<html>
  <head>
    <meta content="text/html; charset=utf-8" http-equiv="Content-Type">
  </head>
  <body bgcolor="#FFFFFF" text="#000000">
    Agreed.<br>
    <br>
    Nicolas<br>
    <br>
    <div class="moz-cite-prefix">On 2015-10-11 10:54 AM, James Gannon
      wrote:<br>
    </div>
    <blockquote
      cite="mid:C25AA424-3B26-490B-8D31-D3E4EC3D10EC@cyberinvasion.net"
      type="cite">
      <meta http-equiv="Content-Type" content="text/html; charset=utf-8">
      <div>
        <div><font face="Calibri,sans-serif">I reached out to some of
            the registrars and they are not aware of any formal process
            that LEAs would go through on the ICANN side, the process
            appears to be to merely forward straight to the </font><font
            face="Calibri,sans-serif">registrar with no direct
            engagement with the LEA in question. We can/should put this
            question to Allan Grogan when he visits us as I think its an
            interesting one.</font></div>
        <div><font face="Calibri,sans-serif"><br>
          </font></div>
        <div><font face="Calibri,sans-serif">-Jaes</font></div>
        <div style="color: rgb(0, 0, 0); font-family: Calibri,
          sans-serif; font-size: 14px;">
        </div>
      </div>
      <div style="color: rgb(0, 0, 0); font-family: Calibri, sans-serif;
        font-size: 14px;">
        <br>
      </div>
      <span id="OLK_SRC_BODY_SECTION" style="color: rgb(0, 0, 0);
        font-family: Calibri, sans-serif; font-size: 14px;">
        <div style="font-family:Calibri; font-size:12pt;
          text-align:left; color:black; BORDER-BOTTOM: medium none;
          BORDER-LEFT: medium none; PADDING-BOTTOM: 0in; PADDING-LEFT:
          0in; PADDING-RIGHT: 0in; BORDER-TOP: #b5c4df 1pt solid;
          BORDER-RIGHT: medium none; PADDING-TOP: 3pt">
          <span style="font-weight:bold">From: </span>NCSG-Discuss on
          behalf of Rafik Dammak<br>
          <span style="font-weight:bold">Reply-To: </span>Rafik Dammak<br>
          <span style="font-weight:bold">Date: </span>Sunday 11 October
          2015 at 2:49 p.m.<br>
          <span style="font-weight:bold">To: </span>"<a
            moz-do-not-send="true"
            href="mailto:NCSG-DISCUSS@LISTSERV.SYR.EDU"><a class="moz-txt-link-abbreviated" href="mailto:NCSG-DISCUSS@LISTSERV.SYR.EDU">NCSG-DISCUSS@LISTSERV.SYR.EDU</a></a>"<br>
          <span style="font-weight:bold">Subject: </span>Re: DIDP
          Analysis<br>
        </div>
        <div><br>
        </div>
        <div>
          <div>
            <div dir="ltr">
              <div class="gmail_extra">Hi Tamir,<br>
                <br>
                <div class="gmail_quote">2015-10-11 4:10 GMT+09:00 Tamir
                  Israel <span dir="ltr"><<a moz-do-not-send="true"
                      href="mailto:tisrael@cippic.ca" target="_blank">tisrael@cippic.ca</a>></span>:<br>
                  <blockquote class="gmail_quote" style="margin:0 0 0
                    .8ex;border-left:1px #ccc solid;padding-left:1ex">
                    <div bgcolor="#FFFFFF" text="#000000">Thanks Rafik,<br>
                      <br>
                      On second though, I think you are probably right.
                      I know for .CA, LEA requests go directly to CIRA
                      but now that I think about it, it must be because
                      of the way our WHOIS is setup. It would make sense
                      for LEA requests to go to registrars rather than
                      ICANN.<br>
                      <br>
                    </div>
                  </blockquote>
                  <div><br>
                  </div>
                  <div>ccTLD space is another world, even more diverse
                    and unknwon :)</div>
                  <div> </div>
                  <blockquote class="gmail_quote" style="margin:0 0 0
                    .8ex;border-left:1px #ccc solid;padding-left:1ex">
                    <div bgcolor="#FFFFFF" text="#000000">If that's the
                      case though then, as you say, it might still be
                      worth exploring transparency reports, even if
                      these end up coming from the GAC or are imposed
                      onto registrars via ICANN policy. As an
                      accountability mechanism, these reports are
                      becoming fairly standard to have in the
                      telecommunications context..<br>
                    </div>
                  </blockquote>
                  <div><br>
                  </div>
                  <div>ICANN sounds receiving requests and it happened
                    that its teams get involved in some operations which
                    raised the issue about the expansion of ICANN remit
                    .</div>
                  <div> </div>
                  <blockquote class="gmail_quote" style="margin:0 0 0
                    .8ex;border-left:1px #ccc solid;padding-left:1ex">
                    <div bgcolor="#FFFFFF" text="#000000"><br>
                      Not sure if the DIDP process is the most
                      appropriate mechanism for it though. Any thoughts
                      on how something like that could be moved forward
                      (or reasons why it should not be moved forward)
                      would be appreciated.. There might be a clearer
                      picture of how to design such a thing after the
                      dublin meeting (which, regrettably, I cannot
                      attend).<br>
                      <br>
                    </div>
                  </blockquote>
                  <div><br>
                  </div>
                  <div>maybe not but the transparency report seems a
                    good framework to start with if we talk about
                    compliance and abuse reports.  I won't think that
                    ICANN should push the registrars and registries for
                    a specific way to do it , but if we can work the
                    contracted parties on that matter it will be worthy
                    to explore. there are already some
                    guidelines/principles/ framework that we can suggest
                    here to registries and registrars. such transparency
                    would protect more users interests.</div>
                  <div><br>
                  </div>
                  <div>Best,</div>
                  <div><br>
                  </div>
                  <div>Rafik </div>
                  <blockquote class="gmail_quote" style="margin:0 0 0
                    .8ex;border-left:1px #ccc solid;padding-left:1ex">
                    <div bgcolor="#FFFFFF" text="#000000">
                      <div>
                        <div class="h5"><br>
                          <div>On 10/10/2015 9:28 AM, Rafik Dammak
                            wrote:<br>
                          </div>
                          <blockquote type="cite">
                            <div dir="ltr">
                              <div class="gmail_extra">Hi Tamir,<br>
                                <div class="gmail_quote">2015-10-10 2:11
                                  GMT+09:00 Tamir Israel <span
                                    dir="ltr"><<a
                                      moz-do-not-send="true"
                                      href="mailto:tisrael@cippic.ca"
                                      target="_blank"><a class="moz-txt-link-abbreviated" href="mailto:tisrael@cippic.ca">tisrael@cippic.ca</a></a>></span>:<br>
                                  <blockquote class="gmail_quote"
                                    style="margin:0px 0px 0px
0.8ex;border-left-width:1px;border-left-color:rgb(204,204,204);border-left-style:solid;padding-left:1ex">Perhaps
                                    a single independent
                                    commissioner-type may make the most
                                    sense.<br>
                                    The trick I think would be to ensure
                                    independence. That tends to be<br>
                                    easier to do if there are more than
                                    one, because you can allocate one<br>
                                    per stakeholder group. Still, I
                                    think by encoding some criteria (no<br>
                                    strong industry or ICANN affil for 2
                                    years back or something; nomination<br>
                                    committee w/CS representation;
                                    dedicated funding for independence)
                                    it<br>
                                    can be done.<br>
                                    <br>
                                    Another quick thought here: I did
                                    not see a proactive disclosure
                                    section<br>
                                    in the document. Would it be worth
                                    adding?<br>
                                    <br>
                                    Related, does anyone know if ICANN
                                    handles law enforcement requests or<br>
                                    whether these are handled by the
                                    registrars? If so, it would seem
                                    that<br>
                                    including the obligation to issue
                                    annual LEA transparency reports
                                    would<br>
                                    not be out of line.<br>
                                    <br>
                                  </blockquote>
                                  <div><br>
                                  </div>
                                  <div><br>
                                  </div>
                                  <div>to be honest, it is unclear how
                                    ICANN handle direct requests from
                                    LEA, while we may get more
                                    information from registrars on the
                                    type of requests they get.</div>
                                  <div> there is some work going with
                                    the new Compliance Chief Officer
                                    regarding how to handle requests or
                                    abuse reports (but not necessarily
                                    LEA) . here a blog post with some
                                    updates <a moz-do-not-send="true"
href="https://www.icann.org/news/blog/update-on-steps-to-combat-abuse-and-illegal-activity"
                                      target="_blank">https://www.icann.org/news/blog/update-on-steps-to-combat-abuse-and-illegal-activity</a>
                                    (there are 2 sessions at ICANN
                                    meeting in wednesday 21st Oct <a
                                      moz-do-not-send="true"
href="https://dublin54.icann.org/en/dublin54/schedule/wed-practices-combating-abuse"
                                      target="_blank"><a class="moz-txt-link-freetext" href="https://dublin54.icann.org/en/dublin54/schedule/wed-practices-combating-abuse">https://dublin54.icann.org/en/dublin54/schedule/wed-practices-combating-abuse</a></a>
                                    & <a moz-do-not-send="true"
                                      href="https://dublin54.icann.org/en/dublin54/schedule/wed-compliance"
                                      target="_blank">https://dublin54.icann.org/en/dublin54/schedule/wed-compliance</a>
                                    . I invited weeks ago The Compliance
                                    Chief Officer to come to NCSG
                                    meeting in Tuesday 20th Oct so we
                                    can discuss with him.</div>
                                  <div><br>
                                  </div>
                                  <div>I would highlight that LEAs have
                                    their GAC Public Safety working
                                    group and it has several sessions in
                                    Dublin meeting too. that was shared
                                    by the LEAs representatives who came
                                    to NCSG meeting in Buenos Aires. it
                                    will be interesting to see what they
                                    are planning to do and push for.</div>
                                  <div><br>
                                  </div>
                                  <div>definitely, the idea of LEA
                                    transparency reports should be
                                    suggested .</div>
                                  <div><br>
                                  </div>
                                  <div>Best,</div>
                                  <div><br>
                                  </div>
                                  <div>Rafik</div>
                                  <blockquote class="gmail_quote"
                                    style="margin:0px 0px 0px
0.8ex;border-left-width:1px;border-left-color:rgb(204,204,204);border-left-style:solid;padding-left:1ex"><br>
                                    <div>
                                      <div><br>
                                        On 10/7/2015 8:46 AM, Michael
                                        Karanicolas wrote:<br>
                                        > That's a very interesting
                                        idea. I feel like the structure
                                        of appeals<br>
                                        > is probably the trickiest
                                        conceptual aspect of improving
                                        the DIDP, so<br>
                                        > good to consider
                                        alternatives. I think in part it
                                        would depend on the<br>
                                        > level of demand for
                                        information that ICANN gets, and
                                        how often appeals<br>
                                        > go forward. It's also
                                        important to bear in mind that,
                                        whoever is<br>
                                        > deciding these things, they
                                        need to have access to
                                        absolutely<br>
                                        > everything ICANN has, and a
                                        high level of familiarity with
                                        the inner<br>
                                        > workings of ICANN, so that
                                        they could determine, for
                                        example, whether<br>
                                        > particular information
                                        would compromise the integrity
                                        of ICANN's<br>
                                        > deliberative and
                                        decision-making process in line
                                        with the second<br>
                                        > defined condition for
                                        nondisclosure.<br>
                                        ><br>
                                        > This is in addition to the
                                        qualities Karel mentions
                                        (robust, cost<br>
                                        > effective, timely appeals)
                                        - which I also fully agree with.<br>
                                        ><br>
                                        > On Tue, Oct 6, 2015 at 2:12
                                        PM, Tamir Israel <<a
                                          moz-do-not-send="true"
                                          href="mailto:tisrael@cippic.ca"
                                          target="_blank"><a class="moz-txt-link-abbreviated" href="mailto:tisrael@cippic.ca">tisrael@cippic.ca</a></a>>
                                        wrote:<br>
                                        >> On 10/6/2015 1:02 PM,
                                        Michael Karanicolas wrote:<br>
                                        >>> This sort of brings
                                        us back to a fundamental
                                        challenge with reforming ICANN's<br>
                                        >>> access to
                                        information system, which is the
                                        need for some sort of analogous
                                        independent branch (I'm not
                                        completely certain the Ombudsman
                                        fits the bill).<br>
                                        >> On this point, I'm not
                                        sure how far we dare go here,
                                        but would it be<br>
                                        >> unreasonable to set up
                                        an arb panel comparable to the
                                        ones private ones<br>
                                        >> used for the UDRP
                                        (only, of course, appointed by a
                                        cross-stakeholder<br>
                                        >> nomination committee
                                        and with strict independence
                                        criteria) for<br>
                                        >> evaluating such things?<br>
                                        >><br>
                                        >> Best,<br>
                                        >> Tamir<br>
                                        >><br>
                                        <br>
                                        <br>
                                      </div>
                                    </div>
                                  </blockquote>
                                </div>
                                <br>
                              </div>
                            </div>
                          </blockquote>
                          <br>
                        </div>
                      </div>
                    </div>
                  </blockquote>
                </div>
                <br>
              </div>
            </div>
          </div>
        </div>
      </span>
    </blockquote>
    <br>
  </body>
</html>