<html><head><meta http-equiv="Content-Type" content="text/html charset=utf-8"></head><body style="word-wrap: break-word; -webkit-nbsp-mode: space; -webkit-line-break: after-white-space;" class="">This is a topic that has the potential to draw the attention of actors with little to no knowledge about ICANN’s structure and remit. With that in mind, one of the (many) things that I find problematic about this response the imprecision in language, particularly in the bulleted list of “potentially adverse scenarios”.<div class=""><br class=""></div><div class="">Take the last point for example: that a fragmented WHOIS would “make it significantly harder to identify fake news and impact the ability to take action against bad actors.” Who is the agent of action here, real or perceived? What is the role of WHOIS and ICANN in determining or rectifying fake news? The lack of clarity could easily be interpreted as an invitation to actors seeking to leverage the DNS for content regulation. </div><div class=""><br class=""></div><div class="">Disappointing to see such a knee-jerk response to Article 29’s thorough contribution.</div><div class=""><br class=""></div><div class="">Best,</div><div class="">Collin Kurre</div><div class=""></div><br class=""><div><blockquote type="cite" class=""><div class="">On Apr 12, 2018, at 11:06 PM, farzaneh badii <<a href="mailto:farzaneh.badii@gmail.com" class="">farzaneh.badii@GMAIL.COM</a>> wrote:</div><br class="Apple-interchange-newline"><div class=""><div dir="ltr" class=""><div class="gmail_default" style="font-family:verdana,sans-serif">And here is ICANN's response to Article 29 WP. </div><div class="gmail_default" style="font-family:verdana,sans-serif"><br class=""></div><div class="gmail_default" style="font-family:verdana,sans-serif"><br class=""></div><div class="gmail_default" style="font-family:verdana,sans-serif"><br class=""></div><div class="gmail_default" style="font-family:verdana,sans-serif"><br class=""></div><div class="gmail_default" style="font-family:verdana,sans-serif">Farzaneh<br class=""></div>
<br class=""><div class="gmail_quote"><br class=""><div class="gmail_default" style="font-family:verdana,sans-serif">​----​</div><br class=""><div bgcolor="white" lang="EN-US" link="blue" vlink="purple" class=""><div class="m_5524904452103774945WordSection1"><br class=""><p class="MsoNormal"><u class=""></u> <u class=""></u></p><p class="MsoNormal">Please see our <a href="https://www.icann.org/news/announcement-2018-04-12-en" target="_blank" class="">most recent announcement</a> <wbr class="">regarding the <a href="https://www.icann.org/en/system/files/correspondence/jelinek-to-marby-11apr18-en.pdf" target="_blank" class="">letter</a> from the
 Article 29 Working Party. The letter was published on our <a href="https://www.icann.org/resources/pages/correspondence" target="_blank" class="">main Correspondence page</a>, and linked to our <a href="https://www.icann.org/dataprotectionprivacy" target="_blank" class="">Data Protection/Privacy page</a>.<u class=""></u><u class=""></u></p><p class="MsoNormal"><u class=""></u> <u class=""></u></p><p class="MsoNormal">------------------------------<wbr class="">----<u class=""></u><u class=""></u></p><p class="MsoNormal"><u class=""></u> <u class=""></u></p><p class="MsoNormal"><b class="">ICANN Receives Data Protection/Privacy Guidance from Article 29 Working Party<u class=""></u><u class=""></u></b></p><p class="MsoNormal">LOS ANGELES – 12 April 2018 – The Internet Corporation for Assigned Names and Numbers ("ICANN") today announced that it has received a
<a href="https://www.icann.org/en/system/files/correspondence/jelinek-to-marby-11apr18-en.pdf" target="_blank" class="">
letter from the Article 29 Working Party (WP29)</a> [PDF, 400 KB] that provides guidance on the European Union's General Data Protection Regulation (GDPR) and its impact on the collection, retention and publication of domain name registration data and the WHOIS
 system. ICANN organization’s response to the letter from the Article 29 Working Party will be published shortly
<a href="https://www.icann.org/resources/pages/correspondence" target="_blank" class="">here</a>.</p><p class="MsoNormal"><u class=""></u> <u class=""></u></p><p class="MsoNormal">“We appreciate the guidance provided by the Article 29 Working Party on this important issue and have accepted an invitation to meet with the WP29 Technology Subgroup in Brussels on 23 April for further discussions,” said Göran Marby, ICANN
 president and CEO. “However, we are disappointed that the letter does not mention our request for a moratorium on enforcement of the law until we implement a model. Without a moratorium on enforcement, WHOIS will become fragmented and we must take steps to
 mitigate this issue. As such, we are studying all available remedies, including legal action in Europe to clarify our ability to continue to properly coordinate this important global information resource. We will provide more information in the coming days.”</p><p class="MsoNormal"><u class=""></u> <u class=""></u></p><p class="MsoNormal">A moratorium on enforcement action by DPAs would potentially allow for the introduction of an agreed-upon accreditation model and for the registries and registrars to implement the accreditation model in conjunction with the measures in
 the agreed final interim compliance model. It will also allow for reconciliation between the advice ICANN has received from its Governmental Advisory Committee (GAC) and the Article 29 Working Party. Unless there is a moratorium, we may no longer be able to
 give instructions to the contracted parties through our agreements to maintain WHOIS. Without resolution of these issues, the WHOIS system will become fragmented until the interim compliance model and the accreditation model are implemented.</p><p class="MsoNormal"><u class=""></u> <u class=""></u></p><p class="MsoNormal">A fragmented WHOIS would no longer employ a common framework for generic top-level domain (gTLD) registration directory services. Registries and registrars would likely implement varying levels of access to data depending on their interpretations
 of the law.</p><p class="MsoNormal">“In parallel, we will carefully consider this advice, along with all of the input we have received from the multistakeholder community, before making changes to the current iteration of the
<a href="https://www.icann.org/en/system/files/files/gdpr-compliance-interim-model-08mar18-en.pdf" target="_blank" class="">
proposed interim model</a>,” Marby continued. “As a part of this, we will explore all options as we continue dialogues with DPAs and the interested parties that comprise the multistakeholder community.”</p><p class="MsoNormal"><u class=""></u> <u class=""></u></p><p class="MsoNormal">It’s important to balance the right to privacy with the need for information. While ICANN recognizes the importance of the GDPR and its goal of protecting personal data, parts of the ICANN community have noted the negative impact of a fragmented
 WHOIS. For example, it will hinder the ability of law enforcement to get important information and the anti-spam community to help ensure the Internet protects end-users. It will also:</p>
<ul style="margin-top:0in" type="disc" class="">
<li class="MsoNormal" style="margin-left:0in">Protect the identity of criminals who may register hundreds of domain names specifically for use in cyberattacks;</li><li class="MsoNormal" style="margin-left:0in">Hamper the ability of consumer protection agencies who track the traffic patterns of illicit businesses;</li><li class="MsoNormal" style="margin-left:0in">Stymie trademark holders from protecting intellectual property; and</li><li class="MsoNormal" style="margin-left:0in">Make it significantly harder to identify fake news and impact the ability to take action against bad actors.</li></ul><p class="MsoNormal"><u class=""></u> <u class=""></u></p><p class="MsoNormal">These are just a few examples from a long list of potentially adverse scenarios.</p><p class="MsoNormal">Marby also requested that the DPAs include ICANN in any proceedings relating to WHOIS, and asks that it be included in all discussions and actions of the privacy regulators with the other WHOIS data controllers. He also said that ICANN
 org is continuing its efforts to prepare for implementation of a new model. Additional information on ICANN’s data protection/privacy activities, including legal analyses, proposed compliance models, and community feedback is published
<a href="https://www.icann.org/dataprotectionprivacy" target="_blank" class="">here</a>.  </p><p class="MsoNormal"><u class=""></u> <u class=""></u></p><p class="MsoNormal">We encourage the community to provide feedback and continue our dialogues on future activities. You may share your views with us via email at
<a href="mailto:gdpr@icann.org" target="_blank" class="">gdpr@icann.org</a>.</p><p class="MsoNormal"><u class=""></u> <u class=""></u></p><p class="MsoNormal"><u class=""></u> <u class=""></u></p>
<div class="">
<div class=""><p class="MsoNormal"><span style="font-size:12.0pt" class=""><u class=""></u> <br class=""></span></p></div>
</div>
</div>
</div>

<br class="">______________________________<wbr class="">_________________<br class="">
So-ac-sg-cleaders mailing list<br class="">
<a href="mailto:So-ac-sg-cleaders@icann.org" class="">So-ac-sg-cleaders@icann.org</a><br class="">
<a href="https://mm.icann.org/mailman/listinfo/so-ac-sg-cleaders" rel="noreferrer" target="_blank" class="">https://mm.icann.org/mailman/<wbr class="">listinfo/so-ac-sg-cleaders</a><br class="">
<br class=""></div><br class=""></div>
</div></blockquote></div><br class=""></body></html>