<div dir="ltr"><div dir="ltr"><div dir="ltr"><div class="gmail_default"><div class="gmail_default"><font face="verdana, sans-serif">Is granting access to sensitive personal information of domain name registrants in ICANN mission? </font></div><div class="gmail_default"><font face="verdana, sans-serif"><br></font></div><div class="gmail_default"><font face="verdana, sans-serif"><br></font></div><div class="gmail_default"><font face="verdana, sans-serif">Among the purposes, EPDP has come up with for ICANN to process WHOIS data I very much dislike: "Maintaining the security, stability and resiliency of the Domain Name System in accordance with ICANN’s mission through the enabling of lawful access for legitimate third-party interests to data elements collected for other purposes identified herein"</font></div><div class="gmail_default"><font face="verdana, sans-serif"><br></font></div><div class="gmail_default"><font face="verdana, sans-serif">This purpose conflates security, stability and resiliency (SSR) with enabling of lawful access for legitimate wrong interests to achieve their other purposes. I have said it many times before there are so many issues  here: </font></div><div class="gmail_default"><font face="verdana, sans-serif"><br></font></div><div class="gmail_default"><font face="verdana, sans-serif">1. SSR is not maintained through providing access to the legitimate third party to use UDRP or enforce their intellectual property. Putting the term here can be interpreted as such. </font></div><div class="gmail_default"><font face="verdana, sans-serif"><br></font></div><div class="gmail_default"><font face="verdana, sans-serif">2. The term  "In accordance with ICANN mission" was added to make it better because some argue that "access" is in ICANN mission, therefore, we can have this as a purpose and it's narrow. This suggestion came from Board liaison to EPDP. Well, I totally disagree. Granting access to domain name registrants data is not in ICANN mission. It is true that Annex G1 of the bylaws says: </font></div><div class="gmail_default"><font face="verdana, sans-serif"><br></font></div><blockquote class="gmail_quote" style="margin:0px 0px 0px 0.8ex;border-left:1px solid rgb(204,204,204);padding-left:1ex"><font face="verdana, sans-serif">"maintenance of and access to accurate and up-to-date information concerning registered names and name servers;"[1]</font></blockquote><div class="gmail_default"><font face="verdana, sans-serif"><br></font></div><div class="gmail_default"><font face="verdana, sans-serif">But one needs to read the paragraph in conjunction with the main Mission clause that says: "[ICANN]<i><b>coordinates the development and implementation of policies </b></i>concerning the registration of second-level domain names in generic top-level domains ("gTLDs"). In this role, <b><i>ICANN's scope is to coordinate the development and implementation of policies."</i></b></font></div><div class="gmail_default"><span style="font-family:verdana,sans-serif"><br></span></div><div class="gmail_default"><span style="font-family:verdana,sans-serif"><br></span></div><div class="gmail_default"><span style="font-family:verdana,sans-serif">Obviously, ICANN's mission is not to "grant" access to personal data of domain name registrants.ICANN's mission is</span><b style="font-family:verdana,sans-serif"> to coordinate the development and implementation of policies that maintain access to WHOIS</b><span style="font-family:verdana,sans-serif">. All my worries were that this was going to lead to ICANN becoming the organization that actually grants access. And my fear might not be baseless since ICANN clearly has the intention and Contracted Party obviously asked ICANN to explore its options. And bloating up SSR ... not a good idea</span><br></div><div class="gmail_default"><span style="font-family:verdana,sans-serif"><br></span></div><div class="gmail_default"><span style="font-family:verdana,sans-serif">Anyhow, I hope these thoughts are useful </span></div><div class="gmail_default"><span style="font-family:verdana,sans-serif"><br></span></div><div class="gmail_default"><br></div><div class="gmail_default"><span style="font-family:verdana,sans-serif"><br></span></div><div class="gmail_default"><span style="font-family:verdana,sans-serif"><br></span></div><div class="gmail_default"><font face="verdana, sans-serif"><br></font></div><div class="gmail_default"><font face="verdana, sans-serif"><br></font></div><div class="gmail_default"><font face="verdana, sans-serif"><br></font></div><div class="gmail_default"><font face="verdana, sans-serif"><br></font></div><div class="gmail_default"><font face="verdana, sans-serif"><br></font></div><div class="gmail_default"><font face="verdana, sans-serif"><br></font></div><div class="gmail_default"><font face="verdana, sans-serif"><br></font></div><div class="gmail_default"><font face="verdana, sans-serif"><br></font></div><div class="gmail_default"><font face="verdana, sans-serif"><br></font></div><div class="gmail_default"><font face="verdana, sans-serif"><br></font></div><div class="gmail_default"><font face="verdana, sans-serif"><br></font></div><div style="font-family:verdana,sans-serif"><br></div><div style="font-family:verdana,sans-serif">****</div><div><span style="font-family:verdana,sans-serif">[1] </span><font face="verdana, sans-serif">section 1.1. MISSION</font></div><div><font face="verdana, sans-serif">(a) The mission of the Internet Corporation for Assigned Names and Numbers ("ICANN") is to ensure the stable and secure operation of the Internet's unique identifier systems as described in this Section 1.1(a) (the "Mission"). Specifically, ICANN: [....] (i) Coordinates the allocation and assignment of names in the root zone of the Domain Name System ("DNS") and coordinates the development and implementation of policies concerning the registration of second-level domain names in generic top-level domains ("gTLDs"). In this role, ICANN's scope is to coordinate the development and implementation of policies: </font><span style="font-family:verdana,sans-serif">For which uniform or coordinated resolution is reasonably necessary to facilitate the openness, interoperability, resilience, security and/or stability of the DNS including, with respect to </span>gTLD registrars<span style="font-family:verdana,sans-serif"> and registries, policies in the areas described in Annex G-1 and Annex G-2;</span></div><div><span style="font-family:verdana,sans-serif"><br></span></div><div><span style="font-family:verdana,sans-serif"><br></span></div></div><div><div dir="ltr" class="gmail_signature"><div dir="ltr"><div><font face="verdana, sans-serif">Farzaneh </font></div></div></div></div></div></div></div>