<div dir="ltr"><div class="gmail_default" style="font-family:arial,sans-serif;font-size:small">Hi all,</div><div class="gmail_default" style="font-family:arial,sans-serif;font-size:small"><br></div><div class="gmail_default" style="font-family:arial,sans-serif;font-size:small">This has been a very helpful discussion. Our ultimate goal is to finalize an NCSG position, and I'd like to provide some context in the interest of reaching that goal.</div><div class="gmail_default" style="font-family:arial,sans-serif;font-size:small"><br></div><div class="gmail_default" style="font-family:arial,sans-serif;font-size:small">Some have pointed out that the question of 'do you agree to publish your data' is a much better one than 'are you a legal or natural person'. I totally agree. But we already have that in the policy. In the EPDP phase 1 final report, recommendation #6 reads: </div><blockquote style="margin:0px 0px 0px 0.8ex;border-left:1px solid rgb(204,204,204);padding-left:1ex" class="gmail_quote"><span style="font-family:Arial,Helvetica,sans-serif">The EPDP Team recommends that, as soon as commercially reasonable, Registrar must </span><span style="font-family:Arial,Helvetica,sans-serif">provide the opportunity for the Registered Name Holder to provide its Consent to </span><span style="font-family:Arial,Helvetica,sans-serif">publish redacted contact information, as well as the email address, in the RDS for the </span><span style="font-family:Arial,Helvetica,sans-serif">sponsoring registrar.</span></blockquote><div><br></div><div class="gmail_default" style="font-family:arial,sans-serif;font-size:small">In the EPDP phase2A, the WG is tasked to address the following questions:</div><div class="gmail_default" style="font-family:arial,sans-serif;font-size:small"><ol><li>Whether any updates are required to the EPDP Phase 1 recommendation on this topic (“Registrars and Registry Operators are permitted to differentiate between registrations of legal and natural persons, but are not obligated to do so“); </li><li>What guidance, if any, can be provided to Registrars and/or Registries who differentiate between registrations of legal and natural persons. </li></ol><div>So it's not that we 'want' the distinction of natural vs. legal. It's the task we're given, and per the WG chair's last email to the EPDP team, it's not something we can avoid. We have to stick to the 'natural vs. legal persons' rhetoric to answer the questions. </div><div><br></div><div>Of course, we can simply assert that 'there's no update needed' and let the contracted parties do whatever they want when they feel like making the distinction. I was personally very tempted by this option every now and then. However, as Milton pointed out in another email, we are already developing guidance in the EPDP, so that option seems far-fetched. </div><div><br></div><div>I hope this explains some of the confusion and helps us to consider Milton's 4 options in the other email. </div><div><br></div><div>Thanks!</div><div><br></div><div><br></div><div>Best, </div><div>Manju</div></div></div><br><div class="gmail_quote"><div dir="ltr" class="gmail_attr">On Wed, Apr 28, 2021 at 4:40 AM Mark Leiser <<a href="mailto:markleiser@gmail.com" target="_blank">markleiser@gmail.com</a>> wrote:<br></div><blockquote class="gmail_quote" style="margin:0px 0px 0px 0.8ex;border-left:1px solid rgb(204,204,204);padding-left:1ex"><div dir="ltr"><font face="arial, sans-serif">Hi Milton,</font><div><font face="arial, sans-serif"><br></font></div><div><font face="arial, sans-serif">First let me say I completely agree with you on your statements about European data privacy. I feel like I've dedicated most of my professional life arguing about the dangers of privacy and data protection maximalism - yet almost always feel like my arguments on deaf ears. While people are arguing that 'everything is personal data', I've been arguing that this makes the regime unmanageable. </font></div><div><font face="arial, sans-serif"><br></font></div><div><font face="arial, sans-serif">So let me try to explain 'relating to' with reference to 'Milton Mueller's Porkbelly Diner'. Because of Recital 14, this would amount to a legal person. It's pretty clear that the intention of the GDPR's drafters was to exclude legal persons. However, let's say you have registered 'MM Porkbelly Diner' in the register of companies. I think you would agree that this would amount to information about a legal person. But say someone searched the company register and discovered Milton Mueller was the principal shareholder of MM Porkbelly Diner. This is an identifier which would <i>tie nformation about Milton Mueller to</i> 'MM PorkBelly Diner'. Therefore, this is 'any information' 'relating to' an identified or identifiable living person. It would be reasonable to infer that MM registered in the registrar database under MM PorkBelly Diner is the same as the Milton Mueller that is in the register of companies. The fact that someone can combine the knowledge from the company register with the knowledge from the registrar database could make 'MM Porkbelly Diner' personal data under Article 4(1) of the GDPR. Someone who did not disclose their identity at all could still be identifiable; hence, the perceived need for protection in the EU data protection regime.</font></div><div><font face="arial, sans-serif"><br></font></div><div><font face="arial, sans-serif"> "I<span style="color:rgb(31,73,125)"> </span><span style="color:rgb(31,73,125)">am saying that the user, the registrant, gets to decide what is personal data or not, because THERE IS NO OBJECTIVE, CLEAR LEGAL DEFINITION" is, on the surface, problematic. </span><font color="#000000">It doesn't matter whether the user says NO or YES or the registrar says no or yes, or whether it is objective or clear, the test is whether any information can be combined with other information to reveal an identifiable living person. I would argue, absent a wholesale change in the reasoning used by the CJEU, this would remain the case for the foreseeable future. This is not intended as a Mark Leiser argument or an attempt to discredit what you are saying, but an honest account of how I think the Courts and the EU data protection Board would react to what you are proposing. </font><br></font></div><div><font face="arial, sans-serif"><br></font></div><div><font face="arial, sans-serif">You asked about <a href="https://iapp.org/news/a/are-ip-addresses-generated-when-users-visit-websites-personal-information/#:~:text=Under%20the%20EU%20General%20Data,header%20information%20that%20website%20hosts" target="_blank">IP addresses</a>, 'port numbers', 'browser config', etc could be used to identify you personally. Yes, absolutely. This is personal data in the EU - if it can relate to a living person. What your writing here reveals, is that you are a little confused about how the GDPR works - the GDPR does not rely on 'consent' or 'explicit permission' as the only basis for processing personal data. Remember the GDPR has six<a href="https://gdpr-info.eu/art-6-gdpr/" target="_blank"> grounds of processing</a>. It is a prohibitive regulation. You cannot process personal data in the EU unless you satisfy one of those six grounds. Most companies will NOT be processing on the basis of 'consent' but on 'legitimate interests' (Article 6(1)(f)) or performance of a contract (Article 6(1)(b)). Don't worry, this is an extremely common mistake among American attorneys! As most of these items are "technical', I would also imagine that there is a 'legal requirement' (another ground) or a lawful basis. All ISPs will be processing personal data through 'IP addresses', 'port browsers', and 'browser config' because of the legal basis found in <a href="https://eur-lex.europa.eu/legal-content/EN/TXT/HTML/?uri=CELEX:32002L0058&from=EN" target="_blank">Article 15 of the e-Privacy Directive</a> which provides Member States with a specific exemption for the purposes of national security. If not covered by this, I would imagine they would rely on 'legitimate interests' as their ground instead. </font></div><div><font face="arial, sans-serif"><br></font></div><div><font face="arial, sans-serif">Finally, even if a registrar has a legitimate interest in processing someone's personal data, this does not address the <i>privacy </i>requirements that i indicated in my previous email. Unless there is a specific provision put into law, I do not know how the registrar can remain compliant with the GDPR and the EU's privacy requirements. In fact, I don't know how the EU can even comment on this, because, of course, the EU Charter is a legal framework completely distinct from the European Convention of Human Rights. </font></div><div><font face="arial, sans-serif"><br></font></div><div><font face="arial, sans-serif">One more thing to consider - if you choose to disclose your name, address, and designate as the contact person of a legal person, what happens when that person exercises their 'right to be forgotten' right under Article 17 GDPR. Maybe Milton Mueller the person chooses to leave the legal entity MM Porkbelly Diner, adopts a vegan lifestyle, and wants no affiliation with the business? If it's published, he can demand a correction of the database thereof. So what then? </font></div><div><font face="arial, sans-serif"><br></font></div><div><font face="arial, sans-serif">Regards,</font></div><div><font face="arial, sans-serif"><br></font></div><div><font face="arial, sans-serif">Mark </font></div><div><div><div dir="ltr"><div dir="ltr"><div dir="ltr"><div dir="ltr"><div dir="ltr"><div dir="ltr"><div dir="ltr"><div dir="ltr"><div dir="ltr"><div dir="ltr"><div dir="ltr"><div dir="ltr"><div dir="ltr"><div dir="ltr"><div dir="ltr"><div dir="ltr"><div><div style="font-size:12.8px"><br></div><div style="font-size:12.8px"><b><font color="#674ea7"><span style="font-size:small;font-family:Tahoma">Dr Mark Leiser | </span><span style="font-size:small">Law and Digital Technologies </span><span style="font-size:small;font-family:Tahoma">| FRSA FHEA </span><span style="font-family:Tahoma;font-size:small">|</span></font></b></div></div></div></div></div></div></div></div></div></div></div></div></div></div></div></div></div></div></div><br></div></div><br><div class="gmail_quote"><div dir="ltr" class="gmail_attr">On Tue, 27 Apr 2021 at 20:35, Mueller, Milton L <<a href="mailto:milton@gatech.edu" target="_blank">milton@gatech.edu</a>> wrote:<br></div><blockquote class="gmail_quote" style="margin:0px 0px 0px 0.8ex;border-left:1px solid rgb(204,204,204);padding-left:1ex">





<div lang="EN-US">
<div>
<p class="MsoNormal"><span style="font-size:11pt;font-family:Calibri,sans-serif;color:rgb(31,73,125)">Mark,
<u></u><u></u></span></p>
<p class="MsoNormal"><span style="font-size:11pt;font-family:Calibri,sans-serif;color:rgb(31,73,125)">Thanks for your intervention. Here is the complete definition of personal data in GDPR:<u></u><u></u></span></p>
<p class="MsoNormal" style="margin-right:0in;margin-bottom:12pt;margin-left:30pt;background:white;vertical-align:baseline">
<span style="color:rgb(51,51,51)">‘personal data’ means any information relating to an identified or identifiable natural person (‘data subject’); an identifiable natural person is one who can be identified, directly or indirectly, in
 particular by reference to an identifier such as a name, an identification number, location data, an online identifier or to one or more factors specific to the physical, physiological, genetic, mental, economic, cultural or social identity of that natural
 person;<u></u><u></u></span></p>
<p class="MsoNormal"><span style="font-size:11pt;font-family:Calibri,sans-serif;color:rgb(31,73,125)">Alas, this raises more questions than it answers. It is not entirely clear what “relating to” means in this construct. E.g., if the name of my company is Milton
 Mueller’s Porkbelly Diner, is the name relating to me as a person, or to my business? Strictly speaking it’s a business name. But it could be used to identify me. An overly broad interpretation of this definition would classify ANY data about ANYTHING as “personal
 data” because at some point it could be “related to” an “identifiable natural person.” So suddenly the business name becomes personal data. Or a bunch of obscure technical indicators inherent in your use of the internet, such as port numbers, browser config,
 etc., could be “related” to your ISP account number, and then used to identify you, personally. But does that mean that every website and hosting service in the world that uses that technical data in the course of their operations cannot process that info
 without your explicit permission, because it’s “personal data?” I hope not, because the internet would cease to function if so.
<u></u><u></u></span></p>
<p class="MsoNormal"><span style="font-size:11pt;font-family:Calibri,sans-serif;color:rgb(31,73,125)"><u></u> <u></u></span></p>
<div>
<div>
<p class="MsoNormal"><span style="font-family:Arial,sans-serif;color:rgb(31,73,125)">></span><span style="font-family:Arial,sans-serif">Therefore,
<a href="mailto:info@myorg.org" target="_blank">info@myorg.org</a> is personal data if someone behind it is identifiable.<span style="color:rgb(31,73,125)"><u></u><u></u></span></span></p>
<p class="MsoNormal"><span style="font-size:11pt;font-family:Calibri,sans-serif;color:rgb(31,73,125)"><u></u> <u></u></span></p>
<p class="MsoNormal"><span style="font-size:11pt;font-family:Calibri,sans-serif;color:rgb(31,73,125)">My point is that whether the user of
<a href="mailto:info@myorg.org" target="_blank">info@myorg.org</a> is identifiable does not depend on that chunk of data, but on a bunch of activities that relate that data to other things. And in a digital world with powerful processing capabilities, no one can fully control
 those correlations and searches. Any attempt to do so simply cripples the entire information economy. So the idea of looking at a registration record and saying “is there personal data in here or not” is a completely invalid test.<u></u><u></u></span></p>
<p class="MsoNormal"><span style="font-size:11pt;font-family:Calibri,sans-serif;color:rgb(31,73,125)"><u></u> <u></u></span></p>
<p class="MsoNormal"><span style="font-size:11pt;font-family:Calibri,sans-serif;color:rgb(31,73,125)">There is an eerie similarity between these exaggerated applications of privacy law and the copyright maximalists of the 1990s. The IP interests thought you needed
 permission to transmit a copyrighted work over the internet, a claim that would have crippled ISPs who had no idea what packets were parts of copyrighted material or not. Privacy maximalists have reached the same point of absurdity, but they don’t seem to
 realize it. They are no longer protecting a tangible privacy interest of internet users, they are trying to give individuals rigid control over information exchanges and imposing largely meaningless consent requirements that do no one any good.<u></u><u></u></span></p>
<p class="MsoNormal"><span style="font-size:11pt;font-family:Calibri,sans-serif;color:rgb(31,73,125)"><u></u> <u></u></span></p>
</div>
<div>
<p class="MsoNormal"><span style="color:rgb(31,73,125)">></span>The confusion comes from Recital 14 of the GDPR which states that it only applies to natural persons and does not cover the processing of personal data concerning legal persons, in particular undertakings
 established as legal persons or legal entities. This also includes the name of the legal person, the form, and the contact details of the legal person.<span style="color:rgb(31,73,125)">
</span>But the second you start adding identifiers to these details, it stops becoming the data of a 'legal person' and starts becoming personal data. <u></u><u></u></p>
<p class="MsoNormal"><span style="font-size:11pt;font-family:Calibri,sans-serif;color:rgb(31,73,125)"><u></u> <u></u></span></p>
<p class="MsoNormal"><span style="font-size:11pt;font-family:Calibri,sans-serif;color:rgb(31,73,125)">Yes, indeed, the GDPR is confused on this score. Unfortunately, you don’t escape that confusion by saying “adding identifiers” is the problem. Your argument fails
 because names of legal persons and contact details ARE “identifiers,” they are just identifiers of legal persons. As I pointed out they can easily overlap with, or be used to identify, natural persons.  <u></u><u></u></span></p>
<p class="MsoNormal"><span style="font-size:11pt;font-family:Calibri,sans-serif;color:rgb(31,73,125)"><u></u> <u></u></span></p>
<p class="MsoNormal"><span style="font-size:11pt;font-family:Calibri,sans-serif;color:rgb(31,73,125)">So my basic point is that we do not solve this problem by reference to GDPR definitions. In fact if GDPR is taken literally no one can ever publish and share
 any kind of information without absurd overhead and legal bureaucracy, because ALL of it can be used to identify you in some way. These kinds of interpretations actually discredit privacy laws and protections, by taking them to counterproductive lengths. We
 have to make common sense-based, practical distinctions between what data needs protection, what data can be easily shared at the registrants’ choice.<u></u><u></u></span></p>
</div>
<div>
<p class="MsoNormal"><u></u> <u></u></p>
</div>
<div>
<p class="MsoNormal">Secondly, I find this statement, "I think it is simplest to just say to the registrant, if you’re a company and don’t mind (or even want) your data to be published, check this box. If you’re not, or you do mind, don’t check it."  to be
 BOTH perplexing and inaccurate.  Whether someone checks the box, or does not check the box is completely irrelevant for determining whether it is personal data. Whether someone checks the box is a question of CONSENT to processing AND publication, not whether
 this amounts to personal data. <span style="color:rgb(31,73,125)"><u></u><u></u></span></p>
<p class="MsoNormal"><span style="font-size:11pt;font-family:Calibri,sans-serif;color:rgb(31,73,125)"><u></u> <u></u></span></p>
<p class="MsoNormal"><span style="font-size:11pt;font-family:Calibri,sans-serif;color:rgb(31,73,125)">We actually seem to agree here, more than you think. I am saying that the user, the registrant, gets to decide what is personal data or not, because THERE IS
 NO OBJECTIVE, CLEAR LEGAL DEFINITION. So the user can decide whether they want to be classified as a legal person and “consent” to publishing their data or not. As an example, that if I decide that publishing the name of “Milton Mueller’s Porkbelly Diner”
 is not a violation of my privacy, it isn’t. It doesn’t matter what the European Union says, it’s my choice.   <u></u><u></u></span></p>
<p class="MsoNormal"><span style="font-size:11pt;font-family:Calibri,sans-serif;color:rgb(31,73,125)"><u></u> <u></u></span></p>
<p class="MsoNormal"><span style="font-size:11pt;font-family:Calibri,sans-serif;color:rgb(31,73,125)">And let’s not overlook the embarrassing fact that the European Union is now one of the key players pushing hard for publication of legal person data. But I’ll
 leave that one to later. <u></u><u></u></span></p>
</div>
</div>
</div>
</div>

</blockquote></div>
</blockquote></div>