<html><head></head><body>Hi again,<div class=""><br class=""/></div><div class="">One other point I forgot to raise:<br class=""/><div><br class=""/><blockquote type="cite" class=""><div class="">On Aug 3, 2018, at 6:01 PM, Kris Seeburn <<a href="mailto:seeburn.k@gmail.com" class="">seeburn.k@gmail.com</a>> wrote:</div><br class="Apple-interchange-newline"/><div class=""><meta http-equiv="Content-Type" content="text/html; charset=utf-8" class=""/><meta http-equiv="Content-Type" content="text/html; charset=utf-8" class=""/></div></blockquote><div><br class=""/></div><div>[SNIP]</div><br class=""/><blockquote type="cite" class=""><div class=""><div style="word-wrap: break-word; -webkit-nbsp-mode: space; line-break: after-white-space;" class=""><blockquote type="cite" class=""><div class="" style="word-wrap: break-word; -webkit-nbsp-mode: space; line-break: after-white-space;"><div class=""><div class=""><br class=""/></div><div class="">And yes wholeheartedly should have a policy in that line to address and also protect the Individuals. Whilst it is not an issue with proxy or paying an extra to not reveal an Individual most of these registrants are companies. So on this end a policy is important.</div></div></div></blockquote></div></div></blockquote><br class=""/></div></div><div>Quite right. The GDPR is applicable in the <i class=""><b class="">“protection of natural persons in relation to the processing of personal data”</b></i>, but it is probably worthwhile to note here that the GDPR also covers PII of natural persons representing organizations.</div><div><br class=""/></div><div>So if the contact in the registration data for a commercial entity I work for is me, and the contact listed is <a href="mailto:amr.elsadr@secondleveldomain.gTLD" class="">amr.elsadr@secondleveldomain.gTLD</a>, this data is also covered by the GDPR.</div><div><br class=""/></div><div>Thanks again.</div><div><br class=""/></div><div>Amr</div></body></html>