<html><head><meta http-equiv="Content-Type" content="text/html; charset=utf-8"></head><body style="word-wrap: break-word; -webkit-nbsp-mode: space; line-break: after-white-space;" class="">This is a vital point for NCSG - civil society organisation absolutely do have their staff and volunteers targeted for harassment, and WHOIS data has been used to do that in the past, and I think all organisational members of NCSG should be behind a strong defence of the PII of people associated with organisations. There have been multiple pushes from other parties that the privacy protection should not apply to corporations etc and we need to keep resisting that simplistic and inaccurate view. <div class=""><div class=""><br class=""></div><div class="">David <br class=""><div class=""><div><br class=""><blockquote type="cite" class=""><div class="">On 4 Aug 2018, at 12:41 am, Amr Elsadr <<a href="mailto:aelsadr@ICANNPOLICY.NINJA" class="">aelsadr@ICANNPOLICY.NINJA</a>> wrote:</div><div class=""><div class=""><div class=""><div class=""><blockquote type="cite" class=""><div class=""><div style="word-wrap: break-word; -webkit-nbsp-mode: space; line-break: after-white-space;" class=""><blockquote type="cite" class=""><div class="" style="word-wrap: break-word; -webkit-nbsp-mode: space; line-break: after-white-space;"><div class=""><div class=""><br class=""></div><div class="">And yes wholeheartedly should have a policy in that line to address and also protect the Individuals. Whilst it is not an issue with proxy or paying an extra to not reveal an Individual most of these registrants are companies. So on this end a policy is important.</div></div></div></blockquote></div></div></blockquote><br class=""></div></div><div class="">Quite right. The GDPR is applicable in the <i class=""><b class="">“protection of natural persons in relation to the processing of personal data”</b></i>, but it is probably worthwhile to note here that the GDPR also covers PII of natural persons representing organizations.</div><div class=""><br class=""></div><div class="">So if the contact in the registration data for a commercial entity I work for is me, and the contact listed is <a href="mailto:amr.elsadr@secondleveldomain.gTLD" class="">amr.elsadr@secondleveldomain.gTLD</a>, this data is also covered by the GDPR.</div><div class=""><br class=""></div><div class="">Thanks again.</div><div class=""><br class=""></div><div class="">Amr</div></div></div></blockquote></div><br class=""></div></div></div></body></html>