<div>I am hardly a fan of that footnote either, but this was a compromise that we agreed to. Note that the IPC are unlikely a fan of the other footnote, which we had inserted, calling for further legal analysis of this same purpose. If I was the IPC, I would be very wary of any legal scrutiny, given how weak many of their claims are.<br></div><div><br></div><div class="protonmail_signature_block"><div class="protonmail_signature_block-user"><div>Ayden <br></div></div><div class="protonmail_signature_block-proton protonmail_signature_block-empty"><br></div></div><div><br></div><div>‐‐‐‐‐‐‐ Original Message ‐‐‐‐‐‐‐<br></div><div> On Tuesday, February 5, 2019 12:59 AM, farzaneh badii <farzaneh.badii@GMAIL.COM> wrote:<br></div><div> <br></div><blockquote type="cite" class="protonmail_quote"><div dir="ltr"><div dir="ltr"><div dir="ltr"><div dir="ltr"><div style="font-family:verdana,sans-serif">Milton,<br></div><div style="font-family:verdana,sans-serif"><br></div><div style="font-family:verdana,sans-serif">I have mentioned that this purpose was a compromise. <br></div><div style="font-family:verdana,sans-serif"><br></div><div style="font-family:verdana,sans-serif">I know what happened in LA and while the "disclosure" compromise was a very good idea, the addition of SSR was not. I said this many times  during that meeting and subsequent meetings.   I objected to it many times, as SSR is undefined and I know the underlying problems (Amr mentioned as well).  Anyhow, we moved on, we accepted SSR, but I heard during the meeting in Toronto that we added a footnote  to purpose 2 which is about disclosure (page 15): "Purpose 2 should not preclude disclosure in the course of investigating intellectual property infringement"<br></div><div style="font-family:verdana,sans-serif"><br></div><div style="font-family:verdana,sans-serif">They have added "investigating IP infringement". Fine, we say it can be interpreted as it does not prevent disclosure in case of "investigating IP infringement". I also set aside the unsettling general and broad wording of "investigating IP infringement" <br></div><div style="font-family:verdana,sans-serif"><br></div><div style="font-family:verdana,sans-serif">Setting all that aside, what are we gonna do with Rec #2 on page 14: "In accordance with the EPDP Team Charter and in line with Purpose #2, the EPDP Team  undertakes to make a recommendation pertaining to a standardised model for lawful disclosure of non-public Registration Data (referred to in the Charter as ’Standardised Access’)[....] In this context, <u>the EPDP team will consider amongst other issues, disclosure in the course of intellectual property infringement and DNS abuse cases.</u><br></div><div style="font-family:verdana,sans-serif"><u>There is a need to confirm that disclosure for legitimate purposes is not incompatible with the purposes for which such data has been collected."</u><br></div><div style="font-family:verdana,sans-serif"><u></u><br></div><div style="font-family:verdana,sans-serif">In a way the battle is left open. In that ongoing battle, they might use the footnote  and rec 2 text to say that IP is not incompatible with SSR and even contributes to maintaining it. <br></div><div style="font-family:verdana,sans-serif"><br></div><div style="font-family:verdana,sans-serif">Hence, unapologetically professor Mueller, I dissent but I will not share my objection on other mailing lists as it seems like it's a done deal. <br></div><div style="font-family:verdana,sans-serif"><u></u><br></div><div style="font-family:verdana,sans-serif"><u></u><br></div><div style="font-family:verdana,sans-serif"><u></u><br></div><div style="font-family:verdana,sans-serif"><u></u><br></div><div style="font-family:verdana,sans-serif"><u></u><br></div><div style="font-family:verdana,sans-serif"><u></u><br></div><div style="font-family:verdana,sans-serif"><br></div><div style="font-family:verdana,sans-serif"><br></div><div style="font-family:verdana,sans-serif"><br></div><div style="font-family:verdana,sans-serif"><br></div><div style="font-family:verdana,sans-serif"><br></div><div style="font-family:verdana,sans-serif"><br></div><div style="font-family:verdana,sans-serif"><br></div><div style="font-family:verdana,sans-serif"><div>Purpose 2 should not preclude disclosure in the course of investigating intellectual property infringement. <br></div><div>25 The EPDP recognizes that ICANN has a responsibility to foster the openness, interoperability, resilience, security<br></div><div>and/or stability of the DNS in accordance with its stated mission (citation required). It may have a purpose to require<br></div><div>actors in the ecosystem to respond to data disclosure requests that are related to the security, stability and resilience<br></div><div>of the system. The proposed Purpose 2 in this report is a placeholder, pending further legal analysis of the<br></div><div>controller/joint controller relationship, and consultation with the EDPB. The EPDP recommends that further work be<br></div><div>done in phase 2 on these issues, including a review of a limited purpose related to the enforcement of contracted<br></div><div>party accountability for disclosure of personal data to legitimate requests.<br></div></div><div style="font-family:verdana,sans-serif"><br></div><div><div dir="ltr"><div dir="ltr"><div><span style="font-family:verdana, sans-serif">Farzaneh</span><br></div></div></div></div><div><br></div></div></div></div></div><div><br></div><div class="gmail_quote"><div dir="ltr">On Mon, Feb 4, 2019 at 2:41 PM Mueller, Milton L <<a href="mailto:milton@gatech.edu" target="_blank">milton@gatech.edu</a>> wrote:<br></div><blockquote class="gmail_quote" style="margin:0px 0px 0px 0.8ex;border-left:1px solid rgb(204,204,204);padding-left:1ex"><div lang="EN-US"><div><p><span style="color:rgb(31, 73, 125)"><span style="font-family:Calibri, sans-serif"><span style="font-size:11pt">I think it’s ok to ask Ruth, the Bird and Bird lawyer, whether Purpose 2 makes any sense. A clear answer NO is the only way to get out of it. NCSG going against
 it now isn’t going to change anything. <u></u><u></u></span></span></span><br></p><p><span style="color:rgb(31, 73, 125)"><span style="font-family:Calibri, sans-serif"><span style="font-size:11pt"><u></u> <u></u></span></span></span><br></p><p><span style="color:rgb(31, 73, 125)"><span style="font-family:Calibri, sans-serif"><span style="font-size:11pt">I don’t understand your “mention of SSR is dangerous” logic because SSR was meant to confine the purpose to things related to SSR of DNS (i.e., ICANN’s mission).
 The reason we have that footnote you hate so much is that the IPC knows that SSR purposes don’t include intellectual property. So all it says is that the purpose cannot be interpreted to PRECLUDE intellectual property concerns, but it doesn’t necessarily INCLUDE
 them, either. <u></u><u></u></span></span></span><br></p><p><span style="color:rgb(31, 73, 125)"><span style="font-family:Calibri, sans-serif"><span style="font-size:11pt"><u></u> <u></u></span></span></span><br></p><p><span style="color:rgb(31, 73, 125)"><span style="font-family:Calibri, sans-serif"><span style="font-size:11pt">While you weren’t in Toronto you were in LA and have been involved in the debate on this for many months. You know, therefore, that Purpose 2 was meant to prevent
 a laundry list of third party interests ranging from consumer protection to IPR to anything else the surveillance caucus can think of. Take a look at section 4 of the temp spec if you want to know what kind of shit Purpose 2 helped us get rid of. <u></u><u></u></span></span></span><br></p><p><span style="color:rgb(31, 73, 125)"><span style="font-family:Calibri, sans-serif"><span style="font-size:11pt"><u></u> <u></u></span></span></span><br></p><div style="border-top:none;border-right:none;border-bottom:none;border-left:1.5pt solid blue;padding:0in 0in 0in 4pt"><div><div style="border-right:none;border-bottom:none;border-left:none;border-top:1pt solid rgb(225,225,225);padding:3pt 0in 0in"><p><b><span style="font-family:Calibri, sans-serif"><span style="font-size:11pt">From:</span></span></b><span style="font-family:Calibri, sans-serif"><span style="font-size:11pt"> NCSG-Discuss [mailto:<a href="mailto:NCSG-DISCUSS@LISTSERV.SYR.EDU" target="_blank">NCSG-DISCUSS@LISTSERV.SYR.EDU</a>] <b>On Behalf Of </b>farzaneh badii<br> <b>Sent:</b> Sunday, February 3, 2019 3:11 PM<br> <b>To:</b> <a href="mailto:NCSG-DISCUSS@LISTSERV.SYR.EDU" target="_blank">NCSG-DISCUSS@LISTSERV.SYR.EDU</a><br> <b>Subject:</b> Re: Some update on EPDP work /Privacy in WHOIS<u></u><u></u></span></span></p></div></div><p><u></u> <u></u><br></p><div><div><p>I had suggested that we ask the law firm whether purpose two is crafted rightly and is actually legal. Dont know if we asked that. Bird and Bird rep was present during re crafting this purpose at Toronto meeting. Her suggestions I think
 were mostly discarded. One was to add the term “where necessary”.<u></u><u></u><br></p></div><div><p><u></u> <u></u><br></p></div><div><p>Also note that the CEO once during the LA meeting told the CPs we are trying to diminish your liability. Is that a bad thing? While this might not be legally viable if ICANN take on a lot of risk to disclose personal info then this purpose
 is unfortunately a terrible purpose. But interestingly while ICANN wants to diminish cps liability, seems like ICANN org doesnt want to be the joint controller, but perhaps wants to be independent controller. It is very ambiguous. <u></u><u></u><br></p></div><div><p><u></u> <u></u><br></p></div><div><p>But we had to compromise. I find the addition of footnote to this purpose extremely risky and will note my objection( though seems like NCSG as a whole does not want to object , i dont know) . I find the mention of SSR dangerous. But I
 couldnt get anywhere with my objections. <u></u><u></u><br></p></div><div><p><u></u> <u></u><br></p></div><div><p> I had to attend F2F remotely because I didnt get my Canadian visa on time since the chair of epdp decided that he should favor one person over 4 others and hold the meeting outside of the US (wonder why that never happens to me). So I
 invite others who were present to correct the record if I am wrong somewhere. <u></u><u></u><br></p></div></div><div><p><u></u> <u></u><br></p><div><div><p>On Sun, Feb 3, 2019 at 11:17 AM James Gannon <<a href="mailto:james@cyberinvasion.net" target="_blank">james@cyberinvasion.net</a>> wrote:<u></u><u></u><br></p></div><blockquote style="border-top:none;border-right:none;border-bottom:none;border-left:1pt solid rgb(204,204,204);padding:0in 0in 0in 6pt;margin-left:4.8pt;margin-right:0in"><div><p>Interesting, as (I assume) one of the few people on this list who is registered as a DPO I think its very interesting to see the group come to those conclusions, its certainly not a risk I would accept in the firm that I am DPO for, will
 be interesting to see how ICANN navigates that with the various DPAs who are surely going to test that interpretation of legitimate interest.<u></u><u></u><br></p></div><div><p><u></u> <u></u><br></p><div><p></p><div><br></div><div><u></u><u></u><br></div><p></p><blockquote style="margin-top:5pt;margin-bottom:5pt"><div><p>On 3 Feb 2019, at 17:13, Ayden Férdeline <<a href="mailto:icann@ferdeline.com" target="_blank">icann@ferdeline.com</a>> wrote:<u></u><u></u><br></p></div><p><u></u> <u></u><br></p><div><div><p>The EPDP team does have external counsel (Bird & Bird), who have issued advice on some topics, including interpretation of 6(1)(b) (contractual necessity) and other pieces of the GDPR where our Legal Committee has thought it necessary to
 seek clarification from counsel. However in this particular instance, from what I recall, the EPDP team felt comfortable making the analysis ourselves. I am personally comfortable with the language. Note that there is a balancing test; the disclosure of registration
 data to a third party is not automatic, and only occurs if the contracted party assesses the harm to the registrant is outweighed by the legitimate interests of the third party. I happen to think this is a high bar, and that most contracted parties will be
 risk-adverse, so registration data is unlikely to be disclosed too freely. I don't think you can rely on consent here, because the circumstances in which I think data should be disclosed (i.e. <i>legitimate</i> investigations of abuse, fraud) are unlikely to result in bad actors consenting to the disclosure of their registration data.<u></u><u></u><br></p></div><div><p><u></u> <u></u><br></p></div><div><div><div><p>Ayden <u></u><u></u><br></p></div></div><div><p><u></u> <u></u><br></p></div></div><div><p><u></u> <u></u><br></p></div><div><p><span style="font-family:"Cambria Math", serif">‐‐‐‐‐‐‐</span> Original Message <span style="font-family:"Cambria Math", serif">‐‐‐‐‐‐‐</span><u></u><u></u><br></p></div><div><p>On Sunday, February 3, 2019 10:58 AM, James Gannon <<a href="mailto:james@cyberinvasion.net" target="_blank">james@cyberinvasion.net</a>> wrote:<u></u><u></u><br></p></div><div><p><u></u> <u></u><br></p></div><blockquote style="margin-top:5pt;margin-bottom:5pt"><div><p>I think ICANN will struggle to find a DPO who will work under the assertion that the disclosure of registration data is an activity covered under legitimate interest. <u></u><u></u><br></p></div><div><div><p>Has the EPDP received external legal advise on any of these?<u></u><u></u><br></p></div><div><p><u></u> <u></u><br></p></div><div><div><p><u></u> <u></u><br></p></div><blockquote style="margin-top:5pt;margin-bottom:5pt"><div><p>On 3 Feb 2019, at 16:56, Ayden Férdeline <<a href="mailto:icann@ferdeline.com" target="_blank">icann@ferdeline.com</a>> wrote:<u></u><u></u><br></p></div><div><p><u></u> <u></u><br></p></div><div><div><p>Hi James,<u></u><u></u><br></p></div><div><p><u></u> <u></u><br></p></div><div><p>For purpose 2, the EPDP team has completed four lawfulness of processing tests, one for each of the following activities:<u></u><u></u><br></p></div><ul type="disc"><li>collection of registration data<u></u><u></u><br></li><li>transfer of registration data from registrar to registry<u></u><u></u><br></li><li>disclosure of non-public registration data to third parties<u></u><u></u><br></li><li>retention of registration data by registrar<u></u><u></u><br></li></ul><div><div><p>In the case of the disclosure of registration data to third parties, we are not relying on consent, therefore Article 7 does not apply. We have assessed this as being a 6(1)(f) (legitimate interest) processing activity. However, in recognition
 of the fact that such a disclosure is not technically necessary to perform the registration contract between the registrant and registrar, the contracted party would still need to perform the requisite balancing test to ensure the third party's legitimate
 interests override the fundamental rights and freedoms of the data subject, before registration data is disclosed.<u></u><u></u><br></p></div><div><p><u></u> <u></u><br></p></div><div><p>Best wishes,<u></u><u></u><br></p></div><div><p><u></u> <u></u><br></p></div></div><div><div><div><p>Ayden  <u></u><u></u><br></p></div></div><div><p><u></u> <u></u><br></p></div></div><div><p><u></u> <u></u><br></p></div><div><p><span style="font-family:"Cambria Math", serif">‐‐‐‐‐‐‐</span> Original Message <span style="font-family:"Cambria Math", serif">‐‐‐‐‐‐‐</span><u></u><u></u><br></p></div><div><p>On Sunday, February 3, 2019 4:08 AM, James Gannon <<a href="mailto:james@CYBERINVASION.NET" target="_blank">james@CYBERINVASION.NET</a>> wrote:<u></u><u></u><br></p></div><div><p><u></u> <u></u><br></p></div><blockquote style="margin-top:5pt;margin-bottom:5pt"><div><p>Would love to know how purpose 2 is defined on a legal basis and also how it complies with Art 7 section 4.<u></u><u></u><br></p></div><div><p><u></u> <u></u><br></p></div><div><div><p><u></u> <u></u><br></p></div><blockquote style="margin-top:5pt;margin-bottom:5pt"><div><p>On 3 Feb 2019, at 09:45, farzaneh badii <<a href="mailto:farzaneh.badii@gmail.com" target="_blank">farzaneh.badii@gmail.com</a>> wrote:<u></u><u></u><br></p></div><div><p><u></u> <u></u><br></p></div><div><div><div><p><span style="font-family:Verdana, sans-serif">Our update on EPDP work is overdue, so I thought I write my thoughts and report a bit on the developments, and others from EPDP team can chime in if they think I got something wrong. <u></u><u></u></span><br></p></div><div><p><span style="font-family:Verdana, sans-serif"><u></u> <u></u></span><br></p></div><div><p><b><span style="font-family:Verdana, sans-serif">where we are at:</span></b><span style="font-family:Verdana, sans-serif"><u></u><u></u></span><br></p></div><div><p><span style="font-family:Verdana, sans-serif">we are now finalizing the preliminary report and need to come to a consensus quickly and send the report off to the council for approval. So pressure is high. We have to come up with an interim
 policy plan  to cover the gap between implementation and approval of the recs. <u></u><u></u></span><br></p></div><div><p><span style="font-family:Verdana, sans-serif"><u></u> <u></u></span><br></p></div><div><p><b><span style="font-family:Verdana, sans-serif">Our principles: </span></b><span style="font-family:Verdana, sans-serif"><u></u><u></u></span><br></p></div><div><p><span style="font-family:Verdana, sans-serif">- Maximum data protection for domain name registrants globally<u></u><u></u></span><br></p></div><div><p><span style="font-family:Verdana, sans-serif">- Accountable disclosure and accountable receipt  of domain name registrants personal info<u></u><u></u></span><br></p></div><div><p><span style="font-family:Verdana, sans-serif">- Side with providing data protection when in doubt whether GDPR applies<u></u><u></u></span><br></p></div><div><p><span style="font-family:Verdana, sans-serif">- Keep ICANN's mission limited <u></u><u></u></span><br></p></div><div><p><span style="font-family:Verdana, sans-serif"><u></u> <u></u></span><br></p></div><div><p><span style="font-family:Verdana, sans-serif">I have attached a PDF with markation of what we have problems with or doubts for the moment. I am still working on it but it's attached. <u></u><u></u></span><br></p></div><div><p><span style="font-family:Verdana, sans-serif"><u></u> <u></u></span><br></p></div><div><p><span style="font-family:Verdana, sans-serif"> <b>Purposes for domain name registrants data processing -</b><u></u><u></u></span><br></p></div><div><p><span style="font-family:Verdana, sans-serif"><u></u> <u></u></span><br></p></div><div><p><span style="font-family:Verdana, sans-serif"><u></u> <u></u></span><br></p></div><div><ol start="1" type="1"><li><span style="font-family:Verdana, sans-serif">Purpose 1. To establish registrants rights (generally is a good purpose, in favor of registrants). Note that some would like to add the word obligation of domain name registrants to this purpose which we have resisted
 and argued that if they want to do that they need a standalone purpose. <u></u><u></u></span><br></li><li><span style="font-family:Verdana, sans-serif">Contributing to the maintenance of SSR through disclosure to lawful requests: we initially opposed this purpose because it's not a purpose for data processing. you don't collect data to disclose it later to third
 parties. Now the purpose has canged to: "Contributing to the maintenance of the security, stability, and </span><span style="color:rgb(182, 8, 46)"><span style="font-family:Helvetica, sans-serif"><span style="font-size:7pt">resiliency of the</span></span></span><span style="font-family:Verdana, sans-serif">Domain Name System in accordance with ICANN’s mission through enabling responses to lawful data disclosure
 requests." This is not a bad compromise. But the footnotes are not very helpful. The first footnote says that this purpose does not preclude IP based requests. Though this was a compromise makes me very worried. We have always said that SSR does not include
 IP issues and this footnote can make it easier to include IP in SSR in the future. My solution would be to re-word this and say: This purpose does not preclude lawful disclosure for non-SSR issues i.e. trademark infringement (in accordance with ICANN bylaws).
 The details of the disclosure will be discussed in phase two. <u></u><u></u></span><br></li></ol><div><p><span style="font-family:Verdana, sans-serif">What we have achieved so far (relatively):<u></u><u></u></span><br></p></div><div><p><span style="font-family:Verdana, sans-serif">1. there might be no differentiation between legal and natural persons <u></u><u></u></span><br></p></div><div><p><span style="font-family:Verdana, sans-serif">2.Tech admin contact might become optional <u></u><u></u></span><br></p></div><div><p><span style="font-family:Verdana, sans-serif">3. There might be no differentiation in treating domain name registrants based on their geographical location<u></u><u></u></span><br></p></div><div><p><span style="font-family:Verdana, sans-serif">4. Thin registries might not have to implement thick registries policy (unsure about that, please correct me if I am wrong)<u></u><u></u></span><br></p></div><div><p><span style="font-family:Verdana, sans-serif"><u></u> <u></u></span><br></p></div><div><p><span style="font-family:Verdana, sans-serif"><u></u> <u></u></span><br></p></div><div><p><span style="font-family:Verdana, sans-serif"><u></u> <u></u></span><br></p></div></div><div><p><span style="font-family:Verdana, sans-serif"><u></u> <u></u></span><br></p></div><div><p><span style="font-family:Verdana, sans-serif"><u></u> <u></u></span><br></p></div><div><p><span style="font-family:Verdana, sans-serif"><u></u> <u></u></span><br></p></div><div><div><div><div><p><span style="font-family:Verdana, sans-serif">Farzaneh</span><u></u><u></u><br></p></div></div></div></div></div><div><p><EPDP Team Draft Final Report - Annotated.pdf><u></u><u></u><br></p></div></div></blockquote></div></blockquote><div><p><u></u> <u></u><br></p></div></div></blockquote></div></div></blockquote><div><p><u></u> <u></u><br></p></div></div></blockquote></div><p><u></u> <u></u><br></p></div></blockquote></div></div><p>-- <u></u><u></u><br></p><div><div><div><p><span style="font-family:Verdana, sans-serif">Farzaneh </span> <u></u><u></u><br></p></div></div></div></div></div></div></blockquote></div></blockquote><div><br></div>