<!DOCTYPE html PUBLIC "-//W3C//DTD HTML 4.0 Transitional//EN"
"http://www.w3.org/TR/REC-html40/loose.dtd">
<html>
<head>
<meta http-equiv="content-type" content="text/html; charset=utf-8">
<title></title>
</head>
<body style="font-family:Arial;font-size:14px">
<p>Dear Milton,<br>
Tx you for writing this email.  I know you and Stephanie have been trying to figure this out for a long time.  It’s good to bring the larger NCSG community into the discussion.<br>
<br>
I’m afraid that even after 30 years of working with the EU Privacy Directive and now the GDPR, I am one of those NCSG members who could not easily figure out how to answer the question of (i) legal person or natural person (ii) is there personal data in the domain name registration for the non-profit and individual domain name registrations that I created and work with.<br>
<br>
Since we corresponded during ICANN70, I’ve also surveyed my children (savvy Internet users in their 20’s) and my students (2nd and 3rd year law students) and they don’t know the answers either.  <em>In particular, are we answering under EU law or our personal sense of the definitions? Their questions include:<br>
a)      Is a name “personal data”?<br>
b)      Is an address “personal data”?<br>
c)       Is a cell phone “personal data”?<br>
d)      Is an email “personal data”?</em><br>
<br>
Good questions. And we know from our involvement with the Registrar Accreditation Agreement negotiations around 2011/2012 (of which only a small part was public) that the EU and US have very different answers on c) and d).  Which one is right for the questions now being discussed by EPDP? I’m sure I don’t know. <br>
<br>
Further, and I hope you will acknowledge in future communication on the subject, <em>many members of NCSG – non-commercial organizations around the world, and their staff and members who register their domain names – are likely to be protected under the EU GDPR Article 9 – Processing of special categories of personal data.</em><br>
<br>
<strong>What EU GDPR Art 9 tells us is that processing personal data revealing “racial or ethnic origin, political opinions, religious or philosophical beliefs, or trade union membership… data concerning health or data concerning a natural person’s sex life or sexual orientation shall be prohibited.”</strong><br>
<br>
<em>That’s our members, Milton, and it has been from the start.  Political groups, LGBTQ groups, ethnic minorities, political dissidents. That’s the noncommercial speech we protected in our original NCUC charter – and the groups who most rely on us to tell their story of why their online speech (and its importance) should be separated from their location (and its easy and public access).  It’s a story we told in the first WHOIS Review Team Task Force report.</em><br>
<br>
Lest we think that only EU protects “sensitive data,” it’s the US as well (and I would urge others to tell us of the laws of your countries).  In NAACP v. Alabama, the US Supreme Court said that a political organization could not be forced to disclose its members.  A domain name registrant on behalf of an organization, e.g., an LGBTQ groups, a political group, a racial or ethnic group, can be deemed to be that disclosure.  Marc Rotenberg, founder of the Electronic Privacy Information Center, raised these issues when I wrote to him recently.<br>
<br>
I am satisfied on behalf of our NCSG members with the current state of the WHOIS/RDS database:<br>
a) generally redacted registrant data,<br>
b) the option to publish all domain name registration data (as Facebook and other large companies and likely some large noncommercial organizations will want to do too), and<br>
c) continue to allow the registrars to weigh the risks of disclosure with the legitimate needs being presented by intellectual property owners.<br>
<br>
<em>Can we hold with these positions - do we have to negotiate an alternative state?</em><br>
<br>
**But what I think we should be discussing more is your underlying concern – and I hope it is OK to share. That some IP owners (and perhaps some Law Enforcement) are trying to bypass ICANN process and go to the EU and US Congress directly.**<br>
<br>
I'd like to talk about this problem explicitly.  <em>Could others, including our other EPDP Representatives weigh in on this issues and others close to politics, weigh in? What would be the likelihood of success of such requests to the European Parliament and US Congress?  How likely would they be to bypass their own privacy protections for “sensitive data” (EU) and free speech and “freedom to associate” (US)?  What should we be doing directly on this problem of bypassing ICANN's policy development process, if anything?<br>
<br>
Best,</em><br>
Kathy Kleiman<br>
p.s. to the underlying question, Milton, as a lawyer and law professor, <strong>I think is there great legal liability in making the wrong answer to the legal/natural person and personal/not personal data questions under consideration,  and per my analysis above, I believe the right answer for many of our NCSG members is murky.</strong> Accordingly, from the perspective of NCSG, I think it would not be fair to ask. <br>
<br>
Quoting "Mueller, Milton L" <<a href="mailto:milton@gatech.edu">milton@gatech.edu</a>>:<br>
<br>
> Dear Noncommercials,<br>
> I am one of your representatives of the EPDP, and ICANN working group<br>
> that is trying to bring ICANN's Whois policy into compliance with<br>
> privacy principles.<br>
> Just yesterday we received this statement from the current chair of<br>
> the group, Keith Drazek:<br>
><br>
>           The EPDP Team is a representative group - you have all been<br>
> appointed by your respective groups to represent them in this effort.<br>
> As a result, any proposals and interventions you make are expected to<br>
> be on behalf of your group. We understand that this requires<br>
> significant coordination which is not always possible in real-time<br>
> but it is important that we do not find ourselves in a situation<br>
> where a specific proposal or suggestion is debated to then find that<br>
> other members of the same group do not stand behind the proposal or<br>
> suggestion.<br>
><br>
> I suspect Keith found it necessary to say this because lately another<br>
> NCSG representative on the EPDP, Stephanie, and I have been openly<br>
> disagreeing. Let me explain what the disagreement is about. We will<br>
> have to appeal to the Policy Committee, and the membership, to help<br>
> resolve it.<br>
><br>
> Privacy protections under the GDPR only apply to natural persons,<br>
> that is to say living breathing humans, not to legal persons, i.e.<br>
> corporations or companies. And in most cases, we do not mind if<br>
> company data is published in their domain record. In many cases it<br>
> can even help with economic and legal accountability. However, we<br>
> both recognize that there is a large gray area of small companies or<br>
> home offices where the line between personal and legal is thin,<br>
> blurry or nonexistent. A registrant that is formally a legal person<br>
> may want the privacy protection of a natural person.<br>
><br>
> One of the issues we are dealing with in Phase 2 is whether and how<br>
> registrars  should differentiate between those two types of<br>
> registrants. Under the current Phase 1 agreement, contracted parties<br>
> are not required to differentiate between registrants who are legal<br>
> or natural persons, but they can do so if they wish to. I believe<br>
> both Stephanie and I (and the contracted parties) agree on NOT<br>
> requiring them to differentiate.<br>
><br>
> But if registrars DO choose to differentiate, we have to worry about<br>
> HOW they do it. Currently, the EPDP is working on a guidance document<br>
> that will set out ways to do it. I want to make sure that the<br>
> guidance protects the rights of registrants.<br>
><br>
> My position is that registrants should be given a clear choice to<br>
> self-designate as a legal person or not. When given that choice, they<br>
> must be clearly told that their data will be published, and if they<br>
> don't want the data published, they should not self-designate as a<br>
> legal person. Under my view, the registrant, and the registrant<br>
> alone, should decide for themselves whether to declare as legal<br>
> person or not.<br>
><br>
> Stephanie's position is that registrants are not smart enough to make<br>
> this choice for themselves. Worse, her belief that registrants cannot<br>
> look out for their own interests makes her in favor of the idea that<br>
> REGISTRARS should be able to make the choice for them. In other<br>
> words, a commercial registrar, based on their own information about<br>
> you, could decide that you are registering a domain name on behalf of<br>
> a company and classify you as a legal person without your<br>
> participation or consent.<br>
><br>
> In my view, this is a very bad idea, even a dangerous one. It makes<br>
> the registrar responsible for verifying certain aspects of your<br>
> identity. We already know that those who want more surveillance and<br>
> control of registrants want registrars to be more restrictive and<br>
> take on a bigger role vetting who is registering domains. This idea<br>
> is also very bad for the registrars, because if a registrar is making<br>
> the decision about whether you are a legal or natural person, then<br>
> the registrar will be legally liable for the decision. Further down<br>
> the road, those who want a more restrictive internet will love the<br>
> precedent set, they will ask the registrars to do more and more to<br>
> vet and regulate their customers.<br>
><br>
> I believe that Stephanie has good motives for her position; as I<br>
> understand it she thinks that if registrars have this ability to<br>
> decide for the registrant, they will err on the side of<br>
> non-disclosure. But this is very naïve. Yes, some of the registrars<br>
> we are dealing with in EPDP are sincere supporters of their customers<br>
> privacy. But others are not. Further, Stephanie is forgetting about<br>
> the fact that many registrars are operating in authoritarian<br>
> countries where individual rights are not respected. I am also deeply<br>
> troubled by a position that registrants are children who cannot take<br>
> care of themselves. I think Stephanie's position is also motivated by<br>
> the view that we are better off if there is no differentiation at<br>
> all. This may be true, but it is unrealistic. The default policy,<br>
> ALREADY, is that registrars will be able to differentiate if they<br>
> want to. I am trying to plan for the possibility that many of them<br>
> will want to. If they do, we want registrants to be in control of<br>
> their status, not registrars or any other third party allegedly<br>
> acting on their behalf.<br>
><br>
> My hope is that the membership and the PC will resolve this issue in<br>
> favor of the "registrant in control" position.<br>
><br>
> Sorry for the long message<br>
><br>
> Dr. Milton L Mueller<br>
> Georgia Institute of Technology<br>
> School of Public Policy<br>
> [IGP_logo_gold block]<br>
<br></p>
</body>
</html>