<div dir="ltr"><div dir="ltr"><div class="gmail_default" style="font-size:small"><font face="arial, sans-serif">Hi everyone, <br><br>This is Manju Chen. I'm also one of your representatives on the EPDP. I'm happy to see this thread going as it clears many misunderstandings and confusions. I have to admit I wasn't sure about what either Milton or Stephanie's proposal was about before seeing their elaboration on the mailing list. <br><br>Thinking people might feel as confused as I did, below I will try to provide a summary of the disagreements in the hope of furthering the group's discussion on the issue.<br><br>First of all, I think the disagreement boils down to 2 major questions.<br></font><ol style=""><li><font face="arial, sans-serif">Should we allow the 3rd scenario in the current guidance write-up?</font></li><li><font face="arial, sans-serif">Should we concede to the 'legal vs. natural' distinction?</font></li></ol><font face="arial, sans-serif"><br>To discuss question 1, we have to firstly know what 'the 3rd scenario' is about.<br>In the EPDP, we are currently discussing a 'guidance' (not a requirement) for CPs who wish to distinguish between legal vs. natural persons. 3 scenarios were proposed in the guidance:<br></font><ol style=""><li><font face="arial, sans-serif">Registrant (data subject) self-identification at time of data collection / registration</font></li><li><font face="arial, sans-serif">Registrant (data subject) self-identification after initial collection</font></li><li><font face="arial, sans-serif">Registrar determines type based on data provided</font></li></ol><font face="arial, sans-serif"><br>The 3rd scenario is where we're having problems with. To give more context, the current 3rd scenario write-up is as below:<br></font><ul style=""><li><font face="arial, sans-serif">The Registrar collects Registration Data and provisionally redacts the data.</font></li><li><font face="arial, sans-serif">The Registrar uses collected data to infer legal or natural person type.</font></li><li><font face="arial, sans-serif">If legal person is inferred by the Registrar and subsequently the Registrant (data subject) is informed (per guidance #3 above) and confirms that no personal data is present, the Registrar should (i) contact the provided contact details to verify the Registrant claim (ii) sets the registration data set to automated disclosure in response to SSAD queries and (iii) publishes the data. </font></li><li><font face="arial, sans-serif">If the Registrar has inferred natural person or has detected personal data, the Registrar must not disclose registration data unless the Registrant provides consent for publication or the Registrar Discloses the data in response to a legitimate disclosure request.</font></li></ul><font face="arial, sans-serif">Milton thinks we should not allow this scenario because it denies registrants the right to self-designation. A counterpoint might be made that staff has added the instruction for registrars to 'contact the registrant to verify' to mitigate the harm of possible wrong designation by the registrars.</font></div><div class="gmail_default" style="font-size:small"><font face="arial, sans-serif"><br>Stephanie seems to be OK with this scenario. (This was my impression, I might be wrong. Please feel free to correct me if I am Stephanie.) Her argument is that registrars should be able to reduce their risk by adjusting registrants' wrong self-designation. The counterpoint here is that this is not a 'registrant identifies and then checked by registrars' scenario.<br><br>In summary, I think the question we should answer here is:<br><ul><li><font face="arial, sans-serif"><b><u>Does the NCSG allow the scenario where 'registrars determine registrant's person type without providing registrants the option of doing it themselves first'?</u></b></font></li></ul><br>Now we come to question 2. The current guidance proposes a 2-step approach to distinguish between natural vs. legal persons:<br><ol><li><font face="arial, sans-serif">Ask registrant to identify as natural or legal.</font></li><li><font face="arial, sans-serif">If legal, ask registrant to confirm whether there is personal information in the data provided. If yes, data redacted. If no, data published.</font></li></ol>Note that this is a 'guidance', not mandatory requirements. Registrars will only do it when they wish to make the distinction. Also note that we're arguing for publish as 'automatic disclosure via SSAD', not publicly available online for everyone. <br><br>The disagreement here:</font></div><div class="gmail_default" style="font-size:small"><font face="arial, sans-serif"><br>Milton supports the 2-step approach. He agrees with the first step because it is the necessary political compromise to make to reach consensus within EPDP. (Again, please feel free to correct me if I misunderstood.) </font></div><div class="gmail_default" style="font-size:small"><font face="arial, sans-serif"><br>Stephanie opposes the 2-step approach. She argues that person type is hard to define, which leads to 2 points: a) we should just ask whether the data contains personal data, and b) registrars should be able to overrule registrant's self-designation to protect them.<br> <br>In summary, the questions we are asking here:<br><ul><li><font face="arial, sans-serif"><b><u>Do we agree with the 2-step approach on the premise that a) it stays as only guidance and b) registrants are given the option to 'not identify as either'?</u></b></font></li><li><font face="arial, sans-serif"><b><u>Or, do we stick to 'no distinction between natural and legal persons, only check the data types'?</u></b></font></li><li><font face="arial, sans-serif"><b><u>Do we agree registrars should be able to overrule registrants' self-designation? This has to be on the premise of 'registrar only overrules to hide and not disclose', but currently there's no such language in the policy.</u></b></font></li></ul><br>Hope this helps! <br><br></font></div><font face="arial, sans-serif"><span class="gmail_default" style="font-family:georgia,serif;font-size:small">Best,</span></font></div><div><font face="arial, sans-serif"><span class="gmail_default" style="font-family:georgia,serif;font-size:small">Manju</span><br></font></div><font face="arial, sans-serif"><br></font><div class="gmail_quote"><div dir="ltr" class="gmail_attr"><font face="arial, sans-serif">On Mon, Apr 26, 2021 at 5:11 AM Mueller, Milton L <<a href="mailto:milton@gatech.edu">milton@gatech.edu</a>> wrote:<br></font></div><blockquote class="gmail_quote" style="margin:0px 0px 0px 0.8ex;border-left:1px solid rgb(204,204,204);padding-left:1ex">
<div lang="EN-US">
<div class="gmail-m_1570404167473597983WordSection1">
<p><span style="color:rgb(31,73,125)"><font face="arial, sans-serif">Stephanie:<u></u><u></u></font></span></p>
<p><span style="color:rgb(31,73,125)"><font face="arial, sans-serif">I knew that you were against what I was proposing but until now I did not know what you were actually for. This is seemingly cleared up in the email below. In my response I will first clarify some
of the misunderstandings you have about the issue, then I will take a critical look at the proposal you have made.<u></u><u></u></font></span></p>
<p><font face="arial, sans-serif"><span style="color:rgb(31,73,125)">></span>At no time have I ever suggested that it would be acceptable for registrars to overrule my designation of
<span style="color:rgb(31,73,125)">></span>myself as a natural person, or in the case of a legal person, a statement that the contact data of employees
<span style="color:rgb(31,73,125)">></span>needs to be protected because it contains personal data.<span style="color:rgb(31,73,125)"><u></u><u></u></span></font></p>
<p><span style="font-size:11pt;color:rgb(31,73,125)"><font face="arial, sans-serif">I could provide evidence to the contrary. If you are backing away from that position now, it’s good, we will have an easier time coming to an agreement. If we agree on this, you
will then agree that the “3<sup>rd</sup> scenario” in the current Guidance should be deleted, as I have suggested? A yes or no would be good.<u></u><u></u></font></span></p>
<p><font face="arial, sans-serif"><span style="color:rgb(31,73,125)">></span>So to push all data of legal persons into a published registry is neither necessary or sound policy.<span style="color:rgb(31,73,125)"><u></u><u></u></span></font></p>
<p><span style="font-size:11pt;color:rgb(31,73,125)"><font face="arial, sans-serif">But that is not what we are debating. My idea gives legal persons who do not want to identify themselves as legal persons the right not to. No one is being pushed.
<u></u><u></u></font></span></p>
<p><font face="arial, sans-serif"><span style="color:rgb(31,73,125)">></span>Now lets talk about how difficult it is to differentiate between legal persons and individuals.<span style="color:rgb(31,73,125)">
</span>Milton makes it sound easy<span style="color:rgb(31,73,125)"><u></u><u></u></span></font></p>
<p><span style="font-size:11pt;color:rgb(31,73,125)"><font face="arial, sans-serif">Again, you seem to misunderstand the issue that is before us. We are not promoting a process of “differentiating between legal and natural persons” We are promoting an ability
to “Self-designate” as a legal person, if you want to. That is not hard at all. That is tremendously easy, if you do it the way I am proposing. If you say you are a legal person, the RDS treats you as one. If you don’t, it doesn’t.
<u></u><u></u></font></span></p>
<p><span style="font-size:11pt;color:rgb(31,73,125)"><font face="arial, sans-serif">You go on to raise valid concerns about the complexity of registering a domain. Surprisingly, this is followed by a proposals that would make the situation worse!
<u></u><u></u></font></span></p>
<p><span style="font-size:11pt;color:rgb(31,73,125)"><font face="arial, sans-serif">Here is how I interpret what you are proposing: I am using your own words to characterize your position, so I think it should be correct, but if it’s not let me know in your response:<u></u><u></u></font></span></p>
<p style="margin-left:0.5in"><font face="arial, sans-serif"><u></u><span style="font-size:10pt;color:rgb(31,78,121)"><span>a)<span style="font-style:normal;font-variant:normal;font-weight:normal;font-stretch:normal;font-size:7pt;line-height:normal">
</span></span></span><u></u><span style="font-size:11pt;color:rgb(31,78,121)">individuals who register a domain must knowledgeably attest to one of the
following statements</span><span style="font-size:10pt;color:rgb(31,78,121)"><u></u><u></u></span></font></p>
<p style="margin-left:1in">
<font face="arial, sans-serif"><u></u><span style="font-size:10pt;color:rgb(31,78,121)"><span><span style="font-style:normal;font-variant:normal;font-weight:normal;font-stretch:normal;font-size:7pt;line-height:normal">
</span>i.<span style="font-style:normal;font-variant:normal;font-weight:normal;font-stretch:normal;font-size:7pt;line-height:normal"> </span></span></span><u></u><span style="font-size:11pt;color:rgb(31,78,121)">they are
an individual, and if they choose to publish their personal information they are doing so in full knowledge of the risks and what will happen to their data</span><span style="font-size:10pt;color:rgb(31,78,121)"><u></u><u></u></span></font></p>
<p style="margin-left:1in">
<font face="arial, sans-serif"><u></u><span style="font-size:10pt;color:rgb(31,78,121)"><span><span style="font-style:normal;font-variant:normal;font-weight:normal;font-stretch:normal;font-size:7pt;line-height:normal">
</span>ii.<span style="font-style:normal;font-variant:normal;font-weight:normal;font-stretch:normal;font-size:7pt;line-height:normal"> </span></span></span><u></u><span style="font-size:10pt;color:rgb(31,78,121)">that they
are responsible for a legal person's registrations, and that they can attest to the fact that no personal information is being disclosed in the registration.<u></u><u></u></span></font></p>
<p style="margin-left:0.5in"><font face="arial, sans-serif"><u></u><span style="font-size:9pt;color:rgb(31,78,121)"><span>b)<span style="font-style:normal;font-variant:normal;font-weight:normal;font-stretch:normal;font-size:7pt;line-height:normal">
</span></span></span><u></u><span style="font-size:11pt;color:rgb(31,78,121)">if the contracted parties feel there might be an error in the designation
of "legal person" they should err on the side of caution and protect their customer's data</span><span style="font-size:9pt;color:rgb(31,78,121)"><u></u><u></u></span></font></p>
<p><span style="font-size:11pt;color:rgb(31,78,121)"><font face="arial, sans-serif">OK. Now we have a basis for comparison.
<u></u><u></u></font></span></p>
<p><span style="font-size:11pt;color:rgb(31,78,121)"><font face="arial, sans-serif">Note, first that item b) directly contradicts your claim that the registrant’s decision cannot be overridden.
The registrar would have the authority to look at what data they entered, decide it’s wrong, and change it. This implies that the registrars are carefully reviewing every registrants’ record at the point of registration, checking out what choices they make,
and making a decision about its validity. This is not a slippery slope, you are at the bottom of the hill already. Note also how meaningless it is to say to “err on the side of caution”. Many registrars will err on the side of the lowest expense. Other registrars
may be told by their government to differentiate. <u></u><u></u></font></span></p>
<p><span style="font-size:11pt;color:rgb(31,78,121)"><font face="arial, sans-serif">Note, too that your “attestations” in a) and b) are actually trying to differentiate between legal and
natural persons. In your criticism of my proposal, you said it was really difficult to do that. You raised many complications and procedural non-uniformities in the registration process. You said that not all jurisdictions recognize the term, You said registrants
can’t understand all that stuff. But here we see that your solution doubles down on the process of differentiation and makes it all legally actionable.
<u></u><u></u></font></span></p>
<p><span style="font-size:11pt;color:rgb(31,78,121)"><font face="arial, sans-serif">You are forcing – pushing was your word - registrants to make two legally consequential attestations
that are far more complicated than asking them whether they are a company. Then you are asking the registrar to check the accuracy of those attestations. I think we really want to avoid that. It is against the interests of both registrars and their customers.
<u></u><u></u></font></span></p>
<p><span style="font-size:11pt;color:rgb(31,78,121)"><font face="arial, sans-serif">What happens if the person making the registration and attests (as in b) that there is no personal information,
and they turn out to be wrong? Are they legally liable for violating their attestation? Thanks, Steph, for criminalizing domain name registration.
<u></u><u></u></font></span></p>
<p><font face="arial, sans-serif"><span style="color:rgb(31,73,125)">></span>I believe that if the contracted parties, who are the data controllers in this situation and therefore own the
<span style="color:rgb(31,73,125)">></span>risk and the liability attendant with this decision, have to do this verification or trust the decision of the
<span style="color:rgb(31,73,125)">></span>registrant, we will see either rising costs of domain names (if they do it right) or the same kind of opt-in
<span style="color:rgb(31,73,125)">></span>situation we see throughout the world now, where people opt in to things without understanding their
<span style="color:rgb(31,73,125)">></span>risk.<span style="color:rgb(31,73,125)"><u></u><u></u></span></font></p>
<p><span style="font-size:11pt;color:rgb(31,73,125)"><font face="arial, sans-serif">The proposal of yours that I outlined above would make the registration process more risky to BOTH registrars and registrants. You are asking for legal attestations, creating administrative
burden and risk, but you will not protect any more data. In fact, your option would likely protect fewer registrant records, because in my plan people who really are legal persons but don’t want to declare as such can do so, whereas under your plan they are
being put under the microscope and forced to make a legal attestation that they are one or the other.
<u></u><u></u></font></span></p>
<p><span style="font-size:11pt;color:rgb(31,73,125)"><font face="arial, sans-serif">This would also be drastically more costly. Two attestations by the registrant, a review of the choices made by the registrar, a possibility of the registrar overruling it, this
is all really complicated, non-automatable stuff.<u></u><u></u></font></span></p>
<p><span style="font-size:11pt;color:rgb(31,73,125)"><font face="arial, sans-serif">So I would have to conclude by saying that you need to reconsider your position, and take a closer look at the real consequences of it. Then compare it to mine. I look forward
to your support on that. <u></u><u></u></font></span></p>
<p><span style="font-size:11pt;color:rgb(31,73,125)"><font face="arial, sans-serif">Here is another key difference between us:<u></u><u></u></font></span></p>
<p><font face="arial, sans-serif"><span style="color:rgb(31,73,125)">></span>There is no need to compromise, and while I understand Milton's desire to compromise,
<span style="color:rgb(31,73,125)"><u></u><u></u></span></font></p>
<p><font face="arial, sans-serif"><span style="color:rgb(31,73,125)">></span>I see absolutely no need to do so here. <span style="color:rgb(31,73,125)">
<u></u><u></u></span></font></p>
<p><span style="font-size:11pt;color:rgb(31,73,125)"><font face="arial, sans-serif">You say we just stick to our position. This is actually your strongest point and it’s one we need to face directly. It probably overrides all the others. I will address it in another
message. </font><font face="Calibri, sans-serif"><u></u><u></u></font></span></p>
</div>
</div>
</blockquote></div></div>