens<br>
them to significant fines in many cases) or ICANN's rules (which runs the<br>
risk of them beign suspended by their registry IIRC).<br>
<span class="HOEnZb"><font color="#888888"><br>
<br>
<br>
--<br>
Professor Andrew A Adams <a href="mailto:aaa@meiji.ac.jp">aaa@meiji.ac.jp</a><br>
Professor at Graduate School of Business Administration, and<br>
Deputy Director of the Centre for Business Information Ethics<br>
Meiji University, Tokyo, Japan <a href="http://www.a-cubed.info/" target="_blank">http://www.a-cubed.info/</a><br>
</font></span></blockquote></div><br></div>