<html><head>
<meta http-equiv="Content-Type" content="text/html; charset=utf-8">
  </head>
  <body>
    <p>Manju, thanks so much for this very helpful summary!  I think you
      have seized most of the key elements, as Milton and I continue to
      talk past each other, it would seem.  I consulted one of our long
      time members, Kim von Arx, who replied but seems to have been
      unable to post to the list.  Dr von Arx practices law in London,
      and has considerable experience in GDPR compliance and as former
      legal counsel at CIRA, the Canadian cctld.  Here is his response,
      I think he sees the delta of our differing views in a similar way
      to your own summary.</p>
    <p>Kind regards, Stephanie Perrin<br>
    </p>
    <div dir="auto"><br>
    </div>
    <div dir="auto"><br>
    </div>
    <div dir="auto">
      <div style="font-family:sans-serif;font-size:12.8px" dir="auto">Dear
        Noncommercials, </div>
      <div style="font-family:sans-serif;font-size:12.8px" dir="auto"><br>
      </div>
      <div style="font-family:sans-serif;font-size:12.8px" dir="auto">I
        have not participated in the discussions and activities of the
        NCSG for quite a few years, but I have seen this recent
        discussion between Stephanie and Milton and being a tech,
        privacy, and IP lawyer myself this topic is very close to my
        heart.  </div>
      <div style="font-family:sans-serif;font-size:12.8px" dir="auto"><br>
      </div>
      <div style="font-family:sans-serif;font-size:12.8px" dir="auto">I
        can see both sides of the argument to a degree and as I
        understand it, the delta between the two views is really not
        that big at all.  I understand and if I am correct I completely
        agree with both positions: </div>
      <div style="font-family:sans-serif;font-size:12.8px" dir="auto"><br>
      </div>
      <div style="font-family:sans-serif;font-size:12.8px" dir="auto">1.
        Milton suggests that the natural RANT should be entitled to make
        his/her/their own determination re: his/her/their status; </div>
      <div style="font-family:sans-serif;font-size:12.8px" dir="auto">2.
        Stephanie suggests that the natural RANT should be entitled to
        make his/her/their own determination re: his/her/their status, <b>BUT</b> argues
        that RARs should keep a vigilant eye out to make sure that the
        natural RANT has not selected legal RANT status by accident or
        out of ignorance.  This, of course does not and must not apply
        the other way.  Therefore, this is a safety net for the natural
        RANT.   </div>
      <div style="font-family:sans-serif;font-size:12.8px" dir="auto"><br>
      </div>
      <div style="font-family:sans-serif;font-size:12.8px" dir="auto">I
        think this makes sense and protects the natural RANT.  At the
        end of the day our position should aways be “err on the side of
        protecting”.  As Stephanie pointed out correctly this does not
        mean it is now locked in Fort Knox or some such, but that it is
        protected from quick and dirty exploitation by and because of
        administrative protection. The magic will be, btw, how this is
        going to be implemented in the real world, i.e., how RARs make
        the determination and assessment and introduces the checks and
        balances.  I suggest the one way may be: </div>
      <div style="font-family:sans-serif;font-size:12.8px" dir="auto"><br>
      </div>
      <div style="font-family:sans-serif;font-size:12.8px" dir="auto">1.
        self selection; and if legal RANT, then</div>
      <div style="font-family:sans-serif;font-size:12.8px" dir="auto">2.
        Have a double check online binary questionnaire that will then
        determine, based on the responses, whether he/she/they self
        selected properly as legal RAR. </div>
      <div style="font-family:sans-serif;font-size:12.8px" dir="auto"><br>
      </div>
      <div style="font-family:sans-serif;font-size:12.8px" dir="auto">Anyway,
        if it was my call, I would, as I had implemented CIRA’s privacy
        practice back in the early 2000s, start with the position of all
        information is protected until there is clear reason for not
        doing so and, of course, a clear process to get access to the
        information if there is good reason to do so.  But, as I said,
        we should always err on the side of protecting PII provided
        there is always a legitimate and auditable process to have
        access to it for good and sound reasons.   </div>
      <div style="font-family:sans-serif;font-size:12.8px" dir="auto"><br>
      </div>
      <div style="font-family:sans-serif;font-size:12.8px" dir="auto">Anyway,
        my two cents on this. </div>
      <div style="font-family:sans-serif;font-size:12.8px" dir="auto"><br>
      </div>
      <div style="font-family:sans-serif;font-size:12.8px" dir="auto">Best
        wishes, </div>
      <div style="font-family:sans-serif;font-size:12.8px" dir="auto"><br>
      </div>
      <div style="font-family:sans-serif;font-size:12.8px" dir="auto">Kim 
         </div>
      <div dir="auto"><br>
        <div data-smartmail="gmail_signature" dir="auto"><a href="mailto:kim@vonarx.ca">kim@vonarx.ca</a><br>
          +44 7473 506060</div>
      </div>
    </div>
    <div class="moz-cite-prefix">On 2021-04-25 10:52 p.m., 陳曼茹 Manju
      Chen wrote:<br>
    </div>
    <blockquote type="cite" cite="mid:CAMeQZi27qh6DLdGNNmu7Yg-UN_zxfM3cEi9ePWg+CNFSyWUu5Q@mail.gmail.com">
      
      <div style="font-size: 10pt; font-family: sans-serif; color:
        white; font-style: normal; font-weight: bold; padding: .2em;">
        <strong><span style="color: #c75000;">EXTERNAL EMAIL:</span></strong></div>
      <div>
        <div dir="ltr">
          <div dir="ltr">
            <div class="gmail_default" style="font-size:small"><font face="arial, sans-serif">Hi everyone,
                <br>
                <br>
                This is Manju Chen. I'm also one of your representatives
                on the EPDP. I'm happy to see this thread going as it
                clears many misunderstandings and confusions. I have to
                admit I wasn't sure about what either Milton or
                Stephanie's proposal was about before seeing their
                elaboration on the mailing list.  <br>
                <br>
                Thinking people might feel as confused as I did, below I
                will try to provide a summary of the disagreements in
                the hope of furthering the group's discussion on the
                issue.<br>
                <br>
                First of all, I think the disagreement boils down to 2
                major questions.<br>
              </font>
              <ol style="">
                <li><font face="arial, sans-serif">Should we allow the
                    3rd scenario in the current guidance write-up?</font></li>
                <li><font face="arial, sans-serif">Should we concede to
                    the 'legal vs. natural' distinction?</font></li>
              </ol>
              <font face="arial, sans-serif"><br>
                To discuss question 1, we have to firstly know what 'the
                3rd scenario' is about.<br>
                In the EPDP, we are currently discussing a 'guidance'
                (not a requirement) for CPs who wish to distinguish
                between legal vs. natural persons. 3 scenarios were
                proposed in the guidance:<br>
              </font>
              <ol style="">
                <li><font face="arial, sans-serif">Registrant (data
                    subject) self-identification at time of data
                    collection / registration</font></li>
                <li><font face="arial, sans-serif">Registrant (data
                    subject) self-identification after initial
                    collection</font></li>
                <li><font face="arial, sans-serif">Registrar determines
                    type based on data provided</font></li>
              </ol>
              <font face="arial, sans-serif"><br>
                The 3rd scenario is where we're having problems with. To
                give more context, the current 3rd scenario write-up is
                as below:<br>
              </font>
              <ul style="">
                <li><font face="arial, sans-serif">The Registrar
                    collects Registration Data and provisionally redacts
                    the data.</font></li>
                <li><font face="arial, sans-serif">The Registrar uses
                    collected data to infer legal or natural person
                    type.</font></li>
                <li><font face="arial, sans-serif">If legal person is
                    inferred by the Registrar and subsequently the
                    Registrant (data subject) is informed (per guidance
                    #3 above) and confirms that no personal data is
                    present, the Registrar should (i) contact the
                    provided contact details to verify the Registrant
                    claim (ii) sets the registration data set to
                    automated disclosure in response to SSAD queries and
                    (iii) publishes the data.
                  </font></li>
                <li><font face="arial, sans-serif">If the Registrar has
                    inferred natural person or has detected personal
                    data, the Registrar must not disclose registration
                    data unless the Registrant provides consent for
                    publication or the Registrar Discloses the data in
                    response to a legitimate disclosure request.</font></li>
              </ul>
              <font face="arial, sans-serif">Milton thinks we should not
                allow this scenario because it denies registrants the
                right to self-designation. A counterpoint might be made
                that staff has added the instruction for registrars to
                'contact the registrant to verify' to mitigate the harm
                of possible wrong designation by the registrars.</font></div>
            <div class="gmail_default" style="font-size:small"><font face="arial, sans-serif"><br>
                Stephanie seems to be OK with this scenario. (This was
                my impression, I might be wrong. Please feel free to
                correct me if I am Stephanie.) Her argument is that
                registrars should be able to reduce their risk by
                adjusting registrants' wrong self-designation. The
                counterpoint here is that this is not a 'registrant
                identifies and then checked by registrars' scenario.<br>
                <br>
                In summary, I think the question we should answer here
                is:<br>
                <ul>
                  <li><font face="arial, sans-serif"><b><u>Does the NCSG
                          allow the scenario where 'registrars determine
                          registrant's person type without providing
                          registrants the option of doing it themselves
                          first'?</u></b></font></li>
                </ul>
                <br>
                Now we come to question 2. The current guidance proposes
                a 2-step approach to distinguish between natural vs.
                legal persons:<br>
                <ol>
                  <li><font face="arial, sans-serif">Ask registrant to
                      identify as natural or legal.</font></li>
                  <li><font face="arial, sans-serif">If legal, ask
                      registrant to confirm whether there is personal
                      information in the data provided. If yes, data
                      redacted. If no, data published.</font></li>
                </ol>
                Note that this is a 'guidance', not mandatory
                requirements. Registrars will only do it when they wish
                to make the distinction. Also note that we're arguing
                for publish as 'automatic disclosure via SSAD', not
                publicly available online for everyone.
                <br>
                <br>
                The disagreement here:</font></div>
            <div class="gmail_default" style="font-size:small"><font face="arial, sans-serif"><br>
                Milton supports the 2-step approach. He agrees with the
                first step because it is the necessary political
                compromise to make to reach consensus within EPDP.
                (Again, please feel free to correct me if I
                misunderstood.) </font></div>
            <div class="gmail_default" style="font-size:small"><font face="arial, sans-serif"><br>
                Stephanie opposes the 2-step approach. She argues that
                person type is hard to define, which leads to 2 points:
                a) we should just ask whether the data contains personal
                data, and b) registrars should be able to overrule
                registrant's self-designation to protect them.<br>
                  <br>
                In summary, the questions we are asking here:<br>
                <ul>
                  <li><font face="arial, sans-serif"><b><u>Do we agree
                          with the 2-step approach on the premise that
                          a) it stays as only guidance and b)
                          registrants are given the option to 'not
                          identify as either'?</u></b></font></li>
                  <li><font face="arial, sans-serif"><b><u>Or, do we
                          stick to 'no distinction between natural and
                          legal persons, only check the data types'?</u></b></font></li>
                  <li><font face="arial, sans-serif"><b><u>Do we agree
                          registrars should be able to overrule
                          registrants' self-designation? This has to be
                          on the premise of 'registrar only overrules to
                          hide and not disclose', but currently there's
                          no such language in the policy.</u></b></font></li>
                </ul>
                <br>
                Hope this helps! <br>
                <br>
              </font></div>
            <font face="arial, sans-serif"><span class="gmail_default" style="font-family:georgia,serif;font-size:small">Best,</span></font></div>
          <div><font face="arial, sans-serif"><span class="gmail_default" style="font-family:georgia,serif;font-size:small">Manju</span><br>
            </font></div>
          <font face="arial, sans-serif"><br>
          </font>
          <div class="gmail_quote">
            <div dir="ltr" class="gmail_attr"><font face="arial,
                sans-serif">On Mon, Apr 26, 2021 at 5:11 AM Mueller,
                Milton L <<a href="mailto:milton@gatech.edu" moz-do-not-send="true">milton@gatech.edu</a>>
                wrote:<br>
              </font></div>
            <blockquote class="gmail_quote" style="margin:0px 0px 0px
              0.8ex;border-left:1px solid
              rgb(204,204,204);padding-left:1ex">
              <div lang="EN-US">
                <div class="gmail-m_1570404167473597983WordSection1">
                  <p><span style="color:rgb(31,73,125)"><font face="arial, sans-serif">Stephanie:</font></span></p>
                  <p><span style="color:rgb(31,73,125)"><font face="arial, sans-serif">I knew that you were
                        against what I was proposing but until now I did
                        not know what you were actually for. This is
                        seemingly cleared up in the email below. In my
                        response I will first clarify some of the
                        misunderstandings you have about the issue, then
                        I will take a critical look at the proposal you
                        have made.</font></span></p>
                  <p><font face="arial, sans-serif"><span style="color:rgb(31,73,125)">></span>At no
                      time have I ever suggested that it would be
                      acceptable for registrars to overrule my
                      designation of
                      <span style="color:rgb(31,73,125)">></span>myself
                      as a natural person, or in the case of a legal
                      person, a statement that the contact data of
                      employees
                      <span style="color:rgb(31,73,125)">></span>needs
                      to be protected because it contains personal data.<span style="color:rgb(31,73,125)"></span></font></p>
                  <p><span style="font-size:11pt;color:rgb(31,73,125)"><font face="arial, sans-serif">I could provide
                        evidence to the contrary. If you are backing
                        away from that position now, it’s good, we will
                        have an easier time coming to an agreement.  If
                        we agree on this, you will then agree that the
                        “3<sup>rd</sup> scenario” in the current
                        Guidance should be deleted, as I have suggested?
                        A yes or no would be good.</font></span></p>
                  <p><font face="arial, sans-serif"><span style="color:rgb(31,73,125)">></span>So to
                      push all data of legal persons into a published
                      registry is neither necessary or sound policy.<span style="color:rgb(31,73,125)"></span></font></p>
                  <p><span style="font-size:11pt;color:rgb(31,73,125)"><font face="arial, sans-serif">But that is not what we
                        are debating. My idea gives legal persons who do
                        not want to identify themselves as legal persons
                        the right not to. No one is being pushed.
                      </font></span></p>
                  <p><font face="arial, sans-serif"><span style="color:rgb(31,73,125)">></span>Now lets
                      talk about how difficult it is to differentiate
                      between legal persons and individuals.<span style="color:rgb(31,73,125)">
                      </span>Milton makes it sound easy<span style="color:rgb(31,73,125)"></span></font></p>
                  <p><span style="font-size:11pt;color:rgb(31,73,125)"><font face="arial, sans-serif">Again, you seem to
                        misunderstand the issue that is before us. We
                        are not promoting a process of “differentiating
                        between legal and natural persons” We are
                        promoting an ability to “Self-designate” as a
                        legal person, if you want to. That is not hard
                        at all. That is tremendously easy, if you do it
                        the way I am proposing. If you say you are a
                        legal person, the RDS treats you as one. If you
                        don’t, it doesn’t.
                      </font></span></p>
                  <p><span style="font-size:11pt;color:rgb(31,73,125)"><font face="arial, sans-serif">You go on to raise
                        valid concerns about the complexity of
                        registering a domain. Surprisingly, this is
                        followed by a proposals that would make the
                        situation worse!
                      </font></span></p>
                  <p><span style="font-size:11pt;color:rgb(31,73,125)"><font face="arial, sans-serif">Here is how I interpret
                        what you are proposing: I am using your own
                        words to characterize your position, so I think
                        it should be correct, but if it’s not let me
                        know in your response:</font></span></p>
                  <p style="margin-left:0.5in"><font face="arial,
                      sans-serif"><span style="font-size:10pt;color:rgb(31,78,121)"><span>a)<span style="font-style:normal;font-variant:normal;font-weight:normal;font-stretch:normal;font-size:7pt;line-height:normal">      
                          </span></span></span><span style="font-size:11pt;color:rgb(31,78,121)">individuals
                        who register a domain must knowledgeably attest
                        to one of the following statements</span><span style="font-size:10pt;color:rgb(31,78,121)"></span></font></p>
                  <p style="margin-left:1in"><font face="arial,
                      sans-serif"><span style="font-size:10pt;color:rgb(31,78,121)"><span><span style="font-style:normal;font-variant:normal;font-weight:normal;font-stretch:normal;font-size:7pt;line-height:normal">                                
                          </span>i.<span style="font-style:normal;font-variant:normal;font-weight:normal;font-stretch:normal;font-size:7pt;line-height:normal">           
                          </span></span></span><span style="font-size:11pt;color:rgb(31,78,121)">they
                        are an individual, and if they choose to publish
                        their personal information they are doing so in
                        full knowledge of the risks and what will happen
                        to their data</span><span style="font-size:10pt;color:rgb(31,78,121)"></span></font></p>
                  <p style="margin-left:1in"><font face="arial,
                      sans-serif"><span style="font-size:10pt;color:rgb(31,78,121)"><span><span style="font-style:normal;font-variant:normal;font-weight:normal;font-stretch:normal;font-size:7pt;line-height:normal">                               
                          </span>ii.<span style="font-style:normal;font-variant:normal;font-weight:normal;font-stretch:normal;font-size:7pt;line-height:normal">           
                          </span></span></span><span style="font-size:10pt;color:rgb(31,78,121)">that
                        they are responsible for a legal person's
                        registrations, and that they can attest to the
                        fact that no personal information is being
                        disclosed in the registration.</span></font></p>
                  <p style="margin-left:0.5in"><font face="arial,
                      sans-serif"><span style="font-size:9pt;color:rgb(31,78,121)"><span>b)<span style="font-style:normal;font-variant:normal;font-weight:normal;font-stretch:normal;font-size:7pt;line-height:normal">      
                          </span></span></span><span style="font-size:11pt;color:rgb(31,78,121)">if
                        the contracted parties feel there might be an
                        error in the designation of "legal person" they
                        should err on the side of caution and protect
                        their customer's data</span><span style="font-size:9pt;color:rgb(31,78,121)"></span></font></p>
                  <p><span style="font-size:11pt;color:rgb(31,78,121)"><font face="arial, sans-serif">OK. Now we have a basis
                        for comparison.
                      </font></span></p>
                  <p><span style="font-size:11pt;color:rgb(31,78,121)"><font face="arial, sans-serif">Note, first that item
                        b) directly contradicts your claim that the
                        registrant’s decision cannot be overridden. The
                        registrar would have the authority to look at
                        what data they entered, decide it’s wrong, and
                        change it. This implies that the registrars are
                        carefully reviewing every registrants’ record at
                        the point of registration, checking out what
                        choices they make, and making a decision about
                        its validity. This is not a slippery slope, you
                        are at the bottom of the hill already. Note also
                        how meaningless it is to say to “err on the side
                        of caution”. Many registrars will err on the
                        side of the lowest expense. Other registrars may
                        be told by their government to differentiate.
                      </font></span></p>
                  <p><span style="font-size:11pt;color:rgb(31,78,121)"><font face="arial, sans-serif">Note, too that your
                        “attestations” in a) and b) are actually trying
                        to differentiate between legal and natural
                        persons. In your criticism of my proposal, you
                        said it was really difficult to do that. You
                        raised many complications and procedural
                        non-uniformities in the registration process.
                        You said that not all jurisdictions recognize
                        the term, You said registrants can’t understand
                        all that stuff. But here we see that your
                        solution doubles down on the process of
                        differentiation and makes it all legally
                        actionable.
                      </font></span></p>
                  <p><span style="font-size:11pt;color:rgb(31,78,121)"><font face="arial, sans-serif">You are forcing –
                        pushing was your word - registrants to make two
                        legally consequential attestations that are far
                        more complicated than asking them whether they
                        are a company. Then you are asking the registrar
                        to check the accuracy of those attestations. I
                        think we really want to avoid that. It is
                        against the interests of both registrars and
                        their customers.
                      </font></span></p>
                  <p><span style="font-size:11pt;color:rgb(31,78,121)"><font face="arial, sans-serif">What happens if the
                        person making the registration and attests (as
                        in b) that there is no personal information, and
                        they turn out to be wrong? Are they legally
                        liable for violating their attestation? Thanks,
                        Steph, for criminalizing domain name
                        registration.  <u>
                        </u></font></span></p>
                  <p><font face="arial, sans-serif"><span style="color:rgb(31,73,125)">></span>I
                      believe that if the contracted parties, who are
                      the data controllers in this situation and
                      therefore own the
                      <span style="color:rgb(31,73,125)">></span>risk
                      and the liability attendant with this decision,
                      have to do this verification or trust the decision
                      of the
                      <span style="color:rgb(31,73,125)">></span>registrant,
                      we will see either rising costs of domain names
                      (if they do it right) or the same kind of opt-in
                      <span style="color:rgb(31,73,125)">></span>situation
                      we see throughout the world now, where people opt
                      in to things without understanding their
                      <span style="color:rgb(31,73,125)">></span>risk.<span style="color:rgb(31,73,125)"></span></font></p>
                  <p><span style="font-size:11pt;color:rgb(31,73,125)"><font face="arial, sans-serif">The proposal of yours
                        that I outlined above would make the
                        registration process more risky to BOTH
                        registrars and registrants. You are asking for
                        legal attestations, creating administrative
                        burden and risk, but you will not protect any
                        more data. In fact, your option would likely
                        protect fewer registrant records, because in my
                        plan people who really are legal persons but
                        don’t want to declare as such can do so, whereas
                        under your plan they are being put under the
                        microscope and forced to make a legal
                        attestation that they are one or the other. 
                      </font></span></p>
                  <p><span style="font-size:11pt;color:rgb(31,73,125)"><font face="arial, sans-serif">This would also be
                        drastically more costly. Two attestations by the
                        registrant, a review of the choices made by the
                        registrar, a possibility of the registrar
                        overruling it, this is all really complicated,
                        non-automatable stuff.</font></span></p>
                  <p><span style="font-size:11pt;color:rgb(31,73,125)"><font face="arial, sans-serif">So I would have to
                        conclude by saying that you need to reconsider
                        your position, and take a closer look at the
                        real consequences of it. Then compare it to
                        mine. I look forward to your support on that. </font></span></p>
                  <p><span style="font-size:11pt;color:rgb(31,73,125)"><font face="arial, sans-serif">Here is another key
                        difference between us:</font></span></p>
                  <p><font face="arial, sans-serif"><span style="color:rgb(31,73,125)">></span>There is
                      no need to compromise, and while I understand
                      Milton's desire to compromise,
                      <span style="color:rgb(31,73,125)"></span></font></p>
                  <p><font face="arial, sans-serif"><span style="color:rgb(31,73,125)">></span>I see
                      absolutely no need to do so here. 
                      <span style="color:rgb(31,73,125)"></span></font></p>
                  <p><span style="font-size:11pt;color:rgb(31,73,125)"><font face="arial, sans-serif">You say we just stick
                        to our position. This is actually your strongest
                        point and it’s one we need to face directly. It
                        probably overrides all the others. I will
                        address it in another message. </font></span></p>
                </div>
              </div>
            </blockquote>
          </div>
        </div>
      </div>
    </blockquote>
  </body>
</html>