<html>
  <head>
    <meta content="text/html; charset=windows-1252"
      http-equiv="Content-Type">
  </head>
  <body bgcolor="#FFFFFF" text="#000000">
    <p>Milton, I understand the comments below and I wish I could
      support them as the whole of the NCSG comments, but I cannot.
      However, I support much of them -- and let me share:</p>
    <p>1. "The purpose of Whois must be strictly tied to ICANN's
      mission." ==> that's absolutely true but we don't have that
      purpose yet (and I have to tell you that the RDS Working Group is
      not doing a great job of analyzng "purpose" right now (it is not
      closely following the strict legal rules of the GDPR and other
      comprehensive data protection laws -- this will be debated on
      Tuesday). But we (ICANN) does not have that "purpose" yet, and
      won't in the next 3 months (since any recommendation of the RDS WG
      would take months for review and acceptance, and the WG is nowhere
      near publishing it). But right now, we do have an open and public
      WHOIS system - all available all the time (unless you have signed
      up for a proxy or privacy service) - with <i>unlimited "all you
        can eat access" by everyone, </i>including intellectual
      property attorneys and law enforcement. That is happily going to
      change!!<br>
    </p>
    2. "Whois service, like the DNS itself, should be globally uniform
    and not vary by jurisdiction." ==> Yes, and that's what the ECO
    Model and Model 2B provide. But, unfortunately, that's Model 3 does
    not provide uniformity; Model 3 provide great differentiation of
    protection, with only private individuals being protected, and not
    the political, sexual, religious, educational groups that I
    discussed in one of my recent emails - the array of groups that we
    protect engaged in huge amount of controversial and critical speech
    and services. <b>The ICANN Model 3 here is very clear: </b>"<b>Display
      unless field includes personal data." (ICANN's Proposed Interim
      Models for Compliance, pages 12-14).</b>  Thus, for noncommercial
    organizations, exposure of Registrant/Admin/Tech name, address,
    phone and email will remain completely open. Model 2B and ECO do
    better and protect legal and natural persons. That's hugely
    important - and a tribute to our years of work on this subject!<br>
    <br>
    3. "No tiered access solution that involves establishing new
    criteria for access can feasibly be created in the next 3 months." 
    ==> We are unlikely to go from infinite public access to
    completely restricted private access right now. The Multistakeholder
    Process won't support that. But the ECO model does a lot to help on
    this particular issue. I'll outline in my next email.<br>
    <br>
    Overall, it's great to have models and options. After fifteen years
    working in this WHOIS space, and I am optimistic that we are about
    to see the biggest change of our lifetimes coming up in this space.
    We have waited a long time!<br>
    Best, <br>
    Kathy<br>
    <br>
    On 1/26/2018 6:00 PM, Mueller, Milton L wrote:<br>
    <blockquote
cite="mid:BN3PR0701MB126542154BE3020610BA792EA1E70@BN3PR0701MB1265.namprd07.prod.outlook.com"
      type="cite">
      <meta http-equiv="Content-Type" content="text/html;
        charset=windows-1252">
      <meta name="Generator" content="Microsoft Word 15 (filtered
        medium)">
      <style><!--
/* Font Definitions */
@font-face
        {font-family:"Cambria Math";
        panose-1:2 4 5 3 5 4 6 3 2 4;}
@font-face
        {font-family:Calibri;
        panose-1:2 15 5 2 2 2 4 3 2 4;}
/* Style Definitions */
p.MsoNormal, li.MsoNormal, div.MsoNormal
        {margin:0in;
        margin-bottom:.0001pt;
        font-size:11.0pt;
        font-family:"Calibri",sans-serif;}
a:link, span.MsoHyperlink
        {mso-style-priority:99;
        color:#0563C1;
        text-decoration:underline;}
a:visited, span.MsoHyperlinkFollowed
        {mso-style-priority:99;
        color:#954F72;
        text-decoration:underline;}
span.EmailStyle17
        {mso-style-type:personal-compose;
        font-family:"Calibri",sans-serif;
        color:windowtext;}
.MsoChpDefault
        {mso-style-type:export-only;
        font-family:"Calibri",sans-serif;}
@page WordSection1
        {size:8.5in 11.0in;
        margin:1.0in 1.0in 1.0in 1.0in;}
div.WordSection1
        {page:WordSection1;}
--></style><!--[if gte mso 9]><xml>
<o:shapedefaults v:ext="edit" spidmax="1026" />
</xml><![endif]--><!--[if gte mso 9]><xml>
<o:shapelayout v:ext="edit">
<o:idmap v:ext="edit" data="1" />
</o:shapelayout></xml><![endif]-->
      <div class="WordSection1">
        <p class="MsoNormal">I offer the following as a first draft of
          the NCSG position on the 12 January 2018 call for comments
          released by ICANN org.
          <o:p></o:p></p>
        <p class="MsoNormal"><o:p> </o:p></p>
        <p class="MsoNormal">Principles<o:p></o:p></p>
        <p class="MsoNormal">Our evaluation of the models offered by
          ICANN are based on three fundamental principles. No model that
          fails to conform to all three is acceptable to the NCSG.<o:p></o:p></p>
        <p class="MsoNormal"><o:p> </o:p></p>
        <p class="MsoNormal">1. The purpose of whois must be strictly
          tied to ICANN's mission. That is, the data that is collected
          and the data that are published must directly and demonstrably
          contribute to ICANN's mission as defined in Article 1 of its
          new bylaws. We reject any definition of Whois purpose that is
          based on the way people happen to make use of data that can be
          accessed indiscriminately in a public directory. The fact that
          certain people currently use Whois for any purpose does not
          mean that the purpose of Whois is to provide thick data about
          the domain and its registrant to anyone who wants it for any
          reason.
          <o:p></o:p></p>
        <p class="MsoNormal"><o:p> </o:p></p>
        <p class="MsoNormal">2. Whois service, like the DNS itself,
          should be globally uniform and not vary by jurisdiction. ICANN
          was created to provide globalized governance of the DNS so
          that it would continue to be globally compatible and
          coordinated. Any solution that involves fragmenting the
          policies and practices of Whois along jurisdictional lines is
          not desirable.<o:p></o:p></p>
        <p class="MsoNormal"><o:p> </o:p></p>
        <p class="MsoNormal">3. No tiered access solution that involves
          establishing new criteria for access can feasibly be created
          in the next 3 months. We would strongly resist throwing the
          community into a hopeless rush to come up with entirely new
          policies, standards and practices involving tiered access to
          data, and we do not want ICANN staff to invent a policy that
          is not subject to community review and approval. 
          <o:p></o:p></p>
        <p class="MsoNormal"><o:p> </o:p></p>
        <p class="MsoNormal">Based on these three principles, we believe
          that Model 3 is the only viable option available. Model 3
          minimizes the data publicly displayed to that which is
          required for maintaining the stability, security and
          resiliency of the DNS. Model 3 could be applied across the
          board, and would be presumptively legal regardless of which
          jurisdiction the registrar, registry or registrant are in. And
          Model 3 relies on established legal due process for gaining
          access to additional information.
          <o:p></o:p></p>
        <p class="MsoNormal"><o:p> </o:p></p>
        <p class="MsoNormal">There is room for discussion about how much
          data could be publicly displayed under Model 3 consistent with
          ICANN's mission. E.g., it may be within ICANN's mission to
          include additional data in the public record, such as an email
          address for the technical contact and even possibly the name
          of the registrant. <o:p></o:p></p>
        <p class="MsoNormal"><o:p> </o:p></p>
        <p class="MsoNormal">The process of gaining access to additional
          data in Model 1 is completely unacceptable. Self-certification
          by any third party requestor is, we believe, not compliant
          with GDPR nor does is such access justified by the purpose of
          Whois or ICANN's mission.<o:p></o:p></p>
        <p class="MsoNormal"><o:p> </o:p></p>
        <p class="MsoNormal">Model 2 might possibly be acceptable if an
          suitable set of criteria and processes were devised, but it
          simply is not feasible for such a certification program to be
          developed in 3 months. A certification program thrown together
          in a rush poses huge risks for loopholes, poor procedures, and
          a legal challenge to ICANN, either from DPAs or from
          individuals affected.<o:p></o:p></p>
        <p class="MsoNormal"><o:p> </o:p></p>
        <p class="MsoNormal">Dr. Milton L. Mueller<o:p></o:p></p>
        <p class="MsoNormal">Professor, School of Public Policy<o:p></o:p></p>
        <p class="MsoNormal">Georgia Institute of Technology<o:p></o:p></p>
        <p class="MsoNormal"><o:p> </o:p></p>
        <p class="MsoNormal"><o:p> </o:p></p>
      </div>
    </blockquote>
    <br>
  </body>
</html>