<html xmlns:v="urn:schemas-microsoft-com:vml" xmlns:o="urn:schemas-microsoft-com:office:office" xmlns:w="urn:schemas-microsoft-com:office:word" xmlns:m="http://schemas.microsoft.com/office/2004/12/omml" xmlns="http://www.w3.org/TR/REC-html40"><head><meta http-equiv=Content-Type content="text/html; charset=utf-8"><meta name=Generator content="Microsoft Word 15 (filtered medium)"><style><!--
/* Font Definitions */
@font-face
        {font-family:"MS Gothic";
        panose-1:2 11 6 9 7 2 5 8 2 4;}
@font-face
        {font-family:"Cambria Math";
        panose-1:2 4 5 3 5 4 6 3 2 4;}
@font-face
        {font-family:Calibri;
        panose-1:2 15 5 2 2 2 4 3 2 4;}
@font-face
        {font-family:Verdana;
        panose-1:2 11 6 4 3 5 4 4 2 4;}
@font-face
        {font-family:Consolas;
        panose-1:2 11 6 9 2 2 4 3 2 4;}
@font-face
        {font-family:"Microsoft JhengHei";
        panose-1:2 11 6 4 3 5 4 4 2 4;}
@font-face
        {font-family:"\@Microsoft JhengHei";}
@font-face
        {font-family:"\@MS Gothic";
        panose-1:2 11 6 9 7 2 5 8 2 4;}
/* Style Definitions */
p.MsoNormal, li.MsoNormal, div.MsoNormal
        {margin:0in;
        margin-bottom:.0001pt;
        font-size:11.0pt;
        font-family:"Calibri",sans-serif;
        color:black;}
a:link, span.MsoHyperlink
        {mso-style-priority:99;
        color:blue;
        text-decoration:underline;}
a:visited, span.MsoHyperlinkFollowed
        {mso-style-priority:99;
        color:purple;
        text-decoration:underline;}
pre
        {mso-style-priority:99;
        mso-style-link:"HTML Preformatted Char";
        margin:0in;
        margin-bottom:.0001pt;
        font-size:10.0pt;
        font-family:"Courier New";
        color:black;}
p.msonormal0, li.msonormal0, div.msonormal0
        {mso-style-name:msonormal;
        mso-margin-top-alt:auto;
        margin-right:0in;
        mso-margin-bottom-alt:auto;
        margin-left:0in;
        font-size:11.0pt;
        font-family:"Calibri",sans-serif;
        color:black;}
span.font
        {mso-style-name:font;}
span.size
        {mso-style-name:size;}
span.colour
        {mso-style-name:colour;}
span.HTMLPreformattedChar
        {mso-style-name:"HTML Preformatted Char";
        mso-style-priority:99;
        mso-style-link:"HTML Preformatted";
        font-family:Consolas;
        color:black;}
span.EmailStyle24
        {mso-style-type:personal-reply;
        font-family:"Calibri",sans-serif;
        color:windowtext;}
.MsoChpDefault
        {mso-style-type:export-only;
        font-size:10.0pt;}
@page WordSection1
        {size:8.5in 11.0in;
        margin:1.0in 1.0in 1.0in 1.0in;}
div.WordSection1
        {page:WordSection1;}
--></style><!--[if gte mso 9]><xml>
<o:shapedefaults v:ext="edit" spidmax="1026" />
</xml><![endif]--><!--[if gte mso 9]><xml>
<o:shapelayout v:ext="edit">
<o:idmap v:ext="edit" data="1" />
</o:shapelayout></xml><![endif]--></head><body bgcolor=white lang=EN-US link=blue vlink=purple><div class=WordSection1><p class=MsoNormal><span style='color:windowtext'>I tend to agree with Sam on this … the GDPR is a good standard, but it is not a universal standard.  And just as we don’t want ICANN to be in the business of content regulation we don’t want it to be the standard setter for world wide privacy.  Our goal should be to identify the minimum contractually necessary and then allow divergence across the globe.  The more difficult question is what, precisely, that minimum is … <o:p></o:p></span></p><p class=MsoNormal><span style='color:windowtext'><o:p> </o:p></span></p><p class=MsoNormal><span style='color:windowtext'>P<o:p></o:p></span></p><p class=MsoNormal><span style='color:windowtext'><o:p> </o:p></span></p><div><p class=MsoNormal><span style='color:windowtext'>Paul Rosenzweig<o:p></o:p></span></p><p class=MsoNormal><span style='color:windowtext'><a href="mailto:paul.rosenzweig@redbranchconsulting.com"><span style='color:#0563C1'>paul.rosenzweig@redbranchconsulting.com</span></a><o:p></o:p></span></p><p class=MsoNormal><span style='color:windowtext'>O: +1 (202) 547-0660<o:p></o:p></span></p><p class=MsoNormal><span style='color:windowtext'>M: +1 (202) 329-9650<o:p></o:p></span></p><p class=MsoNormal><span style='color:windowtext'>VOIP: +1 (202) 738-1739<o:p></o:p></span></p><p class=MsoNormal><span style='color:windowtext'><a href="http://www.redbranchconsulting.com/"><span style='color:#0563C1'>www.redbranchconsulting.com</span></a><o:p></o:p></span></p><p class=MsoNormal><span style='color:windowtext'>My PGP Key: <a href="https://keys.mailvelope.com/pks/lookup?op=get&search=0x9A830097CA066684"><span style='color:#0563C1'>https://keys.mailvelope.com/pks/lookup?op=get&search=0x9A830097CA066684</span></a><o:p></o:p></span></p></div><p class=MsoNormal><span style='color:windowtext'><o:p> </o:p></span></p><div><div style='border:none;border-top:solid #E1E1E1 1.0pt;padding:3.0pt 0in 0in 0in'><p class=MsoNormal><b><span style='color:windowtext'>From:</span></b><span style='color:windowtext'> NCSG-Discuss [mailto:NCSG-DISCUSS@LISTSERV.SYR.EDU] <b>On Behalf Of </b>Sam Lanfranco<br><b>Sent:</b> Sunday, January 14, 2018 10:59 AM<br><b>To:</b> NCSG-DISCUSS@LISTSERV.SYR.EDU<br><b>Subject:</b> Re: Data Protection and Privacy Update: Seeking Community Feedback on Proposed Compliance Models<o:p></o:p></span></p></div></div><p class=MsoNormal><o:p> </o:p></p><p>Colleagues,<o:p></o:p></p><p>I may have an overly simplistic view of the issue here, but I would like to put it on the table. ICANN has a narrow remit within the growing area of global, regional (e.g. EU), and national Internet governance. It exercises that remit through a serious of contracts with entities (registrars and registries) that operate under diverse national Internet governance jurisdictions. <o:p></o:p></p><p>With differing specific data protection language in diverse contexts, it is highly unlikely that ICANN can draft “higher standard” contract language that will satisfy the data privacy regulations of all, most, or even many, national data privacy regimes. So, what is the path forward here?<o:p></o:p></p><p>There seem to be two components of a path forward. First, ICANN must figure out how it exercises ICANN agency as a stakeholder in the various legislative policy venues in which data privacy and other Internet governance policy is debated and where regulations are formed. Some ICANN stakeholders already “have skin in those games” and are already present in those policy debates. ICANN writes contract language and needs to be engaged as a stakeholder. <o:p></o:p></p><p>Second, in contrast to seeking “higher standard” contract language, ICANN may need to look for “minimum conditions” contract language that offers contracted parties maximum freedom to negotiate with and meet the conditions of national Internet governance policies. At the same time ICANN can use its agency as a stakeholder to press for “higher standard” national policies that harmonize regulations, and facilitate the work and interests of various stakeholders in the Internet ecosystem. <o:p></o:p></p><p>In short, the path forward may be (a) more ICANN agency as a stakeholder, and (b) minimal contract language to maximize the ability of contracted parties to deal with national policies and regulations. <o:p></o:p></p><p style='margin-bottom:12.0pt'>Sam L. <o:p></o:p></p><p class=MsoNormal style='margin-bottom:12.0pt'><o:p> </o:p></p><div><p class=MsoNormal>On 1/14/2018 10:02 AM, Ayden Férdeline wrote:<o:p></o:p></p></div><blockquote style='margin-top:5.0pt;margin-bottom:5.0pt'><div><p class=MsoNormal>Hi Caleb,<o:p></o:p></p></div><div><p class=MsoNormal><o:p> </o:p></p></div><div><p class=MsoNormal>While I appreciate that not all countries have data protection laws, privacy remains a fundamental human right. My suggestion is thus that we should adopt the highest level of protection for all domain name registrants. And I suspect it is a lot easier to implement one model, rather than fragmented models for different jurisdictions.<o:p></o:p></p></div><div><p class=MsoNormal><o:p> </o:p></p></div><div><p class=MsoNormal>Please also remember that ICANN sets policy by contract; i.e. registries, registrars, and registrants agree by contract to follow the rules and policies created by ICANN, and these policies can be revised and deleted. So while ICANN must of course comply with the law, it can adopt and impose a higher standard on the contracted parties.<o:p></o:p></p></div><div><p class=MsoNormal><o:p> </o:p></p></div><div><p class=MsoNormal>Many thanks,<o:p></o:p></p></div><div><p class=MsoNormal><o:p> </o:p></p></div><div><p class=MsoNormal>Ayden<o:p></o:p></p></div><div><p class=MsoNormal><o:p> </o:p></p></div><div><div><p class=MsoNormal><o:p> </o:p></p></div></div><div><p class=MsoNormal><o:p> </o:p></p></div><blockquote style='margin-top:5.0pt;margin-bottom:5.0pt'><div><p class=MsoNormal>-------- Original Message --------<o:p></o:p></p></div><div><p class=MsoNormal>Subject: Re: Data Protection and Privacy Update: Seeking Community Feedback on Proposed Compliance Models<o:p></o:p></p></div><div><p class=MsoNormal>Local Time: 14 January 2018 3:56 PM<o:p></o:p></p></div><div><p class=MsoNormal>UTC Time: 14 January 2018 14:56<o:p></o:p></p></div><div><p class=MsoNormal>From: <a href="mailto:muyiwacaleb@GMAIL.COM">muyiwacaleb@GMAIL.COM</a><o:p></o:p></p></div><div><p class=MsoNormal>To: <a href="mailto:NCSG-DISCUSS@LISTSERV.SYR.EDU">NCSG-DISCUSS@LISTSERV.SYR.EDU</a><o:p></o:p></p></div><div><p class=MsoNormal><o:p> </o:p></p></div><div><div><p class=MsoNormal>Hello Badii and Ayden,<o:p></o:p></p></div><div><p class=MsoNormal><o:p> </o:p></p></div><div><p class=MsoNormal>For me, i think the Model 2A serves the purposes. Don't forget that not all countries have data protection laws or policy in place.<o:p></o:p></p></div><div><p class=MsoNormal>Hence, based on jurisdiction, they cannot be governed by laws that is peculiar to a certain continent or sovereign state. <o:p></o:p></p></div><div><p class=MsoNormal><o:p> </o:p></p></div><div><p class=MsoNormal>Caleb Ogundele<o:p></o:p></p></div></div><div><div><p class=MsoNormal><o:p> </o:p></p></div><div><div><p class=MsoNormal>On Sun, Jan 14, 2018 at 3:36 PM, Ayden Férdeline <<a href="mailto:icann@ferdeline.com">icann@ferdeline.com</a>> wrote:<o:p></o:p></p></div><blockquote style='border:none;border-left:solid #CCCCCC 1.0pt;padding:0in 0in 0in 6.0pt;margin-left:4.8pt;margin-right:0in'><div><p class=MsoNormal>I could live with the second model.<o:p></o:p></p></div><div><p class=MsoNormal><o:p> </o:p></p></div><div><p class=MsoNormal>The key differentiation between Model 2A and 2B is its applicability: 2A applies only "where the registrant, registry, registrar or a processor are located in the European Economic Area"; 2B "applies to all registrations on a global basis without regard to location of registry, registrar registrant, and processing activities"<o:p></o:p></p></div><div><p class=MsoNormal><o:p> </o:p></p></div><div><p class=MsoNormal>On this basis I think Model 2B is the best path forward. To have fragmented approaches for different regions would be a mistake, in my opinion.<o:p></o:p></p></div><div><p class=MsoNormal><o:p> </o:p></p></div><div><p class=MsoNormal>Given the short turnaround time here (we need to agree on a position and submit a comment by 29 January) and other obstacles between now and then (Intersessional, GNSO Council Strategic Planning Session), may I suggest that we schedule a call next week to discuss our response?<o:p></o:p></p></div><div><p class=MsoNormal><o:p> </o:p></p></div><div><p class=MsoNormal>Best wishes, Ayden<o:p></o:p></p></div><div><div><div><div><p class=MsoNormal><o:p> </o:p></p></div></div><div><p class=MsoNormal><o:p> </o:p></p></div><blockquote style='margin-top:5.0pt;margin-bottom:5.0pt'><div><p class=MsoNormal>-------- Original Message --------<o:p></o:p></p></div><div><p class=MsoNormal>Subject: Data Protection and Privacy Update: Seeking Community Feedback on Proposed Compliance Models<o:p></o:p></p></div><div><p class=MsoNormal>Local Time: 13 January 2018 7:40 PM<o:p></o:p></p></div><div><p class=MsoNormal>UTC Time: 13 January 2018 18:40<o:p></o:p></p></div><div><p class=MsoNormal>From: <a href="mailto:farzaneh.badii@GMAIL.COM">farzaneh.badii@GMAIL.COM</a><o:p></o:p></p></div><div><p class=MsoNormal>To: <a href="mailto:NCSG-DISCUSS@LISTSERV.SYR.EDU">NCSG-DISCUSS@LISTSERV.SYR.EDU</a><o:p></o:p></p></div><div><p class=MsoNormal><o:p> </o:p></p></div><div><div><p class=MsoNormal><span style='font-family:"Verdana",sans-serif'>Please see the CEO blog on Data protection and privacy:<o:p></o:p></span></p></div><div><p class=MsoNormal><span style='font-family:"Verdana",sans-serif'><o:p> </o:p></span></p></div><div><p class=MsoNormal><span class=font><span style='font-family:"Verdana",sans-serif'><a href="https://www.icann.org/news/blog/data-protection-and-privacy-update-seeking-community-feedback-on-proposed-compliance-models">https://www.icann.org/news/blog/data-protection-and-privacy-update-seeking-community-feedback-on-proposed-compliance-models</a></span></span><o:p></o:p></p></div><div><p class=MsoNormal><o:p> </o:p></p></div><div><p class=MsoNormal>We should understand these models, discuss them and provide feedback. <o:p></o:p></p></div><div><p class=MsoNormal><o:p> </o:p></p></div><div><p class=MsoNormal>Best<o:p></o:p></p></div><div><div><div><div><p class=MsoNormal><span class=font><span style='font-family:"Verdana",sans-serif'>Farzaneh</span></span><o:p></o:p></p></div></div></div></div></div></blockquote><div><p class=MsoNormal><o:p> </o:p></p></div></div></div></blockquote></div><div><p class=MsoNormal><o:p> </o:p></p></div><div><p class=MsoNormal><o:p> </o:p></p></div><div><p class=MsoNormal><o:p> </o:p></p></div><div><p class=MsoNormal>-- <o:p></o:p></p></div><div><div><div><p class=MsoNormal><span class=colour><b><span style='font-size:13.5pt;color:#33CCFF'>Ogundele Olumuyiwa Caleb</span></b></span><o:p></o:p></p></div><div><p class=MsoNormal><span class=colour><b><i><span style='color:#993300'><a href="mailto:muyiwacaleb@gmail.com">muyiwacaleb@gmail.com</a></span></i></b></span><o:p></o:p></p></div><div><p class=MsoNormal><span class=colour><b><i><span style='color:#666666'>234 - 8077377378</span></i></b></span><o:p></o:p></p></div><div><p class=MsoNormal><span class=colour><b><i><span style='color:#666666'>234 - 07030777969</span></i></b></span><o:p></o:p></p></div></div></div></div></blockquote><div><p class=MsoNormal><o:p> </o:p></p></div></blockquote><p class=MsoNormal><br><br><o:p></o:p></p><pre>-- <o:p></o:p></pre><pre>------------------------------------------------<o:p></o:p></pre><pre>"It is a disgrace to be rich and honoured<o:p></o:p></pre><pre>in an unjust state" -Confucius<o:p></o:p></pre><pre> <span style='font-family:"MS Gothic"'>邦有道,</span><span style='font-family:"Microsoft JhengHei",sans-serif'>贫且贱焉,耻也。邦无道,富且贵焉,耻也</span><o:p></o:p></pre><pre>------------------------------------------------<o:p></o:p></pre><pre>Dr Sam Lanfranco (Prof Emeritus & Senior Scholar)<o:p></o:p></pre><pre>Econ, York U., Toronto, Ontario, CANADA - M3J 1P3<o:p></o:p></pre><pre>email: <a href="mailto:Lanfran@Yorku.ca">Lanfran@Yorku.ca</a>   Skype: slanfranco<o:p></o:p></pre><pre>blog:  <a href="https://samlanfranco.blogspot.com">https://samlanfranco.blogspot.com</a><o:p></o:p></pre><pre>Phone: +1 613-476-0429 cell: +1 416-816-2852<o:p></o:p></pre></div></body></html>