<html>
  <head>
    <meta http-equiv="Content-Type" content="text/html; charset=utf-8">
  </head>
  <body text="#000000" bgcolor="#FFFFFF">
    <p>Colleagues,</p>
    <p>I may have an overly simplistic view of the issue here, but I
      would like to put it on the table. ICANN has a narrow remit within
      the growing area of global, regional (e.g. EU), and national
      Internet governance. It exercises that remit through a serious of
      contracts with entities (registrars and registries) that operate
      under diverse national Internet governance jurisdictions. <br>
    </p>
    <p>With differing specific data protection language in diverse
      contexts, it is highly unlikely that ICANN can draft “higher
      standard” contract language that will satisfy the data privacy
      regulations of all, most, or even many, national data privacy
      regimes. So, what is the path forward here?</p>
    <p>There seem to be two components of a path forward. First, ICANN
      must figure out how it exercises ICANN agency as a stakeholder in
      the various legislative policy venues in which data privacy and
      other Internet governance policy is debated and where regulations
      are formed. Some ICANN stakeholders already “have skin in those
      games” and are already present in those policy debates. ICANN
      writes contract language and needs to be engaged as a stakeholder.
      <br>
    </p>
    <p>Second, in contrast to seeking “higher standard” contract
      language, ICANN may need to look for “minimum conditions” contract
      language that offers contracted parties maximum freedom to
      negotiate with and meet the conditions of national Internet
      governance policies. At the same time ICANN can use its agency as
      a stakeholder to press for “higher standard” national policies
      that harmonize regulations, and facilitate the work and interests
      of various stakeholders in the Internet ecosystem. <br>
    </p>
    <p>In short, the path forward may be (a) more ICANN agency as a
      stakeholder, and (b) minimal contract language to maximize the
      ability of contracted parties to deal with national policies and
      regulations. <br>
    </p>
    <p>Sam L. <br>
      <br>
    </p>
    <br>
    <br>
    <div class="moz-cite-prefix">On 1/14/2018 10:02 AM, Ayden Férdeline
      wrote:<br>
    </div>
    <blockquote type="cite"
cite="mid:F2j9NNUvNfxnBDleIFabdV1-oicsC9eiYgQTibUhRevPDXvMv4wUpFJcOONJ_bE0T8A45FMSmuqceKIqW7X4ogX-yGAg6Xo08nGpvG4_kCE=@ferdeline.com">
      <div>Hi Caleb,<br>
      </div>
      <div><br>
      </div>
      <div>While I appreciate that not all countries have data
        protection laws, privacy remains a fundamental human right. My
        suggestion is thus that we should adopt the highest level of
        protection for all domain name registrants. And I suspect it is
        a lot easier to implement one model, rather than fragmented
        models for different jurisdictions.<br>
      </div>
      <div><br>
      </div>
      <div>Please also remember that ICANN sets policy by contract; i.e.
        registries, registrars, and registrants agree by contract to
        follow the rules and policies created by ICANN, and these
        policies can be revised and deleted. So while ICANN must of
        course comply with the law, it can adopt and impose a higher
        standard on the contracted parties.<br>
      </div>
      <div><br>
      </div>
      <div>Many thanks,<br>
      </div>
      <div><br>
      </div>
      <div>Ayden<br>
      </div>
      <div><br>
      </div>
      <div class="protonmail_signature_block">
        <div class="protonmail_signature_block-proton
          protonmail_signature_block-empty"><br>
        </div>
      </div>
      <div><br>
      </div>
      <blockquote type="cite" class="protonmail_quote">
        <div>-------- Original Message --------<br>
        </div>
        <div>Subject: Re: Data Protection and Privacy Update: Seeking
          Community Feedback on Proposed Compliance Models<br>
        </div>
        <div>Local Time: 14 January 2018 3:56 PM<br>
        </div>
        <div>UTC Time: 14 January 2018 14:56<br>
        </div>
        <div>From: <a class="moz-txt-link-abbreviated" href="mailto:muyiwacaleb@GMAIL.COM">muyiwacaleb@GMAIL.COM</a><br>
        </div>
        <div>To: <a class="moz-txt-link-abbreviated" href="mailto:NCSG-DISCUSS@LISTSERV.SYR.EDU">NCSG-DISCUSS@LISTSERV.SYR.EDU</a><br>
        </div>
        <div><br>
        </div>
        <div dir="ltr">
          <div>Hello Badii and Ayden,<br>
          </div>
          <div><br>
          </div>
          <div>For me, i think the Model 2A serves the purposes. Don't
            forget that not all countries have data protection laws or
            policy in place.<br>
          </div>
          <div>Hence, based on jurisdiction, they cannot be governed by
            laws that is peculiar to a certain continent or sovereign
            state. <br>
          </div>
          <div><br>
          </div>
          <div>Caleb Ogundele<br>
          </div>
        </div>
        <div class="gmail_extra">
          <div><br>
          </div>
          <div class="gmail_quote">
            <div>On Sun, Jan 14, 2018 at 3:36 PM, Ayden Férdeline <span
                dir="ltr"><<a href="mailto:icann@ferdeline.com"
                  moz-do-not-send="true">icann@ferdeline.com</a>></span>
              wrote:<br>
            </div>
            <blockquote class="gmail_quote" style="margin:0 0 0
              .8ex;border-left:1px #ccc solid;padding-left:1ex">
              <div>I could live with the second model.<br>
              </div>
              <div><br>
              </div>
              <div>The key differentiation between Model 2A and 2B is
                its applicability: 2A applies only "where the
                registrant, registry, registrar or a processor are
                located in the European Economic Area"; 2B "applies to
                all registrations on a global basis without regard to
                location of registry, registrar registrant, and
                processing activities"<br>
              </div>
              <div><br>
              </div>
              <div>On this basis I think Model 2B is the best path
                forward. To have fragmented approaches for different
                regions would be a mistake, in my opinion.<br>
              </div>
              <div><br>
              </div>
              <div>Given the short turnaround time here (we need to
                agree on a position and submit a comment by 29 January)
                and other obstacles between now and then
                (Intersessional, GNSO Council Strategic Planning
                Session), may I suggest that we schedule a call next
                week to discuss our response?<br>
              </div>
              <div><br>
              </div>
              <div>Best wishes, Ayden<br>
              </div>
              <div class="HOEnZb">
                <div class="h5">
                  <div
                    class="m_7719732525519400768protonmail_signature_block">
                    <div
                      class="m_7719732525519400768protonmail_signature_block-proton
m_7719732525519400768protonmail_signature_block-empty"><br>
                    </div>
                  </div>
                  <div><br>
                  </div>
                  <blockquote
                    class="m_7719732525519400768protonmail_quote"
                    type="cite">
                    <div>-------- Original Message --------<br>
                    </div>
                    <div>Subject: Data Protection and Privacy Update:
                      Seeking Community Feedback on Proposed Compliance
                      Models<br>
                    </div>
                    <div>Local Time: 13 January 2018 7:40 PM<br>
                    </div>
                    <div>UTC Time: 13 January 2018 18:40<br>
                    </div>
                    <div>From: <a
                        href="mailto:farzaneh.badii@GMAIL.COM"
                        moz-do-not-send="true">farzaneh.badii@GMAIL.COM</a><br>
                    </div>
                    <div>To: <a
                        href="mailto:NCSG-DISCUSS@LISTSERV.SYR.EDU"
                        moz-do-not-send="true">NCSG-DISCUSS@LISTSERV.SYR.EDU</a><br>
                    </div>
                    <div><br>
                    </div>
                    <div dir="ltr">
                      <div style="font-family:verdana,sans-serif"
                        class="gmail_default">Please see the CEO blog on
                        Data protection and privacy:<br>
                      </div>
                      <div style="font-family:verdana,sans-serif"
                        class="gmail_default"><br>
                      </div>
                      <div class="gmail_default"><span
                          style="font-family:verdana, sans-serif"
                          class="font"><a
href="https://www.icann.org/news/blog/data-protection-and-privacy-update-seeking-community-feedback-on-proposed-compliance-models"
                            moz-do-not-send="true">https://www.icann.org/news/<wbr>blog/data-protection-and-<wbr>privacy-update-seeking-<wbr>community-feedback-on-<wbr>proposed-compliance-models</a></span><br>
                      </div>
                      <div class="gmail_default"><br>
                      </div>
                      <div class="gmail_default">We should understand
                        these models, discuss them and provide
                        feedback. <br>
                      </div>
                      <div class="gmail_default"><br>
                      </div>
                      <div class="gmail_default">Best<br>
                      </div>
                      <div>
                        <div
                          class="m_7719732525519400768gmail_signature">
                          <div dir="ltr">
                            <div><span style="font-family:verdana,
                                sans-serif" class="font">Farzaneh</span><br>
                            </div>
                          </div>
                        </div>
                      </div>
                    </div>
                  </blockquote>
                  <div><br>
                  </div>
                </div>
              </div>
            </blockquote>
          </div>
          <div><br>
          </div>
          <div><br>
          </div>
          <div><br>
          </div>
          <div>-- <br>
          </div>
          <div class="gmail_signature" data-smartmail="gmail_signature">
            <div dir="ltr">
              <div><b><span style="font-size:18px" class="size"><span
                      style="color:#33ccff" class="colour">Ogundele
                      Olumuyiwa Caleb</span></span></b><br>
              </div>
              <div><span style="color:#993300" class="colour"><i><b><a
                        href="mailto:muyiwacaleb@gmail.com"
                        moz-do-not-send="true">muyiwacaleb@gmail.com</a></b></i></span><br>
              </div>
              <div><i><b><span style="color:#666666" class="colour">234
                      - 8077377378</span></b></i><br>
              </div>
              <div><i><b><span style="color:#666666" class="colour">234
                      - 07030777969</span></b></i><br>
              </div>
            </div>
          </div>
        </div>
      </blockquote>
      <div><br>
      </div>
    </blockquote>
    <br>
    <pre class="moz-signature" cols="72">-- 
------------------------------------------------
"It is a disgrace to be rich and honoured
in an unjust state" -Confucius
 邦有道,贫且贱焉,耻也。邦无道,富且贵焉,耻也
------------------------------------------------
Dr Sam Lanfranco (Prof Emeritus & Senior Scholar)
Econ, York U., Toronto, Ontario, CANADA - M3J 1P3
email: <a class="moz-txt-link-abbreviated" href="mailto:Lanfran@Yorku.ca">Lanfran@Yorku.ca</a>   Skype: slanfranco
blog:  <a class="moz-txt-link-freetext" href="https://samlanfranco.blogspot.com">https://samlanfranco.blogspot.com</a>
Phone: +1 613-476-0429 cell: +1 416-816-2852</pre>
  </body>
</html>