<div dir="ltr">Hello all, <div><br></div><div>I'm Assistant Professor in Law and Digital Technologies at Leiden University in the Netherlands. I wanted to add a little European perspective to this thread. I find it all a bit bizarre and some of the arguments to be a little off point. Article 4(1) GDPR states that personal data is 'any information related to an identifiable living person', The Article 29 Working Party has made this clear - ANY information is to be interpreted very broadly. This approach has been endorsed by the CJEU. Furthermore, it matters not whether someone has given permission, consented, or otherwise. It is still personal data and as far as the GDPR goes, you need to have a valid ground for processing personal data - otherwise you will be falling foul of the Regulation. Pseudonymous data is also to be considered personal data. Either way, the Registrars will be processing personal data if any information is related to a living individual. </div><div><br></div><div>Let me answer Kathy's questions -</div><div><br></div><div><span style="font-family:Arial">a) Is a name “personal data”? <b>YES</b></span><br style="font-family:Arial"><span style="font-family:Arial">b) Is an address “personal data”? <b>YES - because it is 'any information' 'relating to' a living individual (the people that live there)</b></span></div><div><span style="font-family:Arial">c) Is a cell phone “personal data”? <b>YES - because it is information that relates to a living individual</b></span></div><div><span style="font-family:Arial">d) Is an email “personal data”? <b>YES - because most emails are related to an identifiable person. Kathy's email above relates to her, therefore, it is personal data. </b></span><br></div><div><span style="font-family:Arial"><b><br></b></span></div><div><font face="Arial">Therefore, <a href="mailto:info@myorg.org">info@myorg.org</a> is personal data if someone behind it is identifiable. If more than one person is running that account it would amount to personal data about BOTH individuals. So Kathy is kind of right here. </font><span style="font-family:Arial">As far as the GDPR goes, you are processing personal data. Furthermore, even if someone is not identifiable, if the email is able to be combined with data from another set to reveal the user of the account, the email would still amount to 'personal data' within the meaning of Article 4(1). </span></div><div><span style="font-family:Arial"><br></span></div><div><span style="font-family:Arial">Stephanie's email made reference to the fact that employees do not know and understand their rights. The GDPR offers the type of protection that makes this irrelevant.. They are protected. The GDPR would also protect 'legal persons' if there is a natural person behind the entity that is identifiable. The confusion comes from </span>Recital 14 of the GDPR which states that it only applies to natural persons and does not cover the processing of personal data concerning legal persons, in particular undertakings established as legal persons or legal entities. This also includes the name of the legal person, the form, and the contact details of the legal person.</div><div><br></div><div>But the second you start adding identifiers to these details, it stops becoming the data of a 'legal person' and starts becoming personal data. </div><div><br></div><div>Secondly, I find this statement, "I think it is simplest to just say to the registrant, if you’re a company and don’t mind (or even want) your data to be published, check this box. If you’re not, or you do mind, don’t check it."
to be BOTH perplexing and inaccurate. </div><div><br></div><div>Whether someone checks the box, or does not check the box is completely irrelevant for determining whether it is personal data. Whether someone checks the box is a question of CONSENT to processing AND publication, not whether this amounts to personal data. So If MIlton's position (as represented by Stephanie is true), if the Registrars overrule the designation of a registrant or whether Stephanie's approach of 'erring on the side of caution' is viable. Registrants must protect personal data as a legal obligation - and must have a legal ground for processing personal data in all instances. Remember the GDPR has extra-jurisdictional effects. If a registrant chooses to self-designate as a legal person or not is irrelevant for the purposes of the GDPR. If a registrar decides to identify you, or take steps to do so then they are processing personal data and need a legal basis for doing so. If the legal person becomes identifiable, then the registrar is STILL processing personal data. And it would make sense for them to have a LEGAL BASIS for doing so. </div><div><br></div><div>So without a lot of further discussion from me about the three emails in this thread, I would just conclude that what you are all proposing is somewhat irrelevant for compliance with European data privacy obligations. If the person is identifiable from the data, the registrar will be processing personal data if there is a living individual that is related to that personal data. The Registrar might not want to be a data controller and subject to the GDPR's obligations. Although a legal person might not be considered 'personal data' under Recital 14, if this data can be combined with additional data, it will become personal data. Therefore it is not a question of whether they should designate as a legal person or not, it is whether either a 'natural' person or a 'legal' person consents to the publication of its data. </div><div><br></div><div>Finally, Kathy, MIlton, and Stephanie are confusing the regulatory obligations under the GDPR, with the privacy rights of both the EU Charter and the European Convention of Human Rights. Data Protection is a STANDALONE fundamental right in Europe. While you may be compliant with the GDPR but you have to ALSO be compliant with the privacy obligations of the European Convention of Human Rights. Therefore, to build on Kathy's suggestion in the email thread and to cover the GDPR's requirements and the ECHR's privacy obligations, I would argue that the question needs to be at least the following: 'do you consent to your domain name registration data being published in the WHOIS/RDS database?'. I would also argue that the default should be 'no' in order to comply with both the GDPR and European privacy obligations. </div><div><br></div><div>Happy to discuss further. </div><div><br></div><div>Regards,</div><div><br>Mark </div><div><br></div><div><div><div dir="ltr" class="gmail_signature" data-smartmail="gmail_signature"><div dir="ltr"><div dir="ltr"><div dir="ltr"><div dir="ltr"><div dir="ltr"><div dir="ltr"><div dir="ltr"><div dir="ltr"><div dir="ltr"><div dir="ltr"><div dir="ltr"><div dir="ltr"><div dir="ltr"><div dir="ltr"><div dir="ltr"><div><div style="font-size:12.8px"><b><font color="#674ea7"><span style="font-size:small;font-family:Tahoma">Dr Mark Leiser | </span><span style="font-size:small">Law and Digital Technologies </span><span style="font-size:small;font-family:Tahoma">| FRSA FHEA </span><span style="font-family:Tahoma;font-size:small">|</span></font></b></div></div></div></div></div></div></div></div></div></div></div></div></div></div></div></div></div></div></div><br></div></div><br><div class="gmail_quote"><div dir="ltr" class="gmail_attr">On Mon, 26 Apr 2021 at 14:19, <kathy@dnrc.tech> wrote:<br></div><blockquote class="gmail_quote" style="margin:0px 0px 0px 0.8ex;border-left:1px solid rgb(204,204,204);padding-left:1ex"><u></u>
<div style="font-family:Arial;font-size:14px">
<p>Dear Milton,<br>
This is a very important conversation we are having. I'll respond in order, but note that the most interesting thing you said was in your last sentence. That's worth discussing!<br>
<br>
To my questions:<br>
a) Is a name “personal data”?<br>
> b) Is an address “personal data”?<br>
> c) Is a cell phone “personal data”?<br>
> d) Is an email “personal data”?<br>
><br>
<br>
You believe "In a digital world, there is no hard, well-defined nugget of data that is “personal” and<br>
> everything else is not." <em>In the legal world, however, there hard but not fast answers. </em> That's why after being an attorney in this space for a long time, I can tell you that the answer is "it depends" to many of the questions above. Under EU rules, my email can be personal data since it includes my name. Under EU rules, as I understand them, even <a href="mailto:info@myorg.org" target="_blank">info@myorg.org</a> can be personal data if only person runs the "Info" desk of a hypothetical "myorg".<br>
<br>
These are not easy questions for anyone going through the fast process of domain name registrations (where questions should be clear and straightforward).<br>
<br>
Please do not underestimate the value of domain name data. SSN, driver's licenses and national ID cards all have high level of protection under national and state laws. They are not available in 24*7 open and public databases as WHOIS has been (prior to GDPR-based redaction). More on this below.<br>
<br>
<strong>But happily, you email ended on a stunning note:<br>
<br>
> So I think it is simplest to just say to the registrant, if you’re a<br>
> company and don’t mind (or even want) your data to be published,<br>
> check this box. If you’re not, or you do mind, don’t check it.</strong><br>
<br>
<em><strong>Great - can we ask exactly what you said above?! </strong></em> <strong>Not the binary question: are you a legal or natural person (with its legal liability), but <em>would you like like to have your domain name registration data published in the WHOIS/RDS database? </em></strong> That way there are no traps for the unwary, no legal liability for wrong answers, and our NCSG members don't have to become great data protection scholars before registering a domain ame.<br>
<br>
I think we'll find that some companies, organizations and individuals will want their data published and some won't (banks were one of the biggest users of proxy/privacy services in the WHOIS I Review Team Studies). It's a clear question with no legal liability for wrong answers.<br>
<br>
Are we done? Does this work? It seems odd that it would be so simple, but I'm willing to take "yes" for an answer :-).<br>
<br>
-------------------------<br>
<br>
As for WHOIS/RDS data, please don't diminish its value. On the first WHOIS Reveiw Team (I vice-chaired), we found great concern about then-massive publication of WHOIS data. The WHOIS/RDS databases were (before GDPR) a major place to associate a speaker and his/her speech. That's a huge issue, especially for speakers and organizations who are supposed to be assured privacy under freedom of expression, free speech and freedom of association laws. <br>
<br>
For our NCSG members, this is a real problem since this association can lead to jailing, fining, doxxing, and more of themselves or their familiers. We are the human rights representatives in ICANN, among other groups and orgs we represent. No other Stakeholder Group faces the risks that our members - and those we speak for across the world - do.<br>
<br>
In our Review Team research, we also clear evidence of data miners gathering WHOIS data in large numbers. It was part of the large system of data mining and profiling - and the EU is right, IMHO, to work to shut this down.<br>
<br>
<em>So can we leave the binary question aside and ask the underlying question: Do you want your data published? It leads to a much clearer, cleaner, simpler answer without unintended legal liability and pitfalls.</em><br>
<br>
Best regards,<br>
Kathy<br>
<br>
<br>
<br>
><br>
Quoting "Mueller, Milton L" <<a href="mailto:milton@gatech.edu" target="_blank">milton@gatech.edu</a>>:<br>
<br>
> Kathy,<br>
> Thanks for your helpful intervention. I especially liked your<br>
> discussion of this:<br>
><br>
> a) Is a name “personal data”?<br>
> b) Is an address “personal data”?<br>
> c) Is a cell phone “personal data”?<br>
> d) Is an email “personal data”?<br>
><br>
> Thinking about this problem – what is personal data – is what led me<br>
> to start modifying my position on this issue. In a digital world<br>
> there is no hard, well-defined nugget of data that is “personal” and<br>
> everything else is not. Your “personality” is reflected in a lot of<br>
> _activity_ on the net, and anyone who can gather and correlate all of<br>
> those footprints knows a lot of personal info about you. True, your<br>
> name and location, where you live, or your SSN or national identity<br>
> number of drivers’ license, provide a stronger basis for putting all<br>
> these correlations into an actionable identity. And that data is out<br>
> there in a number of places, whois is relatively small part of that<br>
> problem. A very small part, in fact<br>
><br>
> This is one of the reasons I don’t like Stephanie’s proposed approach<br>
> (I will try to answer her message separately). Instead of a simple<br>
> self-designation as legal or natural (company or individual), they<br>
> want to try to force registrars into an elaborate process of<br>
> eliminating personal data from the record. But anything can be<br>
> personal data. OR some things that seem to be personal are not so<br>
> personal. I think such a process is going to make registering a<br>
> domain complicated and expensive and ultimately will not protect<br>
> much. Worse, such a process will also be a camel’s nose under the<br>
> tent process in which registrars assume more and more responsibility<br>
> for determining the accuracy of registration data and for verifying<br>
> the identity of everyone who registers.<br>
><br>
> Let’s keep it simple and under the registrants’ control. The more you<br>
> involve third party rules and regulations in the registration<br>
> process, the more complicated and expensive it becomes, and the<br>
> privacy gains of such processes are miniscule, they are mostly<br>
> hypothetical and theoretical.<br>
><br>
> So I think it is simplest to just say to the registrant, if you’re a<br>
> company and don’t mind (or even want) your data to be published,<br>
> check this box. If you’re not, or you do mind, don’t check it.<br>
<br></p>
</div>
</blockquote></div>