<html>
<head>
<meta content="text/html; charset=UTF-8" http-equiv="Content-Type">
</head>
<body text="#000000" bgcolor="#FFFFFF">
Thanks for sending, I am having trouble with attachments but I got
it. I think I have made all the corrections now, here is the
amended version 6, I believe you can post it.<br>
cheers Stephanie<br>
<div class="moz-cite-prefix">On 2014-08-01, 6:11, Rafik Dammak
wrote:<br>
</div>
<blockquote
cite="mid:CAH5sThn+DmhHAbS1TA1WRjcqy5YoZ_KVMO=cLjDBDtJ8g=Yxmg@mail.gmail.com"
type="cite">
<meta http-equiv="Content-Type" content="text/html; charset=UTF-8">
<p dir="ltr">Hi Stephanie,</p>
<p dir="ltr">I think joy included her language in the attached
document, can you please merge that with the latest draft you
circulated?<br>
Lesson learned: using a shared online document and avoid the
word document versioning nightmare.</p>
<p dir="ltr">Best,</p>
<p dir="ltr">Rafik</p>
<div class="gmail_quote">---------- Forwarded message ----------<br>
From: "joy" <<a moz-do-not-send="true"
href="mailto:joy@apc.org">joy@apc.org</a>><br>
Date: Jul 31, 2014 3:05 AM<br>
Subject: Re: [NCSG-Discuss] Draft Comments for Whois Proceeding<br>
To: <<a moz-do-not-send="true"
href="mailto:NCSG-DISCUSS@listserv.syr.edu">NCSG-DISCUSS@listserv.syr.edu</a>><br>
Cc: <br>
<br type="attribution">
Hi - thanks everyone for the effort on this<br>
I have also added some information on the recent report of the
UN High<br>
Commissioner for Human Rights on the right to privacy in the
digital age<br>
- which includes aspects relevant for companies - plus one or
two other<br>
minor comments<br>
Hope you get these in time!<br>
Joy<br>
<br>
On 31/07/2014 4:17 a.m., Kathy Kleiman wrote:<br>
> Hi All,<br>
> Attached is the revised version of the comments. It has the
changes of<br>
> Stephanie and Ed incorporated (tx you!) I have drafted it
for Rafik's<br>
> signature and submission on behalf of the NCSG (feel free
to add an<br>
> electronic signature, Rafik!). (Track changes version
showing edits<br>
> attached)<br>
><br>
> If you could please use _this version _of the revised
comments for<br>
> review and submission, that would be great.<br>
> Best,<br>
> Kathy<br>
><br>
><br>
>
-----------------------------------------------------------------------------------------------------------------------------------------------<br>
><br>
> NCSG Response to the Questions of the<br>
><br>
> /Review of the ICANN Procedure for Handling WHOIS Conflicts
with<br>
> Privacy Law /<br>
><br>
> <a moz-do-not-send="true"
href="https://www.icann.org/public-comments/whois-conflicts-procedure-2014-05-22-en//"
target="_blank">https://www.icann.org/public-comments/whois-conflicts-procedure-2014-05-22-en//</a><br>
><br>
><br>
> **<br>
><br>
> The Noncommercial Stakeholders Group represents
noncommercial<br>
> organizations and individual noncommercial users in their
work in the<br>
> policy and proceedings of ICANN and the GNSO. We
respectfully submit<br>
> as an opening premise that every legal business has the
right and<br>
> obligation to operate within the bounds and limits of its
national<br>
> laws and regulations. No legal business establishes itself
to violate<br>
> the law; and to do so is an invitation to civil and
criminal<br>
> penalties, in addition to reputational damage and a loss of
the trust<br>
> of their customers and business partner. ICANN Registries
and<br>
> Registrars are no different – they want and need to abide
by their laws.<br>
><br>
> To that end, Registries and Registrars strive to comply
with their<br>
> national and local laws.They strive affirmatively and
proactively to<br>
> follow the laws and regulations under which they operate as
legal<br>
> entities. To do otherwise is to violate the purpose of a
legal regime,<br>
> to threaten the well being of the company, and to expose
Directors,<br>
> Officers and Employees to fines, jail, or civil litigation.
In the<br>
> matter of protection of personal and confidential
information, which<br>
> is a very newsworthy issue in the 21^st century, privacy
practices are<br>
> a matter of consumer trust, and therefore high risk for
those<br>
> operating an Internet business.Even if customers have
obediently<br>
> complied with demands for excessive collection and
disclosure of<br>
> personal information up to this point, in the current news
furor over<br>
> Snowden and the cooperation of business with national
governments<br>
> engaged in surveillance, this could change with the next
news<br>
> story.The Internet facilitates successful privacy
campaigns.<br>
><br>
> Thus, it is wise and timely for ICANN to raise the
questions of this<br>
> proceeding, /Review of the ICANN Procedure for Handling
WHOIS<br>
> Conflicts with Privacy Law/ (albeit at a busy time for the
Community<br>
> and at the height of summer; we expect to see more interest
in this<br>
> time towards the Fall and recommend that ICANN not construe
the small<br>
> number of comments received to date as a reflection of lack
of<br>
> interest). We submit these comments in response to the
issues raises<br>
> and the questions asked.<br>
><br>
> *Background*<br>
><br>
> The /ICANN Procedure for Handling Whois Conflicts with
Privacy Law<br>
> /was adopted in 2006 after years of debate on Whois issues.
This<br>
> Consensus Procedure was the first step of recognition that
data<br>
> protection laws and privacy law DO apply to the personal
and sensitive<br>
> data being collected by Registries and Registrars for the
Whois database.<br>
><br>
> But for those of us in the Noncommercial Users Constituency
(now part<br>
> of the Noncommercial Stakeholders Group/NCSG) who helped
debate, draft<br>
> and adopt this Consensus Procedure in the mid-2000s, we
were always<br>
> shocked that the ICANN Community did not do more. At the
time, several<br>
> Whois Task Forces were at work with multiple proposals
which include<br>
> important and pro-active suggestions to allow Registrars
and<br>
> Registries to come into compliance with their national and
local data<br>
> protection and privacy laws.<br>
><br>
> At the time, we never expected this Consensus Procedure to
be an end<br>
> itself – but the first of many steps. We are glad the
discussion is<br>
> now reopened and we support empowering Registrars and
Registries to be<br>
> in full compliance with their national and local data
protection,<br>
> consumer protection and privacy laws – from the moment they
enter into<br>
> their contracts with ICANN.<br>
><br>
> We note there have been a number of recent decisions in
higher courts<br>
> in various jurisdictions which impact the constitutional
rights of<br>
> citizens to be free from warrantless disclosure and
retention of their<br>
> personal information for law enforcement purposes.This
reflects the<br>
> time it takes for data protection issues to wend their way
to the high<br>
> courts for a ruling.We would urge ICANN, who otherwise sit
on the<br>
> cutting edge of Internet technical issues, to reflect on
their role as<br>
> a key global player in Internet governance.Do we lead or do
we wait<br>
> until we are dragged into Court, to realize our
responsibilities to<br>
> protect the fundamental rights of the citizens who depend
on the<br>
> Internet to participate in modern society?//<br>
><br>
> II. Data Protection and Privacy Laws – A Quick Overview of
the<br>
> Principles that Protect the Personal and Sensitive Data of
Individuals<br>
> and Organizations/Small Businesses<br>
><br>
> It is important to stress that while the discourse about
data<br>
> protection requirements at ICANN has tended to focus on the
European<br>
> Union and its Data Commissioners, as represented in the
Article 29<br>
> Working Party on Data Protection, there are a great many
countries<br>
> which have data protection law in place, including Canada,
Mexico,<br>
> much of South America, Korea, Japan, Australia, New
Zealand,<br>
> Singapore, South Africa, and many others.It is therefore
quite<br>
> puzzling that ICANN does not assemble a working group to
study the<br>
> matter and develop a harmonized approach to the issue,
rather than<br>
> take this rather odd approach of forcing registrars and
registries to<br>
> break national and local law.<br>
><br>
> It is also important to note that there are many levels of
data<br>
> protection law, from local municipal law to state and
national<br>
> law.There is also sectoral law which applies to certain
sectors.It<br>
> would be a reasonable approach to develop a policy that
reflects<br>
> harmonized best practice, and abide by the policy rather
than engage<br>
> in this adversarial approach to local law.Data protection
law is<br>
> overwhelmingly complaints based, so it is inherently
difficult for<br>
> registrars and registries to get a ruling from data
protection<br>
> commissioners absent a complaint and a set of facts.<br>
><br>
> In this regard, we also find it puzzling that despite the
fact that<br>
> the Article 29 Working Party wrote to ICANN senior
management to<br>
> indicate that they have reviewed the matter and reached an
opinion<br>
> that the practices involving WHOIS do indeed violate EU
law, ICANN has<br>
> not taken that message and developed a policy that guides
their data<br>
> protection practices, starting with a clear statement of
limited<br>
> purpose for the collection, use, and disclosure of personal
information.<br>
><br>
> The NCSG held a privacy meeting at the London ICANN 50
meeting, which<br>
> was quite well attended.While we did not specifically
address or<br>
> attempt to brainstorm this particular problem, we feel it
is safe to<br>
> summarize the following points:<br>
><br>
> ·There is considerable interest, in civil society, in the
protection<br>
> of personal information at ICANN.<br>
><br>
> ·Policies and procedures such as were developed for the
2013 RAA are<br>
> very puzzling to those who are engaged in government and
business in<br>
> the privacy field.This is not 1995, when the EU Directive
on data<br>
> protection was passed and was still controversial.ICANN
needs to catch<br>
> up with global business practice, preferably by developing
binding<br>
> corporate rules which would take a harmonized approach to
the<br>
> differing local laws. It is not appropriate for all data
protection to<br>
> fall away in jurisdictions where there is not yet a data
protection<br>
> law that applies to the provision of internet services,
including<br>
> domain name registration.<br>
><br>
> ·NCSG is ramping up a team of volunteers to provide more
detailed<br>
> expertise and input on a number of privacy and free speech<br>
> issues.While civil society is inherently stretched and
short of<br>
> resources, this is an issue that they care deeply about,
and our<br>
> outreach has begun to bear fruit in engaging others who are
outside<br>
> the immediate sphere of ICANN membership.This is important
as they are<br>
> part of the constituency we seek to represent.<br>
><br>
> ICANN spends considerable time on technical parameters,
data accuracy,<br>
> and retention.More time needs to be spent on data
protection policy.In<br>
> this respect, more expertise would be required as there is
very little<br>
> evidence of privacy expertise in the ICANN community.<br>
><br>
> III*/./*Questions asked of the Community in this Proceeding<br>
><br>
> The ICANN Review Paper raised a number of excellent
questions. In<br>
> keeping with the requirements of a Reply Period, these NCSG
comments<br>
> will address both our comments and those comments we
particularly<br>
> support in this proceeding.<br>
><br>
> However we would first like to note that the paper appears
to start<br>
> from the position that the procedures involved in this
waiver process<br>
> simply need to be tweaked.Operating under the first
principle that all<br>
> business must comply with local law, there is a need for
ICANN to<br>
> embrace data protection law as a well recognized branch of
law which<br>
> codifies well recognized business best practices with
respect to the<br>
> confidentiality of customer data.We respectfully submit
that, if ICANN<br>
> had a professional privacy officer, it is highly unlikely
that he/she<br>
> would recommend to senior management that the current
approach be<br>
> entertained in 2014.<br>
><br>
> 1.1Is it impractical for ICANN to require that a contracted
party<br>
> already haslitigation or a government proceeding initiated
against it<br>
> prior to being able to invoke the Whois Procedure?<br>
><br>
> 1.1 Response: Yes, it is completely impractical (and
ill-advised) to<br>
> force a company to violate a national law as a condition of
complying<br>
> with their contract. Every lawyer advises businesses to
comply with<br>
> the laws and regulations of their field. To do otherwise is
to face<br>
> fines, penalties, loss of the business, even jail for
officers and<br>
> directors. Legal business strives to be law-abiding; no
officer or<br>
> director wants to go to jail for her company's violations.
It is the<br>
> essence of an attorney's advice to his/her clients to fully
comply<br>
> with the laws and operate clearly within the clear
boundaries and<br>
> limits of laws and regulations, both national, by province
or state<br>
> and local.<br>
><br>
> In these Reply Comments, we support and encourage ICANN to
adopt<br>
> policies consistent with the initial comments submitted by
the<br>
> European Commission:<br>
><br>
> -that the Whois Procedure be changed from requiring
specific<br>
> prosecutorial action instead to allowing “demonstrating
evidence of a<br>
> potential conflict widely and e.g. accepting information on
the<br>
> legislation imposing requirements that the contractual
requirements<br>
> would breach as sufficient evidence.” (European Commission
comments)<br>
><br>
> We also agree with Blacknight:<br>
><br>
> -“It's completely illogical for ICANN to require that a
contracting<br>
> party already has litigation before they can use a process.
We would<br>
> have loved to use a procedure or process to get exemptions,
but<br>
> expecting us to already be litigating before we can do so
is, for lack<br>
> of a better word, nuts.” (Blacknight comments in this
proceeding).<br>
><br>
> -<br>
><br>
> 1.1a How can the triggering event be meaningfully defined?<br>
><br>
> This is an important question. Rephrased, we might ask
together –what<br>
> must a Registry or Registrar show ICANN in support of its
claim that<br>
> certain provisions involving Whois data violate provisions
of national<br>
> data protection and privacy laws?<br>
><br>
> NCSG respectfully submits that there are at least four
“triggering<br>
> events” that ICANN should recognize:<br>
><br>
> -Evidence from a national Data Protection Commissioner or
his/her<br>
> office (or from a internationally recognized body of
national Data<br>
> Protection Commissioners in a certain region of the world,
including<br>
> the Article 29 Working Party that analyzes the national
data<br>
> protection and privacy laws) that ICANN's contractual
obligations for<br>
> Registry and/or Registrar contracts violate the data
protection laws<br>
> of their country or their group of countries;<br>
><br>
> -Evidence of legal and/or jurisdictional conflict arising
from<br>
> analysis performed by ICANN's legal department or by
national legal<br>
> experts hired by ICANN to evaluate the Whois requirements
of the ICANN<br>
> contracts for compliance and conflicts with national data
protection<br>
> laws and cross-border transfer limits) (similar to the
process we<br>
> understand was undertaken for the data retention issue);<br>
><br>
> -Receipt of a written legal opinion from a nationally
recognized law<br>
> firm or qualified legal practitioner in the applicable
jurisdiction<br>
> that states that the collection, retention and/or transfer
of certain<br>
> Whois data elements as required by Registrar or Registry
Agreements is<br>
> “reasonably likely to violate the applicable law” of the
Registry or<br>
> Registrar (per the process allowed in RAA Data Retention<br>
> Specification); or<br>
><br>
> -An official opinion of any other governmental body of
competent<br>
> jurisdiction providing that compliance with the data
protection<br>
> requirements of the Registry/Registrar contracts violates
applicable<br>
> national law (although such pro-active opinions may not be
the<br>
> practice of the Data Protection Commissioner's office).<br>
><br>
> The above list draws from the comments of the European
Commission,<br>
> Data Retention Specification of the 2013Registrar
Accreditation<br>
> Agreement, and sound compliance and business practices for
the ICANN<br>
> General Counsel's office.<br>
><br>
> We further agree with Blacknight that the requirements for
triggering<br>
> any review and consideration by ICANN be: simple and
straightforward,<br>
> quick and easy to access.<br>
><br>
> 1.3Are there any components of the triggering
event/notification<br>
> portion of the RAA's Data Retention waiver process that
should be<br>
> considered as optional for incorporation into a modified
Whois Procedure?<br>
><br>
> 1.3 Response:Absolutely, the full list in 1.1a above,
together with<br>
> other constructive contributions in the Comments and Reply
Comments of<br>
> this proceeding, should be strongly considered for
incorporation into<br>
> a modified Whois Procedure, or simply written into the
contracts of<br>
> the Registries and Registrars contractual language, or a
new Annex or<br>
> Specification.<br>
><br>
> We respectfully submit that the obligation of Registries
and<br>
> Registrars to comply with their national laws is not a
matter of<br>
> multistakeholder decision making, but a matter of law and
compliance.<br>
> In this case, we wholeheartedly embrace the concept of
building a<br>
> process together that will allow exceptions for data
protection and<br>
> privacy laws to be adopted quickly and easily.<br>
><br>
> 1.4Should parties be permitted to invoke the Whois
Procedure before<br>
> contracting with ICANN as a registrar or registry?<br>
><br>
> 1.4 Response: Of course, Registries and Registrars should
be allowed<br>
> to invoke the Whois Procedure, or other appropriate annexes
and<br>
> specifications that may be added into Registry and
Registrar contracts<br>
> with ICANN. As discussed above, the right of a legal
company to enter<br>
> into a legal contracts is the most basic of expectations
under law.<br>
><br>
> 2.1Are there other relevant parties who should be included
in this step?<br>
><br>
> 2.1 Response: We agree with the EC that ICANN should be
working as<br>
> closely with National Data Protection Authorities as they
will allow.<br>
> In light of the overflow of work into these national
commissions, and<br>
> the availability of national experts at law firms, ICANN
should also<br>
> turn to the advice of private experts,such as
well-respected law firms<br>
> who specialize in national data protection laws. The law
firm's<br>
> opinions on these matters would help to guide ICANN's
knowledge and<br>
> evaluation of this important issue.<br>
><br>
> 3.1How is an agreement reached and published?<br>
><br>
> 3.1 Response. As discussed above, compliance with national
law may not<br>
> be the best matter for negotiation within a
multistakeholder process.<br>
> It really should not be a chose for others to make whether
you comply<br>
> with your national data protection and privacy laws. That
said, the<br>
> process of refining the Consensus Procedure, and adopting
new policies<br>
> and procedures, or simply putting new contract provisions,
annexes or<br>
> specifications into the Registry and Registrar contracts
SHOULD be<br>
> subject to community discussion, notification and
review.But once the<br>
> new process is adopted, we think the new changes,
variations,<br>
> modifications or exceptions of Individual Registries and
Registrars<br>
> need go through a public review and process. The results,
however,<br>
> Should be published for Community notification and review.<br>
><br>
> We note that in conducting the discussion with the
Community on the<br>
> overall or general procedure, policy or contractual
changes, ICANN<br>
> should be assertive in its outreach to the Data Protection<br>
> Commissioners. Individual and through their organizations,
they have<br>
> offered to help ICANN evaluate this issue numerous times.
The Whois<br>
> Review Team noted the inability of many external bodies to
monitor<br>
> ICANN regularly, but the need for outreach to them by ICANN
staff<br>
> nonetheless:<br>
><br>
> *Recommendation 3:Outreach*<br>
><br>
> *ICANN should ensure that WHOIS policy issues are
accompanied by<br>
> cross-community outreach, including outreach to the
communities<br>
> outside of ICANN with a specific interest in the issues,
and an<br>
> ongoing program for consumer awareness. (Whois Review Team
Final Report)*<br>
><br>
> This is a critical policy item for such outreach and input.<br>
><br>
> 3.2If there is an agreed outcome among the relevant
parties, should<br>
> the Board be involved in this procedure?<br>
><br>
> 3.2 Response: Clearly, the changing of the procedure, or
the adoption<br>
> of a new policy or new contractual language for Registries
and<br>
> Registrars, Board oversight and review should be involved.
But once<br>
> the new procedure, policy or contractual language is in
place, then<br>
> subsequent individual changes, variations, modifications or
exceptions<br>
> should be handled through the process and ICANN Staff – as
the Data<br>
> Retention Process is handled today.<br>
><br>
> 4.1Would it be fruitful to incorporate public comment in
each of the<br>
> resolution scenarios.<br>
><br>
> 4.1 Response: We think this question means whether there
should be<br>
> public input on each and every exception?We respectfully
submit that<br>
> the answer is No. Once the new policy, procedure or
contractual<br>
> language is adopted, then the process should kick in and
the<br>
> Registrar/Registry should be allowed to apply for the
waiver,<br>
> modification or revision consistent with its data
protection and<br>
> privacy laws.Of course, once the waiver or modification is
granted,<br>
> the decision should be matter of public record so that
other<br>
> Registries and Registrars in the jurisdiction know and so
that the<br>
> ICANN Community as a whole can monitor this process'
implementation<br>
> and compliance.<br>
><br>
> Step Five: Public notice<br>
><br>
> 5.2Is the exemption or modification termed to the length of
the<br>
> agreement? Or is it indefinite as long as the contracted
party is<br>
> located in the jurisdiction in question, or so long as the
applicable<br>
> law is in force.<br>
><br>
> 5.2 Response:We agree with the European Commission in its
response,<br>
><br>
> “/By logic the exemption or modification shall be in place
as long as<br>
> the party is subject to the jurisdiction in conflict with
ICANN rules.<br>
> If the applicable law was to change, or the contacted party
moved to a<br>
> different jurisdiction, the conditions should be reviewed
to assess if<br>
> the exemption is still justified.”/<br>
><br>
> //<br>
><br>
> But provided it is the same parties, operating under the
same laws,<br>
> the modification or change should continue through the
duration of the<br>
> relationship between the Registry/Registrar and ICANN.<br>
><br>
> 5.3Should an exemption or modification based on the same
laws and<br>
> facts then be granted to other affected contracted parties
in the same<br>
> jurisdiction without invoking the Whois Procedure.<br>
><br>
> 5.3 Response. The European Commission in its comments
wrote, and we<br>
> strongly agree: /“the same exception should apply to others
in the<br>
> same jurisdiction who can demonstrate that they are in the
same<br>
> situation.” /Further, Blacknight wrote and we support: /“if
ANY<br>
> registrar in Germany, for example, is granted a waiver
based on German<br>
> law, than ALL registrars based in Germany should receive
the same<br>
> treatment.” /Once a national data protection or privacy law
is<br>
> interpreted as requiring and exemption or modification, it
should be<br>
> available to all Registries/Registrars in that country.<br>
><br>
> Further, we recommend that ICANN should be required to
notify each<br>
> gTLD Registry and Registrar in the same jurisdiction as
that of the<br>
> decision so they will have notice of the change.<br>
><br>
> We thank ICANN staff for holding this comment period.<br>
><br>
> Respectfully submitted,<br>
><br>
> Rafik Dammak<br>
><br>
> Chairman, NCSG<br>
><br>
> On behalf of the Noncommercial Stakeholders Group<br>
><br>
><br>
><br>
<br>
</div>
</blockquote>
<br>
</body>
</html>