<html>
<head>
<meta content="text/html; charset=utf-8" http-equiv="Content-Type">
</head>
<body bgcolor="#FFFFFF" text="#000000">
<p>Looks good to me! Perhaps for the next step we could add timing
-- so that we know the minutes for each section in our limited
time period?</p>
<p>Best, Kathy<br>
</p>
<br>
<div class="moz-cite-prefix">On 2/19/2018 4:17 PM, farzaneh badii
wrote:<br>
</div>
<blockquote
cite="mid:CAN1qJvC8dEy0JR9Td2fZ2T_83JiS6FxM3=j0ac=kfRMNtJrTgw@mail.gmail.com"
type="cite">
<div dir="ltr">
<div class="gmail_default"
style="font-family:verdana,sans-serif">Thanks a lot everyone
with the very good suggestions:</div>
<div class="gmail_default"
style="font-family:verdana,sans-serif"><br>
</div>
<div class="gmail_default"
style="font-family:verdana,sans-serif">We can go with </div>
<div class="gmail_default"
style="font-family:verdana,sans-serif"><br>
</div>
<div class="gmail_default">
<div class="gmail_default"><font face="verdana, sans-serif">Agenda
of NCSG meeting with GAC:</font></div>
<div class="gmail_default"><font face="verdana, sans-serif"><br>
</font></div>
<div class="gmail_default"><font face="verdana, sans-serif">-
Background on NCSG, </font><span
style="font-family:verdana,sans-serif">our values and
convergence of our values with GAC</span></div>
<div class="gmail_default"><span
style="font-family:verdana,sans-serif"><br>
</span></div>
<div class="gmail_default"><span
style="font-family:verdana,sans-serif">- Rights Protection
Mechanisms: Our NCSG view </span></div>
<div class="gmail_default"><span
style="font-family:verdana,sans-serif"><br>
</span></div>
<div class="gmail_default"><font face="verdana, sans-serif">-
Privacy</font></div>
<div class="gmail_default"><font face="verdana, sans-serif"><br>
</font></div>
<div class="gmail_default"><font face="verdana, sans-serif">-
Wrap up </font></div>
<div class="gmail_default"><font face="verdana, sans-serif"><br>
</font></div>
<div class="gmail_default"><font face="verdana, sans-serif">I
will submit this to NCSG PC.</font></div>
<div class="gmail_default"><font face="verdana, sans-serif"><br>
</font></div>
<div class="gmail_default"><font face="verdana, sans-serif">Best </font></div>
<div class="gmail_default"><font face="verdana, sans-serif"><br>
</font></div>
<div class="gmail_default"><font face="verdana, sans-serif">Farzaneh </font></div>
<div class="gmail_default"
style="font-family:verdana,sans-serif"><br>
</div>
</div>
</div>
<div class="gmail_extra"><br clear="all">
<div>
<div class="gmail_signature" data-smartmail="gmail_signature">
<div dir="ltr">
<div><font face="verdana, sans-serif">Farzaneh </font></div>
</div>
</div>
</div>
<br>
<div class="gmail_quote">On Mon, Feb 12, 2018 at 1:20 PM, Nick
Shorey <span dir="ltr"><<a moz-do-not-send="true"
href="mailto:lists@nickshorey.com" target="_blank">lists@nickshorey.com</a>></span>
wrote:<br>
<blockquote class="gmail_quote" style="margin:0 0 0
.8ex;border-left:1px #ccc solid;padding-left:1ex">
<div dir="ltr">
<div>Hi everyone,</div>
<div><br>
</div>
<div>GDPR and privacy are definitely the priority issues
within ICANN's remit, and as we only have 30mins we
should probably keep it quite focused.</div>
<div><br>
</div>
<div>Next step is to think about what we want out of the
meeting? Do we want the GAC to take an action? Do we
want their agreement on a policy position? Do we want
them to commit to entering a dialogue?</div>
<div><br>
</div>
<div>In regards to GDPR, in my view I think we want the
GAC to at the very least review the position they've
taken on WHOIS.</div>
<div><br>
</div>
<div>The recent GAC documents on this (Abu Dhabi
communique, compliance model proposal) contain some very
worrying statements, which I can't help thinking have
been endorsed and submitted with very little scrutiny,
consultation or debate.</div>
<div><br>
</div>
<div><br>
</div>
<div>I think we need to broaden the GAC's source material
on GDPR, and politely challenge some of their
assumptions, by making several points:</div>
<div><br>
</div>
<div><br>
</div>
<div>- GDPR is THE most pressing issue for the ICANN
community since the IANA transition, and we need the
full engagement of the GAC (not simply delegating to
PSWG) in ensuring WHOIS policies adhere to the
principles of International law and Human Rights.</div>
<div><br>
</div>
<div>- WHOIS personal data is not a reliable / best
practice intelligence source (as stated by PSWG) /
professionals use other sources as indicators of abuse;</div>
<div><br>
</div>
<div>- Governments aalready have court orders, which are a
much more effective and legally enforceable mechanism,
including for intellectual property (UK has LEA for
this);</div>
<div><br>
</div>
<div>- Consumer protection is not a justified reason for
overriding privacy. End users don't reference WHOIS (CCT
study) and as an example, public WHOIS data is not even
referenced as a requirement under the UK Companies Act
(companies have to provide registration details on
websites, but no mention of WHOIS);</div>
<div><br>
</div>
<div>- The requirement for publicly visible email
addresses will facilitate crime;</div>
<div><br>
</div>
<div>- Retaining data for 60 days beyond expiry is not
proportionate: a common example cited by PSWG is DGA
domains, where the domain will be used for abuse within
days of being registered. Thus if the domain was
registered for 1 year, the investigating agency will
have almost a whole year to make the request;</div>
<div><br>
</div>
<div>Kind regards,</div>
<div><br>
</div>
<div>Nick</div>
</div>
<div class="gmail_extra"><span class="HOEnZb"><font
color="#888888"><br clear="all">
<div>
<div class="m_3769679951905385691gmail_signature"
data-smartmail="gmail_signature">
<div dir="ltr">
<div>
<div dir="ltr"><b>Nick Shorey</b>
<div>Phone: <a moz-do-not-send="true"
href="tel:+44%207552%20455988"
value="+447552455988" target="_blank">+44
(0) 7552 455 988</a></div>
<div>Email: <a moz-do-not-send="true"
href="mailto:lists@nickshorey.com"
target="_blank">lists@nickshorey.com</a></div>
<div>Skype: nick.shorey</div>
<div>Twitter: @nickshorey</div>
<div>LinkedIn: <a moz-do-not-send="true"
href="http://www.linkedin.com/in/nicklinkedin"
target="_blank">www.linkedin.com/in/<wbr>nicklinkedin</a></div>
<div>Web: <a moz-do-not-send="true"
href="http://www.nickshorey.com"
target="_blank">www.nickshorey.com</a></div>
</div>
</div>
</div>
</div>
</div>
</font></span>
<div>
<div class="h5">
<br>
<div class="gmail_quote">On Mon, Feb 12, 2018 at 5:26
PM, Ayden Férdeline <span dir="ltr"><<a
moz-do-not-send="true"
href="mailto:icann@ferdeline.com"
target="_blank">icann@ferdeline.com</a>></span>
wrote:<br>
<blockquote class="gmail_quote" style="margin:0 0 0
.8ex;border-left:1px #ccc solid;padding-left:1ex">Hi,<br>
<br>
I think this question is somewhat similar to what
I asked the GAC during our Abu Dhabi bilateral,
when I said "we’re unsure as to how GAC members
consult with their justice departments in order to
find the right balance between maintaining public
safety while<br>
respecting fundamental rights such as the right to
privacy which can be found in the constitutions of
over 100 countries." See page 18 onwards of the
transcript: <a moz-do-not-send="true"
href="https://schd.ws/hosted_files/icann60abudhabi2017/e3/I60AUH_Mon30Oct2017-GAC%20meeting%20with%20the%20NCUC-en.pdf"
rel="noreferrer" target="_blank">https://schd.ws/hosted_files/i<wbr>cann60abudhabi2017/e3/I60AUH_M<wbr>on30Oct2017-GAC%20meeting%20wi<wbr>th%20the%20NCUC-en.pdf</a><br>
<br>
I think we need to be very delicate with questions
to do with what process the GAC follows. I'm
certainly curious as to how they form their
opinions, and work internally, but I don't know if
it appropriate for us to flat out say or even
insinuate that they are only consulting with their
trade representatives. And I do think that is the
insinuation some are making. Real or perceived,
right or wrong, we can't make it (in my opinion).<br>
<span class="m_3769679951905385691im
m_3769679951905385691HOEnZb"><br>
Best wishes,<br>
<br>
Ayden<br>
<br>
<br>
<br>
-------- Original Message --------<br>
</span>
<div class="m_3769679951905385691HOEnZb">
<div class="m_3769679951905385691h5"> On 12
February 2018 2:41 PM, Johan Helsingius <<a
moz-do-not-send="true"
href="mailto:julf@JULF.COM" target="_blank">julf@JULF.COM</a>>
wrote:<br>
<br>
>I really like Michael's suggestion:<br>
><br>
>>Could we ask the representatives more
generally about how they develop<br>
>> their policy positions, and whether
and how they consult with human<br>
>> rights/privacy/data protection voices
in government, or with domestic<br>
>> NGOs or civil society voices, in
formulating the policy positions that<br>
>> they bring to ICANN - maybe phrasing
the question a bit more broadly<br>
>> than just asking directly about the
RPMs. I feel like this might need<br>
>> to be approached delicately, but it
may be a good question to get the<br>
>> GAC delegates themselves to
reconsider...<br>
>><br>
> W§e have to remember that a lot of GAC
members are fairly junior,<br>
> pretty new to ICANN, and not always very
well briefed. They also<br>
> often biased to see GNSO as "A club of
domain industry lobbyists with<br>
> a small group of free speech academics".
I think it would be good to<br>
> point out that we speak on behalf of
civil society in their countries<br>
> too, and encourage the GAC members, as
representatives of their<br>
> governments, to extend the sphere of
people they talk to and seek<br>
> advice from.<br>
><br>
> Julf<br>
><br>
</div>
</div>
</blockquote>
</div>
<br>
</div>
</div>
</div>
</blockquote>
</div>
<br>
</div>
</blockquote>
<br>
</body>
</html>