<html>
<head>
<meta http-equiv="Content-Type" content="text/html; charset=utf-8">
</head>
<body text="#000000" bgcolor="#FFFFFF">
<p><font size="+1"><font face="Lucida Grande">We have asked a
similar line of questions (why doesn't ICANN have a privacy
policy, why not a privacy officer) a few years ago. We never
really got a decent answer, as I recall. I suspect that we
will not get a great answer this time either, and I think we
can depend upon it, ICANN management is getting a great deal
of grief from the registrars and registries over the mess that
they have dragged them into. Remember that the contracted
parties have very little leeway in their contract negotiations,
the WHOIS conflicts with law policy does not work, and the
contracted parties are considered data controllers under the
EU law...although I would argue that ICANN is the data
controller and they are only processors for any data which is
mandated by the RAA. So I am not sure our we-told-you-so and
how-could-you-mess-this-up would be helpful at this point. We
should give Daniel a chance, he might be excellent. Who
knows, maybe he has been telling them all along that they
really ought to comply with law, we are not likely to know
that.</font></font></p>
<p><font size="+1"><font face="Lucida Grande">I just think if I were
the CEO I would be asking for the risk management plan that
had been developed to manage this risk. I can assure you I
have been reminding everyone on every working group I have
been on of the impending regulation since I arrived here in
2013.<br>
</font></font></p>
<p><font size="+1"><font face="Lucida Grande">cheers Stephanie</font></font><br>
</p>
<br>
<div class="moz-cite-prefix">On 2017-07-31 08:06, Michael Oghia
wrote:<br>
</div>
<blockquote type="cite"
cite="mid:CAMCMt7rW0vas=wbYiRhDAOh4CurT8opL9XBkW+Q9GjGneunUHQ@mail.gmail.com">
<meta http-equiv="Content-Type" content="text/html; charset=utf-8">
<div dir="ltr">I agree too Stephanie, excellent points David.
<div><br>
</div>
<div>Would anyone support us as the NCSG requesting a formal
response to David's points (and a formal explanation as to the
motivation behind Mr. Halloran's appointment)?</div>
<div>
<div class="gmail_extra"><br clear="all">
<div>
<div class="gmail_signature">
<div dir="ltr">
<div>
<div dir="ltr">
<div>
<div dir="ltr">
<div>
<div dir="ltr">
<div>
<div dir="ltr">
<div dir="ltr">
<div dir="ltr">
<div dir="ltr">
<div dir="ltr">
<div dir="ltr">
<div dir="ltr">
<div dir="ltr">
<div dir="ltr">
<div dir="ltr">
<div dir="ltr">
<div dir="ltr">
<div dir="ltr">
<div dir="ltr">
<div dir="ltr">
<div dir="ltr">
<div dir="ltr">
<div dir="ltr">
<div dir="ltr">
<div dir="ltr">
<div dir="ltr">
<div dir="ltr">
<div dir="ltr">
<div dir="ltr">
<div dir="ltr">
<div><font
size="2"
face="arial,
helvetica,
sans-serif">Best,</font></div>
<div><font
size="2"
face="arial,
helvetica,
sans-serif">-Michael<br>
</font></div>
<div dir="ltr">
<div>
<div dir="ltr">
<div dir="ltr"><br>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
<div class="gmail_quote">On Mon, Jul 31, 2017 at 1:51 PM,
Stephanie Perrin <span dir="ltr"><<a
href="mailto:stephanie.perrin@mail.utoronto.ca"
target="_blank" moz-do-not-send="true">stephanie.perrin@mail.utoronto.ca</a>></span>
wrote:<br>
<blockquote class="gmail_quote" style="margin:0px 0px 0px
0.8ex;border-left:1px solid
rgb(204,204,204);padding-left:1ex">
<div bgcolor="#FFFFFF">
<p><font size="+1"><font face="Lucida Grande">I
totally agree David, and as someone who last
worked in risk management, if I were the CEO
looking at this mess right now I would be asking
hard questions of the people who have advised
the Board to just ignore the data protection
commissioners for the past 17 years. First
position paper on WHOIS being illegal was in
2000. Makes a heck of an easy case to take to
Court....</font></font></p>
<span class="gmail-HOEnZb"><font color="#888888">
<p><font size="+1"><font face="Lucida Grande">Stephanie
Perrin</font></font><br>
</p>
</font></span>
<div>
<div class="gmail-h5"> <br>
<div
class="gmail-m_-4063821553450781781moz-cite-prefix">On
2017-07-31 03:33, David Cake wrote:<br>
</div>
<blockquote type="cite"> I admit I find this
development disappointing.
<div>While it is a sign (along with the GDPR
task force established at the last meeting)
that ICANN has finally understood the
significance of its downplaying and avoidance
of the GDPR and other international data
protection law over the last few years, it is
disappointing that:</div>
<div> a) ICANN is still not taking the issue
that seriously, as it is in addition to
existing Deputy General Counsel duties, so
represents a limited allocation of resources
to the issue; </div>
<div>b) is a missed opportunity to bring
additional experience and expertise into the
organisation, expertise ICANN desperately
needs (and is currently relying on its
volunteers to provide);</div>
<div>c) is continuing to the have the issue
managed by the same team whose denial and
obstinate avoidance of the issue has led to
the organisation now facing a crisis;</div>
<div>d) continues a pattern of having ICANN
legal be put in charge of areas where it is
largely responsible for continued organisation
dysfunction, so effectively being given the
opportunity to manage criticism but not given
any strong inventive to admit to past
mistakes. . </div>
<div><br>
</div>
<div>David</div>
<div><br>
<div><br>
</div>
<div><br>
<div>
<blockquote type="cite">
<div>On 29 Jul 2017, at 3:32 am, Ayden
Férdeline <<a
href="mailto:icann@ferdeline.com"
target="_blank"
moz-do-not-send="true">icann@ferdeline.com</a>>
wrote:</div>
<br
class="gmail-m_-4063821553450781781Apple-interchange-newline">
<div>
<div>ICANN has now <a
href="https://www.icann.org/news/blog/introducing-icann-s-chief-data-protection-officer-cdpo"
title="appointed someone"
rel="nofollow" target="_blank"
moz-do-not-send="true">appointed
someone</a> to the role of "Chief
Data Protection Officer". Daniel
Halloran, who in his bio is
described as "one of
ICANN's longest-serving employees"
and reports directly to John
Jeffrey, does not list his
experience in establishing privacy
frameworks nor their associated
compliance structures in his bio.
That said, I wish him all the best
in this new role and look forward to
seeing how ICANN's understanding of
data protection law evolves over the
coming months now that this position
has been created...<br>
</div>
<div><br>
</div>
<div
class="gmail-m_-4063821553450781781protonmail_signature_block">
<div
class="gmail-m_-4063821553450781781protonmail_signature_block-user">
<div>Best wishes, Ayden Férdeline <br>
</div>
</div>
</div>
</div>
</blockquote>
</div>
<br>
</div>
</div>
</blockquote>
<br>
</div>
</div>
</div>
</blockquote>
</div>
<br>
</div>
</div>
</div>
</blockquote>
<br>
</body>
</html>