<div dir="ltr"><div class="gmail_default" style="font-family:verdana,sans-serif">Thanks a lot everyone with the very good suggestions:</div><div class="gmail_default" style="font-family:verdana,sans-serif"><br></div><div class="gmail_default" style="font-family:verdana,sans-serif">We can go with </div><div class="gmail_default" style="font-family:verdana,sans-serif"><br></div><div class="gmail_default"><div class="gmail_default"><font face="verdana, sans-serif">Agenda of NCSG meeting with GAC:</font></div><div class="gmail_default"><font face="verdana, sans-serif"><br></font></div><div class="gmail_default"><font face="verdana, sans-serif">- Background on NCSG, </font><span style="font-family:verdana,sans-serif">our values and convergence of our values with GAC</span></div><div class="gmail_default"><span style="font-family:verdana,sans-serif"><br></span></div><div class="gmail_default"><span style="font-family:verdana,sans-serif">- Rights Protection Mechanisms: Our NCSG view </span></div><div class="gmail_default"><span style="font-family:verdana,sans-serif"><br></span></div><div class="gmail_default"><font face="verdana, sans-serif">- Privacy</font></div><div class="gmail_default"><font face="verdana, sans-serif"><br></font></div><div class="gmail_default"><font face="verdana, sans-serif">- Wrap up </font></div><div class="gmail_default"><font face="verdana, sans-serif"><br></font></div><div class="gmail_default"><font face="verdana, sans-serif">I will submit this to NCSG PC.</font></div><div class="gmail_default"><font face="verdana, sans-serif"><br></font></div><div class="gmail_default"><font face="verdana, sans-serif">Best </font></div><div class="gmail_default"><font face="verdana, sans-serif"><br></font></div><div class="gmail_default"><font face="verdana, sans-serif">Farzaneh </font></div><div class="gmail_default" style="font-family:verdana,sans-serif"><br></div></div></div><div class="gmail_extra"><br clear="all"><div><div class="gmail_signature" data-smartmail="gmail_signature"><div dir="ltr"><div><font face="verdana, sans-serif">Farzaneh </font></div></div></div></div>
<br><div class="gmail_quote">On Mon, Feb 12, 2018 at 1:20 PM, Nick Shorey <span dir="ltr"><<a href="mailto:lists@nickshorey.com" target="_blank">lists@nickshorey.com</a>></span> wrote:<br><blockquote class="gmail_quote" style="margin:0 0 0 .8ex;border-left:1px #ccc solid;padding-left:1ex"><div dir="ltr"><div>Hi everyone,</div><div><br></div><div>GDPR and privacy are definitely the priority issues within ICANN's remit, and as we only have 30mins we should probably keep it quite focused.</div><div><br></div><div>Next step is to think about what we want out of the meeting? Do we want the GAC to take an action? Do we want their agreement on a policy position? Do we want them to commit to entering a dialogue?</div><div><br></div><div>In regards to GDPR, in my view I think we want the GAC to at the very least review the position they've taken on WHOIS.</div><div><br></div><div>The recent GAC documents on this (Abu Dhabi communique, compliance model proposal) contain some very worrying statements, which I can't help thinking have been endorsed and submitted with very little scrutiny, consultation or debate.</div><div><br></div><div><br></div><div>I think we need to broaden the GAC's source material on GDPR, and politely challenge some of their assumptions, by making several points:</div><div><br></div><div><br></div><div>- GDPR is THE most pressing issue for the ICANN community since the IANA transition, and we need the full engagement of the GAC (not simply delegating to PSWG) in ensuring WHOIS policies adhere to the principles of International law and Human Rights.</div><div><br></div><div>- WHOIS personal data is not a reliable / best practice intelligence source (as stated by PSWG) / professionals use other sources as indicators of abuse;</div><div><br></div><div>- Governments aalready have court orders, which are a much more effective and legally enforceable mechanism, including for intellectual property (UK has LEA for this);</div><div><br></div><div>- Consumer protection is not a justified reason for overriding privacy. End users don't reference WHOIS (CCT study) and as an example, public WHOIS data is not even referenced as a requirement under the UK Companies Act (companies have to provide registration details on websites, but no mention of WHOIS);</div><div><br></div><div>- The requirement for publicly visible email addresses will facilitate crime;</div><div><br></div><div>- Retaining data for 60 days beyond expiry is not proportionate: a common example cited by PSWG is DGA domains, where the domain will be used for abuse within days of being registered. Thus if the domain was registered for 1 year, the investigating agency will have almost a whole year to make the request;</div><div><br></div><div>Kind regards,</div><div><br></div><div>Nick</div></div><div class="gmail_extra"><span class="HOEnZb"><font color="#888888"><br clear="all"><div><div class="m_3769679951905385691gmail_signature" data-smartmail="gmail_signature"><div dir="ltr"><div><div dir="ltr"><b>Nick Shorey</b><div>Phone: <a href="tel:+44%207552%20455988" value="+447552455988" target="_blank">+44 (0) 7552 455 988</a></div><div>Email: <a href="mailto:lists@nickshorey.com" target="_blank">lists@nickshorey.com</a></div><div>Skype: nick.shorey</div><div>Twitter: @nickshorey</div><div>LinkedIn: <a href="http://www.linkedin.com/in/nicklinkedin" target="_blank">www.linkedin.com/in/<wbr>nicklinkedin</a></div><div>Web: <a href="http://www.nickshorey.com" target="_blank">www.nickshorey.com</a></div></div></div></div></div></div></font></span><div><div class="h5">
<br><div class="gmail_quote">On Mon, Feb 12, 2018 at 5:26 PM, Ayden Férdeline <span dir="ltr"><<a href="mailto:icann@ferdeline.com" target="_blank">icann@ferdeline.com</a>></span> wrote:<br><blockquote class="gmail_quote" style="margin:0 0 0 .8ex;border-left:1px #ccc solid;padding-left:1ex">Hi,<br>
<br>
I think this question is somewhat similar to what I asked the GAC during our Abu Dhabi bilateral, when I said "we’re unsure as to how GAC members consult with their justice departments in order to find the right balance between maintaining public safety while<br>
respecting fundamental rights such as the right to privacy which can be found in the constitutions of over 100 countries." See page 18 onwards of the transcript: <a href="https://schd.ws/hosted_files/icann60abudhabi2017/e3/I60AUH_Mon30Oct2017-GAC%20meeting%20with%20the%20NCUC-en.pdf" rel="noreferrer" target="_blank">https://schd.ws/hosted_files/i<wbr>cann60abudhabi2017/e3/I60AUH_M<wbr>on30Oct2017-GAC%20meeting%20wi<wbr>th%20the%20NCUC-en.pdf</a><br>
<br>
I think we need to be very delicate with questions to do with what process the GAC follows. I'm certainly curious as to how they form their opinions, and work internally, but I don't know if it appropriate for us to flat out say or even insinuate that they are only consulting with their trade representatives. And I do think that is the insinuation some are making. Real or perceived, right or wrong, we can't make it (in my opinion).<br>
<span class="m_3769679951905385691im m_3769679951905385691HOEnZb"><br>
Best wishes,<br>
<br>
​Ayden<br>
<br>
​<br>
<br>
-------- Original Message --------<br>
</span><div class="m_3769679951905385691HOEnZb"><div class="m_3769679951905385691h5"> On 12 February 2018 2:41 PM, Johan Helsingius <<a href="mailto:julf@JULF.COM" target="_blank">julf@JULF.COM</a>> wrote:<br>
<br>
>I really like Michael's suggestion:<br>
><br>
>>Could we ask the representatives more generally about how they develop<br>
>> their policy positions, and whether and how they consult with human<br>
>> rights/privacy/data protection voices in government, or with domestic<br>
>> NGOs or civil society voices, in formulating the policy positions that<br>
>> they bring to ICANN - maybe phrasing the question a bit more broadly<br>
>> than just asking directly about the RPMs. I feel like this might need<br>
>> to be approached delicately, but it may be a good question to get the<br>
>> GAC delegates themselves to reconsider...<br>
>><br>
> W§e have to remember that a lot of GAC members are fairly junior,<br>
> pretty new to ICANN, and not always very well briefed. They also<br>
> often biased to see GNSO as "A club of domain industry lobbyists with<br>
> a small group of free speech academics". I think it would be good to<br>
> point out that we speak on behalf of civil society in their countries<br>
> too, and encourage the GAC members, as representatives of their<br>
> governments, to extend the sphere of people they talk to and seek<br>
> advice from.<br>
><br>
> Julf<br>
><br>
</div></div></blockquote></div><br></div></div></div>
</blockquote></div><br></div>