<html>
  <head>
    <meta content="text/html; charset=UTF-8" http-equiv="Content-Type">
  </head>
  <body text="#000000" bgcolor="#FFFFFF">
    Thanks for sending, I am having trouble with attachments but I got
    it.  I think I have made all the corrections now, here is the
    amended version 6, I believe you can post it.<br>
    cheers Stephanie<br>
    <div class="moz-cite-prefix">On 2014-08-01, 6:11, Rafik Dammak
      wrote:<br>
    </div>
    <blockquote
cite="mid:CAH5sThn+DmhHAbS1TA1WRjcqy5YoZ_KVMO=cLjDBDtJ8g=Yxmg@mail.gmail.com"
      type="cite">
      <meta http-equiv="Content-Type" content="text/html; charset=UTF-8">
      <p dir="ltr">Hi Stephanie,</p>
      <p dir="ltr">I think joy included her language in the attached
        document, can you please merge that with the latest draft you
        circulated?<br>
        Lesson learned: using a shared online document and avoid the
        word document versioning nightmare.</p>
      <p dir="ltr">Best,</p>
      <p dir="ltr">Rafik</p>
      <div class="gmail_quote">---------- Forwarded message ----------<br>
        From: "joy" <<a moz-do-not-send="true"
          href="mailto:joy@apc.org">joy@apc.org</a>><br>
        Date: Jul 31, 2014 3:05 AM<br>
        Subject: Re: [NCSG-Discuss] Draft Comments for Whois Proceeding<br>
        To: <<a moz-do-not-send="true"
          href="mailto:NCSG-DISCUSS@listserv.syr.edu">NCSG-DISCUSS@listserv.syr.edu</a>><br>
        Cc: <br>
        <br type="attribution">
        Hi - thanks everyone for the effort on this<br>
        I have also added some information on the recent report of the
        UN High<br>
        Commissioner for Human Rights on the right to privacy in the
        digital age<br>
        - which includes aspects relevant for companies - plus one or
        two other<br>
        minor comments<br>
        Hope you get these in time!<br>
        Joy<br>
        <br>
        On 31/07/2014 4:17 a.m., Kathy Kleiman wrote:<br>
        > Hi All,<br>
        > Attached is the revised version of the comments. It has the
        changes of<br>
        > Stephanie and Ed incorporated (tx you!) I have drafted it
        for Rafik's<br>
        > signature and submission on behalf of the NCSG (feel free
        to add an<br>
        > electronic signature, Rafik!).  (Track changes version
        showing edits<br>
        > attached)<br>
        ><br>
        > If you could please use _this version _of the revised
        comments for<br>
        > review and submission, that would be great.<br>
        > Best,<br>
        > Kathy<br>
        ><br>
        ><br>
        >
-----------------------------------------------------------------------------------------------------------------------------------------------<br>
        ><br>
        > NCSG Response to the Questions of the<br>
        ><br>
        > /Review of the ICANN Procedure for Handling WHOIS Conflicts
        with<br>
        > Privacy Law /<br>
        ><br>
        > <a moz-do-not-send="true"
href="https://www.icann.org/public-comments/whois-conflicts-procedure-2014-05-22-en//"
          target="_blank">https://www.icann.org/public-comments/whois-conflicts-procedure-2014-05-22-en//</a><br>
        ><br>
        ><br>
        > **<br>
        ><br>
        > The Noncommercial Stakeholders Group represents
        noncommercial<br>
        > organizations and individual noncommercial users in their
        work in the<br>
        > policy and proceedings of ICANN and the GNSO. We
        respectfully submit<br>
        > as an opening premise that every legal business has the
        right and<br>
        > obligation to operate within the bounds and limits of its
        national<br>
        > laws and regulations. No legal business establishes itself
        to violate<br>
        > the law; and to do so is an invitation to civil and
        criminal<br>
        > penalties, in addition to reputational damage and a loss of
        the trust<br>
        > of their customers and business partner. ICANN Registries
        and<br>
        > Registrars are no different – they want and need to abide
        by their laws.<br>
        ><br>
        > To that end, Registries and Registrars strive to comply
        with their<br>
        > national and local laws.They strive affirmatively and
        proactively to<br>
        > follow the laws and regulations under which they operate as
        legal<br>
        > entities. To do otherwise is to violate the purpose of a
        legal regime,<br>
        > to threaten the well being of the company, and to expose
        Directors,<br>
        > Officers and Employees to fines, jail, or civil litigation.
        In the<br>
        > matter of protection of personal and confidential
        information, which<br>
        > is a very newsworthy issue in the 21^st century, privacy
        practices are<br>
        > a matter of consumer trust, and therefore high risk for
        those<br>
        > operating an Internet business.Even if customers have
        obediently<br>
        > complied with demands for excessive collection and
        disclosure of<br>
        > personal information up to this point, in the current news
        furor over<br>
        > Snowden and the cooperation of business with national
        governments<br>
        > engaged in surveillance, this could change with the next
        news<br>
        > story.The Internet facilitates successful privacy
        campaigns.<br>
        ><br>
        > Thus, it is wise and timely for ICANN to raise the
        questions of this<br>
        > proceeding, /Review of the ICANN Procedure for Handling
        WHOIS<br>
        > Conflicts with Privacy Law/ (albeit at a busy time for the
        Community<br>
        > and at the height of summer; we expect to see more interest
        in this<br>
        > time towards the Fall and recommend that ICANN not construe
        the small<br>
        > number of comments received to date as a reflection of lack
        of<br>
        > interest). We submit these comments in response to the
        issues raises<br>
        > and the questions asked.<br>
        ><br>
        > *Background*<br>
        ><br>
        > The /ICANN Procedure for Handling Whois Conflicts with
        Privacy Law<br>
        > /was adopted in 2006 after years of debate on Whois issues.
        This<br>
        > Consensus Procedure was the first step of recognition that
        data<br>
        > protection laws and privacy law DO apply to the personal
        and sensitive<br>
        > data being collected by Registries and Registrars for the
        Whois database.<br>
        ><br>
        > But for those of us in the Noncommercial Users Constituency
        (now part<br>
        > of the Noncommercial Stakeholders Group/NCSG) who helped
        debate, draft<br>
        > and adopt this Consensus Procedure in the mid-2000s, we
        were always<br>
        > shocked that the ICANN Community did not do more. At the
        time, several<br>
        > Whois Task Forces were at work with multiple proposals
        which include<br>
        > important and pro-active suggestions to allow Registrars
        and<br>
        > Registries to come into compliance with their national and
        local data<br>
        > protection and privacy laws.<br>
        ><br>
        > At the time, we never expected this Consensus Procedure to
        be an end<br>
        > itself – but the first of many steps. We are glad the
        discussion is<br>
        > now reopened and we support empowering Registrars and
        Registries to be<br>
        > in full compliance with their national and local data
        protection,<br>
        > consumer protection and privacy laws – from the moment they
        enter into<br>
        > their contracts with ICANN.<br>
        ><br>
        > We note there have been a number of recent decisions in
        higher courts<br>
        > in various jurisdictions which impact the constitutional
        rights of<br>
        > citizens to be free from warrantless disclosure and
        retention of their<br>
        > personal information for law enforcement purposes.This
        reflects the<br>
        > time it takes for data protection issues to wend their way
        to the high<br>
        > courts for a ruling.We would urge ICANN, who otherwise sit
        on the<br>
        > cutting edge of Internet technical issues, to reflect on
        their role as<br>
        > a key global player in Internet governance.Do we lead or do
        we wait<br>
        > until we are dragged into Court, to realize our
        responsibilities to<br>
        > protect the fundamental rights of the citizens who depend
        on the<br>
        > Internet to participate in modern society?//<br>
        ><br>
        > II. Data Protection and Privacy Laws – A Quick Overview of
        the<br>
        > Principles that Protect the Personal and Sensitive Data of
        Individuals<br>
        > and Organizations/Small Businesses<br>
        ><br>
        > It is important to stress that while the discourse about
        data<br>
        > protection requirements at ICANN has tended to focus on the
        European<br>
        > Union and its Data Commissioners, as represented in the
        Article 29<br>
        > Working Party on Data Protection, there are a great many
        countries<br>
        > which have data protection law in place, including Canada,
        Mexico,<br>
        > much of South America, Korea, Japan, Australia, New
        Zealand,<br>
        > Singapore, South Africa, and many others.It is therefore
        quite<br>
        > puzzling that ICANN does not assemble a working group to
        study the<br>
        > matter and develop a harmonized approach to the issue,
        rather than<br>
        > take this rather odd approach of forcing registrars and
        registries to<br>
        > break national and local law.<br>
        ><br>
        > It is also important to note that there are many levels of
        data<br>
        > protection law, from local municipal law to state and
        national<br>
        > law.There is also sectoral law which applies to certain
        sectors.It<br>
        > would be a reasonable approach to develop a policy that
        reflects<br>
        > harmonized best practice, and abide by the policy rather
        than engage<br>
        > in this adversarial approach to local law.Data protection
        law is<br>
        > overwhelmingly complaints based, so it is inherently
        difficult for<br>
        > registrars and registries to get a ruling from data
        protection<br>
        > commissioners absent a complaint and a set of facts.<br>
        ><br>
        > In this regard, we also find it puzzling that despite the
        fact that<br>
        > the Article 29 Working Party wrote to ICANN senior
        management to<br>
        > indicate that they have reviewed the matter and reached an
        opinion<br>
        > that the practices involving WHOIS do indeed violate EU
        law, ICANN has<br>
        > not taken that message and developed a policy that guides
        their data<br>
        > protection practices, starting with a clear statement of
        limited<br>
        > purpose for the collection, use, and disclosure of personal
        information.<br>
        ><br>
        > The NCSG held a privacy meeting at the London ICANN 50
        meeting, which<br>
        > was quite well attended.While we did not specifically
        address or<br>
        > attempt to brainstorm this particular problem, we feel it
        is safe to<br>
        > summarize the following points:<br>
        ><br>
        > ·There is considerable interest, in civil society, in the
        protection<br>
        > of personal information at ICANN.<br>
        ><br>
        > ·Policies and procedures such as were developed for the
        2013 RAA are<br>
        > very puzzling to those who are engaged in government and
        business in<br>
        > the privacy field.This is not 1995, when the EU Directive
        on data<br>
        > protection was passed and was still controversial.ICANN
        needs to catch<br>
        > up with global business practice, preferably by developing
        binding<br>
        > corporate rules which would take a harmonized approach to
        the<br>
        > differing local laws. It is not appropriate for all data
        protection to<br>
        > fall away in jurisdictions where there is not yet a data
        protection<br>
        > law that applies to the provision of internet services,
        including<br>
        > domain name registration.<br>
        ><br>
        > ·NCSG is ramping up a team of volunteers to provide more
        detailed<br>
        > expertise and input on a number of privacy and free speech<br>
        > issues.While civil society is inherently stretched and
        short of<br>
        > resources, this is an issue that they care deeply about,
        and our<br>
        > outreach has begun to bear fruit in engaging others who are
        outside<br>
        > the immediate sphere of ICANN membership.This is important
        as they are<br>
        > part of the constituency we seek to represent.<br>
        ><br>
        > ICANN spends considerable time on technical parameters,
        data accuracy,<br>
        > and retention.More time needs to be spent on data
        protection policy.In<br>
        > this respect, more expertise would be required as there is
        very little<br>
        > evidence of privacy expertise in the ICANN community.<br>
        ><br>
        > III*/./*Questions asked of the Community in this Proceeding<br>
        ><br>
        > The ICANN Review Paper raised a number of excellent
        questions. In<br>
        > keeping with the requirements of a Reply Period, these NCSG
        comments<br>
        > will address both our comments and those comments we
        particularly<br>
        > support in this proceeding.<br>
        ><br>
        > However we would first like to note that the paper appears
        to start<br>
        > from the position that the procedures involved in this
        waiver process<br>
        > simply need to be tweaked.Operating under the first
        principle that all<br>
        > business must comply with local law, there is a need for
        ICANN to<br>
        > embrace data protection law as a well recognized branch of
        law which<br>
        > codifies well recognized business best practices with
        respect to the<br>
        > confidentiality of customer data.We respectfully submit
        that, if ICANN<br>
        > had a professional privacy officer, it is highly unlikely
        that he/she<br>
        > would recommend to senior management that the current
        approach be<br>
        > entertained in 2014.<br>
        ><br>
        > 1.1Is it impractical for ICANN to require that a contracted
        party<br>
        > already haslitigation or a government proceeding initiated
        against it<br>
        > prior to being able to invoke the Whois Procedure?<br>
        ><br>
        > 1.1 Response: Yes, it is completely impractical (and
        ill-advised) to<br>
        > force a company to violate a national law as a condition of
        complying<br>
        > with their contract. Every lawyer advises businesses to
        comply with<br>
        > the laws and regulations of their field. To do otherwise is
        to face<br>
        > fines, penalties, loss of the business, even jail for
        officers and<br>
        > directors. Legal business strives to be law-abiding; no
        officer or<br>
        > director wants to go to jail for her company's violations.
        It is the<br>
        > essence of an attorney's advice to his/her clients to fully
        comply<br>
        > with the laws and operate clearly within the clear
        boundaries and<br>
        > limits of laws and regulations, both national, by province
        or state<br>
        > and local.<br>
        ><br>
        > In these Reply Comments, we support and encourage ICANN to
        adopt<br>
        > policies consistent with the initial comments submitted by
        the<br>
        > European Commission:<br>
        ><br>
        > -that the Whois Procedure be changed from requiring
        specific<br>
        > prosecutorial action instead to allowing “demonstrating
        evidence of a<br>
        > potential conflict widely and e.g. accepting information on
        the<br>
        > legislation imposing requirements that the contractual
        requirements<br>
        > would breach as sufficient evidence.” (European Commission
        comments)<br>
        ><br>
        > We also agree with Blacknight:<br>
        ><br>
        > -“It's completely illogical for ICANN to require that a
        contracting<br>
        > party already has litigation before they can use a process.
        We would<br>
        > have loved to use a procedure or process to get exemptions,
        but<br>
        > expecting us to already be litigating before we can do so
        is, for lack<br>
        > of a better word, nuts.” (Blacknight comments in this
        proceeding).<br>
        ><br>
        > -<br>
        ><br>
        > 1.1a How can the triggering event be meaningfully defined?<br>
        ><br>
        > This is an important question. Rephrased, we might ask
        together –what<br>
        > must a Registry or Registrar show ICANN in support of its
        claim that<br>
        > certain provisions involving Whois data violate provisions
        of national<br>
        > data protection and privacy laws?<br>
        ><br>
        > NCSG respectfully submits that there are at least four
        “triggering<br>
        > events” that ICANN should recognize:<br>
        ><br>
        > -Evidence from a national Data Protection Commissioner or
        his/her<br>
        > office (or from a internationally recognized body of
        national Data<br>
        > Protection Commissioners in a certain region of the world,
        including<br>
        > the Article 29 Working Party that analyzes the national
        data<br>
        > protection and privacy laws) that ICANN's contractual
        obligations for<br>
        > Registry and/or Registrar contracts violate the data
        protection laws<br>
        > of their country or their group of countries;<br>
        ><br>
        > -Evidence of legal and/or jurisdictional conflict arising
        from<br>
        > analysis performed by ICANN's legal department or by
        national legal<br>
        > experts hired by ICANN to evaluate the Whois requirements
        of the ICANN<br>
        > contracts for compliance and conflicts with national data
        protection<br>
        > laws and cross-border transfer limits) (similar to the
        process we<br>
        > understand was undertaken for the data retention issue);<br>
        ><br>
        > -Receipt of a written legal opinion from a nationally
        recognized law<br>
        > firm or qualified legal practitioner in the applicable
        jurisdiction<br>
        > that states that the collection, retention and/or transfer
        of certain<br>
        > Whois data elements as required by Registrar or Registry
        Agreements is<br>
        > “reasonably likely to violate the applicable law” of the
        Registry or<br>
        > Registrar (per the process allowed in RAA Data Retention<br>
        > Specification); or<br>
        ><br>
        > -An official opinion of any other governmental body of
        competent<br>
        > jurisdiction providing that compliance with the data
        protection<br>
        > requirements of the Registry/Registrar contracts violates
        applicable<br>
        > national law (although such pro-active opinions may not be
        the<br>
        > practice of the Data Protection Commissioner's office).<br>
        ><br>
        > The above list draws from the comments of the European
        Commission,<br>
        > Data Retention Specification of the 2013Registrar
        Accreditation<br>
        > Agreement, and sound compliance and business practices for
        the ICANN<br>
        > General Counsel's office.<br>
        ><br>
        > We further agree with Blacknight that the requirements for
        triggering<br>
        > any review and consideration by ICANN be: simple and
        straightforward,<br>
        > quick and easy to access.<br>
        ><br>
        > 1.3Are there any components of the triggering
        event/notification<br>
        > portion of the RAA's Data Retention waiver process that
        should be<br>
        > considered as optional for incorporation into a modified
        Whois Procedure?<br>
        ><br>
        > 1.3 Response:Absolutely, the full list in 1.1a above,
        together with<br>
        > other constructive contributions in the Comments and Reply
        Comments of<br>
        > this proceeding, should be strongly considered for
        incorporation into<br>
        > a modified Whois Procedure, or simply written into the
        contracts of<br>
        > the Registries and Registrars contractual language, or a
        new Annex or<br>
        > Specification.<br>
        ><br>
        > We respectfully submit that the obligation of Registries
        and<br>
        > Registrars to comply with their national laws is not a
        matter of<br>
        > multistakeholder decision making, but a matter of law and
        compliance.<br>
        > In this case, we wholeheartedly embrace the concept of
        building a<br>
        > process together that will allow exceptions for data
        protection and<br>
        > privacy laws to be adopted quickly and easily.<br>
        ><br>
        > 1.4Should parties be permitted to invoke the Whois
        Procedure before<br>
        > contracting with ICANN as a registrar or registry?<br>
        ><br>
        > 1.4 Response: Of course, Registries and Registrars should
        be allowed<br>
        > to invoke the Whois Procedure, or other appropriate annexes
        and<br>
        > specifications that may be added into Registry and
        Registrar contracts<br>
        > with ICANN. As discussed above, the right of a legal
        company to enter<br>
        > into a legal contracts is the most basic of expectations
        under law.<br>
        ><br>
        > 2.1Are there other relevant parties who should be included
        in this step?<br>
        ><br>
        > 2.1 Response: We agree with the EC that ICANN should be
        working as<br>
        > closely with National Data Protection Authorities as they
        will allow.<br>
        > In light of the overflow of work into these national
        commissions, and<br>
        > the availability of national experts at law firms, ICANN
        should also<br>
        > turn to the advice of private experts,such as
        well-respected law firms<br>
        > who specialize in national data protection laws. The law
        firm's<br>
        > opinions on these matters would help to guide ICANN's
        knowledge and<br>
        > evaluation of this important issue.<br>
        ><br>
        > 3.1How is an agreement reached and published?<br>
        ><br>
        > 3.1 Response. As discussed above, compliance with national
        law may not<br>
        > be the best matter for negotiation within a
        multistakeholder process.<br>
        > It really should not be a chose for others to make whether
        you comply<br>
        > with your national data protection and privacy laws. That
        said, the<br>
        > process of refining the Consensus Procedure, and adopting
        new policies<br>
        > and procedures, or simply putting new contract provisions,
        annexes or<br>
        > specifications into the Registry and Registrar contracts
        SHOULD be<br>
        > subject to community discussion, notification and
        review.But once the<br>
        > new process is adopted, we think the new changes,
        variations,<br>
        > modifications or exceptions of Individual Registries and
        Registrars<br>
        > need go through a public review and process. The results,
        however,<br>
        > Should be published for Community notification and review.<br>
        ><br>
        > We note that in conducting the discussion with the
        Community on the<br>
        > overall or general procedure, policy or contractual
        changes, ICANN<br>
        > should be assertive in its outreach to the Data Protection<br>
        > Commissioners. Individual and through their organizations,
        they have<br>
        > offered to help ICANN evaluate this issue numerous times.
        The Whois<br>
        > Review Team noted the inability of many external bodies to
        monitor<br>
        > ICANN regularly, but the need for outreach to them by ICANN
        staff<br>
        > nonetheless:<br>
        ><br>
        > *Recommendation 3:Outreach*<br>
        ><br>
        > *ICANN should ensure that WHOIS policy issues are
        accompanied by<br>
        > cross-community outreach, including outreach to the
        communities<br>
        > outside of ICANN with a specific interest in the issues,
        and an<br>
        > ongoing program for consumer awareness. (Whois Review Team
        Final Report)*<br>
        ><br>
        > This is a critical policy item for such outreach and input.<br>
        ><br>
        > 3.2If there is an agreed outcome among the relevant
        parties, should<br>
        > the Board be involved in this procedure?<br>
        ><br>
        > 3.2 Response: Clearly, the changing of the procedure, or
        the adoption<br>
        > of a new policy or new contractual language for Registries
        and<br>
        > Registrars, Board oversight and review should be involved.
        But once<br>
        > the new procedure, policy or contractual language is in
        place, then<br>
        > subsequent individual changes, variations, modifications or
        exceptions<br>
        > should be handled through the process and ICANN Staff – as
        the Data<br>
        > Retention Process is handled today.<br>
        ><br>
        > 4.1Would it be fruitful to incorporate public comment in
        each of the<br>
        > resolution scenarios.<br>
        ><br>
        > 4.1 Response: We think this question means whether there
        should be<br>
        > public input on each and every exception?We respectfully
        submit that<br>
        > the answer is No. Once the new policy, procedure or
        contractual<br>
        > language is adopted, then the process should kick in and
        the<br>
        > Registrar/Registry should be allowed to apply for the
        waiver,<br>
        > modification or revision consistent with its data
        protection and<br>
        > privacy laws.Of course, once the waiver or modification is
        granted,<br>
        > the decision should be matter of public record so that
        other<br>
        > Registries and Registrars in the jurisdiction know and so
        that the<br>
        > ICANN Community as a whole can monitor this process'
        implementation<br>
        > and compliance.<br>
        ><br>
        > Step Five: Public notice<br>
        ><br>
        > 5.2Is the exemption or modification termed to the length of
        the<br>
        > agreement? Or is it indefinite as long as the contracted
        party is<br>
        > located in the jurisdiction in question, or so long as the
        applicable<br>
        > law is in force.<br>
        ><br>
        > 5.2 Response:We agree with the European Commission in its
        response,<br>
        ><br>
        > “/By logic the exemption or modification shall be in place
        as long as<br>
        > the party is subject to the jurisdiction in conflict with
        ICANN rules.<br>
        > If the applicable law was to change, or the contacted party
        moved to a<br>
        > different jurisdiction, the conditions should be reviewed
        to assess if<br>
        > the exemption is still justified.”/<br>
        ><br>
        > //<br>
        ><br>
        > But provided it is the same parties, operating under the
        same laws,<br>
        > the modification or change should continue through the
        duration of the<br>
        > relationship between the Registry/Registrar and ICANN.<br>
        ><br>
        > 5.3Should an exemption or modification based on the same
        laws and<br>
        > facts then be granted to other affected contracted parties
        in the same<br>
        > jurisdiction without invoking the Whois Procedure.<br>
        ><br>
        > 5.3 Response. The European Commission in its comments
        wrote, and we<br>
        > strongly agree: /“the same exception should apply to others
        in the<br>
        > same jurisdiction who can demonstrate that they are in the
        same<br>
        > situation.” /Further, Blacknight wrote and we support: /“if
        ANY<br>
        > registrar in Germany, for example, is granted a waiver
        based on German<br>
        > law, than ALL registrars based in Germany should receive
        the same<br>
        > treatment.” /Once a national data protection or privacy law
        is<br>
        > interpreted as requiring and exemption or modification, it
        should be<br>
        > available to all Registries/Registrars in that country.<br>
        ><br>
        > Further, we recommend that ICANN should be required to
        notify each<br>
        > gTLD Registry and Registrar in the same jurisdiction as
        that of the<br>
        > decision so they will have notice of the change.<br>
        ><br>
        > We thank ICANN staff for holding this comment period.<br>
        ><br>
        > Respectfully submitted,<br>
        ><br>
        > Rafik Dammak<br>
        ><br>
        > Chairman, NCSG<br>
        ><br>
        > On behalf of the Noncommercial Stakeholders Group<br>
        ><br>
        ><br>
        ><br>
        <br>
      </div>
    </blockquote>
    <br>
  </body>
</html>