<!DOCTYPE html PUBLIC "-//W3C//DTD HTML 4.0 Transitional//EN"
"http://www.w3.org/TR/REC-html40/loose.dtd">
<html>
<head>
<meta http-equiv="content-type" content="text/html; charset=utf-8">
<title></title>
</head>
<body style="font-family:Arial;font-size:14px">
<p>All,<br>
I would like to urge us to step back from the discussion for a few days. I think there is a lot of data that is being created that needs to be shared - data and studies that should inform our decision. Some of the data presented to the EPDP, I am told, includes:<br>
<br>
1) 50% of gTLD domain name registrations are for natural persons (which makes sense to me since the number of people on the Internet far exceeds the number of companies). That's significant.<br>
<br>
2) That DNS Abuse has dropped meaningfully since the redaction of the data.<br>
<br>
I also think we should explore more meaningfully what our members need. We are noncommercial organizations and individuals seeking to protect noncommerical speech online. Many of our groups are public interest and human rights -- with agendas that "tick off" someone - and our personal data could be used against us or our families. We have legal privacy protections not yet discussed significantly on this list - protections under Art 9 of EU GDPR for "sensitive data" which links us to our political, gender and similar views AND protection for free speech, freedom of expression and freedom of association under the UN Declaration of Human Rights, the US Constitution and the European Convention on Human Rights, and more (feel free to share your own national laws).<br>
<br>
<strong>Stephanie is absolutely right. (I'll have a note below about where I agree with Milton too.) On the Proxy & Privacy Services Accreditation Issues Working Group (PPSAI) we worked on behalf of NCSG to see that NSCG registrants (and others) were not asked to answer questions of "legal and natural persons" that would lead to questions our members would have the most difficult time answering. The answers are not clear or easy - as our discussion of the last few days has shown.</strong><br>
<br>
One goal of the GDPR is to encourage the overprotection rather that the underprotection of privacy - if we are going to err, it is to protect the data. In that spirit, I would vote to hold the present course - Option 1. Let those who want to publish their data publish their data. And keep the rest of us from making the wrong choices with legal implications that threaten us, our organizations and the data controllers and processors.<br>
<br>
<em>As Stephanie writes below, ICANN is designing automated disclosure systems that will operate automatically based on our self-identification. Asking questions registrant can't easily answer, with enormous implications, is not fair or right.</em><br>
<br>
<strong>I agree with Milton that Registrants should be able to disclosure their data only if they want to (which is clear part of the status quo).</strong><br>
<br>
<em>Thus, at this time and with the evidence we have, <strong>Status Quo - Option 1 - preserves the choice registrants have now: Any registrant be it company, organization, individual can publish its/her/his data if they want to.</strong></em><br>
<br>
Tx to our EPDP Team for including us in their evaluations!<br>
<br>
Best, Kathy<br>
<br>
Quoting Stephanie E Perrin <<a href="mailto:stephanie.perrin@mail.utoronto.ca">stephanie.perrin@mail.utoronto.ca</a>>:<br>
<br>
> Thanks again Manju, for your untiring efforts to get us to solve this<br>
> disagreement about next steps. I am going to try to summarize my<br>
> thinking on this, without diving into the complexity of the law and<br>
> the difficulties inherent in implementing it.<br>
><br>
> 1. The push to distinguish between legal and natural is not new. We<br>
> fought it in the PPSAI, and won. In phase 1 EPDP, we managed to get<br>
> recommendation #6 through, but with the concession that ICANN would<br>
> do a study on legal natural, and that we would reexamine. My<br>
> position is basically HOLD THAT LINE! We do not need to change our<br>
> position, we can examine the matter, take a look at what guidance<br>
> would do, and maintain the status quo.<br>
><br>
> 2. We have sought advice from Bird and Bird on mitigating the risk<br>
> to contracted parties in terms of how they provide information to<br>
> their registrants, in order to be in full compliance with data<br>
> protection law (viewed through the GDPR lens). For the contracted<br>
> parties, nothing in there eliminates the risk that the data<br>
> controller has, but certainly guidance mitigates it. However,<br>
> remember that civil society can take a case under GDPR, and if I were<br>
> advising civil society as to how to take a case, I would point out<br>
> the history of WHOIS, the dogged determination of ICANN and the IP<br>
> and business community to get back to the good old WHOIS, the lack of<br>
> evidence that forcing this determination on smaller actors will<br>
> indeed result in greater security and stability of the DNS, and the<br>
> unequal power relationship between ICANN the regulator and the<br>
> contracted parties who must be accredited to do business. Third<br>
> party data accessors are driving this process, and registrants are<br>
> basicly being represented by ourselves, and the Registrars who have<br>
> them as customers. I think we have a responsibility not to cave in.<br>
><br>
> 3. A word on small business, sole proprietors, and home based<br>
> entrepreneurs or gig workers. We are the Non-commercial<br>
> stakeholders, so we do not claim to represent them. Frankly, I don't<br>
> know who does here at ICANN, in my 8 years of volunteering at ICANN I<br>
> have never heard the ALAC folks advance a cohesive argument on behalf<br>
> of these folks (or even an argument, but I hesitate to say that<br>
> because someone will trawl through the archives and come up with<br>
> someone defending the little guy against giant corporations). <br>
> Certainly they are not speaking for them at the EPDP, they are<br>
> speaking for government, law enforcement, and cybersecurity<br>
> operatives. As folks who care about human rights and fairness to<br>
> developing economies, I think we should care about how much this<br>
> differentiation between legal persons and natural persons does not<br>
> work in countries other than the EU states and the US. Countries<br>
> around the world have different ways to describe small business,<br>
> different ways to regulate it, and this differentiation may not match<br>
> tax schemes, municipal registration patterns, etc. There is of<br>
> course an additional barrier in the matter of languages.<br>
><br>
> 4. Remember that what we are arguing about is not providing access<br>
> to data about suspected legal persons through the SSAD. We are<br>
> arguing about Automatic disclosure based on the choice the individual<br>
> makes, legal or natural person. As I have said before, the skies are<br>
> not going to fall if the legitimate requestors have to request the<br>
> data and get it in one or two business days, as opposed to having it<br>
> pre-emptively disclosed. Remember that the registrar or his<br>
> reseller has a wealth of other day about their customer that is<br>
> "below the surface", most importantly credit card info, billing<br>
> address for the credit card, emails, IP address etc. They can look<br>
> at that data if necessary, to figure out whether they are dealing<br>
> with a company or a person. However, the SSAD does not have access<br>
> to that data. If we encourage this differentiation by putting<br>
> guidance into the policy, then we are heading for the slippery slope<br>
> of automated disclosure. Remember that there is already a section in<br>
> there that once the data has been verified as pertaining to a legal<br>
> person and not containing personal data, it MUST be disclosed. What<br>
> happens when that legal entity moves to a jurisdiction where<br>
> employees have privacy rights, either under data protection law or<br>
> other laws such as labour laws or contracts? There is a good chance<br>
> that some of their data becomes personal.<br>
><br>
> 5. Registrars already have excellent advice for their members<br>
> available through their own websites. Remember that at ICANN we are<br>
> only dealing with the big ones, and the responsible ones. We have to<br>
> consider whether any activity we sanction in this policy induces the<br>
> lazy ones to cut corners. They are used to disclosing everything in<br>
> the WHOIS, if given an opportunity to revert to that by creating this<br>
> distinction, they will most likely do what is easiest. At the<br>
> moment, under the temp spec and article 6, the easiest thing to do is<br>
> to consider these grey area folks as natural persons unless proven<br>
> otherwise, and protect the data. Why on earth would we not choose<br>
> this option? There is no law telling us to do otherwise, and there<br>
> is certainly a great deal of law out there that makes differentiation<br>
> a legal risk that carries liability and cost. We want domain names<br>
> to remain affordable, and we want our people protected.<br>
><br>
> 6. One more thing: remember that not all domain names are used for<br>
> websites engaged in commerce. Some are being held by individuals for<br>
> future use. Disclosure provides market information to big players<br>
> who may want to prevent the name from being used, or to purchase<br>
> them, but there is no harm emanating from them in dormancy, and small<br>
> players need not have their competitive positions compromised in this<br>
> way. Most of the online crime that we hear adduced to justify<br>
> disclosure of data is coming from websites. Websites can be<br>
> regulated to protect consumers, but that is not within ICANN's<br>
> bailiwick. Folks come to ICANN to demand this activity because other<br>
> multilateral instruments have failed, but given the lack of oversight<br>
> over ICANN, the responsibility to ensure fairness and human rights<br>
> are respected falls on the shoulders of the stakeholders engaged here.<br>
><br>
> 7. Finally: Several folks are worried that governments will<br>
> regulate if we do not concede here. I say let them, the Courts and<br>
> the Constitution and the much more rigorous defences against<br>
> incursions into human rights available within countries will<br>
> prevail. It certainly will in the EU, where the draft NIS is<br>
> progressing.....I keep pointing out the Opinion of the European Data<br>
> Protection Supervisor on this matter, so one more time here it is<br>
> <a href="https://www.google.com/search?client=firefox-b-d&q=edps+on+the+nis+directive" target="_blank">https://www.google.com/search?client=firefox-b-d&q=edps+on+the+nis+directive</a>. As for the increasing number of autocratic countries interested in curtailing the free speech and internet rights of their citizens, they are regulating anyway and nothing that ICANN does is going to persuade them otherwise. A good example of us falling on the side of customer protection might at least give those individuals in these countries something to point to, as opposed to caving in to<br>
> threats.<br>
><br>
> cheers Stephanie Perrin<br>
><br>
> On 2021-04-27 11:56 p.m., 陳曼茹 Manju Chen wrote:<br>
>> *EXTERNAL EMAIL:*<br>
>> Hi all,<br>
>><br>
>> This has been a very helpful discussion. Our ultimate goal is to<br>
>> finalize an NCSG position, and I'd like to provide some context in<br>
>> the interest of reaching that goal.<br>
>><br>
>> Some have pointed out that the question of 'do you agree to publish<br>
>> your data' is a much better one than 'are you a legal or natural<br>
>> person'. I totally agree. But we already have that in the policy. In<br>
>> the EPDP phase 1 final report, recommendation #6 reads:<br>
>><br>
>> The EPDP Team recommends that, as soon as commercially reasonable,<br>
>> Registrar must provide the opportunity for the Registered Name<br>
>> Holder to provide its Consent to publish redacted contact<br>
>> information, as well as the email address, in the RDS for the<br>
>> sponsoring registrar.<br>
>><br>
>><br>
>> In the EPDP phase2A, the WG is tasked to address the following questions:<br>
>><br>
>> 1. Whether any updates are required to the EPDP Phase 1<br>
>> recommendation on this topic (“Registrars and Registry Operators<br>
>> are permitted to differentiate between registrations of legal and<br>
>> natural persons, but are not obligated to do so“);<br>
>> 2. What guidance, if any, can be provided to Registrars and/or<br>
>> Registries who differentiate between registrations of legal and<br>
>> natural persons.<br>
>><br>
>> So it's not that we 'want' the distinction of natural vs. legal.<br>
>> It's the task we're given, and per the WG chair's last email to the<br>
>> EPDP team, it's not something we can avoid. We have to stick to the<br>
>> 'natural vs. legal persons' rhetoric to answer the questions.<br>
>><br>
>> Of course, we can simply assert that 'there's no update needed' and<br>
>> let the contracted parties do whatever they want when they feel like<br>
>> making the distinction. I was personally very tempted by this option<br>
>> every now and then. However, as Milton pointed out in another email,<br>
>> we are already developing guidance in the EPDP, so that option seems<br>
>> far-fetched.<br>
>><br>
>> I hope this explains some of the confusion and helps us to consider<br>
>> Milton's 4 options in the other email.<br>
>><br>
>> Thanks!<br>
>><br>
>><br>
>> Best,<br>
>> Manju<br>
>><br>
>> On Wed, Apr 28, 2021 at 4:40 AM Mark Leiser <<a href="mailto:markleiser@gmail.com">markleiser@gmail.com</a><br>
>> <mailto:<a href="mailto:markleiser@gmail.com>>">markleiser@gmail.com>></a> wrote:<br>
>><br>
>> Hi Milton,<br>
>><br>
>> First let me say I completely agree with you on your statements<br>
>> about European data privacy. I feel like I've dedicated most of my<br>
>> professional life arguing about the dangers of privacy and data<br>
>> protection maximalism - yet almost always feel like my arguments<br>
>> on deaf ears. While people are arguing that 'everything is<br>
>> personal data', I've been arguing that this makes the regime<br>
>> unmanageable.<br>
>><br>
>> So let me try to explain 'relating to' with reference to 'Milton<br>
>> Mueller's Porkbelly Diner'. Because of Recital 14, this would<br>
>> amount to a legal person. It's pretty clear that the intention of<br>
>> the GDPR's drafters was to exclude legal persons. However, let's<br>
>> say you have registered 'MM Porkbelly Diner' in the register of<br>
>> companies. I think you would agree that this would amount to<br>
>> information about a legal person. But say someone searched the<br>
>> company register and discovered Milton Mueller was the principal<br>
>> shareholder of MM Porkbelly Diner. This is an identifier which<br>
>> would /tie nformation about Milton Mueller to/ 'MM PorkBelly<br>
>> Diner'. Therefore, this is 'any information' 'relating to' an<br>
>> identified or identifiable living person. It would be reasonable<br>
>> to infer that MM registered in the registrar database under MM<br>
>> PorkBelly Diner is the same as the Milton Mueller that is in the<br>
>> register of companies. The fact that someone can combine the<br>
>> knowledge from the company register with the knowledge from the<br>
>> registrar database could make 'MM Porkbelly Diner' personal data<br>
>> under Article 4(1) of the GDPR. Someone who did not disclose their<br>
>> identity at all could still be identifiable; hence, the perceived<br>
>> need for protection in the EU data protection regime.<br>
>><br>
>> "Iam saying that the user, the registrant, gets to decide what is<br>
>> personal data or not, because THERE IS NO OBJECTIVE, CLEAR LEGAL<br>
>> DEFINITION" is, on the surface, problematic. It doesn't matter<br>
>> whether the user says NO or YES or the registrar says no or yes,<br>
>> or whether it is objective or clear, the test is whether any<br>
>> information can be combined with other information to reveal an<br>
>> identifiable living person. I would argue, absent a wholesale<br>
>> change in the reasoning used by the CJEU, this would remain the<br>
>> case for the foreseeable future. This is not intended as a Mark<br>
>> Leiser argument or an attempt to discredit what you are saying,<br>
>> but an honest account of how I think the Courts and the EU data<br>
>> protection Board would react to what you are proposing.<br>
>><br>
>> You asked about IP addresses<br>
>> <br>
>> <<a href="https://iapp.org/news/a/are-ip-addresses-generated-when-users-visit-websites-personal-information/#:~:text=Under%20the%20EU%20General%20Data,header%20information%20that%20website%20hosts" target="_blank">https://iapp.org/news/a/are-ip-addresses-generated-when-users-visit-websites-personal-information/#:~:text=Under%20the%20EU%20General%20Data,header%20information%20that%20website%20hosts</a>>,<br>
>> 'port numbers', 'browser config', etc could be used to identify<br>
>> you personally. Yes, absolutely. This is personal data in the EU -<br>
>> if it can relate to a living person. What your writing here<br>
>> reveals, is that you are a little confused about how the GDPR<br>
>> works - the GDPR does not rely on 'consent' or 'explicit<br>
>> permission' as the only basis for processing personal data.<br>
>> Remember the GDPR has six grounds of processing<br>
>> <<a href="https://gdpr-info.eu/art-6-gdpr/" target="_blank">https://gdpr-info.eu/art-6-gdpr/</a>>. It is a prohibitive<br>
>> regulation. You cannot process personal data in the EU unless you<br>
>> satisfy one of those six grounds. Most companies will NOT be<br>
>> processing on the basis of 'consent' but on 'legitimate interests'<br>
>> (Article 6(1)(f)) or performance of a contract (Article 6(1)(b)).<br>
>> Don't worry, this is an extremely common mistake among American<br>
>> attorneys! As most of these items are "technical', I would also<br>
>> imagine that there is a 'legal requirement' (another ground) or a<br>
>> lawful basis. All ISPs will be processing personal data through<br>
>> 'IP addresses', 'port browsers', and 'browser config' because of<br>
>> the legal basis found in Article 15 of the e-Privacy Directive<br>
>> <br>
>> <<a href="https://eur-lex.europa.eu/legal-content/EN/TXT/HTML/?uri=CELEX:32002L0058&from=EN" target="_blank">https://eur-lex.europa.eu/legal-content/EN/TXT/HTML/?uri=CELEX:32002L0058&from=EN</a>> which<br>
>> provides Member States with a specific exemption for the purposes<br>
>> of national security. If not covered by this, I would imagine they<br>
>> would rely on 'legitimate interests' as their ground instead.<br>
>><br>
>> Finally, even if a registrar has a legitimate interest in<br>
>> processing someone's personal data, this does not address the<br>
>> /privacy /requirements that i indicated in my previous email.<br>
>> Unless there is a specific provision put into law, I do not know<br>
>> how the registrar can remain compliant with the GDPR and the EU's<br>
>> privacy requirements. In fact, I don't know how the EU can even<br>
>> comment on this, because, of course, the EU Charter is a legal<br>
>> framework completely distinct from the European Convention of<br>
>> Human Rights.<br>
>><br>
>> One more thing to consider - if you choose to disclose your name,<br>
>> address, and designate as the contact person of a legal person,<br>
>> what happens when that person exercises their 'right to be<br>
>> forgotten' right under Article 17 GDPR. Maybe Milton Mueller the<br>
>> person chooses to leave the legal entity MM Porkbelly Diner,<br>
>> adopts a vegan lifestyle, and wants no affiliation with the<br>
>> business? If it's published, he can demand a correction of the<br>
>> database thereof. So what then?<br>
>><br>
>> Regards,<br>
>><br>
>> Mark<br>
>><br>
>> *Dr Mark Leiser | Law and Digital Technologies | FRSA FHEA |*<br>
>><br>
>><br>
>> On Tue, 27 Apr 2021 at 20:35, Mueller, Milton L <<a href="mailto:milton@gatech.edu">milton@gatech.edu</a><br>
>> <mailto:<a href="mailto:milton@gatech.edu>>">milton@gatech.edu>></a> wrote:<br>
>><br>
>> Mark,<br>
>><br>
>> Thanks for your intervention. Here is the complete definition<br>
>> of personal data in GDPR:<br>
>><br>
>> ‘personal data’ means any information relating to an<br>
>> identified or identifiable natural person (‘data subject’); an<br>
>> identifiable natural person is one who can be identified,<br>
>> directly or indirectly, in particular by reference to an<br>
>> identifier such as a name, an identification number, location<br>
>> data, an online identifier or to one or more factors specific<br>
>> to the physical, physiological, genetic, mental, economic,<br>
>> cultural or social identity of that natural person;<br>
>><br>
>> Alas, this raises more questions than it answers. It is not<br>
>> entirely clear what “relating to” means in this construct.<br>
>> E.g., if the name of my company is Milton Mueller’s Porkbelly<br>
>> Diner, is the name relating to me as a person, or to my<br>
>> business? Strictly speaking it’s a business name. But it could<br>
>> be used to identify me. An overly broad interpretation of this<br>
>> definition would classify ANY data about ANYTHING as “personal<br>
>> data” because at some point it could be “related to” an<br>
>> “identifiable natural person.” So suddenly the business name<br>
>> becomes personal data. Or a bunch of obscure technical<br>
>> indicators inherent in your use of the internet, such as port<br>
>> numbers, browser config, etc., could be “related” to your ISP<br>
>> account number, and then used to identify you, personally. But<br>
>> does that mean that every website and hosting service in the<br>
>> world that uses that technical data in the course of their<br>
>> operations cannot process that info without your explicit<br>
>> permission, because it’s “personal data?” I hope not, because<br>
>> the internet would cease to function if so.<br>
>><br>
>> >Therefore, <a href="mailto:info@myorg.org">info@myorg.org</a> <mailto:<a href="mailto:info@myorg.org>">info@myorg.org></a> is personal<br>
>> data if someone behind it is identifiable.<br>
>><br>
>> My point is that whether the user of <a href="mailto:info@myorg.org">info@myorg.org</a><br>
>> <mailto:<a href="mailto:info@myorg.org>">info@myorg.org></a> is identifiable does not depend on<br>
>> that chunk of data, but on a bunch of activities that relate<br>
>> that data to other things. And in a digital world with<br>
>> powerful processing capabilities, no one can fully control<br>
>> those correlations and searches. Any attempt to do so simply<br>
>> cripples the entire information economy. So the idea of<br>
>> looking at a registration record and saying “is there personal<br>
>> data in here or not” is a completely invalid test.<br>
>><br>
>> There is an eerie similarity between these exaggerated<br>
>> applications of privacy law and the copyright maximalists of<br>
>> the 1990s. The IP interests thought you needed permission to<br>
>> transmit a copyrighted work over the internet, a claim that<br>
>> would have crippled ISPs who had no idea what packets were<br>
>> parts of copyrighted material or not. Privacy maximalists have<br>
>> reached the same point of absurdity, but they don’t seem to<br>
>> realize it. They are no longer protecting a tangible privacy<br>
>> interest of internet users, they are trying to give<br>
>> individuals rigid control over information exchanges and<br>
>> imposing largely meaningless consent requirements that do no<br>
>> one any good.<br>
>><br>
>> >The confusion comes from Recital 14 of the GDPR which states<br>
>> that it only applies to natural persons and does not cover the<br>
>> processing of personal data concerning legal persons, in<br>
>> particular undertakings established as legal persons or legal<br>
>> entities. This also includes the name of the legal person, the<br>
>> form, and the contact details of the legal person.But the<br>
>> second you start adding identifiers to these details, it stops<br>
>> becoming the data of a 'legal person' and starts becoming<br>
>> personal data.<br>
>><br>
>> Yes, indeed, the GDPR is confused on this score.<br>
>> Unfortunately, you don’t escape that confusion by saying<br>
>> “adding identifiers” is the problem. Your argument fails<br>
>> because names of legal persons and contact details ARE<br>
>> “identifiers,” they are just identifiers of legal persons. As<br>
>> I pointed out they can easily overlap with, or be used to<br>
>> identify, natural persons.<br>
>><br>
>> So my basic point is that we do not solve this problem by<br>
>> reference to GDPR definitions. In fact if GDPR is taken<br>
>> literally no one can ever publish and share any kind of<br>
>> information without absurd overhead and legal bureaucracy,<br>
>> because ALL of it can be used to identify you in some way.<br>
>> These kinds of interpretations actually discredit privacy laws<br>
>> and protections, by taking them to counterproductive lengths.<br>
>> We have to make common sense-based, practical distinctions<br>
>> between what data needs protection, what data can be easily<br>
>> shared at the registrants’ choice.<br>
>><br>
>> Secondly, I find this statement, "I think it is simplest to<br>
>> just say to the registrant, if you’re a company and don’t mind<br>
>> (or even want) your data to be published, check this box. If<br>
>> you’re not, or you do mind, don’t check it." to be BOTH<br>
>> perplexing and inaccurate. Whether someone checks the box, or<br>
>> does not check the box is completely irrelevant for<br>
>> determining whether it is personal data. Whether someone<br>
>> checks the box is a question of CONSENT to processing AND<br>
>> publication, not whether this amounts to personal data.<br>
>><br>
>> We actually seem to agree here, more than you think. I am<br>
>> saying that the user, the registrant, gets to decide what is<br>
>> personal data or not, because THERE IS NO OBJECTIVE, CLEAR<br>
>> LEGAL DEFINITION. So the user can decide whether they want to<br>
>> be classified as a legal person and “consent” to publishing<br>
>> their data or not. As an example, that if I decide that<br>
>> publishing the name of “Milton Mueller’s Porkbelly Diner” is<br>
>> not a violation of my privacy, it isn’t. It doesn’t matter<br>
>> what the European Union says, it’s my choice.<br>
>><br>
>> And let’s not overlook the embarrassing fact that the European<br>
>> Union is now one of the key players pushing hard for<br>
>> publication of legal person data. But I’ll leave that one to<br>
>> later.<br>
>><br>
<br></p>
</body>
</html>