<div dir="ltr"><div class="gmail_default" style="font-family:verdana,sans-serif">Milton,</div><div class="gmail_default" style="font-family:verdana,sans-serif"><br></div><div class="gmail_default" style="font-family:verdana,sans-serif">We have discussed this issue, perhaps not at length, in the past with the members. So we (the NCSG members and the PC) are not necessarily uninformed about the issue but thank you for explicitly calling for a discussion.</div><div class="gmail_default" style="font-family:verdana,sans-serif"><br></div><div class="gmail_default" style="font-family:verdana,sans-serif">The one thing I want to prevent when it comes to legal and natural distinction is to enable some stakeholders to use the distinction as an excuse for making more registrants data public and accessible. As you know, this is what some stakeholders have been wanting to do, despite the fact that we are also coming up with a mechanism that can legitimately give them access to this data. But I guess that's too much work for them and they want to keep their good old WHOIS as public as possible. </div><div class="gmail_default" style="font-family:verdana,sans-serif"><br></div><div class="gmail_default" style="font-family:verdana,sans-serif">I was concerned about the registrants being obliged to identify themselves as legal or natural persons. This would have been worrying. You are saying that they are not obliged to, which is good, but some registrars want to make that distinction. </div><div class="gmail_default" style="font-family:verdana,sans-serif"><br></div><div class="gmail_default" style="font-family:verdana,sans-serif">I agree that legal entities should be able to identify themselves as such and some domain name registrants even want to publish their information in the registration database.</div><div class="gmail_default" style="font-family:verdana,sans-serif"><br></div><div class="gmail_default" style="font-family:verdana,sans-serif">I think the one solution would be that the registrar should not punish a registrant that does not respond to the question about being a legal or a natural person and always consider someone who doesn't respond to the question, a natural person. Have you discussed this, is it possible? <br></div><div class="gmail_default" style="font-family:verdana,sans-serif"><br></div><div class="gmail_default" style="font-family:verdana,sans-serif">I think the solution to inform the registrant of the consequences of declaring legal or natural personhood is also good, but it's not ideal. </div><div class="gmail_default" style="font-family:verdana,sans-serif"><br></div><div class="gmail_default" style="font-family:verdana,sans-serif">Because:</div><div class="gmail_default" style="font-family:verdana,sans-serif"><br></div><div class="gmail_default" style="font-family:verdana,sans-serif">- The distinction between legal and natural personhood might not exist in all the legal systems around the world or if it does, it is not customary for people to use it as much as we see in the rest of the world. So the registrant might simply not know the answer. <br></div><div class="gmail_default" style="font-family:verdana,sans-serif">Also it is not that the registrant is not rational enough to make an informed decision. Some registrants might not be able to make a choice simply because they don't speak English. But I don't know how much that can affect the decision or if it's farfetched. </div><div class="gmail_default" style="font-family:verdana,sans-serif"><br></div><div class="gmail_default" style="font-family:verdana,sans-serif">- Another issue that we might consider is the protection of vulnerable domain name registrants that are legal persons. We know that legal persons are not always commercial organizations or businesses, they can be human rights organizations or political organizations that are under-attack and in danger. Does the solution to inform them about the consequences prevent them from publishing their sensitive info in WHOIS? I am not sure that can even be answered.</div><div class="gmail_default" style="font-family:verdana,sans-serif"><br></div><div class="gmail_default" style="font-family:verdana,sans-serif"><br></div><div class="gmail_default" style="font-family:verdana,sans-serif">I am not sure about the solution to ask the registrar to decide legal/natural personhood. It is actually a very interesting and libertarian idea: businesses want to protect their customers, they have enough information about WHOIS to protect them so they do the right thing and when in doubt consider the registrant a natural person unless the registrant explicitly says they are a legal person. But I am not so sure about the incentives of the registrars in this case.</div><div class="gmail_default" style="font-family:verdana,sans-serif"><br></div><div class="gmail_default" style="font-family:verdana,sans-serif">Overall, I think giving the registrant the option to identify themselves as legal or natural (with all the caveats and informing them about the consequences) is what we might be able to live with. </div><div class="gmail_default" style="font-family:verdana,sans-serif"><br></div><div class="gmail_default" style="font-family:verdana,sans-serif"><br></div><div class="gmail_default" style="font-family:verdana,sans-serif"></div><div class="gmail_default" style="font-family:verdana,sans-serif"></div><div class="gmail_default" style="font-family:verdana,sans-serif"><br clear="all"></div><div><div dir="ltr" class="gmail_signature" data-smartmail="gmail_signature"><div dir="ltr"><div><font face="verdana, sans-serif">Farzaneh </font></div></div></div></div><br></div><br><div class="gmail_quote"><div dir="ltr" class="gmail_attr">On Sat, Apr 24, 2021 at 5:49 PM Mueller, Milton L <<a href="mailto:milton@gatech.edu">milton@gatech.edu</a>> wrote:<br></div><blockquote class="gmail_quote" style="margin:0px 0px 0px 0.8ex;border-left:1px solid rgb(204,204,204);padding-left:1ex">
<div lang="EN-US">
<div class="gmail-m_-3870664314406317465WordSection1">
<p class="MsoNormal">Dear Noncommercials,<u></u><u></u></p>
<p class="MsoNormal">I am one of your representatives of the EPDP, and ICANN working group that is trying to bring ICANN’s Whois policy into compliance with privacy principles.
<u></u><u></u></p>
<p class="MsoNormal">Just yesterday we received this statement from the current chair of the group, Keith Drazek:<u></u><u></u></p>
<p style="margin-right:0in;margin-left:0.25in;margin-bottom:0.0001pt;vertical-align:baseline">
<span style="font-size:7pt"> </span><span style="font-size:6pt;font-family:Calibri,sans-serif">
</span><span style="font-size:11pt;font-family:Calibri,sans-serif">The EPDP Team is a representative group – you have all been appointed by your respective groups to represent them in this effort. As a result, any proposals and interventions you make are
expected to be on behalf of your group. We understand that this requires significant coordination which is not always possible in real-time but it is important that we do not find ourselves in a situation where a specific proposal or suggestion is debated
to then find that other members of the same group do not stand behind the proposal or suggestion. <u></u><u></u></span></p>
<p class="MsoNormal"><span style="font-size:10pt"><u></u> <u></u></span></p>
<p class="MsoNormal">I suspect Keith found it necessary to say this because lately another NCSG representative on the EPDP, Stephanie, and I have been openly disagreeing. Let me explain what the disagreement is about. We will have to appeal to the Policy Committee,
and the membership, to help resolve it. <u></u><u></u></p>
<p class="MsoNormal"><u></u> <u></u></p>
<p class="MsoNormal">Privacy protections under the GDPR only apply to natural persons, that is to say living breathing humans, not to legal persons, i.e. corporations or companies. And in most cases, we do not mind if company data is published in their domain
record. In many cases it can even help with economic and legal accountability. However, we both recognize that there is a large gray area of small companies or home offices where the line between personal and legal is thin, blurry or nonexistent. A registrant
that is formally a legal person may want the privacy protection of a natural person.<u></u><u></u></p>
<p class="MsoNormal"><u></u> <u></u></p>
<p class="MsoNormal">One of the issues we are dealing with in Phase 2 is whether and how registrars should differentiate between those two types of registrants. Under the current Phase 1 agreement, contracted parties are not required to differentiate between
registrants who are legal or natural persons, but they can do so if they wish to. I believe both Stephanie and I (and the contracted parties) agree on NOT requiring them to differentiate.
<u></u><u></u></p>
<p class="MsoNormal"><u></u> <u></u></p>
<p class="MsoNormal">But if registrars DO choose to differentiate, we have to worry about HOW they do it. Currently, the EPDP is working on a guidance document that will set out ways to do it. I want to make sure that the guidance protects the rights of registrants.
<u></u><u></u></p>
<p class="MsoNormal"><u></u> <u></u></p>
<p class="MsoNormal">My position is that registrants should be given a clear choice to self-designate as a legal person or not. When given that choice, they must be clearly told that their data will be published, and if they don’t want the data published, they
should not self-designate as a legal person. Under my view, the registrant, and the registrant alone, should decide for themselves whether to declare as legal person or not.
<u></u><u></u></p>
<p class="MsoNormal"><u></u> <u></u></p>
<p class="MsoNormal">Stephanie’s position is that registrants are not smart enough to make this choice for themselves. Worse, her belief that registrants cannot look out for their own interests makes her in favor of the idea that REGISTRARS should be able to
make the choice for them. In other words, a commercial registrar, based on their own information about you, could decide that you are registering a domain name on behalf of a company and classify you as a legal person without your participation or consent.<u></u><u></u></p>
<p class="MsoNormal"><u></u> <u></u></p>
<p class="MsoNormal">In my view, this is a very bad idea, even a dangerous one. It makes the registrar responsible for verifying certain aspects of your identity. We already know that those who want more surveillance and control of registrants want registrars
to be more restrictive and take on a bigger role vetting who is registering domains. This idea is also very bad for the registrars, because if a registrar is making the decision about whether you are a legal or natural person, then the registrar will be legally
liable for the decision. Further down the road, those who want a more restrictive internet will love the precedent set, they will ask the registrars to do more and more to vet and regulate their customers.
<u></u><u></u></p>
<p class="MsoNormal"><u></u> <u></u></p>
<p class="MsoNormal">I believe that Stephanie has good motives for her position; as I understand it she thinks that if registrars have this ability to decide for the registrant, they will err on the side of non-disclosure. But this is very naïve. Yes, some
of the registrars we are dealing with in EPDP are sincere supporters of their customers privacy. But others are not. Further, Stephanie is forgetting about the fact that many registrars are operating in authoritarian countries where individual rights are not
respected. I am also deeply troubled by a position that registrants are children who cannot take care of themselves. I think Stephanie’s position is also motivated by the view that we are better off if there is no differentiation at all. This may be true,
but it is unrealistic. The default policy, ALREADY, is that registrars will be able to differentiate if they want to. I am trying to plan for the possibility that many of them will want to. If they do, we want registrants to be in control of their status,
not registrars or any other third party allegedly acting on their behalf.<u></u><u></u></p>
<p class="MsoNormal"><u></u> <u></u></p>
<p class="MsoNormal">My hope is that the membership and the PC will resolve this issue in favor of the “registrant in control” position.<u></u><u></u></p>
<p class="MsoNormal"><u></u> <u></u></p>
<p class="MsoNormal">Sorry for the long message<u></u><u></u></p>
<p class="MsoNormal"><u></u> <u></u></p>
<p class="MsoNormal">Dr. Milton L Mueller<u></u><u></u></p>
<p class="MsoNormal">Georgia Institute of Technology<u></u><u></u></p>
<p class="MsoNormal">School of Public Policy<u></u><u></u></p>
<p class="MsoNormal"><img width="196" height="79" style="width: 2.0416in; height: 0.8194in;" id="gmail-m_-3870664314406317465Picture_x0020_1" src="cid:17905ed47dd5b16b21" alt="IGP_logo_gold block"><u></u><u></u></p>
<p class="MsoNormal"><u></u> <u></u></p>
</div>
</div>
</blockquote></div>