<html><head><meta http-equiv="Content-Type" content="text/html; charset=utf-8"></head><body style="word-wrap: break-word; -webkit-nbsp-mode: space; line-break: after-white-space;" class="">Thanks for the update, Farzaneh.<div class=""><br class=""></div><div class="">I think your concerns about the current wording of the SSR footnote are very valid. It seems logical and predictable that this conflation would be a valuable tool for pushing IP interests moving forward. Your suggested edit permits the desired short-term outcome (lawful disclosure for IP) but has a clear demarcation to ward off bad precedents from working their way into the ICANN canon. I support objecting the current footnote wording in favor of this revision.</div><div class=""><br class=""></div><div class="">By the way, the PDF attached to your original email wouldn’t open for me. Could you please re-send?</div><div class=""><br class=""></div><div class="">Thanks,</div><div class="">Collin<br class=""><div><br class=""><blockquote type="cite" class=""><div class="">On Feb 3, 2019, at 8:10 PM, farzaneh badii <<a href="mailto:farzaneh.badii@GMAIL.COM" class="">farzaneh.badii@GMAIL.COM</a>> wrote:</div><br class="Apple-interchange-newline"><div class=""><div class=""><div dir="auto" class="">I had suggested that we ask the law firm whether purpose two is crafted rightly and is actually legal. Dont know if we asked that. Bird and Bird rep was present during re crafting this purpose at Toronto meeting. Her suggestions I think were mostly discarded. One was to add the term “where necessary”.</div><div dir="auto" class=""><br class=""></div><div dir="auto" class="">Also note that the CEO once during the LA meeting told the CPs we are trying to diminish your liability. Is that a bad thing? While this might not be legally viable if ICANN take on a lot of risk to disclose personal info then this purpose is unfortunately a terrible purpose. But interestingly while ICANN wants to diminish cps liability, seems like ICANN org doesnt want to be the joint controller, but perhaps wants to be independent controller. It is very ambiguous. </div><div dir="auto" class=""><br class=""></div><div dir="auto" class="">But we had to compromise. I find the addition of footnote to this purpose extremely risky and will note my objection( though seems like NCSG as a whole does not want to object , i dont know) . I find the mention of SSR dangerous. But I couldnt get anywhere with my objections. </div><div dir="auto" class=""><br class=""></div><div dir="auto" class=""> I had to attend F2F remotely because I didnt get my Canadian visa on time since the chair of epdp decided that he should favor one person over 4 others and hold the meeting outside of the US (wonder why that never happens to me). So I invite others who were present to correct the record if I am wrong somewhere. <br class=""></div></div><div class=""><br class=""><div class="gmail_quote"><div dir="ltr" class="">On Sun, Feb 3, 2019 at 11:17 AM James Gannon <<a href="mailto:james@cyberinvasion.net" class="">james@cyberinvasion.net</a>> wrote:<br class=""></div><blockquote class="gmail_quote" style="margin:0 0 0 .8ex;border-left:1px #ccc solid;padding-left:1ex">



<div style="word-wrap:break-word;line-break:after-white-space" class="">
Interesting, as (I assume) one of the few people on this list who is registered as a DPO I think its very interesting to see the group come to those conclusions, its certainly not a risk I would accept in the firm that I am DPO for, will be interesting to see
 how ICANN navigates that with the various DPAs who are surely going to test that interpretation of legitimate interest.</div><div style="word-wrap:break-word;line-break:after-white-space" class=""><br class="">
<div class=""><br class="">
<blockquote type="cite" class="">
<div class="">On 3 Feb 2019, at 17:13, Ayden Férdeline <<a href="mailto:icann@ferdeline.com" target="_blank" class="">icann@ferdeline.com</a>> wrote:</div>
<br class="m_7449579812413460415Apple-interchange-newline">
<div class="">
<div class="">The EPDP team does have external counsel (Bird & Bird), who have issued advice on some topics, including interpretation of 6(1)(b) (contractual necessity) and other pieces of the GDPR where our Legal Committee has thought it necessary to seek
 clarification from counsel. However in this particular instance, from what I recall, the EPDP team felt comfortable making the analysis ourselves. I am personally comfortable with the language. Note that there is a balancing test; the disclosure of registration
 data to a third party is not automatic, and only occurs if the contracted party assesses the harm to the registrant is outweighed by the legitimate interests of the third party. I happen to think this is a high bar, and that most contracted parties will be
 risk-adverse, so registration data is unlikely to be disclosed too freely. I don't think you can rely on consent here, because the circumstances in which I think data should be disclosed (i.e.
<i class="">legitimate</i> investigations of abuse, fraud) are unlikely to result in bad actors consenting to the disclosure of their registration data.<br class="">
</div>
<div class=""><br class="">
</div>
<div class="m_7449579812413460415protonmail_signature_block">
<div class="m_7449579812413460415protonmail_signature_block-user">
<div class="">Ayden <br class="">
</div>
</div>
<div class="m_7449579812413460415protonmail_signature_block-empty m_7449579812413460415protonmail_signature_block-proton"><br class="">
</div>
</div>
<div class=""><br class="">
</div>
<div class="">‐‐‐‐‐‐‐ Original Message ‐‐‐‐‐‐‐<br class="">
</div>
<div class="">On Sunday, February 3, 2019 10:58 AM, James Gannon <<a href="mailto:james@cyberinvasion.net" target="_blank" class="">james@cyberinvasion.net</a>> wrote:<br class="">
</div>
<div class=""><br class="">
</div>
<blockquote type="cite" class="m_7449579812413460415protonmail_quote">
<div class="">I think ICANN will struggle to find a DPO who will work under the assertion that the disclosure of registration data is an activity covered under legitimate interest.
<br class="">
</div>
<div class="">
<div class="">Has the EPDP received external legal advise on any of these?<br class="">
</div>
<div class=""><br class="">
</div>
<div class="">
<div class=""><br class="">
</div>
<blockquote type="cite" class="">
<div class="">On 3 Feb 2019, at 16:56, Ayden Férdeline <<a href="mailto:icann@ferdeline.com" target="_blank" class="">icann@ferdeline.com</a>> wrote:<br class="">
</div>
<div class=""><br class="">
</div>
<div class="">
<div class="">Hi James,<br class="">
</div>
<div class=""><br class="">
</div>
<div class="">For purpose 2, the EPDP team has completed four lawfulness of processing tests, one for each of the following activities:<br class="">
</div>
<ul class="">
<li class="">collection of registration data<br class="">
</li><li class="">transfer of registration data from registrar to registry<br class="">
</li><li class="">disclosure of non-public registration data to third parties<br class="">
</li><li class="">retention of registration data by registrar<br class="">
</li></ul>
<div class="">
<div class="">In the case of the disclosure of registration data to third parties, we are not relying on consent, therefore Article 7 does not apply. We have assessed this as being a 6(1)(f) (legitimate interest) processing activity. However, in recognition
 of the fact that such a disclosure is not technically necessary to perform the registration contract between the registrant and registrar, the contracted party would still need to perform the requisite balancing test to ensure the third party's legitimate
 interests override the fundamental rights and freedoms of the data subject, before registration data is disclosed.<br class="">
</div>
<div class=""><br class="">
</div>
<div class="">Best wishes,<br class="">
</div>
<div class=""><br class="">
</div>
</div>
<div class="m_7449579812413460415protonmail_signature_block">
<div class="m_7449579812413460415protonmail_signature_block-user">
<div class="">Ayden  <br class="">
</div>
</div>
<div class="m_7449579812413460415protonmail_signature_block-empty m_7449579812413460415protonmail_signature_block-proton"><br class="">
</div>
</div>
<div class=""><br class="">
</div>
<div class="">‐‐‐‐‐‐‐ Original Message ‐‐‐‐‐‐‐<br class="">
</div>
<div class="">On Sunday, February 3, 2019 4:08 AM, James Gannon <<a href="mailto:james@CYBERINVASION.NET" target="_blank" class="">james@CYBERINVASION.NET</a>> wrote:<br class="">
</div>
<div class=""><br class="">
</div>
<blockquote type="cite" class="m_7449579812413460415protonmail_quote">
<div class="">Would love to know how purpose 2 is defined on a legal basis and also how it complies with Art 7 section 4.<br class="">
</div>
<div class=""><br class="">
</div>
<div class="">
<div class=""><br class="">
</div>
<blockquote type="cite" class="">
<div class="">On 3 Feb 2019, at 09:45, farzaneh badii <<a href="mailto:farzaneh.badii@gmail.com" target="_blank" class="">farzaneh.badii@gmail.com</a>> wrote:<br class="">
</div>
<div class=""><br class="">
</div>
<div class="">
<div dir="ltr" class="">
<div style="font-family:verdana,sans-serif" class="">Our update on EPDP work is overdue, so I thought I write my thoughts and report a bit on the developments, and others from EPDP team can chime in if they think I got something wrong. <br class="">
</div>
<div style="font-family:verdana,sans-serif" class=""><br class="">
</div>
<div style="font-family:verdana,sans-serif" class=""><b class="">where we are at:</b><br class="">
</div>
<div style="font-family:verdana,sans-serif" class="">we are now finalizing the preliminary report and need to come to a consensus quickly and send the report off to the council for approval. So pressure is high. We have to come up with an interim policy plan 
 to cover the gap between implementation and approval of the recs. <br class="">
</div>
<div style="font-family:verdana,sans-serif" class=""><br class="">
</div>
<div style="font-family:verdana,sans-serif" class=""><b class="">Our principles: </b><br class="">
</div>
<div style="font-family:verdana,sans-serif" class="">- Maximum data protection for domain name registrants globally<br class="">
</div>
<div style="font-family:verdana,sans-serif" class="">- Accountable disclosure and accountable receipt  of domain name registrants personal info<br class="">
</div>
<div style="font-family:verdana,sans-serif" class="">- Side with providing data protection when in doubt whether GDPR applies<br class="">
</div>
<div style="font-family:verdana,sans-serif" class="">- Keep ICANN's mission limited <br class="">
</div>
<div style="font-family:verdana,sans-serif" class=""><br class="">
</div>
<div style="font-family:verdana,sans-serif" class="">I have attached a PDF with markation of what we have problems with or doubts for the moment. I am still working on it but it's attached. <br class="">
</div>
<div style="font-family:verdana,sans-serif" class=""><br class="">
</div>
<div style="font-family:verdana,sans-serif" class=""> <b class="">Purposes for domain name registrants data processing -</b><br class="">
</div>
<div style="font-family:verdana,sans-serif" class=""><br class="">
</div>
<div style="font-family:verdana,sans-serif" class=""><br class="">
</div>
<div style="font-family:verdana,sans-serif" class="">
<ol class="">
<li class="">Purpose 1. To establish registrants rights (generally is a good purpose, in favor of registrants). Note that some would like to add the word obligation of domain name registrants to this purpose which we have resisted and argued that if they want
 to do that they need a standalone purpose. <br class="">
</li><li class="">Contributing to the maintenance of SSR through disclosure to lawful requests: we initially opposed this purpose because it's not a purpose for data processing. you don't collect data to disclose it later to third parties. Now the purpose has canged
 to: "Contributing to the maintenance of the security, stability, and <span style="color:rgb(182,8,46)" class="">
<span style="font-family:Helvetica" class=""><span style="font-size:9px" class="">resiliency of the</span></span></span>Domain Name System in accordance with ICANN’s mission through enabling responses to lawful data disclosure requests." This is not a bad compromise.
 But the footnotes are not very helpful. The first footnote says that this purpose does not preclude IP based requests. Though this was a compromise makes me very worried. We have always said that SSR does not include IP issues and this footnote can make it
 easier to include IP in SSR in the future. My solution would be to re-word this and say: This purpose does not preclude lawful disclosure for non-SSR issues i.e. trademark infringement (in accordance with ICANN bylaws). The details of the disclosure will be
 discussed in phase two. <br class="">
</li></ol>
<div class="">What we have achieved so far (relatively):<br class="">
</div>
<div class="">1. there might be no differentiation between legal and natural persons <br class="">
</div>
<div class="">2.Tech admin contact might become optional <br class="">
</div>
<div class="">3. There might be no differentiation in treating domain name registrants based on their geographical location<br class="">
</div>
<div class="">4. Thin registries might not have to implement thick registries policy (unsure about that, please correct me if I am wrong)<br class="">
</div>
<div class=""><br class="">
</div>
<div class=""><br class="">
</div>
<div class=""><br class="">
</div>
</div>
<div style="font-family:verdana,sans-serif" class=""><br class="">
</div>
<div style="font-family:verdana,sans-serif" class=""><br class="">
</div>
<div style="font-family:verdana,sans-serif" class=""><br class="">
</div>
<div class="">
<div dir="ltr" data-smartmail="gmail_signature" class="">
<div dir="ltr" class="">
<div class=""><span style="font-family:verdana,sans-serif" class="">Farzaneh</span><br class="">
</div>
</div>
</div>
</div>
</div>
<div class=""><span class=""><EPDP Team Draft Final Report - Annotated.pdf></span><br class="">
</div>
</div>
</blockquote>
</div>
</blockquote>
<div class=""><br class="">
</div>
</div>
</blockquote>
</div>
</div>
</blockquote>
<div class=""><br class="">
</div>
</div>
</blockquote>
</div>
<br class="">
</div>

</blockquote></div></div>-- <br class=""><div dir="ltr" class="gmail_signature" data-smartmail="gmail_signature"><div dir="ltr" class=""><div class=""><font face="verdana, sans-serif" class="">Farzaneh </font></div></div></div>
</div></blockquote></div><br class=""></div></body></html>