<div dir="ltr"><div>Thanks Padmini</div><div><br></div><div>This is very interesting as 12% is a very low number and should be explained by ICANN. </div><div><br></div><div>Based on the low numbers this could be clear evidence of the deliberate misapplication and abuse of the DIDP rules by ICANN. Or, it could be all legitimate responses by ICANN to requests. ICANN may argue that denial ( partial or otherwise) of the 88% requests were because they genuinely were not within the ambit of the DIDP . </div><div><br></div><div>The numbers do raise serious questions , however I would not based my conclusion solely upon the numbers.  We need to delve further and pair your information with a few of the requests. That way we can assess for ourselves the reasonableness of the refusals</div><div><br></div><div>Where a legitimate request for information is refused (hearing the facts of the request) and denied by ICANN (hearing the reasons of the denial) provides a clear picture of what is happening at ICANN.</div><div><br></div><div>great work Padmini.</div><div><br></div><div>regards</div><div><br></div><div>Karel DOUGLAS</div><div><br></div><div><br></div></div><div class="gmail_extra"><br><div class="gmail_quote">On Wed, Oct 14, 2015 at 4:35 AM, Padmini <span dir="ltr"><<a href="mailto:pdmnbaruah@gmail.com" target="_blank">pdmnbaruah@gmail.com</a>></span> wrote:<br><blockquote class="gmail_quote" style="margin:0 0 0 .8ex;border-left:1px #ccc solid;padding-left:1ex"><div dir="ltr">Here's a summary of my findings.<br><br><br></div><div class="gmail_extra"><span><br clear="all"><div><div><div dir="ltr"><div><div dir="ltr">Padmini Baruah<div>V Year, B.A.LL.B. (Hons.)</div><div>NLSIU, Bangalore</div></div></div></div></div></div>
<br></span><div><div class="h5"><div class="gmail_quote">On Mon, Oct 12, 2015 at 9:56 PM, Tamir Israel <span dir="ltr"><<a href="mailto:tisrael@cippic.ca" target="_blank">tisrael@cippic.ca</a>></span> wrote:<br><blockquote class="gmail_quote" style="margin:0px 0px 0px 0.8ex;padding-left:1ex;border-left-color:rgb(204,204,204);border-left-width:1px;border-left-style:solid">
  
    
  
  <div text="#000000" bgcolor="#FFFFFF">
    Hi Padmini,<br>
    <br>
    In addition to the strong and independent adjudicator for
    information request appeals that we discussed below (which will
    require encoding appointment and independence criteria), the
    obligation to provide reasons for every refusal, as well as clear
    rules limiting the imposition of excessive fees on information
    requestors, I think it would be worthwhile including a proactive
    disclosure mechanism.<br>
    <br>
    In doing so, I would go one step further than most proactive
    disclosure mechanisms in FOI laws and add a mechanism by which
    individuals can request categories of information / activity to be
    added to a list of information that is periodically disclosed.
    Something similar to the Australian law: 8(2) <span lang="EN-AU">The
      agency must publish
      the following information: </span>(g) <span lang="EN-AU">information
      in
      documents to which the agency routinely gives access in response
      to requests
      under Part III (access to documents)</span><br>
    <br>
    Best,<br>
    Tamir<div><div><br>
    <br>
    <br>
    <div>On 10/12/2015 8:35 AM, Padmini wrote:<br>
    </div>
    <blockquote type="cite">
      <div dir="ltr">
        <div>
          <div>
            <div>Dear all, <br>
              <br>
            </div>
            This thread has been extremely insightful as far as the LEA
            process is concerned. Nonetheless, I would like to draw the
            conversation back to the original point of concern that I
            had raised, name with respect to the <b>public
              transparency  </b>that the DIDP process is meant to
            enhance. It would be great if we had some suggestions on how
            this could be enhanced.<br>
            <br>
          </div>
          My analysis shows that there is a severe lack of responses
          from ICANN, and there are overbroad exclusions. What are some
          best practices that you all think should be adopted in this
          regard? It is crucial that there be <b>meaningful</b>
          transparency and not mere lip service.<br>
          <br>
        </div>
        Regards<br>
      </div>
      <div class="gmail_extra"><br clear="all">
        <div>
          <div>
            <div dir="ltr">
              <div>
                <div dir="ltr">Padmini Baruah
                  <div>V Year, B.A.LL.B. (Hons.)</div>
                  <div>NLSIU, Bangalore</div>
                </div>
              </div>
            </div>
          </div>
        </div>
        <br>
        <div class="gmail_quote">On Mon, Oct 12, 2015 at 2:47 AM, Tamir
          Israel <span dir="ltr"><<a href="mailto:tisrael@cippic.ca" target="_blank">tisrael@cippic.ca</a>></span>
          wrote:<br>
          <blockquote class="gmail_quote" style="margin:0px 0px 0px 0.8ex;padding-left:1ex;border-left-color:rgb(204,204,204);border-left-width:1px;border-left-style:solid">
            <div text="#000000" bgcolor="#FFFFFF"> Thanks James and
              Rafik,<br>
              <br>
              This sounds good. I think I agree caution is advisable
              with respect to getting ICANN to impose a rigid framework
              (or oversee that framework), but it may be a useful way to
              impose a general transparency requirement?<br>
              <br>
              Best,<br>
              Tamir
              <div>
                <div><br>
                  <br>
                  <div>On 10/11/2015 10:54 AM, James Gannon wrote:<br>
                  </div>
                  <blockquote type="cite">
                    <div>
                      <div><font face="Calibri,sans-serif">I reached out
                          to some of the registrars and they are not
                          aware of any formal process that LEAs would go
                          through on the ICANN side, the process appears
                          to be to merely forward straight to the </font><font face="Calibri,sans-serif">registrar with no
                          direct engagement with the LEA in question. We
                          can/should put this question to Allan Grogan
                          when he visits us as I think its an
                          interesting one.</font></div>
                      <div><font face="Calibri,sans-serif"><br>
                        </font></div>
                      <div><font face="Calibri,sans-serif">-Jaes</font></div>
                      <div style="color:rgb(0,0,0);font-family:Calibri,sans-serif;font-size:14px">
                      </div>
                    </div>
                    <div style="color:rgb(0,0,0);font-family:Calibri,sans-serif;font-size:14px">
                      <br>
                    </div>
                    <span style="color:rgb(0,0,0);font-family:Calibri,sans-serif;font-size:14px">
                      <div style="border-width:1pt medium medium;border-style:solid none none;border-color:rgb(181,196,223) currentColor currentColor;padding:3pt 0in 0in;text-align:left;color:black;font-family:Calibri;font-size:12pt"> <span style="font-weight:bold">From: </span>NCSG-Discuss
                        on behalf of Rafik Dammak<br>
                        <span style="font-weight:bold">Reply-To: </span>Rafik
                        Dammak<br>
                        <span style="font-weight:bold">Date: </span>Sunday
                        11 October 2015 at 2:49 p.m.<br>
                        <span style="font-weight:bold">To: </span>"<a href="mailto:NCSG-DISCUSS@LISTSERV.SYR.EDU" target="_blank">NCSG-DISCUSS@LISTSERV.SYR.EDU</a>"<br>
                        <span style="font-weight:bold">Subject: </span>Re:
                        DIDP Analysis<br>
                      </div>
                      <div><br>
                      </div>
                      <div>
                        <div>
                          <div dir="ltr">
                            <div class="gmail_extra">Hi Tamir,<br>
                              <br>
                              <div class="gmail_quote">2015-10-11 4:10
                                GMT+09:00 Tamir Israel <span dir="ltr"><<a href="mailto:tisrael@cippic.ca" target="_blank">tisrael@cippic.ca</a>></span>:<br>
                                <blockquote class="gmail_quote" style="margin:0px 0px 0px 0.8ex;padding-left:1ex;border-left-color:rgb(204,204,204);border-left-width:1px;border-left-style:solid">
                                  <div text="#000000" bgcolor="#FFFFFF">Thanks
                                    Rafik,<br>
                                    <br>
                                    On second though, I think you are
                                    probably right. I know for .CA, LEA
                                    requests go directly to CIRA but now
                                    that I think about it, it must be
                                    because of the way our WHOIS is
                                    setup. It would make sense for LEA
                                    requests to go to registrars rather
                                    than ICANN.<br>
                                    <br>
                                  </div>
                                </blockquote>
                                <div><br>
                                </div>
                                <div>ccTLD space is another world, even
                                  more diverse and unknwon :)</div>
                                <div> </div>
                                <blockquote class="gmail_quote" style="margin:0px 0px 0px 0.8ex;padding-left:1ex;border-left-color:rgb(204,204,204);border-left-width:1px;border-left-style:solid">
                                  <div text="#000000" bgcolor="#FFFFFF">If
                                    that's the case though then, as you
                                    say, it might still be worth
                                    exploring transparency reports, even
                                    if these end up coming from the GAC
                                    or are imposed onto registrars via
                                    ICANN policy. As an accountability
                                    mechanism, these reports are
                                    becoming fairly standard to have in
                                    the telecommunications context..<br>
                                  </div>
                                </blockquote>
                                <div><br>
                                </div>
                                <div>ICANN sounds receiving requests and
                                  it happened that its teams get
                                  involved in some operations which
                                  raised the issue about the expansion
                                  of ICANN remit .</div>
                                <div> </div>
                                <blockquote class="gmail_quote" style="margin:0px 0px 0px 0.8ex;padding-left:1ex;border-left-color:rgb(204,204,204);border-left-width:1px;border-left-style:solid">
                                  <div text="#000000" bgcolor="#FFFFFF"><br>
                                    Not sure if the DIDP process is the
                                    most appropriate mechanism for it
                                    though. Any thoughts on how
                                    something like that could be moved
                                    forward (or reasons why it should
                                    not be moved forward) would be
                                    appreciated.. There might be a
                                    clearer picture of how to design
                                    such a thing after the dublin
                                    meeting (which, regrettably, I
                                    cannot attend).<br>
                                    <br>
                                  </div>
                                </blockquote>
                                <div><br>
                                </div>
                                <div>maybe not but the transparency
                                  report seems a good framework to start
                                  with if we talk about compliance and
                                  abuse reports.  I won't think that
                                  ICANN should push the registrars and
                                  registries for a specific way to do it
                                  , but if we can work the contracted
                                  parties on that matter it will be
                                  worthy to explore. there are already
                                  some guidelines/principles/ framework
                                  that we can suggest here to registries
                                  and registrars. such transparency
                                  would protect more users interests.</div>
                                <div><br>
                                </div>
                                <div>Best,</div>
                                <div><br>
                                </div>
                                <div>Rafik </div>
                                <blockquote class="gmail_quote" style="margin:0px 0px 0px 0.8ex;padding-left:1ex;border-left-color:rgb(204,204,204);border-left-width:1px;border-left-style:solid">
                                  <div text="#000000" bgcolor="#FFFFFF">
                                    <div>
                                      <div><br>
                                        <div>On 10/10/2015 9:28 AM,
                                          Rafik Dammak wrote:<br>
                                        </div>
                                        <blockquote type="cite">
                                          <div dir="ltr">
                                            <div class="gmail_extra">Hi
                                              Tamir,<br>
                                              <div class="gmail_quote">2015-10-10
                                                2:11 GMT+09:00 Tamir
                                                Israel <span dir="ltr"><<a href="mailto:tisrael@cippic.ca" target="_blank">tisrael@cippic.ca</a>></span>:<br>
                                                <blockquote class="gmail_quote" style="margin:0px 0px 0px 0.8ex;padding-left:1ex;border-left-color:rgb(204,204,204);border-left-width:1px;border-left-style:solid">Perhaps

                                                  a single independent
                                                  commissioner-type may
                                                  make the most sense.<br>
                                                  The trick I think
                                                  would be to ensure
                                                  independence. That
                                                  tends to be<br>
                                                  easier to do if there
                                                  are more than one,
                                                  because you can
                                                  allocate one<br>
                                                  per stakeholder group.
                                                  Still, I think by
                                                  encoding some criteria
                                                  (no<br>
                                                  strong industry or
                                                  ICANN affil for 2
                                                  years back or
                                                  something; nomination<br>
                                                  committee w/CS
                                                  representation;
                                                  dedicated funding for
                                                  independence) it<br>
                                                  can be done.<br>
                                                  <br>
                                                  Another quick thought
                                                  here: I did not see a
                                                  proactive disclosure
                                                  section<br>
                                                  in the document. Would
                                                  it be worth adding?<br>
                                                  <br>
                                                  Related, does anyone
                                                  know if ICANN handles
                                                  law enforcement
                                                  requests or<br>
                                                  whether these are
                                                  handled by the
                                                  registrars? If so, it
                                                  would seem that<br>
                                                  including the
                                                  obligation to issue
                                                  annual LEA
                                                  transparency reports
                                                  would<br>
                                                  not be out of line.<br>
                                                  <br>
                                                </blockquote>
                                                <div><br>
                                                </div>
                                                <div><br>
                                                </div>
                                                <div>to be honest, it is
                                                  unclear how ICANN
                                                  handle direct requests
                                                  from LEA, while we may
                                                  get more information
                                                  from registrars on the
                                                  type of requests they
                                                  get.</div>
                                                <div> there is some work
                                                  going with the new
                                                  Compliance Chief
                                                  Officer regarding how
                                                  to handle requests or
                                                  abuse reports (but not
                                                  necessarily LEA) .
                                                  here a blog post with
                                                  some updates <a href="https://www.icann.org/news/blog/update-on-steps-to-combat-abuse-and-illegal-activity" target="_blank">https://www.icann.org/news/blog/update-on-steps-to-combat-abuse-and-illegal-activity</a>
                                                  (there are 2 sessions
                                                  at ICANN meeting in
                                                  wednesday 21st Oct <a href="https://dublin54.icann.org/en/dublin54/schedule/wed-practices-combating-abuse" target="_blank">https://dublin54.icann.org/en/dublin54/schedule/wed-practices-combating-abuse</a>
                                                  & <a href="https://dublin54.icann.org/en/dublin54/schedule/wed-compliance" target="_blank">https://dublin54.icann.org/en/dublin54/schedule/wed-compliance</a>
                                                  . I invited weeks ago
                                                  The Compliance Chief
                                                  Officer to come to
                                                  NCSG meeting in
                                                  Tuesday 20th Oct so we
                                                  can discuss with him.</div>
                                                <div><br>
                                                </div>
                                                <div>I would highlight
                                                  that LEAs have their
                                                  GAC Public Safety
                                                  working group and it
                                                  has several sessions
                                                  in Dublin meeting too.
                                                  that was shared by the
                                                  LEAs representatives
                                                  who came to NCSG
                                                  meeting in Buenos
                                                  Aires. it will be
                                                  interesting to see
                                                  what they are planning
                                                  to do and push for.</div>
                                                <div><br>
                                                </div>
                                                <div>definitely, the
                                                  idea of LEA
                                                  transparency reports
                                                  should be suggested .</div>
                                                <div><br>
                                                </div>
                                                <div>Best,</div>
                                                <div><br>
                                                </div>
                                                <div>Rafik</div>
                                                <blockquote class="gmail_quote" style="margin:0px 0px 0px 0.8ex;padding-left:1ex;border-left-color:rgb(204,204,204);border-left-width:1px;border-left-style:solid"><br>
                                                  <div>
                                                    <div><br>
                                                      On 10/7/2015 8:46
                                                      AM, Michael
                                                      Karanicolas wrote:<br>
                                                      > That's a very
                                                      interesting idea.
                                                      I feel like the
                                                      structure of
                                                      appeals<br>
                                                      > is probably
                                                      the trickiest
                                                      conceptual aspect
                                                      of improving the
                                                      DIDP, so<br>
                                                      > good to
                                                      consider
                                                      alternatives. I
                                                      think in part it
                                                      would depend on
                                                      the<br>
                                                      > level of
                                                      demand for
                                                      information that
                                                      ICANN gets, and
                                                      how often appeals<br>
                                                      > go forward.
                                                      It's also
                                                      important to bear
                                                      in mind that,
                                                      whoever is<br>
                                                      > deciding
                                                      these things, they
                                                      need to have
                                                      access to
                                                      absolutely<br>
                                                      > everything
                                                      ICANN has, and a
                                                      high level of
                                                      familiarity with
                                                      the inner<br>
                                                      > workings of
                                                      ICANN, so that
                                                      they could
                                                      determine, for
                                                      example, whether<br>
                                                      > particular
                                                      information would
                                                      compromise the
                                                      integrity of
                                                      ICANN's<br>
                                                      > deliberative
                                                      and
                                                      decision-making
                                                      process in line
                                                      with the second<br>
                                                      > defined
                                                      condition for
                                                      nondisclosure.<br>
                                                      ><br>
                                                      > This is in
                                                      addition to the
                                                      qualities Karel
                                                      mentions (robust,
                                                      cost<br>
                                                      > effective,
                                                      timely appeals) -
                                                      which I also fully
                                                      agree with.<br>
                                                      ><br>
                                                      > On Tue, Oct
                                                      6, 2015 at 2:12
                                                      PM, Tamir Israel
                                                      <<a href="mailto:tisrael@cippic.ca" target="_blank">tisrael@cippic.ca</a>>

                                                      wrote:<br>
                                                      >> On
                                                      10/6/2015 1:02 PM,
                                                      Michael
                                                      Karanicolas wrote:<br>
                                                      >>> This
                                                      sort of brings us
                                                      back to a
                                                      fundamental
                                                      challenge with
                                                      reforming ICANN's<br>
                                                      >>>
                                                      access to
                                                      information
                                                      system, which is
                                                      the need for some
                                                      sort of analogous
                                                      independent branch
                                                      (I'm not
                                                      completely certain
                                                      the Ombudsman fits
                                                      the bill).<br>
                                                      >> On this
                                                      point, I'm not
                                                      sure how far we
                                                      dare go here, but
                                                      would it be<br>
                                                      >>
                                                      unreasonable to
                                                      set up an arb
                                                      panel comparable
                                                      to the ones
                                                      private ones<br>
                                                      >> used for
                                                      the UDRP (only, of
                                                      course, appointed
                                                      by a
                                                      cross-stakeholder<br>
                                                      >>
                                                      nomination
                                                      committee and with
                                                      strict
                                                      independence
                                                      criteria) for<br>
                                                      >>
                                                      evaluating such
                                                      things?<br>
                                                      >><br>
                                                      >> Best,<br>
                                                      >> Tamir<br>
                                                      >><br>
                                                      <br>
                                                      <br>
                                                    </div>
                                                  </div>
                                                </blockquote>
                                              </div>
                                              <br>
                                            </div>
                                          </div>
                                        </blockquote>
                                        <br>
                                      </div>
                                    </div>
                                  </div>
                                </blockquote>
                              </div>
                              <br>
                            </div>
                          </div>
                        </div>
                      </div>
                    </span> </blockquote>
                  <br>
                </div>
              </div>
            </div>
          </blockquote>
        </div>
        <br>
      </div>
    </blockquote>
    <br>
  </div></div></div>

</blockquote></div><br></div></div></div>
</blockquote></div><br></div>