<html><head></head><body>Hi Raphael,<div class=""><br class=""/></div><div class="">Same disclaimer as before…, this is not a topic I’m particularly well-versed in, so take whatever I say for granted at your own risk. ;-)</div><div class=""><br class=""/></div><div class="">Some comments in-line below:<br class=""/><div><br class=""/><blockquote type="cite" class=""><div class="">On May 23, 2020, at 5:18 PM, Raphael Beauregard-Lacroix <<a href="mailto:rbeauregardlacroix@GMAIL.COM" class="">rbeauregardlacroix@GMAIL.COM</a>> wrote:</div><br class="Apple-interchange-newline"/><div class="">
<div dir="ltr" class="">Hi Amr<div class=""><br class=""/></div><div class="">Thanks for the detailed comment. By and large I agree with your second point, and that is what I tried to convey. They certainly have to be proactive, and that is what they should emphasize. If they can mitigate that risk themselves, why bring it up as a risk? My point may boil down to their phrasing being bad optics in the end, which is not a major problem. I.e. we may all be in agreement on the substance here. Feel free to suggest alternative wording :)</div><div class=""><br class=""/></div><div class="">As for your first point, I think it reaches to the comment Rafik made directly in the document as well. My response to that is: I'm not quite clear right now who PTI is/will be in the future, in the whole chain of command under data protection law. Probably just a data processor, taking orders (from an agency law perspective) from the controller which would be ICANN Org in this case.</div></div></div></blockquote><div><br class=""/></div><div>…, or the IETF as I have recently been reminded. The concerns raised by PTI on privacy/data protections may very well be due to protocols they are using. In fact, I find this to be a lot more likely as a source of concern than any policies developed at ICANN, which should have no impact on them, one way or the other.</div><div><br class=""/></div><div>I did a quick search on the topic, and found <a href="https://tools.ietf.org/html/rfc6973" class="">RFC 6973 - Privacy Considerations for Internet Protocols</a>, which dates back to 2013, and takes a look at some of the same issues we’re dealing with on the EPDP as a result of data protection regulation.</div><br class=""/><blockquote type="cite" class=""><div class=""><div dir="ltr" class=""><div class="">And my understanding is that the substance of such orders ultimately come from policy decisions, many of which are made by the community. </div><div class=""><br class=""/></div><div class="">I think PTI cares about the trust of the community because ultimately the community has an influence over whether ICANN renews its contract. It is true that only the registries and registrars are customers, and certainly their voice my carry further than our voice for example, were they to deem PTI untrustworthy (or trustworthy, for that matter.)</div></div></div></blockquote><div><br class=""/></div><div>Yeah…, the IANA Naming Function Contract is a 5-year renewable contract, subject to reviews by the IANA Function Review Team and also possibly subject to an IANA Naming Function Separation Process, should one should be initiated. However, my impression is that these safeguards exist to keep ICANN honest, not PTI. PTI is the entity set up to be the contractor, and enable the accountability mechanism, and is meant to follow instructions from different parts of ICANN resulting from the appropriate processes. So if IANA is separated from PTI, ICANN loses it too, which is kind of the point. So I’m not sure how privacy risks are necessarily linked with community issues, unless they concern IETF-developed protocols. Still…, the strategic plan document, there is no mention of any “community” in association with the risk due to the evolving landscape of privacy laws. These “community” risks are found elsewhere in the document.</div><div><br class=""/></div><div>On the other hand, there is very little by means of substance in this document, so a small bullet may imply a great deal more than what is actually there. I don’t know, really. PTI may have made an effort to explain these issues a little more thoroughly.</div><br class=""/><blockquote type="cite" class=""><div dir="ltr" class=""><div class="">But if you are right on the interpretation of the language from the report to start with (i.e. their point is about a standalone, not community-bound risk,) I agree with your point overall. I will try over this weekend to incorporate it under a more general umbrella of "what you (PTI) have written there is difficult to understand to start with, so here's alternative interpretations with alternative implications...) Or if you prefer, I can let you go ahead with that! Let me know.</div></div></blockquote><div><br class=""/></div><div>Thanks, Raphael…, not just for offering to make changes, but for picking up the pen on this draft comment to begin with. I don’t plan on making changes, and don’t expect you to make them because of anything I say. Like I said, I claim no expertise on this topic at all, and am only offering thoughts for discussion. I generally experience a knee-jerk reaction whenever someone says “privacy” or “EPDP”. :-) I’m willing to bet that there’s a lot more to this than I have any idea about.</div><br class=""/><blockquote type="cite" class=""><div dir="ltr" class=""><div class="">Have a nice day,</div></div></blockquote><div><br class=""/></div><div>You too.</div><div><br class=""/></div><div><div>Thanks again.</div><div><br class=""/></div><div>Amr</div></div><br class=""/><blockquote type="cite" class=""><div dir="ltr" class=""><div class=""> </div><div class=""><br class=""/></div></div></blockquote><blockquote type="cite" class=""><div dir="ltr" class=""><div class=""><br class=""/></div></div><br class=""/><div class="gmail_quote"><div dir="ltr" class="gmail_attr">On Sat, May 23, 2020 at 8:30 AM Amr Elsadr <<a href="mailto:aelsadr@icannpolicy.ninja" class="">aelsadr@icannpolicy.ninja</a>> wrote:<br class=""/></div><blockquote class="gmail_quote" style="margin:0px 0px 0px 0.8ex;border-left:1px solid rgb(204,204,204);padding-left:1ex"><div class="">Hi,<div class=""><br class=""/></div><div class="">I believe that some risks have been conflated in the draft NCSG response. The draft PTI Strategic Plan didn’t identify evolving data privacy regulation as a community-related risk. Rather, the risk identified was a stand-alone issue unrelated to the development of policy recommendations by the community. What PTI seems to believe may be a risk is the fact that an evolution in the data privacy regulation landscape exists to begin with. I think they’re very wrong in considering this a risk at all.</div><div class=""><br class=""/></div><div class="">I’m wading into territory that I have little understanding of, so please correct me if I’m mistaken, but the PTI’s concerns with an erosion of its trust and accountability should be focused on how its direct customers perceive its trustworthiness and accountability. If PTI’s customers are gTLD and ccTLD Registry Operators and Registrars, then where is the erosion of trust it refers to coming from?</div><div class=""><br class=""/></div><div class="">The way I see it, privacy/data protection laws have in the past not been sufficiently enforceable or harmonized, and that has had a negative impact on the certainty of the environment in which Registries and Registrars have operated. Now that it has changed, there is a more solid understanding of (or a more solid desire to understand and comply with) these laws and regulations.</div><div class=""><br class=""/></div><div class="">PTI’s own customers are themselves working towards variable degrees of changes to the way in which they operate to comply with these regulations, and there’s no reason why PTI should perceive this as a threat. The only threat in this context that I can see is for PTI’s customers to not comply with regulations, and cause damage both to themselves and the Registrants they serve. This should still have no impact on PTI’s role in carrying out the IANA functions, as far as I can tell. Unless there’s more to this potential “risk” that I don’t understand, it reads a little like hyperbole to me. PTI should probably just focus on continuing to serve its customers, and stay out of issues it is not mandated to deal with.</div><div class=""><br class=""/></div><div class="">Community-related risks in the draft operating plan and budget are another matter altogether, and I don’t understand the level of true risks involved, but would not discount them out-of-hand. For example, one community-related risk identified was simply the workload created by new policies developed by the community, and the possibility of PTI lacking the capacity to keep up with this workload. If this is a real issue, then it is right for PTI to flag it, and take the necessary steps to mitigate against it.</div><div class=""><br class=""/></div><div class="">Another community-related risk identified is the concern that PTI will be unable to meet all the community’s <i class="">“expectations and community deliverables due to dependency on ICANN Operating Plan and Budget”</i>. Again…, I don’t know if this is actually an issue, or not, but they’ve flagged it, so worth looking in to. If ICANN’s Operating Plan and Budget is a constraint on PTI’s ability to perform the IANA functions to the satisfaction of its customers, then something will clearly need to be done about it. If it is an exaggeration, and things may proceed without incident, then grand. I really don’t know, but I’m sure others here do.</div><div class=""><br class=""/></div><div class="">In any case, I don’t see PTI setting itself up to be an arbiter on policy recommendations developed by the community in any way. I don’t believe this is the risk or concern that they are trying to convey.</div><div class=""><br class=""/></div><div class="">I hope this helps.</div><div class=""><br class=""/></div><div class="">Thanks.</div><div class=""><br class=""/></div><div class="">Amr<br class=""/><div class=""><br class=""/><blockquote type="cite" class=""><div class="">On May 23, 2020, at 2:15 AM, Raphael Beauregard-Lacroix <<a href="mailto:rbeauregardlacroix@GMAIL.COM" target="_blank" class="">rbeauregardlacroix@GMAIL.COM</a>> wrote:</div><br class=""/><div class="">
<div dir="ltr" class="">Hi Tomslin, <div class=""><br class=""/></div><div class="">Thanks for jumping in! </div><div class=""><br class=""/></div><div class="">If I understand you correctly, your point is that the risk evoked here is that of conflicting data protection rules? I agree that this is a risk somewhere out there, but I don't quite make the link between a hypothetical "hard" conflict of laws and the trust of the community in PTI; would you have some language to suggest, either to add or modify what is in the comment already? </div><div class=""><br class=""/></div><div class="">Have a nice day, </div></div><br class=""/><div class="gmail_quote"><div dir="ltr" class="gmail_attr">On Fri, May 22, 2020 at 7:52 PM Tomslin Samme-Nlar <<a href="mailto:mesumbeslin@gmail.com" target="_blank" class="">mesumbeslin@gmail.com</a>> wrote:<br class=""/></div><blockquote class="gmail_quote" style="margin:0px 0px 0px 0.8ex;border-left:1px solid rgb(204,204,204);padding-left:1ex"><div dir="auto" class=""><div class="">Thanks for the draft comment Raphael. Much appreciated!</div><div dir="auto" class=""><br class=""/></div><div dir="auto" class="">In the comment regarding "evolving  data  privacy  regulation  landscape  may  have  impacts  on  the  level  of transparency  for  the  IANA  registries,  which  may  erode  trust  and  accountability" being a risk to  <i class="">Maintain  stakeholders’  trust  that  IANA  is  the  proper  home  for  enabling global  interoperability  through  unique  identifier  coordination,</i> </div><div dir="auto" class="">you wrote ".....to imply, for example, that data protection policies (including those seemingly developed by the community in the context of the Expedited Policy Development Process) may adversely affect “transparency,” “trust,” or “accountability,” represents a value judgement. This is problematic because PTI is not the final arbiter when it comes to the implementation of those values into the policies; the community is."</div><div dir="auto" class=""><br class=""/>In my opinion, I think it is fair for PTI to put that as risk, understanding that risk is a function of probability and impact. What they are saying there in my view is the fact that there is potential for different jurisdictional regulations to affect their ability to maintain stakeholders' trust.</div><div dir="auto" class=""><br class=""/><div dir="auto" class="">Cheers,<br class=""/>Tomslin<br class=""/>    </div><br class=""/><div class="gmail_quote" dir="auto"><div dir="ltr" class="gmail_attr">On Mon., 11 May 2020, 23:58 Raphael Beauregard-Lacroix, <<a href="mailto:rbeauregardlacroix@gmail.com" target="_blank" class="">rbeauregardlacroix@gmail.com</a>> wrote:<br class=""/></div><blockquote class="gmail_quote" style="margin:0px 0px 0px 0.8ex;border-left:1px solid rgb(204,204,204);padding-left:1ex"><div dir="ltr" class="">Hi all<div class=""><br class=""/></div><div class="">I have drafted a comment. Comments, suggestions, edits are welcome. The strategic plan itself is quite short so feel free to have a look too! </div><div class=""><br class=""/></div><div class="">Let's give it a week here so that the PC also have ample time for review. </div><div class=""><br class=""/></div><div class="">Have a nice day,</div><br class=""/><div class="gmail_quote"><div dir="ltr" class="gmail_attr">On Mon, Apr 20, 2020 at 7:34 PM Rafik Dammak <<a href="mailto:rafik.dammak@gmail.com" rel="noreferrer" target="_blank" class="">rafik.dammak@gmail.com</a>> wrote:<br class=""/></div><blockquote class="gmail_quote" style="margin:0px 0px 0px 0.8ex;border-left:1px solid rgb(204,204,204);padding-left:1ex"><div dir="ltr" class=""><div dir="ltr" class="">Hi all,<br class=""/></div><div dir="ltr" class=""><br class=""/></div><div class="">PTI just published a public consultation on Draft PTI FY21-24 Strategic Plan and asking for input. We commented previously on PTI budget and operating plan and so it is important for us to review this strategic plan. You can find here all the details here : <a href="https://www.icann.org/public-comments/draft-pti-fy21-24-strategic-plan-2020-04-20-en" rel="noreferrer" target="_blank" class="">https://www.icann.org/public-comments/draft-pti-fy21-24-strategic-plan-2020-04-20-en</a><br class=""/></div><div dir="ltr" class=""><div class=""><br class=""/></div><div class="">I created this google doc to be used during the drafting and accessible to all in order to kick off the discussion and comments: <a href="https://docs.google.com/document/d/1yjqC4fh-X9ISzJQWcxxwE75fHrNmnRuF93lCaweBjck/edit" rel="noreferrer" target="_blank" class="">https://docs.google.com/document/d/1yjqC4fh-X9ISzJQWcxxwE75fHrNmnRuF93lCaweBjck/edit</a> </div><div class=""><br class=""/></div><div class="">Please let me offline if you want to <span class="">volunteer</span> to participate in drafting the NCSG comment, join the drafting team and collaborating with finance committee . </div><div class=""><br class=""/></div><div class="">You can find previous public comments submitted by NCSG in this wiki page <a href="https://community.icann.org/display/gnsononcomstake/Public+Comments+-+2020" style="background-color:rgb(184,234,184)" rel="noreferrer" target="_blank" class="">https://community.icann.org/display/gnsononcomstake/Public+Comments+-+2020</a> and listing those who drafted them or <span class="">volunteered</span>.  </div><div class=""><br class=""/></div><div class="">Best Regards,</div><div class=""><br class=""/></div><div class="">Rafik Dammak</div><div class=""><br class=""/></div><div class="">NCSG Policy Committee Chair </div></div></div>
</blockquote></div></div>
</blockquote></div></div></div>
</blockquote></div>
</div></blockquote></div><br class=""/></div></div></blockquote></div>
</blockquote></div><br class=""/></div></body></html>