<html>
  <head>
    <meta http-equiv="Content-Type" content="text/html;
      charset=windows-1252">
  </head>
  <body text="#000000" bgcolor="#FFFFFF">
    <p><font size="+1"><font face="Lucida Grande">I agree with Kathy,
          there is no overnight solution.  Here is my latest draft
          comment, rewritten as coming from me not NCSG.  Happy to get
          your feedback, but I will send it shortly so as to make sure I
          get it in by the deadline.  AS you can see, I am proposing to
          send them two more sections as a followup.</font></font></p>
    <p><font size="+1"><font face="Lucida Grande">cheers Stephanie
          Perrin</font></font><br>
    </p>
    <div class="moz-cite-prefix">On 2018-01-29 14:00, Kathy Kleiman
      wrote:<br>
    </div>
    <blockquote type="cite"
      cite="mid:b05af3e1-7313-1242-bc7f-d29200407215@kathykleiman.com">
      <meta http-equiv="Content-Type" content="text/html;
        charset=windows-1252">
      <p>Milton, I understand the comments below and I wish I could
        support them as the whole of the NCSG comments, but I cannot.
        However, I support much of them -- and let me share:</p>
      <p>1. "The purpose of Whois must be strictly tied to ICANN's
        mission." ==> that's absolutely true but we don't have that
        purpose yet (and I have to tell you that the RDS Working Group
        is not doing a great job of analyzng "purpose" right now (it is
        not closely following the strict legal rules of the GDPR and
        other comprehensive data protection laws -- this will be debated
        on Tuesday). But we (ICANN) does not have that "purpose" yet,
        and won't in the next 3 months (since any recommendation of the
        RDS WG would take months for review and acceptance, and the WG
        is nowhere near publishing it). But right now, we do have an
        open and public WHOIS system - all available all the time
        (unless you have signed up for a proxy or privacy service) -
        with <i>unlimited "all you can eat access" by everyone, </i>including
        intellectual property attorneys and law enforcement. That is
        happily going to change!!<br>
      </p>
      2. "Whois service, like the DNS itself, should be globally uniform
      and not vary by jurisdiction." ==> Yes, and that's what the ECO
      Model and Model 2B provide. But, unfortunately, that's Model 3
      does not provide uniformity; Model 3 provide great differentiation
      of protection, with only private individuals being protected, and
      not the political, sexual, religious, educational groups that I
      discussed in one of my recent emails - the array of groups that we
      protect engaged in huge amount of controversial and critical
      speech and services. <b>The ICANN Model 3 here is very clear: </b>"<b>Display
        unless field includes personal data." (ICANN's Proposed Interim
        Models for Compliance, pages 12-14).</b>  Thus, for
      noncommercial organizations, exposure of Registrant/Admin/Tech
      name, address, phone and email will remain completely open. Model
      2B and ECO do better and protect legal and natural persons. That's
      hugely important - and a tribute to our years of work on this
      subject!<br>
      <br>
      3. "No tiered access solution that involves establishing new
      criteria for access can feasibly be created in the next 3
      months."  ==> We are unlikely to go from infinite public access
      to completely restricted private access right now. The
      Multistakeholder Process won't support that. But the ECO model
      does a lot to help on this particular issue. I'll outline in my
      next email.<br>
      <br>
      Overall, it's great to have models and options. After fifteen
      years working in this WHOIS space, and I am optimistic that we are
      about to see the biggest change of our lifetimes coming up in this
      space. We have waited a long time!<br>
      Best, <br>
      Kathy<br>
      <br>
      On 1/26/2018 6:00 PM, Mueller, Milton L wrote:<br>
      <blockquote
cite="mid:BN3PR0701MB126542154BE3020610BA792EA1E70@BN3PR0701MB1265.namprd07.prod.outlook.com"
        type="cite">
        <meta name="Generator" content="Microsoft Word 15 (filtered
          medium)">
        <style><!--
/* Font Definitions */
@font-face
        {font-family:"Cambria Math";
        panose-1:2 4 5 3 5 4 6 3 2 4;}
@font-face
        {font-family:Calibri;
        panose-1:2 15 5 2 2 2 4 3 2 4;}
/* Style Definitions */
p.MsoNormal, li.MsoNormal, div.MsoNormal
        {margin:0in;
        margin-bottom:.0001pt;
        font-size:11.0pt;
        font-family:"Calibri",sans-serif;}
a:link, span.MsoHyperlink
        {mso-style-priority:99;
        color:#0563C1;
        text-decoration:underline;}
a:visited, span.MsoHyperlinkFollowed
        {mso-style-priority:99;
        color:#954F72;
        text-decoration:underline;}
span.EmailStyle17
        {mso-style-type:personal-compose;
        font-family:"Calibri",sans-serif;
        color:windowtext;}
.MsoChpDefault
        {mso-style-type:export-only;
        font-family:"Calibri",sans-serif;}
@page WordSection1
        {size:8.5in 11.0in;
        margin:1.0in 1.0in 1.0in 1.0in;}
div.WordSection1
        {page:WordSection1;}
--></style><!--[if gte mso 9]><xml>
<o:shapedefaults v:ext="edit" spidmax="1026" />
</xml><![endif]--><!--[if gte mso 9]><xml>
<o:shapelayout v:ext="edit">
<o:idmap v:ext="edit" data="1" />
</o:shapelayout></xml><![endif]-->
        <div class="WordSection1">
          <p class="MsoNormal">I offer the following as a first draft of
            the NCSG position on the 12 January 2018 call for comments
            released by ICANN org. <o:p></o:p></p>
          <p class="MsoNormal"><o:p> </o:p></p>
          <p class="MsoNormal">Principles<o:p></o:p></p>
          <p class="MsoNormal">Our evaluation of the models offered by
            ICANN are based on three fundamental principles. No model
            that fails to conform to all three is acceptable to the
            NCSG.<o:p></o:p></p>
          <p class="MsoNormal"><o:p> </o:p></p>
          <p class="MsoNormal">1. The purpose of whois must be strictly
            tied to ICANN's mission. That is, the data that is collected
            and the data that are published must directly and
            demonstrably contribute to ICANN's mission as defined in
            Article 1 of its new bylaws. We reject any definition of
            Whois purpose that is based on the way people happen to make
            use of data that can be accessed indiscriminately in a
            public directory. The fact that certain people currently use
            Whois for any purpose does not mean that the purpose of
            Whois is to provide thick data about the domain and its
            registrant to anyone who wants it for any reason. <o:p></o:p></p>
          <p class="MsoNormal"><o:p> </o:p></p>
          <p class="MsoNormal">2. Whois service, like the DNS itself,
            should be globally uniform and not vary by jurisdiction.
            ICANN was created to provide globalized governance of the
            DNS so that it would continue to be globally compatible and
            coordinated. Any solution that involves fragmenting the
            policies and practices of Whois along jurisdictional lines
            is not desirable.<o:p></o:p></p>
          <p class="MsoNormal"><o:p> </o:p></p>
          <p class="MsoNormal">3. No tiered access solution that
            involves establishing new criteria for access can feasibly
            be created in the next 3 months. We would strongly resist
            throwing the community into a hopeless rush to come up with
            entirely new policies, standards and practices involving
            tiered access to data, and we do not want ICANN staff to
            invent a policy that is not subject to community review and
            approval.  <o:p></o:p></p>
          <p class="MsoNormal"><o:p> </o:p></p>
          <p class="MsoNormal">Based on these three principles, we
            believe that Model 3 is the only viable option available.
            Model 3 minimizes the data publicly displayed to that which
            is required for maintaining the stability, security and
            resiliency of the DNS. Model 3 could be applied across the
            board, and would be presumptively legal regardless of which
            jurisdiction the registrar, registry or registrant are in.
            And Model 3 relies on established legal due process for
            gaining access to additional information. <o:p></o:p></p>
          <p class="MsoNormal"><o:p> </o:p></p>
          <p class="MsoNormal">There is room for discussion about how
            much data could be publicly displayed under Model 3
            consistent with ICANN's mission. E.g., it may be within
            ICANN's mission to include additional data in the public
            record, such as an email address for the technical contact
            and even possibly the name of the registrant. <o:p></o:p></p>
          <p class="MsoNormal"><o:p> </o:p></p>
          <p class="MsoNormal">The process of gaining access to
            additional data in Model 1 is completely unacceptable.
            Self-certification by any third party requestor is, we
            believe, not compliant with GDPR nor does is such access
            justified by the purpose of Whois or ICANN's mission.<o:p></o:p></p>
          <p class="MsoNormal"><o:p> </o:p></p>
          <p class="MsoNormal">Model 2 might possibly be acceptable if
            an suitable set of criteria and processes were devised, but
            it simply is not feasible for such a certification program
            to be developed in 3 months. A certification program thrown
            together in a rush poses huge risks for loopholes, poor
            procedures, and a legal challenge to ICANN, either from DPAs
            or from individuals affected.<o:p></o:p></p>
          <p class="MsoNormal"><o:p> </o:p></p>
          <p class="MsoNormal">Dr. Milton L. Mueller<o:p></o:p></p>
          <p class="MsoNormal">Professor, School of Public Policy<o:p></o:p></p>
          <p class="MsoNormal">Georgia Institute of Technology<o:p></o:p></p>
          <p class="MsoNormal"><o:p> </o:p></p>
          <p class="MsoNormal"><o:p> </o:p></p>
        </div>
      </blockquote>
      <br>
    </blockquote>
  </body>
</html>