<!DOCTYPE html PUBLIC "-//W3C//DTD HTML 4.0 Transitional//EN"
"http://www.w3.org/TR/REC-html40/loose.dtd">
<html>
<head>
<meta http-equiv="content-type" content="text/html; charset=utf-8">
<title></title>
</head>
<body style="font-family:Arial;font-size:14px">
<p>Dear Milton,<br>
This is a very important conversation we are having. I'll respond in order, but note that the most interesting thing you said was in your last sentence. That's worth discussing!<br>
<br>
To my questions:<br>
a) Is a name “personal data”?<br>
> b) Is an address “personal data”?<br>
> c) Is a cell phone “personal data”?<br>
> d) Is an email “personal data”?<br>
><br>
<br>
You believe "In a digital world, there is no hard, well-defined nugget of data that is “personal” and<br>
> everything else is not." <em>In the legal world, however, there hard but not fast answers. </em> That's why after being an attorney in this space for a long time, I can tell you that the answer is "it depends" to many of the questions above. Under EU rules, my email can be personal data since it includes my name. Under EU rules, as I understand them, even info@myorg.org can be personal data if only person runs the "Info" desk of a hypothetical "myorg".<br>
<br>
These are not easy questions for anyone going through the fast process of domain name registrations (where questions should be clear and straightforward).<br>
<br>
Please do not underestimate the value of domain name data. SSN, driver's licenses and national ID cards all have high level of protection under national and state laws. They are not available in 24*7 open and public databases as WHOIS has been (prior to GDPR-based redaction). More on this below.<br>
<br>
<strong>But happily, you email ended on a stunning note:<br>
<br>
> So I think it is simplest to just say to the registrant, if you’re a<br>
> company and don’t mind (or even want) your data to be published,<br>
> check this box. If you’re not, or you do mind, don’t check it.</strong><br>
<br>
<em><strong>Great - can we ask exactly what you said above?! </strong></em> <strong>Not the binary question: are you a legal or natural person (with its legal liability), but <em>would you like like to have your domain name registration data published in the WHOIS/RDS database? </em></strong> That way there are no traps for the unwary, no legal liability for wrong answers, and our NCSG members don't have to become great data protection scholars before registering a domain ame.<br>
<br>
I think we'll find that some companies, organizations and individuals will want their data published and some won't (banks were one of the biggest users of proxy/privacy services in the WHOIS I Review Team Studies). It's a clear question with no legal liability for wrong answers.<br>
<br>
Are we done? Does this work? It seems odd that it would be so simple, but I'm willing to take "yes" for an answer :-).<br>
<br>
-------------------------<br>
<br>
As for WHOIS/RDS data, please don't diminish its value. On the first WHOIS Reveiw Team (I vice-chaired), we found great concern about then-massive publication of WHOIS data. The WHOIS/RDS databases were (before GDPR) a major place to associate a speaker and his/her speech. That's a huge issue, especially for speakers and organizations who are supposed to be assured privacy under freedom of expression, free speech and freedom of association laws. <br>
<br>
For our NCSG members, this is a real problem since this association can lead to jailing, fining, doxxing, and more of themselves or their familiers. We are the human rights representatives in ICANN, among other groups and orgs we represent. No other Stakeholder Group faces the risks that our members - and those we speak for across the world - do.<br>
<br>
In our Review Team research, we also clear evidence of data miners gathering WHOIS data in large numbers. It was part of the large system of data mining and profiling - and the EU is right, IMHO, to work to shut this down.<br>
<br>
<em>So can we leave the binary question aside and ask the underlying question: Do you want your data published? It leads to a much clearer, cleaner, simpler answer without unintended legal liability and pitfalls.</em><br>
<br>
Best regards,<br>
Kathy<br>
<br>
<br>
<br>
><br>
Quoting "Mueller, Milton L" <<a href="mailto:milton@gatech.edu">milton@gatech.edu</a>>:<br>
<br>
> Kathy,<br>
> Thanks for your helpful intervention. I especially liked your<br>
> discussion of this:<br>
><br>
> a) Is a name “personal data”?<br>
> b) Is an address “personal data”?<br>
> c) Is a cell phone “personal data”?<br>
> d) Is an email “personal data”?<br>
><br>
> Thinking about this problem – what is personal data – is what led me<br>
> to start modifying my position on this issue. In a digital world<br>
> there is no hard, well-defined nugget of data that is “personal” and<br>
> everything else is not. Your “personality” is reflected in a lot of<br>
> _activity_ on the net, and anyone who can gather and correlate all of<br>
> those footprints knows a lot of personal info about you. True, your<br>
> name and location, where you live, or your SSN or national identity<br>
> number of drivers’ license, provide a stronger basis for putting all<br>
> these correlations into an actionable identity. And that data is out<br>
> there in a number of places, whois is relatively small part of that<br>
> problem. A very small part, in fact<br>
><br>
> This is one of the reasons I don’t like Stephanie’s proposed approach<br>
> (I will try to answer her message separately). Instead of a simple<br>
> self-designation as legal or natural (company or individual), they<br>
> want to try to force registrars into an elaborate process of<br>
> eliminating personal data from the record. But anything can be<br>
> personal data. OR some things that seem to be personal are not so<br>
> personal. I think such a process is going to make registering a<br>
> domain complicated and expensive and ultimately will not protect<br>
> much. Worse, such a process will also be a camel’s nose under the<br>
> tent process in which registrars assume more and more responsibility<br>
> for determining the accuracy of registration data and for verifying<br>
> the identity of everyone who registers.<br>
><br>
> Let’s keep it simple and under the registrants’ control. The more you<br>
> involve third party rules and regulations in the registration<br>
> process, the more complicated and expensive it becomes, and the<br>
> privacy gains of such processes are miniscule, they are mostly<br>
> hypothetical and theoretical.<br>
><br>
> So I think it is simplest to just say to the registrant, if you’re a<br>
> company and don’t mind (or even want) your data to be published,<br>
> check this box. If you’re not, or you do mind, don’t check it.<br>
<br></p>
</body>
</html>