<div dir="ltr">I've always found the natural/legal distinction to be doubtful in this context, but still I prefer Milton's position, maybe with a slight modification.<div><br></div><div>The determination of what is and isnt personal data will be in the hands of DPAs or judges, at the end of the day. As it has been noted several times, the definition we're looking at is a relative one: one piece of data may be personal data in some context, and not in others; and may even be personal data in the hands of some persons, and not others... the key being whether it allows the identification of a natural person. </div><div><br></div><div>Hence for the purpose of the scope of the law and its operation, it does not matter whether one says "there is no personal data in these form fields" or "I am not a natural person but a legal person." Not that people are idiots and cannot understand the law, but their determination is not binding on anyone and does not have legal effect. For example, if I claim to be a legal person (hence out of scope of the law) and proceed to give someone else's full address+name+phone number, the fact that this data may genuinely relate to a legal person, and that I made that claim by ticking a box, does not change the fact that the disclosure, in this case, amounts to processing of personal data, which puts me "back" into the scope of the law.</div><div><br></div><div>It does matter, however, whether someone says "I consent to this processing of data <i>about me</i>" (here would be the modification) That makes the processing legal, provided that the general rules on consent and the provision of information about the processing are followed. </div><div><br></div><div>Consent as a basis is fraught with issues, but even for those like me who are generally skeptical of it, I think that the processing and the data concerned are narrow/limited enough to make consent an otherwise "acceptable" legal basis for processing. </div><div><br></div><div>Now if in consenting, people end up disclosing personal data pertaining to someone else, willingly or unwillingly, with or without "bad" intent, well yes we do have a problem... and ticking an additional box will not absolve them of liability under their local law (or any other), as the case may be. If that is such a potential issue, however, then the only solution that I see is not to have any disclosures possible outside of mandatory ones. But that would be out of scope, as I understand it, and as pointed out by Manju, and would raise the potentially valid point of what if someone wants to disclose. </div><div><br></div><div>Additionally, I do not think that forcing mandatory rules or refraining from saying anything would be a good idea at this point. </div><div><br></div><div>Have a nice day, </div><div><br></div><div><br></div><div></div><div></div><div></div></div><br><div class="gmail_quote"><div dir="ltr" class="gmail_attr">On Wed, Apr 28, 2021 at 10:53 AM Stephanie E Perrin <<a href="mailto:stephanie.perrin@mail.utoronto.ca" target="_blank">stephanie.perrin@mail.utoronto.ca</a>> wrote:<br></div><blockquote class="gmail_quote" style="margin:0px 0px 0px 0.8ex;border-left:1px solid rgb(204,204,204);padding-left:1ex">

  
  <div>
    <p>Thanks again Manju, for your untiring efforts to get us to solve
      this disagreement about next steps.  I am going to try to
      summarize my thinking on this, without diving into the complexity
      of the law and the difficulties inherent in implementing it.</p>
    <p>1.  The push to distinguish between legal and natural is not
      new.  We fought it in the PPSAI, and won.  In phase 1 EPDP, we
      managed to get recommendation #6 through, but with the concession
      that ICANN would do a study on legal natural, and that we would
      reexamine.  My position is basically HOLD THAT LINE!  We do not
      need to change our position, we can examine the matter, take a
      look at what guidance would do, and maintain the status quo.</p>
    <p>2.  We have sought advice from Bird and Bird on mitigating the
      risk to contracted parties in terms of how they provide
      information to their registrants, in order to be in full
      compliance with data protection law (viewed through the GDPR
      lens).  For the contracted parties, nothing in there eliminates
      the risk that the data controller has, but certainly guidance
      mitigates it.  However, remember that civil society can take a
      case under GDPR, and if I were advising civil society as to how to
      take a case, I would point out the history of WHOIS, the dogged
      determination of ICANN and the IP and business community to get
      back to the good old WHOIS, the lack of evidence that forcing this
      determination on smaller actors will indeed result in greater
      security and stability  of the DNS, and the unequal power
      relationship between ICANN the regulator and the contracted
      parties who must be accredited to do business.  Third party data
      accessors are driving this process, and registrants are basicly
      being represented by ourselves, and the Registrars who have them
      as customers.  I think we have a responsibility not to cave in.</p>
    <p>3.  A word on small business, sole proprietors, and home based
      entrepreneurs or gig workers.  We are the Non-commercial
      stakeholders, so we do not claim to represent them.  Frankly, I
      don't know who does here at ICANN, in my 8 years of volunteering
      at ICANN I have never heard the ALAC folks advance a cohesive
      argument on behalf of these folks (or even an argument, but I
      hesitate to say that because someone will trawl through the
      archives and come up with someone defending the little guy against
      giant corporations).  Certainly they are not speaking for them at
      the EPDP, they are speaking for government, law enforcement, and
      cybersecurity operatives.  As folks who care about human rights
      and fairness to developing economies, I think we should care about
      how much this differentiation between legal persons and natural
      persons does not work in countries other than the EU states and
      the US.  Countries around the world have different ways to
      describe small business, different ways to regulate it, and this
      differentiation may not match tax schemes, municipal registration
      patterns, etc.  There is of course an additional barrier in the
      matter of languages.<br>
    </p>
    <p>4.  Remember that what we are arguing about is not providing
      access to data about suspected legal persons through the SSAD.  We
      are arguing about Automatic disclosure based on the choice the
      individual makes, legal or natural person.  As I have said before,
      the skies are not going to fall if the legitimate requestors have
      to request the data and get it in one or two business days, as
      opposed to having it pre-emptively disclosed.   Remember that the
      registrar or his reseller has a wealth of other day about their
      customer that is "below the surface", most importantly credit card
      info, billing address for the credit card, emails, IP address
      etc.  They can look at that data if necessary, to figure out
      whether they are dealing with a company or a person.  However, the
      SSAD does not have access to that data.  If we encourage this
      differentiation by putting guidance into the policy, then we are
      heading for the slippery slope of automated disclosure. Remember
      that there is already a section in there that once the data has
      been verified as pertaining to a legal person and not containing
      personal data, it MUST be disclosed.  What happens when that legal
      entity moves to a jurisdiction where employees have privacy
      rights, either under data protection law or other laws such as
      labour laws or contracts?  There is a good chance that some of
      their data becomes personal.<br>
    </p>
    <p>5.  Registrars already have excellent advice for their members
      available through their own websites.  Remember that at ICANN we
      are only dealing with the big ones, and the responsible ones.  We
      have to consider whether any activity we sanction in this policy
      induces the lazy ones to cut corners.  They are used to disclosing
      everything in the WHOIS, if given an opportunity to revert to that
      by creating this distinction, they will most likely do what is
      easiest.  At the moment, under the temp spec and article 6, the
      easiest thing to do is to consider these grey area folks as
      natural persons unless proven otherwise, and protect the data. 
      Why on earth would we not choose this option?  There is no law
      telling us to do otherwise, and there is certainly a great deal of
      law out there that makes differentiation a legal risk that carries
      liability and cost.  We want domain names to remain affordable,
      and we want our people protected.</p>
    <p>6.  One more thing:  remember that not all domain names are used
      for websites engaged in commerce.  Some are being held by
      individuals for future use.  Disclosure provides market
      information to big players who may want to prevent the name from
      being used, or to purchase them, but there is no harm emanating
      from them in dormancy, and small players need not have their
      competitive positions compromised in this way.  Most of the online
      crime that we hear adduced to justify disclosure of data is coming
      from websites.  Websites can be regulated to protect consumers,
      but that is not within ICANN's bailiwick.  Folks come to ICANN to
      demand this activity because other multilateral instruments have
      failed, but given the lack of oversight over ICANN, the
      responsibility to ensure fairness and human rights are respected
      falls on the shoulders of the stakeholders engaged here. <br>
    </p>
    <p>7.  Finally:  Several folks are worried that governments will
      regulate if we do not concede here.  I say let them, the Courts
      and the Constitution and the much more rigorous defences against
      incursions into human rights available within countries will
      prevail.  It certainly will in the EU, where the draft NIS is
      progressing.....I keep pointing out the Opinion of the European
      Data Protection Supervisor on this matter, so one more time here
      it is
<a href="https://www.google.com/search?client=firefox-b-d&q=edps+on+the+nis+directive" target="_blank">https://www.google.com/search?client=firefox-b-d&q=edps+on+the+nis+directive</a>. 
      As for the increasing number of autocratic countries interested in
      curtailing the free speech and internet rights of their citizens,
      they are regulating anyway and nothing that ICANN does is going to
      persuade them otherwise.  A good example of us falling on the side
      of customer protection might at least give those individuals in
      these countries something to point to, as opposed to caving in to
      threats.<br>
    </p>
    <p>cheers Stephanie Perrin<br>
    </p>
    <div>On 2021-04-27 11:56 p.m., 陳曼茹 Manju
      Chen wrote:<br>
    </div>
    <blockquote type="cite">
      
      <div style="font-size:10pt;font-family:sans-serif;color:white;font-style:normal;font-weight:bold;padding:0.2em">
        <strong><span style="color:rgb(199,80,0)">EXTERNAL EMAIL:</span></strong></div>
      <div>
        <div dir="ltr">
          <div class="gmail_default" style="font-family:arial,sans-serif;font-size:small">Hi all,</div>
          <div class="gmail_default" style="font-family:arial,sans-serif;font-size:small"><br>
          </div>
          <div class="gmail_default" style="font-family:arial,sans-serif;font-size:small">This
            has been a very helpful discussion. Our ultimate goal is to
            finalize an NCSG position, and I'd like to provide some
            context in the interest of reaching that goal.</div>
          <div class="gmail_default" style="font-family:arial,sans-serif;font-size:small"><br>
          </div>
          <div class="gmail_default" style="font-family:arial,sans-serif;font-size:small">Some
            have pointed out that the question of 'do you agree to
            publish your data' is a much better one than 'are you a
            legal or natural person'. I totally agree. But we already
            have that in the policy. In the EPDP phase 1 final report,
            recommendation #6 reads: </div>
          <blockquote style="margin:0px 0px 0px 0.8ex;border-left:1px solid rgb(204,204,204);padding-left:1ex" class="gmail_quote">
            <span style="font-family:Arial,Helvetica,sans-serif">The
              EPDP Team recommends that, as soon as commercially
              reasonable, Registrar must </span><span style="font-family:Arial,Helvetica,sans-serif">provide the
              opportunity for the Registered Name Holder to provide its
              Consent to </span><span style="font-family:Arial,Helvetica,sans-serif">publish
              redacted contact information, as well as the email
              address, in the RDS for the </span><span style="font-family:Arial,Helvetica,sans-serif">sponsoring
              registrar.</span></blockquote>
          <div><br>
          </div>
          <div class="gmail_default" style="font-family:arial,sans-serif;font-size:small">In the
            EPDP phase2A, the WG is tasked to address the following
            questions:</div>
          <div class="gmail_default" style="font-family:arial,sans-serif;font-size:small">
            <ol>
              <li>Whether any updates are required to the EPDP Phase 1
                recommendation on this topic (“Registrars and Registry
                Operators are permitted to differentiate between
                registrations of legal and natural persons, but are not
                obligated to do so“);
              </li>
              <li>What guidance, if any, can be provided to Registrars
                and/or Registries who differentiate between
                registrations of legal and natural persons. </li>
            </ol>
            <div>So it's not that we 'want' the distinction of
              natural vs. legal. It's the task we're given, and per the
              WG chair's last email to the EPDP team, it's not something
              we can avoid. We have to stick to the 'natural vs. legal
              persons' rhetoric to answer the questions. </div>
            <div><br>
            </div>
            <div>Of course, we can simply assert that 'there's no update
              needed' and let the contracted parties do whatever they
              want when they feel like making the distinction. I was
              personally very tempted by this option every now and then.
              However, as Milton pointed out in another email, we are
              already developing guidance in the EPDP, so that option
              seems far-fetched. </div>
            <div><br>
            </div>
            <div>I hope this explains some of the confusion and helps us
              to consider Milton's 4 options in the other email. </div>
            <div><br>
            </div>
            <div>Thanks!</div>
            <div><br>
            </div>
            <div><br>
            </div>
            <div>Best, </div>
            <div>Manju</div>
          </div>
        </div>
        <br>
        <div class="gmail_quote">
          <div dir="ltr" class="gmail_attr">On Wed, Apr 28, 2021 at 4:40
            AM Mark Leiser <<a href="mailto:markleiser@gmail.com" target="_blank">markleiser@gmail.com</a>>
            wrote:<br>
          </div>
          <blockquote class="gmail_quote" style="margin:0px 0px 0px 0.8ex;border-left:1px solid rgb(204,204,204);padding-left:1ex">
            <div dir="ltr"><font face="arial, sans-serif">Hi Milton,</font>
              <div><font face="arial, sans-serif"><br>
                </font></div>
              <div><font face="arial, sans-serif">First let me say I
                  completely agree with you on your statements about
                  European data privacy. I feel like I've dedicated most
                  of my professional life arguing about the dangers of
                  privacy and data protection maximalism - yet almost
                  always feel like my arguments on deaf ears. While
                  people are arguing that 'everything is personal data',
                  I've been arguing that this makes the regime
                  unmanageable. </font></div>
              <div><font face="arial, sans-serif"><br>
                </font></div>
              <div><font face="arial, sans-serif">So let me try to
                  explain 'relating to' with reference to 'Milton
                  Mueller's Porkbelly Diner'. Because of Recital 14,
                  this would amount to a legal person. It's pretty clear
                  that the intention of the GDPR's drafters was to
                  exclude legal persons. However, let's say you have
                  registered 'MM Porkbelly Diner' in the register of
                  companies. I think you would agree that this would
                  amount to information about a legal person. But say
                  someone searched the company register and discovered
                  Milton Mueller was the principal shareholder of MM
                  Porkbelly Diner. This is an identifier which would
                  <i>tie nformation about Milton Mueller to</i> 'MM
                  PorkBelly Diner'. Therefore, this is 'any information'
                  'relating to' an identified or identifiable living
                  person. It would be reasonable to infer that MM
                  registered in the registrar database under MM
                  PorkBelly Diner is the same as the Milton Mueller that
                  is in the register of companies. The fact that someone
                  can combine the knowledge from the company register
                  with the knowledge from the registrar database could
                  make 'MM Porkbelly Diner' personal data under Article
                  4(1) of the GDPR. Someone who did not disclose their
                  identity at all could still be identifiable; hence,
                  the perceived need for protection in the EU data
                  protection regime.</font></div>
              <div><font face="arial, sans-serif"><br>
                </font></div>
              <div><font face="arial, sans-serif"> "I<span style="color:rgb(31,73,125)"> </span><span style="color:rgb(31,73,125)">am saying that the
                    user, the registrant, gets to decide what is
                    personal data or not, because THERE IS NO OBJECTIVE,
                    CLEAR LEGAL DEFINITION" is, on the surface,
                    problematic. </span><font color="#000000">It
                    doesn't matter whether the user says NO or YES or
                    the registrar says no or yes, or whether it is
                    objective or clear, the test is whether any
                    information can be combined with other information
                    to reveal an identifiable living person. I would
                    argue, absent a wholesale change in the reasoning
                    used by the CJEU, this would remain the case for the
                    foreseeable future. This is not intended as a Mark
                    Leiser argument or an attempt to discredit what you
                    are saying, but an honest account of how I think the
                    Courts and the EU data protection Board would react
                    to what you are proposing. </font><br>
                </font></div>
              <div><font face="arial, sans-serif"><br>
                </font></div>
              <div><font face="arial, sans-serif">You asked about <a href="https://iapp.org/news/a/are-ip-addresses-generated-when-users-visit-websites-personal-information/#:~:text=Under%20the%20EU%20General%20Data,header%20information%20that%20website%20hosts" target="_blank">
                    IP addresses</a>, 'port numbers', 'browser config',
                  etc could be used to identify you personally. Yes,
                  absolutely. This is personal data in the EU - if it
                  can relate to a living person. What your writing here
                  reveals, is that you are a little confused about how
                  the GDPR works - the GDPR does not rely on 'consent'
                  or 'explicit permission' as the only basis for
                  processing personal data. Remember the GDPR has six<a href="https://gdpr-info.eu/art-6-gdpr/" target="_blank"> grounds of
                    processing</a>. It is a prohibitive regulation. You
                  cannot process personal data in the EU unless you
                  satisfy one of those six grounds. Most companies will
                  NOT be processing on the basis of 'consent' but on
                  'legitimate interests' (Article 6(1)(f)) or
                  performance of a contract (Article 6(1)(b)). Don't
                  worry, this is an extremely common mistake among
                  American attorneys! As most of these items are
                  "technical', I would also imagine that there is a
                  'legal requirement' (another ground) or a lawful
                  basis. All ISPs will be processing personal data
                  through 'IP addresses', 'port browsers', and 'browser
                  config' because of the legal basis found in <a href="https://eur-lex.europa.eu/legal-content/EN/TXT/HTML/?uri=CELEX:32002L0058&from=EN" target="_blank">Article 15 of
                    the e-Privacy Directive</a> which provides
                  Member States with a specific exemption for the
                  purposes of national security. If not covered by this,
                  I would imagine they would rely on 'legitimate
                  interests' as their ground instead. </font></div>
              <div><font face="arial, sans-serif"><br>
                </font></div>
              <div><font face="arial, sans-serif">Finally, even if a
                  registrar has a legitimate interest in processing
                  someone's personal data, this does not address the
                  <i>privacy </i>requirements that i indicated in my
                  previous email. Unless there is a specific provision
                  put into law, I do not know how the registrar can
                  remain compliant with the GDPR and the EU's privacy
                  requirements. In fact, I don't know how the EU can
                  even comment on this, because, of course, the EU
                  Charter is a legal framework completely distinct from
                  the European Convention of Human Rights. </font></div>
              <div><font face="arial, sans-serif"><br>
                </font></div>
              <div><font face="arial, sans-serif">One more thing to
                  consider - if you choose to disclose your name,
                  address, and designate as the contact person of a
                  legal person, what happens when that person exercises
                  their 'right to be forgotten' right under Article 17
                  GDPR. Maybe Milton Mueller the person chooses to leave
                  the legal entity MM Porkbelly Diner, adopts a vegan
                  lifestyle, and wants no affiliation with the business?
                  If it's published, he can demand a correction of the
                  database thereof. So what then? </font></div>
              <div><font face="arial, sans-serif"><br>
                </font></div>
              <div><font face="arial, sans-serif">Regards,</font></div>
              <div><font face="arial, sans-serif"><br>
                </font></div>
              <div><font face="arial, sans-serif">Mark </font></div>
              <div>
                <div>
                  <div dir="ltr">
                    <div dir="ltr">
                      <div dir="ltr">
                        <div dir="ltr">
                          <div dir="ltr">
                            <div dir="ltr">
                              <div dir="ltr">
                                <div dir="ltr">
                                  <div dir="ltr">
                                    <div dir="ltr">
                                      <div dir="ltr">
                                        <div dir="ltr">
                                          <div dir="ltr">
                                            <div dir="ltr">
                                              <div dir="ltr">
                                                <div dir="ltr">
                                                  <div>
                                                    <div style="font-size:12.8px"><br>
                                                    </div>
                                                    <div style="font-size:12.8px"><b><font color="#674ea7"><span style="font-size:small;font-family:Tahoma">Dr Mark
                                                          Leiser |
                                                          </span><span style="font-size:small">Law
                                                          and Digital
                                                          Technologies </span><span style="font-size:small;font-family:Tahoma">| FRSA FHEA </span><span style="font-family:Tahoma;font-size:small">|</span></font></b></div>
                                                  </div>
                                                </div>
                                              </div>
                                            </div>
                                          </div>
                                        </div>
                                      </div>
                                    </div>
                                  </div>
                                </div>
                              </div>
                            </div>
                          </div>
                        </div>
                      </div>
                    </div>
                  </div>
                </div>
                <br>
              </div>
            </div>
            <br>
            <div class="gmail_quote">
              <div dir="ltr" class="gmail_attr">On Tue, 27 Apr 2021 at
                20:35, Mueller, Milton L <<a href="mailto:milton@gatech.edu" target="_blank">milton@gatech.edu</a>>
                wrote:<br>
              </div>
              <blockquote class="gmail_quote" style="margin:0px 0px 0px 0.8ex;border-left:1px solid rgb(204,204,204);padding-left:1ex">
                <div lang="EN-US">
                  <div>
                    <p class="MsoNormal"><span style="font-size:11pt;font-family:Calibri,sans-serif;color:rgb(31,73,125)">Mark,
                      </span></p>
                    <p class="MsoNormal"><span style="font-size:11pt;font-family:Calibri,sans-serif;color:rgb(31,73,125)">Thanks
                        for your intervention. Here is the complete
                        definition of personal data in GDPR:</span></p>
                    <p class="MsoNormal" style="margin-right:0in;margin-bottom:12pt;margin-left:30pt;background:white;vertical-align:baseline"><span style="color:rgb(51,51,51)">‘personal data’
                        means any information relating to an identified
                        or identifiable natural person (‘data subject’);
                        an identifiable natural person is one who can be
                        identified, directly or indirectly, in
                        particular by reference to an identifier such as
                        a name, an identification number, location data,
                        an online identifier or to one or more factors
                        specific to the physical, physiological,
                        genetic, mental, economic, cultural or social
                        identity of that natural person;</span></p>
                    <p class="MsoNormal"><span style="font-size:11pt;font-family:Calibri,sans-serif;color:rgb(31,73,125)">Alas,
                        this raises more questions than it answers. It
                        is not entirely clear what “relating to” means
                        in this construct. E.g., if the name of my
                        company is Milton Mueller’s Porkbelly Diner, is
                        the name relating to me as a person, or to my
                        business? Strictly speaking it’s a business
                        name. But it could be used to identify me. An
                        overly broad interpretation of this definition
                        would classify ANY data about ANYTHING as
                        “personal data” because at some point it could
                        be “related to” an “identifiable natural
                        person.” So suddenly the business name becomes
                        personal data. Or a bunch of obscure technical
                        indicators inherent in your use of the internet,
                        such as port numbers, browser config, etc.,
                        could be “related” to your ISP account number,
                        and then used to identify you, personally. But
                        does that mean that every website and hosting
                        service in the world that uses that technical
                        data in the course of their operations cannot
                        process that info without your explicit
                        permission, because it’s “personal data?” I hope
                        not, because the internet would cease to
                        function if so.
                      </span></p>
                    <p class="MsoNormal"><span style="font-size:11pt;font-family:Calibri,sans-serif;color:rgb(31,73,125)"> </span></p>
                    <div>
                      <div>
                        <p class="MsoNormal"><span style="font-family:Arial,sans-serif;color:rgb(31,73,125)">></span><span style="font-family:Arial,sans-serif">Therefore,
                            <a href="mailto:info@myorg.org" target="_blank">info@myorg.org</a>
                            is personal data if someone behind it is
                            identifiable.<span style="color:rgb(31,73,125)"></span></span></p>
                        <p class="MsoNormal"><span style="font-size:11pt;font-family:Calibri,sans-serif;color:rgb(31,73,125)"> </span></p>
                        <p class="MsoNormal"><span style="font-size:11pt;font-family:Calibri,sans-serif;color:rgb(31,73,125)">My
                            point is that whether the user of
                            <a href="mailto:info@myorg.org" target="_blank">info@myorg.org</a>
                            is identifiable does not depend on that
                            chunk of data, but on a bunch of activities
                            that relate that data to other things. And
                            in a digital world with powerful processing
                            capabilities, no one can fully control those
                            correlations and searches. Any attempt to do
                            so simply cripples the entire information
                            economy. So the idea of looking at a
                            registration record and saying “is there
                            personal data in here or not” is a
                            completely invalid test.</span></p>
                        <p class="MsoNormal"><span style="font-size:11pt;font-family:Calibri,sans-serif;color:rgb(31,73,125)"> </span></p>
                        <p class="MsoNormal"><span style="font-size:11pt;font-family:Calibri,sans-serif;color:rgb(31,73,125)">There
                            is an eerie similarity between these
                            exaggerated applications of privacy law and
                            the copyright maximalists of the 1990s. The
                            IP interests thought you needed permission
                            to transmit a copyrighted work over the
                            internet, a claim that would have crippled
                            ISPs who had no idea what packets were parts
                            of copyrighted material or not. Privacy
                            maximalists have reached the same point of
                            absurdity, but they don’t seem to realize
                            it. They are no longer protecting a tangible
                            privacy interest of internet users, they are
                            trying to give individuals rigid control
                            over information exchanges and imposing
                            largely meaningless consent requirements
                            that do no one any good.</span></p>
                        <p class="MsoNormal"><span style="font-size:11pt;font-family:Calibri,sans-serif;color:rgb(31,73,125)"> </span></p>
                      </div>
                      <div>
                        <p class="MsoNormal"><span style="color:rgb(31,73,125)">></span>The
                          confusion comes from Recital 14 of the GDPR
                          which states that it only applies to natural
                          persons and does not cover the processing of
                          personal data concerning legal persons, in
                          particular undertakings established as legal
                          persons or legal entities. This also includes
                          the name of the legal person, the form, and
                          the contact details of the legal person.<span style="color:rgb(31,73,125)">
                          </span>But the second you start adding
                          identifiers to these details, it stops
                          becoming the data of a 'legal person' and
                          starts becoming personal data. </p>
                        <p class="MsoNormal"><span style="font-size:11pt;font-family:Calibri,sans-serif;color:rgb(31,73,125)"> </span></p>
                        <p class="MsoNormal"><span style="font-size:11pt;font-family:Calibri,sans-serif;color:rgb(31,73,125)">Yes,
                            indeed, the GDPR is confused on this score.
                            Unfortunately, you don’t escape that
                            confusion by saying “adding identifiers” is
                            the problem. Your argument fails because
                            names of legal persons and contact details
                            ARE “identifiers,” they are just identifiers
                            of legal persons. As I pointed out they can
                            easily overlap with, or be used to identify,
                            natural persons.  </span></p>
                        <p class="MsoNormal"><span style="font-size:11pt;font-family:Calibri,sans-serif;color:rgb(31,73,125)"> </span></p>
                        <p class="MsoNormal"><span style="font-size:11pt;font-family:Calibri,sans-serif;color:rgb(31,73,125)">So
                            my basic point is that we do not solve this
                            problem by reference to GDPR definitions. In
                            fact if GDPR is taken literally no one can
                            ever publish and share any kind of
                            information without absurd overhead and
                            legal bureaucracy, because ALL of it can be
                            used to identify you in some way. These
                            kinds of interpretations actually discredit
                            privacy laws and protections, by taking them
                            to counterproductive lengths. We have to
                            make common sense-based, practical
                            distinctions between what data needs
                            protection, what data can be easily shared
                            at the registrants’ choice.</span></p>
                      </div>
                      <div>
                        <p class="MsoNormal"> </p>
                      </div>
                      <div>
                        <p class="MsoNormal">Secondly, I find this
                          statement, "I think it is simplest to just say
                          to the registrant, if you’re a company and
                          don’t mind (or even want) your data to be
                          published, check this box. If you’re not, or
                          you do mind, don’t check it."  to be BOTH
                          perplexing and inaccurate.  Whether someone
                          checks the box, or does not check the box is
                          completely irrelevant for determining whether
                          it is personal data. Whether someone checks
                          the box is a question of CONSENT to processing
                          AND publication, not whether this amounts to
                          personal data. <span style="color:rgb(31,73,125)"></span></p>
                        <p class="MsoNormal"><span style="font-size:11pt;font-family:Calibri,sans-serif;color:rgb(31,73,125)"> </span></p>
                        <p class="MsoNormal"><span style="font-size:11pt;font-family:Calibri,sans-serif;color:rgb(31,73,125)">We
                            actually seem to agree here, more than you
                            think. I am saying that the user, the
                            registrant, gets to decide what is personal
                            data or not, because THERE IS NO OBJECTIVE,
                            CLEAR LEGAL DEFINITION. So the user can
                            decide whether they want to be classified as
                            a legal person and “consent” to publishing
                            their data or not. As an example, that if I
                            decide that publishing the name of “Milton
                            Mueller’s Porkbelly Diner” is not a
                            violation of my privacy, it isn’t. It
                            doesn’t matter what the European Union says,
                            it’s my choice.   </span></p>
                        <p class="MsoNormal"><span style="font-size:11pt;font-family:Calibri,sans-serif;color:rgb(31,73,125)"> </span></p>
                        <p class="MsoNormal"><span style="font-size:11pt;font-family:Calibri,sans-serif;color:rgb(31,73,125)">And
                            let’s not overlook the embarrassing fact
                            that the European Union is now one of the
                            key players pushing hard for publication of
                            legal person data. But I’ll leave that one
                            to later. </span></p>
                      </div>
                    </div>
                  </div>
                </div>
              </blockquote>
            </div>
          </blockquote>
        </div>
      </div>
    </blockquote>
  </div>

</blockquote></div>