<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">
<html xmlns="http://www.w3.org/1999/xhtml" xmlns:v="urn:schemas-microsoft-com:vml" xmlns:o="urn:schemas-microsoft-com:office:office">
<head>
<meta name="viewport" content="width=device-width, initial-scale=1.0">
<!--[if gte mso 9]>
<xml>
<o:OfficeDocumentSettings>
<o:AllowPNG/>
<o:PixelsPerInch>96</o:PixelsPerInch>
</o:OfficeDocumentSettings>
</xml>
<![endif]-->
<style type="text/css">* a:hover{cursor:pointer;}</style>
<style>body {-webkit-animation:bugfix infinite 1s;}@-webkit-keyframes bugfix {from {position:relative;}to {position:relative;}}</style>
</head>
<body style="word-wrap:normal; word-break:break-word;">
<style>a {word-wrap:normal;word-break:break-word;}.background-contain {background-size:contain;}@media only screen and (max-width:600px) {.container {-webkit-text-size-adjust:none !important;}.container,.palm-one-whole {width:100% !important;min-width:100% !important;}.palm-one-half {width:50% !important;min-width:50% !important;box-sizing:border-box;}blockquote .container,blockquote .container div,blockquote .container table {width:auto !important;min-width:0 !important;position:relative !important;}img {max-width:100%;}.border-outer,.border-middle,.border-inner,.inner,[title="separator"] {width:100% !important;}.innercell {padding:8px !important;}.palm-block {display:block !important;}td.palm-one-whole {display:inline-block !important;padding:0;}td.palm-one-whole:first-child:not(:only-child) {margin-bottom:16px;}td.hostname {padding-top:3px !important;}}@media only screen and (min-width:601px) {.preview-card {max-width:600px !important;}}@media only screen and (min-device-width :320px) and (max-device-width :568px),only screen and (min-device-width :768px) and (max-device-width :1024px),only screen and (max-device-width:640px),only screen and (max-device-width:667px),only screen and (max-width:480px){.container {width:100% !important;min-width:100% !important;}.p,.small,li,font[size="2"],font[size="3"] {font-size:1em !important;}}@media only screen and (min-device-width :320px) and (max-device-width :568px),only screen and (min-device-width :768px) and (max-device-width :1024px),only screen and (min-device-width :1224px) {.message-wrapper {padding-top:6px;}.apple-only[style] {display:block !important;max-height:none !important;line-height:normal !important;overflow:visible !important;height:auto !important;width:100% !important;position:relative !important;}.no-apple {display:none !important;}form {font-size:inherit;}input[type="text"] {height:43px;padding-left:4px !important;}button:hover {cursor:pointer;}}@media only screen and (min-device-width :1224px) {.apple-mail-form {display:block !important;background-color:white !important;}}* [office365] .outlook-com-hidden {display:none !important;}* [office365] .outlook-com-button {display:block;}* [office365] .outlook-com-only {display:block !important;max-height:none !important;line-height:normal !important;overflow:visible !important;height:auto !important;width:100% !important;position:relative !important;}</style>
<!--[if (gte mso 9)|(IE)]>
<style>a,body {font-family:'Calibri',Arial,sans-serif;}img {border:none !important;-ms-interpolation-mode:bicubic;}td {mso-line-height-rule:exactly !important;}.mso-card-inner table {border-collapse:collapse !important;mso-table-lspace:0pt;mso-table-rspace:0pt;vertical-align:top;}.outlook-com-only {display:none !important;font-size:0 !important;}#mso-one-whole {width:100% !important;}.border-outer,.border-middle,.border-inner {border:none !important;}.border-middle,.border-inner {width:100% !important;}.mso-border-outer,.mso-border-middle,.mso-border-inner {padding:1px;}.mso-border-outer {background-color:rgb(245,255,255);}.mso-border-middle {background-color:rgb(223,246,255);}.mso-border-inner {background-color:rgb(153,176,225);}</style>
<![endif]-->
<table class="container" lang="container" border="0" cellpadding="0" cellspacing="0" valign="top" style="width:100%; margin-top:6px;">
<tr>
<td valign="top" class="message-wrapper" style="line-height: 1.31; color: #222; font-family: arial, sans-serif;">
<!--[if mso]><table border="0" cellpadding="0" cellspacing="0" valign="top" style="border-collapse:separate;"><tr><td valign="top"><![endif]-->
<div>Hi Shane,</div><div><br>These are very good points. Within the working group, we're still deciding on the best path forward, and what I (and others in the NCSG) are advocating for is to first decide if there is even a basis for collecting registration data. I tend to think there is not, and the only reason WHOIS exists at the moment is because of historical accidents left uncorrected because of endless contention. </div><div><font><br></font></div><div>At the moment WHOIS records are publicly accessible — there's no gated access, let alone records kept on how frequently a particular record is viewed (though I understand some registrars do voluntarily collect this information). If we do decide that personally identifiable data must be collected, even if access is restricted to law enforcement or similar parties, I would hope we could have some transparency around who is accessing data, for what purposes, and which records. </div><div><font><br></font></div><div>There are a few requirements flagged at the moment in the list to do with knowing the purpose of why a record is queried, but I agree with you that we should be asking for stronger audits and the timely publication of transparency reports. I write this, of course, on the proviso that there even is a need to collect personally identifiable information in the first place — which I do not think is a given, and do not think should be happening. </div><div><br></div><div>So yes. I think this is something that Farell should be taking back to the working group as of concern to one of our members :-)</div><div><font><br></font></div><div>Best wishes,</div><div><font><br></font></div><div>Ayden</div><div class="mixmax_signature"></div><div>
</div><div>
<p><br></p>
<div class="gmail_extra">
<p><br></p>
<div class="gmail_quote">
On Wed, Jun 15, 2016 12:56 PM, Shane Kerr <span dir="ltr"> <a href="mailto:shane@time-travellers.org" target="_blank">shane@time-travellers.org</a></span>
wrote:<br>
<blockquote class="gmail_quote" style="margin:0 0 0 .8ex;border-left:1px #ccc solid;padding-left:1ex">
<u></u>
<p>Ayden,</p><p><br></p><p>I haven't gone through the (780) possible requirements - apologies.</p><p>Your mail sparked some thoughts that I mentioned earlier on-list, but</p><p>I'll bring up again.</p><p><br></p><p>----</p><p><br></p><p>One thing that I am curious about is whether there are requirements for</p><p>how access is delivered, as well as transparency and auditing of access</p><p>to data.</p><p><br></p><p>I am thinking of the case where a law-enforcement agency (LEA) gains</p><p>access to private data (like phone numbers). Ideally the LEA would have</p><p>to impose controls over who within the LEA has access to the data. For</p><p>example, it would be nice to know if a police officer was using RDS</p><p>data for extortion of stalking or the like - which can only be done if</p><p>the LEA has unique access credentials with strong authentication. I'm</p><p>not sure how this could be best made into a policy, but I think that it</p><p>is important (surely ICANN has experience with related</p><p>cross-organizational privacy restrictions from the registry/registrar</p><p>model).</p><p><br></p><p>Likewise, it would be good to know if an LEA (or anyone else) was</p><p>mining the data for mass-surveillance purposes or the like. While</p><p>registries may not be legally permitted to report such information,</p><p>there are good models that can be encouraged, such as:</p><p><br></p><p>https://en.wikipedia.org/wiki/Transparency_report</p><p><br></p><p>----</p><p><br></p><p>In a related topic, both registrars and registrants may want to know</p><p>when information about the registrant is accessed. (This is certainly</p><p>technologically possible. LinkedIn tells me how many people have looked</p><p>at my page when I log in.) As a registrant, I probably also want</p><p>context... if my basic data was shown 10 times in a month and my full</p><p>data was shown 2 times, is that less or more than average?</p><p><br></p><p>On the other hand, registrants may NOT want information stored about</p><p>access to their data, as any information that is stored can presumably</p><p>be accessed by LEA. That implies some sort of way for registrants and/or</p><p>registrars to specify preferences for the handling of meta-information</p><p>about who has accessed what records.</p><p><br></p><p>----</p><p><br></p><p>Again, sorry for not going through the possible requirements to see if</p><p>they are listed. I am being lazy and hoping that since you have put in</p><p>so much work on this that you will know roughly what is contained. ;)</p><p><br></p><p>Cheers,</p><p><br></p><p>--</p><p>Shane</p><p><br></p><p>At 2016-06-15 11:27:55 +0000</p><p>Ayden Férdeline <icann@FERDELINE.COM> wrote:</p><p><br></p><p>> One gap that I see among the (780) possible requirements is to do with under</p><p>> what conditions transfers of data to foreign jurisdictions is permitted.</p><p>> [CM-D30-R10] does talk about Privacy Shield and the transfer of data between the</p><p>> US and EU, but it doesn't seem sufficient to me. Does anyone know of any</p><p>> resources we can turn to re: restrictions on the overseas transfer of personally</p><p>> identifiable information? Would also be great if we had some case studies or</p><p>> costly judgements to include which make it clear that the data controller has</p><p>> legal liability for any breaches of privacy… I think we need to turn this debate</p><p>> into one about $$$ and less about privacy rights, because to come up with a</p><p>> wishlist of so many pieces of data to collect (and we are not yet even looking</p><p>> to consolidate this - just to expand it even further) seems not only unwise, but</p><p>> scandalously expensive. Particularly so if we go down the path of gated access</p><p>> and there are breaches - which there inevitably will be.</p><p>> - Ayden</p><p>> </p><p>> </p><p>> On Wed, Jun 15, 2016 10:06 AM, Farell FOLLY farell@BENIN2POINT0.ORG wrote:</p><p>> Dear all,</p><p>> </p><p>> </p><p>> </p><p>> In addition to my previous e-mail, I think it would be nice to recall a brief</p><p>> history about the next-gen RDS. You can either read this e-mail for brevity or</p><p>> download the attached presentation (from which I withdrew the information).</p><p>> </p><p>> </p><p>> </p><p>> 1. Why this PDP Working ?</p><p>> </p><p>> </p><p>> </p><p>> WHOIS was created in the 80s to identify & contact those responsible for</p><p>> operation of Internet network resources. After nearly 15 years of GNSO task</p><p>> forces, working groups, workshops, surveys & studies, the ICANN community has</p><p>> been unable to reach consensus on comprehensive WHOIS policy reforms. In</p><p>> response to the 2012 WHOIS Policy Review Team’s Final Report, the ICANN Board</p><p>> launched the RDS PDP & the Expert Working Group (EWG) to inform it The EWG was</p><p>> tasked with taking a fresh approach by redefining the purpose of gTLD</p><p>> registration data & then proposing a new model for gTLD Registration Directory</p><p>> Services to address accuracy, privacy & access issues.</p><p>> </p><p>> </p><p>> </p><p>> 2. What is WHOIS</p><p>> </p><p>> </p><p>> </p><p>> <<WHOIS is an overloaded term, it could mean:</p><p>> </p><p>> ü Registration data</p><p>> </p><p>> ü Access protocol (WHOIS protocol)</p><p>> </p><p>> ü Directory Service</p><p>> </p><p>> ü It is best to use individual terms</p><p>> </p><p>> </p><p>> </p><p>> It was created in 1982, but as the Internet grew, WHOIS began to serve the needs</p><p>> of different stakeholders such as registrants, law enforcement, intellectual</p><p>> property & trademark owners, businesses & individual users - but the protocol</p><p>> remained largely unchanged. Through the Affirmation of Commitments (AOC), ICANN</p><p>> is committed to “enforcing its existing policy relating to WHOIS, subject to</p><p>> applicable laws. Such existing policy requires that ICANN implement measures to</p><p>> maintain timely, unrestricted & public access to accurate & complete WHOIS</p><p>> information, including registrant, technical, billing, & administrative contact</p><p>> information.”>> </p><p>> </p><p>> </p><p>> </p><p>> 3. What is Next-Gen RDS</p><p>> </p><p>> </p><p>> </p><p>> << In 2012, the ICANN Board resolved to</p><p>> </p><p>> ü launch a new effort to redefine the purpose of collecting, maintaining, &</p><p>> providing access to gTLD registration data, & consider safeguards for protecting</p><p>> data, as a foundation for a new gTLD policy & contractual negotiations, as</p><p>> appropriate</p><p>> </p><p>> ü Prepare an Issue Report on the purpose of collecting & maintaining gTLD</p><p>> registration data & on solutions to improve accuracy & access to gTLD</p><p>> registration data, as part of a Board-initiated GNSO PDP</p><p>> </p><p>> ü These efforts are collectively known as the: Next-Generation gTLD Registration Directory Services to Replace WHOIS (Next-Gen</p><p>> RDS)>> </p><p>> </p><p>> </p><p>> </p><p>> This RDS is described by 180 principles and should address the following</p><p>> questions :</p><p>> </p><p>> i. Users & Purposes</p><p>> </p><p>> ii. Gated Access</p><p>> </p><p>> iii. Privacy & Data Protection</p><p>> </p><p>> iv. Data Quality</p><p>> </p><p>> v. Data Elements</p><p>> </p><p>> vi. Compliance & Accountability</p><p>> </p><p>> vii. Implementation Model</p><p>> </p><p>> viii. Cost</p><p>> </p><p>> ix. Risks & Benefits</p><p>> </p><p>> </p><p>> </p><p>> </p><p>> </p><p>> </p><p>> </p><p>> I hope this will help you understand more and stimulate your contribution.</p><p>> </p><p>> </p><p>> </p><p>> </p><p>> </p><p>> --ff--</p><p>> </p><p>> Best regards</p><p>> </p><p>> ------------------------------------------------------------------------------</p><p>> </p><p>> Farell FOLLY</p><p>> </p><p>> Africa 2.0 Foundation</p><p>> </p><p>> Chapter Head - Technology Champion</p><p>> </p><p>> </p><p>> </p><p>> t: +22997 248100</p><p>> </p><p>> s : Skype: farellf</p><p>> </p><p>> m: farell@benin2point0.org</p><p>> </p><p>> w :www.africa2point0.org</p><p>> </p><p>> l : www.linkedin.com/in/farellf</p><p>> </p><p>> tt : www.twitter.com/__f_f__</p><p>> </p><p>> </p><p>> </p><p>> </p><p>> </p><p>> </p><p>> </p><p>> -----Message d'origine-----</p><p>> De : NCSG-Discuss [mailto:NCSG-DISCUSS@LISTSERV.SYR.EDU] De la part de Farell</p><p>> FOLLY</p><p>> Envoyé : lundi 13 juin 2016 17:13</p><p>> À : NCSG-DISCUSS@LISTSERV.SYR.EDU</p><p>> Objet : Re: Request for additional “possible” requirements for Next Generation</p><p>> RDS</p><p>> </p><p>> </p><p>> </p><p>> (Sorry to have forwarded an unfinished e-mail, This is the final response)</p><p>> </p><p>> </p><p>> </p><p>> @Shane, and all</p><p>> </p><p>> </p><p>> </p><p>> The RDS PDP WG has the job to gather all “possible” requirements for the</p><p>> next-gen RDS to replace the WHOIS protocol. So many documents has been found</p><p>> useful / relevant to provide insightful issues to serve as inputs for the</p><p>> characteristics of the next-Gen RDS. However, WG found it impossible to read all</p><p>> documents together as a team and agree on what can be a “possible” requirement</p><p>> and what can/should not be a requirement (one by one, document per document).</p><p>> Then it was proposed and adopted that group members volunteer to read the docs</p><p>> and extract as many as inputs as possible. Then the ICANN staff worked hard and</p><p>> concatenated all these requirements by naming them appropriately without no</p><p>> change to the requirements themselves</p><p>> </p><p>> </p><p>> </p><p>> Therefore the word “possible” means that the stated requirement may be removed</p><p>> at the end of the current phase if it is judged so. However, it is not yet time</p><p>> to make this decision.</p><p>> </p><p>> </p><p>> </p><p>> Consequently, if you find any bogus or meaningless information (according to</p><p>> you), please just make a comment to me offline and I will forward to the staff</p><p>> as necessary. At this stage, we just need to propose new “possible”</p><p>> requirements, so if you think you have a new requirement for the next-gen RDS</p><p>> that is not already in the RDS PDP list I previously sent (or by discarding all</p><p>> inputs you classify as bogus or legalese), please send it/them through.</p><p>> </p><p>> </p><p>> </p><p>> Finally for other members I would to clarify that each requirement has been</p><p>> given a specific annotation in the form of [QQ-R#-D#], for instance in</p><p>> [UP-D26-R06] : the first two letters identify the associated charter question</p><p>> (Users Purposes, in this case), the D26 identifies the input document (Annex A)</p><p>> from which the requirement has been extracted, and R06 means is the 6th</p><p>> “possible” requirement).</p><p>> </p><p>> </p><p>> </p><p>> I suggest to anyone in this group to read (in priority, iteratively) a sub-list</p><p>> of all these “possible” requirements depending or based on his/her expertise or</p><p>> background. For instance, If you have experience in data privacy, you can</p><p>> quickly check all “possible” requirements starting by [PR-Dxx-Ryy] and a new one</p><p>> if any. For any new “possible” requirement, don’t forget to add the source</p><p>> document.</p><p>> </p><p>> </p><p>> </p><p>> --ff--</p><p>> </p><p>> Best regards</p><p>> </p><p>> ------------------------------------------------------------------------------</p><p>> </p><p>> Farell FOLLY</p><p>> </p><p>> Africa 2.0 Foundation</p><p>> </p><p>> Chapter Head - Technology Champion</p><p>> </p><p>> </p><p>> </p><p>> t: +22997 248100</p><p>> </p><p>> s : Skype: farellf</p><p>> </p><p>> m: farell@benin2point0.org</p><p>> </p><p>> w :www.africa2point0.org</p><p>> </p><p>> l : www.linkedin.com/in/farellf</p><p>> </p><p>> tt : www.twitter.com/__f_f__</p><p>> </p><p>> </p><p>> </p><p>> </p><p>> </p><p>> </p><p>> </p><p>> -----Message d'origine-----</p><p>> </p><p>> De : Shane Kerr [ mailto:shane@time-travellers.org ]</p><p>> </p><p>> Envoyé : lundi 13 juin 2016 15:37</p><p>> </p><p>> À : Farell FOLLY</p><p>> </p><p>> Cc : NCSG-DISCUSS@LISTSERV.SYR.EDU</p><p>> </p><p>> Objet : Re: Request for additional “possible” requirements for Next Generation</p><p>> RDS</p><p>> </p><p>> </p><p>> </p><p>> Farell,</p><p>> </p><p>> </p><p>> </p><p>> At 2016-06-13 11:30:10 +0100</p><p>> </p><p>> Farell FOLLY < farell@BENIN2POINT0.ORG > wrote:</p><p>> </p><p>> </p><p>> </p><p>> > Few months ago I decided to join the NCSG in order to serve and defend </p><p>> </p><p>> > the interest of the community regarding Internet resources use. Before </p><p>> </p><p>> > that, I started working with the GNSO Policy Development Process </p><p>> </p><p>> > Working Group (PDP </p><p>> </p><p>> > WG) to contribute in the development process of the Next Generation </p><p>> </p><p>> > Registration Directory Services (Next-Gen RDS). Time comes now that I </p><p>> </p><p>> > engage more and participate within this stakeholder Group. Therefore, </p><p>> </p><p>> > I volunteer to serve as a liaison/point of contact between NCSG and </p><p>> </p><p>> > GNSO PDP WG as far as the attached documents are concerned. </p><p>> </p><p>> </p><p>> </p><p>> Cool, thanks for this!</p><p>> </p><p>> </p><p>> </p><p>> > 1. Read the outreach message 2 in attach </p><p>> </p><p>> > </p><p>> </p><p>> > 2. Read and check the RDS PDP list of possible requirements, also in </p><p>> </p><p>> > attach </p><p>> </p><p>> > </p><p>> </p><p>> > 3. Reply to this mail by asking any questions to me or adding </p><p>> </p><p>> > additional requirement </p><p>> </p><p>> > </p><p>> </p><p>> > Please before replying to this e-mail to add a “new” requirement, make </p><p>> </p><p>> > sure you read the entire document and check whether this requirement </p><p>> </p><p>> > was not duplicated already. Also, ensure that you send your contact </p><p>> </p><p>> > details (name, first name, e-mail) if not explicitly included in your mail </p><p>> signature.</p><p>> </p><p>> </p><p>> </p><p>> [ Apologies if the following reads as a rant. It kind of is. Probably</p><p>> </p><p>> my own fault for looking at policy stuff. ]</p><p>> </p><p>> </p><p>> </p><p>> Is there a summary of the PDF, or any kind of specific issues that seem</p><p>> contentious that one would look at?</p><p>> </p><p>> </p><p>> </p><p>> I ask because the PDF alone is over 100 pages. Is this a typical ICANN document?</p><p>> I was going to have a look since I'm somewhat technical and was involved with</p><p>> WHOIS in the distant past, but honestly I don't really have the many days time</p><p>> that would be necessary to make any sense out of this. :(</p><p>> </p><p>> </p><p>> </p><p>> ------</p><p>> </p><p>> </p><p>> </p><p>> I did skim a bit, and while parts of it are pretty clear:</p><p>> </p><p>> </p><p>> </p><p>> [UP-D01-R17] – Since it is likely that further [permissible</p><p>> </p><p>> purposes] will be identified over time, any [gTLD registration</p><p>> </p><p>> directory service] must be designed with extensibility in mind.</p><p>> </p><p>> </p><p>> </p><p>> (This is a bogus requirement, BTW. Without specific descriptions of the expected</p><p>> changes then it is impossible to implement. It's like someone saying “prepare</p><p>> for the weather tomorrow” without telling you what the weather will be. Better</p><p>> to leave this out and let people make their own design decisions.)</p><p>> </p><p>> </p><p>> </p><p>> Other parts are complete legalese:</p><p>> </p><p>> </p><p>> </p><p>> [UP-D26-R06] – According to the Directive (30), whereas, in order</p><p>> </p><p>> to be lawful, the processing of personal data must in addition be</p><p>> </p><p>> carried out with the consent of the data subject or be necessary</p><p>> </p><p>> for the conclusion or performance of a contract binding on the data</p><p>> </p><p>> subject, or as a legal requirement, or for the performance of a</p><p>> </p><p>> task carried out in the public interest or in the exercise of</p><p>> </p><p>> official authority, or in the legitimate interests of a natural or</p><p>> </p><p>> legal person, provided that the interests or the rights and</p><p>> </p><p>> freedoms of the data subject are not overriding....subject to the</p><p>> </p><p>> provisions allowing a data subject to object to the processing of</p><p>> </p><p>> data regarding him, at no cost and without having to state his</p><p>> </p><p>> reasons;</p><p>> </p><p>> </p><p>> </p><p>> I mean, really, the last person to use “whereas” in English outside of legal</p><p>> documents died before the invention of the telephone. ;) (The Wikipedia article</p><p>> on plain English suggests “because” or “since”, as does the “ www.plainlanguage.gov ” site, although in this particular case I'd say just leave it out.)</p><p>> </p><p>> </p><p>> </p><p>> I don't even know what the requirement is here. I read it 4 times and can't</p><p>> figure it out. I feel sorry for the poor software engineer that has to try to</p><p>> convert this to running code. :P</p><p>> </p><p>> </p><p>> </p><p>> Given the many hundreds of possible requirements, many of which are written like</p><p>> this, I don't see any way that anyone who has anything else to do for before the</p><p>> deadline can possibly hope to help properly review this work, at least without</p><p>> some coordinated plan such as “please review the following 10 requirements” for</p><p>> 50 volunteers.</p><p>> </p><p>> </p><p>> </p><p>> Sorry for ranting. :(</p><p>> </p><p>> </p><p>> </p><p>> Cheers,</p><p>> </p><p>> </p><p>> </p><p>> --</p><p>> </p><p>> Shane</p><p>> </p><p>> </p><p>> Ayden Férdeline Statement of Interest</p><p><br></p>
</blockquote>
</div>
</div>
</div><div>
</div><div><br></div><div class="mixmax_signature"><div>Ayden Férdeline</div><div><a href="https://community.icann.org/display/gnsosoi/Ayden+Férdeline+SOI" style="background-color: white;">Statement of Interest</a></div></div><img align="left" width="0" height="0" style="border:0; width:0px; height:0px;" src="https://app.mixmax.com/api/track/v2/QAQCWxO3cL5Tc36J0/i02bj5SZulGblRmclZGQu5WYjlmI/gI1RWZuIXez5idyV2c0NXasB0UTV1QTlERtc0UD5kI/?sc=false" alt="">
<!--[if mso]></td></tr></table><![endif]-->
</td>
</tr>
</table>
</body>
</html>