<html xmlns:o="urn:schemas-microsoft-com:office:office" xmlns:w="urn:schemas-microsoft-com:office:word" xmlns:m="http://schemas.microsoft.com/office/2004/12/omml" xmlns="http://www.w3.org/TR/REC-html40">
<head>
<meta http-equiv="Content-Type" content="text/html; charset=utf-8">
<meta name="Generator" content="Microsoft Word 15 (filtered medium)">
<style><!--
/* Font Definitions */
@font-face
{font-family:"Cambria Math";
panose-1:2 4 5 3 5 4 6 3 2 4;}
@font-face
{font-family:Calibri;
panose-1:2 15 5 2 2 2 4 3 2 4;}
/* Style Definitions */
p.MsoNormal, li.MsoNormal, div.MsoNormal
{margin:0in;
margin-bottom:.0001pt;
font-size:12.0pt;
font-family:"Times New Roman",serif;}
a:link, span.MsoHyperlink
{mso-style-priority:99;
color:blue;
text-decoration:underline;}
a:visited, span.MsoHyperlinkFollowed
{mso-style-priority:99;
color:purple;
text-decoration:underline;}
p
{mso-style-priority:99;
mso-margin-top-alt:auto;
margin-right:0in;
mso-margin-bottom-alt:auto;
margin-left:0in;
font-size:12.0pt;
font-family:"Times New Roman",serif;}
p.msonormal0, li.msonormal0, div.msonormal0
{mso-style-name:msonormal;
mso-style-priority:99;
mso-margin-top-alt:auto;
margin-right:0in;
mso-margin-bottom-alt:auto;
margin-left:0in;
font-size:12.0pt;
font-family:"Times New Roman",serif;}
span.EmailStyle19
{mso-style-type:personal;
font-family:"Calibri",sans-serif;
color:#1F497D;}
span.EmailStyle21
{mso-style-type:personal;
font-family:"Calibri",sans-serif;
color:#1F497D;}
span.EmailStyle22
{mso-style-type:personal-compose;
font-family:"Calibri",sans-serif;
color:windowtext;}
.MsoChpDefault
{mso-style-type:export-only;
font-size:10.0pt;}
@page WordSection1
{size:8.5in 11.0in;
margin:1.0in 1.0in 1.0in 1.0in;}
div.WordSection1
{page:WordSection1;}
/* List Definitions */
@list l0
{mso-list-id:652485081;
mso-list-template-ids:1311775996;}
@list l0:level1
{mso-level-start-at:2;
mso-level-tab-stop:.5in;
mso-level-number-position:left;
text-indent:-.25in;}
@list l1
{mso-list-id:694816051;
mso-list-template-ids:894482048;}
@list l1:level1
{mso-level-start-at:3;
mso-level-tab-stop:.5in;
mso-level-number-position:left;
text-indent:-.25in;}
@list l2
{mso-list-id:994069162;
mso-list-type:hybrid;
mso-list-template-ids:-230374090 67698703 67698713 67698715 67698703 67698713 67698715 67698703 67698713 67698715;}
@list l2:level1
{mso-level-tab-stop:none;
mso-level-number-position:left;
text-indent:-.25in;}
@list l2:level2
{mso-level-number-format:alpha-lower;
mso-level-tab-stop:none;
mso-level-number-position:left;
text-indent:-.25in;}
@list l2:level3
{mso-level-number-format:roman-lower;
mso-level-tab-stop:none;
mso-level-number-position:right;
text-indent:-9.0pt;}
@list l2:level4
{mso-level-tab-stop:none;
mso-level-number-position:left;
text-indent:-.25in;}
@list l2:level5
{mso-level-number-format:alpha-lower;
mso-level-tab-stop:none;
mso-level-number-position:left;
text-indent:-.25in;}
@list l2:level6
{mso-level-number-format:roman-lower;
mso-level-tab-stop:none;
mso-level-number-position:right;
text-indent:-9.0pt;}
@list l2:level7
{mso-level-tab-stop:none;
mso-level-number-position:left;
text-indent:-.25in;}
@list l2:level8
{mso-level-number-format:alpha-lower;
mso-level-tab-stop:none;
mso-level-number-position:left;
text-indent:-.25in;}
@list l2:level9
{mso-level-number-format:roman-lower;
mso-level-tab-stop:none;
mso-level-number-position:right;
text-indent:-9.0pt;}
@list l3
{mso-list-id:1473211490;
mso-list-template-ids:-1936184762;}
@list l3:level2 lfo2
{mso-level-start-at:0;
mso-level-number-format:alpha-lower;
mso-level-numbering:continue;
mso-level-tab-stop:none;
mso-level-number-position:left;
margin-left:0in;
text-indent:0in;}
@list l0:level1 lfo4
{mso-level-start-at:0;
mso-level-numbering:continue;
mso-level-tab-stop:none;
mso-level-number-position:left;
margin-left:0in;
text-indent:0in;}
@list l0:level1 lfo5
{mso-level-start-at:0;
mso-level-numbering:continue;
mso-level-tab-stop:none;
mso-level-number-position:left;
margin-left:0in;
text-indent:0in;}
@list l0:level2 lfo5
{mso-level-start-at:0;
mso-level-number-format:alpha-lower;
mso-level-numbering:continue;
mso-level-tab-stop:none;
mso-level-number-position:left;
margin-left:0in;
text-indent:0in;}
@list l1:level1 lfo7
{mso-level-start-at:0;
mso-level-numbering:continue;
mso-level-tab-stop:none;
mso-level-number-position:left;
margin-left:0in;
text-indent:0in;}
@list l1:level1 lfo8
{mso-level-start-at:0;
mso-level-numbering:continue;
mso-level-tab-stop:none;
mso-level-number-position:left;
margin-left:0in;
text-indent:0in;}
@list l1:level2 lfo8
{mso-level-start-at:0;
mso-level-number-format:alpha-lower;
mso-level-numbering:continue;
mso-level-tab-stop:none;
mso-level-number-position:left;
margin-left:0in;
text-indent:0in;}
ol
{margin-bottom:0in;}
ul
{margin-bottom:0in;}
--></style>
</head>
<body lang="EN-US" link="blue" vlink="purple">
<div class="WordSection1">
<p class="MsoNormal"><span style="font-size:11.0pt;font-family:"Calibri",sans-serif;color:#1F497D">Actually, this is a fairly convincing argument,
<o:p></o:p></span></p>
<p>If we as a matter of policy create guidance, it will be examined by any DPA investigating a complaint about the SSAD. The co-controllers will be held accountable for whether or not they adhere to it. It may be reference in the Registrars Accreditation
Agreements, negotiations for which are going on as we argue about this. There is no reason that I can see to include the guidance that has been developed in our policy, I do not agree that this particular ship has sailed. As far as I am concerned, it is
still in drydock.<o:p></o:p></p>
<p><span style="font-size:11.0pt;font-family:"Calibri",sans-serif;color:#1F497D">OK, so finally you are confronting the issue of Guidance. Although I think your reasoning about DPAs is invalid, “No change, no guidance” is a coherent position – ASSUMING the
ship has not sailed. So are you prepared to come to the EPDP meeting tomorrow, and announce with me, that NCSG are abandoning the ship, and no longer want to see any guidance developed? I will go along with that, once/if we receive confirmation from the PC
or the vote of this list.<o:p></o:p></span></p>
<p><span style="font-size:11.0pt;font-family:"Calibri",sans-serif;color:#1F497D">We can justify our shift in the following way:
<o:p></o:p></span></p>
<p style="margin-left:.5in;text-indent:-.25in;mso-list:l2 level1 lfo9"><![if !supportLists]><span style="font-size:11.0pt;font-family:"Calibri",sans-serif;color:#1F497D"><span style="mso-list:Ignore">1.<span style="font:7.0pt "Times New Roman"">
</span></span></span><![endif]><span style="font-size:11.0pt;font-family:"Calibri",sans-serif;color:#1F497D">If there is guidance, NCSG have proven to be completely unable to agree on what it should be. It is safer for Registrants not to have any, and rely
on market choices among CPs to protect registrants<o:p></o:p></span></p>
<p style="margin-left:.5in;text-indent:-.25in;mso-list:l2 level1 lfo9"><![if !supportLists]><span style="font-size:11.0pt;font-family:"Calibri",sans-serif;color:#1F497D"><span style="mso-list:Ignore">2.<span style="font:7.0pt "Times New Roman"">
</span></span></span><![endif]><span style="font-size:11.0pt;font-family:"Calibri",sans-serif;color:#1F497D">We are concerned about legal obligations or liabilities that might be incurred by registrants self-identification as a company or legal person.<o:p></o:p></span></p>
<p style="margin-left:.5in;text-indent:-.25in;mso-list:l2 level1 lfo9"><![if !supportLists]><span style="font-size:11.0pt;font-family:"Calibri",sans-serif;color:#1F497D"><span style="mso-list:Ignore">3.<span style="font:7.0pt "Times New Roman"">
</span></span></span><![endif]><span style="font-size:11.0pt;font-family:"Calibri",sans-serif;color:#1F497D">We don’t want the guidance to be mandatory, but if it’s not mandatory why do we need it?
<o:p></o:p></span></p>
<p style="margin-left:.5in;text-indent:-.25in;mso-list:l2 level1 lfo9"><![if !supportLists]><span style="font-size:11.0pt;font-family:"Calibri",sans-serif;color:#1F497D"><span style="mso-list:Ignore">4.<span style="font:7.0pt "Times New Roman"">
</span></span></span><![endif]><span style="font-size:11.0pt;font-family:"Calibri",sans-serif;color:#1F497D">There is a chance that it might become a de facto standard<o:p></o:p></span></p>
<p><span style="font-size:11.0pt;font-family:"Calibri",sans-serif;color:#1F497D">So I cast my vote: NO on guidance (yes this is a shift)<o:p></o:p></span></p>
<p><span style="font-size:11.0pt;font-family:"Calibri",sans-serif;color:#1F497D">Now tell me what you propose to do if they go ahead and develop guidance? Here is what you say:<o:p></o:p></span></p>
<p>What we have been discussing in the EPDP is the guidance that the registrars have already developed on a voluntary basis. We can simply leave them to do this. There is no need to treat the deliberations of this EPDP as holy writ that cannot be set aside,
we have debated all kinds of nonsense over the past three years. Putting it in a google doc does not mean it cannot land on the cutting room floor.
<o:p></o:p></p>
<p><span style="font-size:11.0pt;font-family:"Calibri",sans-serif;color:#1F497D">This would be a fail, in my opinion. If the CPs develop guidance, it will become part of the Phase 2a report. All the arguments you make against guidance would still apply. A more
desirable idea is that we get the CPs to abandon guidance as well, or at least enough of them to block consensus. From Volcker’s statement on behalf of Registrars I got the idea they are going along with guidance because they think everyone wants it.
<o:p></o:p></span></p>
<p class="MsoNormal"><span style="color:#1F497D">--MM</span><o:p></o:p></p>
<p style="margin:0in;margin-bottom:.0001pt;background:white"> <o:p></o:p></p>
<p style="margin:0in;margin-bottom:.0001pt;background:white"> <o:p></o:p></p>
<p style="margin:0in;margin-bottom:.0001pt"><span style="font-size:11.0pt;font-family:"Arial",sans-serif;color:black">This chart provides guidance for how a Registrar could comply with GDPR principles in each of the three example scenarios (see section below),
along with some notes about risks present for various options.</span><o:p></o:p></p>
<p class="MsoNormal"><o:p> </o:p></p>
<div style="margin-left:-5.0pt">
<table class="MsoNormalTable" border="0" cellspacing="0" cellpadding="0" style="border-collapse:collapse">
<tbody>
<tr>
<td valign="top" style="border:solid black 1.0pt;background:#C9DAF8;padding:5.0pt 5.0pt 5.0pt 5.0pt;overflow-wrap:break-word;overflow:hidden">
<p style="margin:0in;margin-bottom:.0001pt"><b><span style="font-size:11.0pt;font-family:"Arial",sans-serif;color:black">Principle</span></b><o:p></o:p></p>
</td>
<td valign="top" style="border:solid black 1.0pt;border-left:none;background:#C9DAF8;padding:5.0pt 5.0pt 5.0pt 5.0pt;overflow-wrap:break-word;overflow:hidden">
<p style="margin:0in;margin-bottom:.0001pt"><b><span style="font-size:11.0pt;font-family:"Arial",sans-serif;color:black">Data subject self-identification at time of data collection resulting in publication of non-personal data</span></b><o:p></o:p></p>
</td>
<td valign="top" style="border:solid black 1.0pt;border-left:none;background:#C9DAF8;padding:5.0pt 5.0pt 5.0pt 5.0pt;overflow-wrap:break-word;overflow:hidden">
<p style="margin:0in;margin-bottom:.0001pt"><b><span style="font-size:11.0pt;font-family:"Arial",sans-serif;color:black">Data subject self-identification after initial data collection resulting in publication of non-personal data</span></b><o:p></o:p></p>
</td>
<td valign="top" style="border:solid black 1.0pt;border-left:none;background:#C9DAF8;padding:5.0pt 5.0pt 5.0pt 5.0pt;overflow-wrap:break-word;overflow:hidden">
<p style="margin:0in;margin-bottom:.0001pt"><b><span style="font-size:11.0pt;font-family:"Arial",sans-serif;color:black">Registrar determines type based on data provided resulting in publication of non-personal data</span></b><o:p></o:p></p>
</td>
</tr>
<tr>
<td valign="top" style="border:solid black 1.0pt;border-top:none;padding:5.0pt 5.0pt 5.0pt 5.0pt;overflow-wrap:break-word;overflow:hidden">
<p style="margin:0in;margin-bottom:.0001pt"><b><span style="font-size:11.0pt;font-family:"Arial",sans-serif;color:black">Lawfulness, Fairness and Transparency:</span></b><span style="font-size:11.0pt;font-family:"Arial",sans-serif;color:black"> </span><o:p></o:p></p>
<p style="margin:0in;margin-bottom:.0001pt"><span style="font-size:11.0pt;font-family:"Arial",sans-serif;color:black">Controller must identify their legal basis (or bases) for processing data and ensure the data subject is aware of the processing prior to when
it occurs. If the legal basis is consent, then consent must be obtained prior to the processing.</span><o:p></o:p></p>
<p class="MsoNormal"><o:p> </o:p></p>
<p style="margin:0in;margin-bottom:.0001pt"><b><span style="font-size:11.0pt;font-family:"Arial",sans-serif;color:black">See also: </span></b><o:p></o:p></p>
<p style="margin:0in;margin-bottom:.0001pt"><b><span style="font-size:11.0pt;font-family:"Arial",sans-serif;color:black">Transparency:</span></b><span style="font-size:11.0pt;font-family:"Arial",sans-serif;color:black"> RAA 3.7.7.4</span><o:p></o:p></p>
<p style="margin:0in;margin-bottom:.0001pt"><b><span style="font-size:11.0pt;font-family:"Arial",sans-serif;color:black">Consent:</span></b><span style="font-size:11.0pt;font-family:"Arial",sans-serif;color:black"> RAA 3.7.7.5</span><o:p></o:p></p>
</td>
<td valign="top" style="border-top:none;border-left:none;border-bottom:solid black 1.0pt;border-right:solid black 1.0pt;padding:5.0pt 5.0pt 5.0pt 5.0pt;overflow-wrap:break-word;overflow:hidden">
<p style="margin:0in;margin-bottom:.0001pt"><span style="font-size:11.0pt;font-family:"Arial",sans-serif;color:black">Identify and document legal basis for each processing activity (collection, retention, publication, erasure); provide explanation to data subject
when data is collected and data subject selects person type.</span><o:p></o:p></p>
<p class="MsoNormal"><o:p> </o:p></p>
<p style="margin:0in;margin-bottom:.0001pt"><b><span style="font-size:11.0pt;font-family:"Arial",sans-serif;color:black">Risk</span></b><span style="font-size:11.0pt;font-family:"Arial",sans-serif;color:black">: Data subject identifies person type/provides
consent on behalf of a third party (Bird & Bird Memo II on Consent) </span><o:p></o:p></p>
</td>
<td valign="top" style="border-top:none;border-left:none;border-bottom:solid black 1.0pt;border-right:solid black 1.0pt;padding:5.0pt 5.0pt 5.0pt 5.0pt;overflow-wrap:break-word;overflow:hidden">
<p style="margin:0in;margin-bottom:.0001pt"><span style="font-size:11.0pt;font-family:"Arial",sans-serif;color:black">Identify and document legal basis for each processing activity (collection, retention, publication, erasure); provide explanation at the time
when data subject self-identifies (post collection) and when option to change or correct self-designation is provided.</span><o:p></o:p></p>
<p class="MsoNormal"><o:p> </o:p></p>
<p style="margin:0in;margin-bottom:.0001pt"><b><span style="font-size:11.0pt;font-family:"Arial",sans-serif;color:black">Risk</span></b><span style="font-size:11.0pt;font-family:"Arial",sans-serif;color:black">: Data subject identifies person type/provides
consent on behalf of a third party (Bird & Bird Memo II on Consent) </span><o:p></o:p></p>
</td>
<td valign="top" style="border-top:none;border-left:none;border-bottom:solid black 1.0pt;border-right:solid black 1.0pt;padding:5.0pt 5.0pt 5.0pt 5.0pt;overflow-wrap:break-word;overflow:hidden">
<p style="margin:0in;margin-bottom:.0001pt"><span style="font-size:11.0pt;font-family:"Arial",sans-serif;color:black">Identify and document legal basis for each processing activity (collection, retention, publication, erasure); provide explanation at the time
when data is collected and person type is inferred. </span><o:p></o:p></p>
<p class="MsoNormal"><o:p> </o:p></p>
<p style="margin:0in;margin-bottom:.0001pt"><b><span style="font-size:11.0pt;font-family:"Arial",sans-serif;color:black">Risk:
</span></b><span style="font-size:11.0pt;font-family:"Arial",sans-serif;color:black">Registrar identification post-collection does not allow for pre-processing disclosure to data subject.</span><o:p></o:p></p>
</td>
</tr>
<tr>
<td valign="top" style="border:solid black 1.0pt;border-top:none;padding:5.0pt 5.0pt 5.0pt 5.0pt;overflow-wrap:break-word;overflow:hidden">
<p style="margin:0in;margin-bottom:.0001pt"><b><span style="font-size:11.0pt;font-family:"Arial",sans-serif;color:black">Purpose Limitation:
</span></b><span style="font-size:11.0pt;font-family:"Arial",sans-serif;color:black">Controller must ensure that data is not processed beyond the purposes disclosed to the data subject</span><o:p></o:p></p>
<p class="MsoNormal"><o:p> </o:p></p>
<p style="margin:0in;margin-bottom:.0001pt"><b><span style="font-size:11.0pt;font-family:"Arial",sans-serif;color:black">See also:
</span></b><span style="font-size:11.0pt;font-family:"Arial",sans-serif;color:black">RAA 3.7.7.4.1, 3.7.7.4.2, EPDP Phase 1 and Phase 2 Addendum Purposes</span><o:p></o:p></p>
</td>
<td valign="top" style="border-top:none;border-left:none;border-bottom:solid black 1.0pt;border-right:solid black 1.0pt;padding:5.0pt 5.0pt 5.0pt 5.0pt;overflow-wrap:break-word;overflow:hidden">
<p style="margin:0in;margin-bottom:.0001pt"><span style="font-size:11.0pt;font-family:"Arial",sans-serif;color:black">All relevant processing activities (including post-publication activities) must be included in the explanation to the data subject. </span><o:p></o:p></p>
<p class="MsoNormal"><o:p> </o:p></p>
<p style="margin:0in;margin-bottom:.0001pt"><b><span style="font-size:11.0pt;font-family:"Arial",sans-serif;color:black">Risk</span></b><span style="font-size:11.0pt;font-family:"Arial",sans-serif;color:black">: post-publication processing may be unknown to
both the controller and the data subject and thus cannot be adequately disclosed</span><o:p></o:p></p>
</td>
<td valign="top" style="border-top:none;border-left:none;border-bottom:solid black 1.0pt;border-right:solid black 1.0pt;padding:5.0pt 5.0pt 5.0pt 5.0pt;overflow-wrap:break-word;overflow:hidden">
<p style="margin:0in;margin-bottom:.0001pt"><span style="font-size:11.0pt;font-family:"Arial",sans-serif;color:black">All relevant processing activities (including post-publication activities) must be included in the explanation to the data subject.</span><o:p></o:p></p>
<p class="MsoNormal"><o:p> </o:p></p>
<p style="margin:0in;margin-bottom:.0001pt"><b><span style="font-size:11.0pt;font-family:"Arial",sans-serif;color:black">Risk</span></b><span style="font-size:11.0pt;font-family:"Arial",sans-serif;color:black">: post-publication processing may be unknown to
both the controller and the data subject and thus cannot be adequately disclosed</span><o:p></o:p></p>
</td>
<td valign="top" style="border-top:none;border-left:none;border-bottom:solid black 1.0pt;border-right:solid black 1.0pt;padding:5.0pt 5.0pt 5.0pt 5.0pt;overflow-wrap:break-word;overflow:hidden">
<p style="margin:0in;margin-bottom:.0001pt"><span style="font-size:11.0pt;font-family:"Arial",sans-serif;color:black">All relevant processing activities (including post-publication activities) must be included in the explanation to the data subject.</span><o:p></o:p></p>
<p class="MsoNormal"><o:p> </o:p></p>
<p style="margin:0in;margin-bottom:.0001pt"><b><span style="font-size:11.0pt;font-family:"Arial",sans-serif;color:black">Risk</span></b><span style="font-size:11.0pt;font-family:"Arial",sans-serif;color:black">: post-publication processing may be unknown to
both the controller and the data subject and thus cannot be adequately disclosed</span><o:p></o:p></p>
</td>
</tr>
<tr>
<td valign="top" style="border:solid black 1.0pt;border-top:none;padding:5.0pt 5.0pt 5.0pt 5.0pt;overflow-wrap:break-word;overflow:hidden">
<p style="margin:0in;margin-bottom:.0001pt"><b><span style="font-size:11.0pt;font-family:"Arial",sans-serif;color:black">Data Minimisation:</span></b><span style="font-size:11.0pt;font-family:"Arial",sans-serif;color:black"> </span><o:p></o:p></p>
<p style="margin:0in;margin-bottom:.0001pt"><span style="font-size:11.0pt;font-family:"Arial",sans-serif;color:black">Controller must ensure that no data is collected/processed beyond what is required to achieve the identified purpose(s)</span><o:p></o:p></p>
<p class="MsoNormal"><o:p> </o:p></p>
<p style="margin:0in;margin-bottom:.0001pt"><b><span style="font-size:11.0pt;font-family:"Arial",sans-serif;color:black">See also:
</span></b><span style="font-size:11.0pt;font-family:"Arial",sans-serif;color:black">RAA 3.7.7.4.3, EPDP Phase 1 exercise justifying all data elements collected</span><o:p></o:p></p>
</td>
<td valign="top" style="border-top:none;border-left:none;border-bottom:solid black 1.0pt;border-right:solid black 1.0pt;padding:5.0pt 5.0pt 5.0pt 5.0pt;overflow-wrap:break-word;overflow:hidden">
<p style="margin:0in;margin-bottom:.0001pt"><span style="font-size:11.0pt;font-family:"Arial",sans-serif;color:black">Only the minimum required data must be collected and published.</span><o:p></o:p></p>
</td>
<td valign="top" style="border-top:none;border-left:none;border-bottom:solid black 1.0pt;border-right:solid black 1.0pt;padding:5.0pt 5.0pt 5.0pt 5.0pt;overflow-wrap:break-word;overflow:hidden">
<p style="margin:0in;margin-bottom:.0001pt"><span style="font-size:11.0pt;font-family:"Arial",sans-serif;color:black">Only the minimum required data must be collected and published.</span><o:p></o:p></p>
</td>
<td valign="top" style="border-top:none;border-left:none;border-bottom:solid black 1.0pt;border-right:solid black 1.0pt;padding:5.0pt 5.0pt 5.0pt 5.0pt;overflow-wrap:break-word;overflow:hidden">
<p style="margin:0in;margin-bottom:.0001pt"><span style="font-size:11.0pt;font-family:"Arial",sans-serif;color:black">Only the minimum required data must be collected and published.</span><o:p></o:p></p>
</td>
</tr>
<tr>
<td valign="top" style="border:solid black 1.0pt;border-top:none;padding:5.0pt 5.0pt 5.0pt 5.0pt;overflow-wrap:break-word;overflow:hidden">
<p style="margin:0in;margin-bottom:.0001pt"><b><span style="font-size:11.0pt;font-family:"Arial",sans-serif;color:black">Accuracy: </span></b><o:p></o:p></p>
<p style="margin:0in;margin-bottom:.0001pt"><span style="font-size:11.0pt;font-family:"Arial",sans-serif;color:black">Controller must take all reasonable steps to ensure data subject can keep person type data updated and accurate<o:p></o:p></span></p>
<p style="margin:0in;margin-bottom:.0001pt"><span style="font-size:11.0pt;font-family:"Arial",sans-serif;color:black"><o:p> </o:p></span></p>
<p class="MsoNormal"><o:p></o:p></p>
<p style="margin:0in;margin-bottom:.0001pt"><b><span style="font-size:11.0pt;font-family:"Arial",sans-serif;color:black">See also:</span></b><span style="font-size:11.0pt;font-family:"Arial",sans-serif;color:black"> WHOIS Accuracy Program Specification</span><o:p></o:p></p>
</td>
<td valign="top" style="border-top:none;border-left:none;border-bottom:solid black 1.0pt;border-right:solid black 1.0pt;padding:5.0pt 5.0pt 5.0pt 5.0pt;overflow-wrap:break-word;overflow:hidden">
<p style="margin:0in;margin-bottom:.0001pt"><span style="font-size:11.0pt;font-family:"Arial",sans-serif;color:black">Allow the data subject to provide person type information and make updates when needed.</span><o:p></o:p></p>
</td>
<td valign="top" style="border-top:none;border-left:none;border-bottom:solid black 1.0pt;border-right:solid black 1.0pt;padding:5.0pt 5.0pt 5.0pt 5.0pt;overflow-wrap:break-word;overflow:hidden">
<p style="margin:0in;margin-bottom:.0001pt"><span style="font-size:11.0pt;font-family:"Arial",sans-serif;color:black">Allow the data subject to provide person type information and make updates when needed.</span><o:p></o:p></p>
</td>
<td valign="top" style="border-top:none;border-left:none;border-bottom:solid black 1.0pt;border-right:solid black 1.0pt;padding:5.0pt 5.0pt 5.0pt 5.0pt;overflow-wrap:break-word;overflow:hidden">
<p style="margin:0in;margin-bottom:.0001pt"><span style="font-size:11.0pt;font-family:"Arial",sans-serif;color:black">Allow the data subject to view their inferred person type designation and make updates when needed.</span><o:p></o:p></p>
<p class="MsoNormal"><o:p> </o:p></p>
<p style="margin:0in;margin-bottom:.0001pt"><b><span style="font-size:11.0pt;font-family:"Arial",sans-serif;color:black">Risk:</span></b><span style="font-size:11.0pt;font-family:"Arial",sans-serif;color:black"> registrar incorrectly infers data subject person
type, resulting in improper publication of natural person data </span><o:p></o:p></p>
</td>
</tr>
<tr>
<td valign="top" style="border:solid black 1.0pt;border-top:none;padding:5.0pt 5.0pt 5.0pt 5.0pt;overflow-wrap:break-word;overflow:hidden">
<p style="margin:0in;margin-bottom:.0001pt"><b><span style="font-size:11.0pt;font-family:"Arial",sans-serif;color:black">Storage Limitation: </span></b><o:p></o:p></p>
<p style="margin:0in;margin-bottom:.0001pt"><span style="font-size:11.0pt;font-family:"Arial",sans-serif;color:black">Controller must retain data only as long as is necessary for the purposes for which the data are processed</span><o:p></o:p></p>
<p class="MsoNormal"><o:p> </o:p></p>
<p style="margin:0in;margin-bottom:.0001pt"><b><span style="font-size:11.0pt;font-family:"Arial",sans-serif;color:black">See also:
</span></b><span style="font-size:11.0pt;font-family:"Arial",sans-serif;color:black">RAA 3.4, EPDP Phase 1 data retention requirement</span><o:p></o:p></p>
</td>
<td valign="top" style="border-top:none;border-left:none;border-bottom:solid black 1.0pt;border-right:solid black 1.0pt;padding:5.0pt 5.0pt 5.0pt 5.0pt;overflow-wrap:break-word;overflow:hidden">
<p style="margin:0in;margin-bottom:.0001pt"><span style="font-size:11.0pt;font-family:"Arial",sans-serif;color:black">Ensure that personal data is erased as soon as it is no longer required to fulfill the processing purposes</span><o:p></o:p></p>
<p class="MsoNormal"><o:p> </o:p></p>
<p style="margin:0in;margin-bottom:.0001pt"><b><span style="font-size:11.0pt;font-family:"Arial",sans-serif;color:black">Risk</span></b><span style="font-size:11.0pt;font-family:"Arial",sans-serif;color:black">: When data is public and erasure is required,
controller has obligation to inform other controllers that the data subject has requested erasure. </span><o:p></o:p></p>
</td>
<td valign="top" style="border-top:none;border-left:none;border-bottom:solid black 1.0pt;border-right:solid black 1.0pt;padding:5.0pt 5.0pt 5.0pt 5.0pt;overflow-wrap:break-word;overflow:hidden">
<p style="margin:0in;margin-bottom:.0001pt"><span style="font-size:11.0pt;font-family:"Arial",sans-serif;color:black">Ensure that personal data is erased as soon as it is no longer required to fulfill the processing purposes</span><o:p></o:p></p>
<p class="MsoNormal"><o:p> </o:p></p>
<p style="margin:0in;margin-bottom:.0001pt"><b><span style="font-size:11.0pt;font-family:"Arial",sans-serif;color:black">Risk</span></b><span style="font-size:11.0pt;font-family:"Arial",sans-serif;color:black">: When data is public and erasure is required,
controller has obligation to inform other controllers that the data subject has requested erasure. </span><o:p></o:p></p>
</td>
<td valign="top" style="border-top:none;border-left:none;border-bottom:solid black 1.0pt;border-right:solid black 1.0pt;padding:5.0pt 5.0pt 5.0pt 5.0pt;overflow-wrap:break-word;overflow:hidden">
<p style="margin:0in;margin-bottom:.0001pt"><span style="font-size:11.0pt;font-family:"Arial",sans-serif;color:black">Ensure that personal data is erased as soon as it is no longer required to fulfill the processing purposes</span><o:p></o:p></p>
<p class="MsoNormal"><o:p> </o:p></p>
<p style="margin:0in;margin-bottom:.0001pt"><b><span style="font-size:11.0pt;font-family:"Arial",sans-serif;color:black">Risk:
</span></b><span style="font-size:11.0pt;font-family:"Arial",sans-serif;color:black">registrar incorrectly infers data subject person type, resulting in disclosure of data which cannot be recalled and redacted; when data is public and erasure is required, controller
has obligation to inform other controllers that the data subject has requested erasure.</span><o:p></o:p></p>
</td>
</tr>
<tr>
<td valign="top" style="border:solid black 1.0pt;border-top:none;padding:5.0pt 5.0pt 5.0pt 5.0pt;overflow-wrap:break-word;overflow:hidden">
<p style="margin:0in;margin-bottom:.0001pt"><b><span style="font-size:11.0pt;font-family:"Arial",sans-serif;color:black">Integrity and Confidentiality</span></b><span style="font-size:11.0pt;font-family:"Arial",sans-serif;color:black">: Controller must process
personal data in a way that ensures security, protects against unlawful processing</span><o:p></o:p></p>
<p class="MsoNormal"><o:p> </o:p></p>
<p style="margin:0in;margin-bottom:.0001pt"><b><span style="font-size:11.0pt;font-family:"Arial",sans-serif;color:black">See also:
</span></b><span style="font-size:11.0pt;font-family:"Arial",sans-serif;color:black">RAA 3.4.1 “securely maintain, in its own electronic database…” </span><o:p></o:p></p>
</td>
<td valign="top" style="border-top:none;border-left:none;border-bottom:solid black 1.0pt;border-right:solid black 1.0pt;padding:5.0pt 5.0pt 5.0pt 5.0pt;overflow-wrap:break-word;overflow:hidden">
<p style="margin:0in;margin-bottom:.0001pt"><span style="font-size:11.0pt;font-family:"Arial",sans-serif;color:black">Ensure that only non-personal data is published </span><o:p></o:p></p>
</td>
<td valign="top" style="border-top:none;border-left:none;border-bottom:solid black 1.0pt;border-right:solid black 1.0pt;padding:5.0pt 5.0pt 5.0pt 5.0pt;overflow-wrap:break-word;overflow:hidden">
<p style="margin:0in;margin-bottom:.0001pt"><span style="font-size:11.0pt;font-family:"Arial",sans-serif;color:black">Ensure that only non-personal data is published</span><o:p></o:p></p>
</td>
<td valign="top" style="border-top:none;border-left:none;border-bottom:solid black 1.0pt;border-right:solid black 1.0pt;padding:5.0pt 5.0pt 5.0pt 5.0pt;overflow-wrap:break-word;overflow:hidden">
<p style="margin:0in;margin-bottom:.0001pt"><span style="font-size:11.0pt;font-family:"Arial",sans-serif;color:black">Ensure that only non-personal data is published. </span><o:p></o:p></p>
<p class="MsoNormal"><o:p> </o:p></p>
<p style="margin:0in;margin-bottom:.0001pt"><b><span style="font-size:11.0pt;font-family:"Arial",sans-serif;color:black">Risk:
</span></b><span style="font-size:11.0pt;font-family:"Arial",sans-serif;color:black">publishing personal data due to mis-identification</span><o:p></o:p></p>
</td>
</tr>
<tr>
<td valign="top" style="border:solid black 1.0pt;border-top:none;padding:5.0pt 5.0pt 5.0pt 5.0pt;overflow-wrap:break-word;overflow:hidden">
<p style="margin:0in;margin-bottom:.0001pt"><b><span style="font-size:11.0pt;font-family:"Arial",sans-serif;color:black">Accountability:</span></b><span style="font-size:11.0pt;font-family:"Arial",sans-serif;color:black"> </span><o:p></o:p></p>
<p style="margin:0in;margin-bottom:.0001pt"><span style="font-size:11.0pt;font-family:"Arial",sans-serif;color:black">Controller must be able to demonstrate that they comply with GDPR Principles</span><o:p></o:p></p>
</td>
<td valign="top" style="border-top:none;border-left:none;border-bottom:solid black 1.0pt;border-right:solid black 1.0pt;padding:5.0pt 5.0pt 5.0pt 5.0pt;overflow-wrap:break-word;overflow:hidden">
<p style="margin:0in;margin-bottom:.0001pt"><span style="font-size:11.0pt;font-family:"Arial",sans-serif;color:black">Document processing activities with explanation of how the chosen implementation complies with GDPR Principles for processing data</span><o:p></o:p></p>
</td>
<td valign="top" style="border-top:none;border-left:none;border-bottom:solid black 1.0pt;border-right:solid black 1.0pt;padding:5.0pt 5.0pt 5.0pt 5.0pt;overflow-wrap:break-word;overflow:hidden">
<p style="margin:0in;margin-bottom:.0001pt"><span style="font-size:11.0pt;font-family:"Arial",sans-serif;color:black">Document processing activities with explanation of how the chosen implementation complies with GDPR Principles for processing data</span><o:p></o:p></p>
</td>
<td valign="top" style="border-top:none;border-left:none;border-bottom:solid black 1.0pt;border-right:solid black 1.0pt;padding:5.0pt 5.0pt 5.0pt 5.0pt;overflow-wrap:break-word;overflow:hidden">
<p style="margin:0in;margin-bottom:.0001pt"><span style="font-size:11.0pt;font-family:"Arial",sans-serif;color:black">Document processing activities with explanation of how the chosen implementation complies with GDPR Principles for processing data</span><o:p></o:p></p>
</td>
</tr>
</tbody>
</table>
</div>
<p style="margin:0in;margin-bottom:.0001pt;background:white"> <o:p></o:p></p>
<p style="margin:0in;margin-bottom:.0001pt;background:white"> <o:p></o:p></p>
<p style="margin:0in;margin-bottom:.0001pt;background:white"><span style="font-family:"Calibri",sans-serif;color:black">Example scenarios</span><o:p></o:p></p>
<p style="margin:0in;margin-bottom:.0001pt;background:white"> <o:p></o:p></p>
<p style="margin:0in;margin-bottom:.0001pt;background:white"><span style="font-family:"Calibri",sans-serif;color:black">The EPDP Team has identified three different high-level scenarios for how differentiation could occur based on who is responsible and the
timing of such differentiation. It should be noted that other approaches and/or a combination of these may be possible. </span><o:p></o:p></p>
<p style="margin:0in;margin-bottom:.0001pt;background:white"> <o:p></o:p></p>
<p style="mso-margin-top-alt:0in;margin-right:0in;margin-bottom:0in;margin-left:.5in;margin-bottom:.0001pt;text-indent:-.25in;mso-list:l3 level1 lfo1;vertical-align:baseline">
<![if !supportLists]><span style="font-family:"Calibri",sans-serif;color:black"><span style="mso-list:Ignore">1.<span style="font:7.0pt "Times New Roman"">
</span></span></span><![endif]><span style="font-family:"Calibri",sans-serif;color:black">Data subject self-identification at time of data collection / registration <o:p></o:p></span></p>
<p style="mso-margin-top-alt:0in;margin-right:0in;margin-bottom:0in;margin-left:.75in;margin-bottom:.0001pt;text-indent:-.25in;mso-list:l3 level2 lfo2;vertical-align:baseline">
<![if !supportLists]><span style="font-family:"Calibri",sans-serif;color:black"><span style="mso-list:Ignore">a.<span style="font:7.0pt "Times New Roman"">
</span></span></span><![endif]><span style="font-family:"Calibri",sans-serif;color:black">The Registrar informs the Registrant (per guidance #3 above) and requests the Registrant (data subject) at the moment of Registration data collection to designate legal
or natural person type. The Registrar must also request the Registrant to confirm whether only non-personal data is provided for legal person type. <o:p></o:p></span></p>
<p style="mso-margin-top-alt:0in;margin-right:0in;margin-bottom:0in;margin-left:.75in;margin-bottom:.0001pt;text-indent:-.25in;mso-list:l3 level2 lfo2;vertical-align:baseline">
<![if !supportLists]><span style="font-family:"Calibri",sans-serif;color:black"><span style="mso-list:Ignore">b.<span style="font:7.0pt "Times New Roman"">
</span></span></span><![endif]><span style="font-family:"Calibri",sans-serif;color:black">If the Registrant (data subject) has selected legal person and has provided a confirmation that the registration data does not include any personal data, the Registrar
should (i) contact the provided contact details to verify the Registrant claim (ii) sets the registration data set to automated disclosure in response to SSAD queries and (iii) Ppublishes the data (to provide Registration Data in the publicly accessible Registration
Data Directory Services). <o:p></o:p></span></p>
<p style="mso-margin-top-alt:0in;margin-right:0in;margin-bottom:0in;margin-left:.75in;margin-bottom:.0001pt;text-indent:-.25in;mso-list:l3 level2 lfo2;vertical-align:baseline">
<![if !supportLists]><span style="font-family:"Calibri",sans-serif;color:black"><span style="mso-list:Ignore">c.<span style="font:7.0pt "Times New Roman"">
</span></span></span><![endif]><span style="font-family:"Calibri",sans-serif;color:black">If the Registrant (data subject) has selected natural person or has confirmed that personal data is present, the Registrar does not set that registration data to automated
Disclosure and Publication, unless the data subject consents to Publication. <o:p></o:p></span></p>
<p style="mso-margin-top-alt:0in;margin-right:0in;margin-bottom:0in;margin-left:.75in;margin-bottom:.0001pt;text-indent:-.25in;mso-list:l3 level2 lfo2;vertical-align:baseline">
<![if !supportLists]><span style="font-size:11.0pt;font-family:"Calibri",sans-serif;color:black"><span style="mso-list:Ignore">d.<span style="font:7.0pt "Times New Roman"">
</span></span></span><![endif]><span style="font-family:"Calibri",sans-serif;color:black">If the Registrant (data subject) makes any substantive change to the registration data, the Registrar is expected to confirm that these updates do not result in changes
to the registrant type or the previous confirmation of whether only non-personal data is provided for legal person type. If the updates do result in changes, Registrar must repeat Steps a-c above. </span><span style="font-size:11.0pt;font-family:"Calibri",sans-serif;color:black"><o:p></o:p></span></p>
<p class="MsoNormal"><br>
<br>
<o:p></o:p></p>
<p style="mso-margin-top-alt:0in;margin-right:0in;margin-bottom:0in;margin-left:.5in;margin-bottom:.0001pt;text-indent:-.25in;mso-list:l0 level1 lfo4;vertical-align:baseline">
<![if !supportLists]><span style="font-family:"Calibri",sans-serif;color:black"><span style="mso-list:Ignore">2.<span style="font:7.0pt "Times New Roman"">
</span></span></span><![endif]><span style="font-family:"Calibri",sans-serif;color:black">Data subject self-identification after initial collection <o:p></o:p></span></p>
<p style="mso-margin-top-alt:0in;margin-right:0in;margin-bottom:0in;margin-left:.75in;margin-bottom:.0001pt;text-indent:-.25in;mso-list:l0 level2 lfo5;vertical-align:baseline">
<![if !supportLists]><span style="font-family:"Calibri",sans-serif;color:black"><span style="mso-list:Ignore">a.<span style="font:7.0pt "Times New Roman"">
</span></span></span><![endif]><span style="font-family:"Calibri",sans-serif;color:black">The Registrar collects Registration Data and provisionally redacts the data.<o:p></o:p></span></p>
<p style="mso-margin-top-alt:0in;margin-right:0in;margin-bottom:0in;margin-left:.75in;margin-bottom:.0001pt;text-indent:-.25in;mso-list:l0 level2 lfo5;vertical-align:baseline">
<![if !supportLists]><span style="font-family:"Calibri",sans-serif;color:black"><span style="mso-list:Ignore">b.<span style="font:7.0pt "Times New Roman"">
</span></span></span><![endif]><span style="font-family:"Calibri",sans-serif;color:black">The Registrar informs the Registrant (per guidance #3 above) and requests the Registrant (data subject) to designate legal or natural person type. The Registrar must also
request the Registrant to confirm whether only non-personal data is provided for legal person type. <o:p></o:p></span></p>
<p style="mso-margin-top-alt:0in;margin-right:0in;margin-bottom:0in;margin-left:.75in;margin-bottom:.0001pt;text-indent:-.25in;mso-list:l0 level2 lfo5;vertical-align:baseline">
<![if !supportLists]><span style="font-family:"Calibri",sans-serif;color:black"><span style="mso-list:Ignore">c.<span style="font:7.0pt "Times New Roman"">
</span></span></span><![endif]><span style="font-family:"Calibri",sans-serif;color:black">Registrant (data subject) indicates legal or natural person type and whether or not the registration contains personal information after registration is completed. For
example, the Registrant may confirm person type at the time of initial data verification, in response to its receipt of the Whois data reminder email for existing registrations, or through a separate notice requesting self-identification. <o:p></o:p></span></p>
<p style="mso-margin-top-alt:0in;margin-right:0in;margin-bottom:0in;margin-left:.75in;margin-bottom:.0001pt;text-indent:-.25in;mso-list:l0 level2 lfo5;vertical-align:baseline">
<![if !supportLists]><span style="font-family:"Calibri",sans-serif;color:black"><span style="mso-list:Ignore">d.<span style="font:7.0pt "Times New Roman"">
</span></span></span><![endif]><span style="font-family:"Calibri",sans-serif;color:black">If the data subject identifies as a legal person and confirms that the registration data does not include personal data, the Registrar should (i) contact the provided
contact details to verify the Registrant claim (ii) (i) sets the registration data set to automated disclosure in response to SSAD queries and (iii) pPublishes the data. <o:p></o:p></span></p>
<p class="MsoNormal"><br>
<br>
<o:p></o:p></p>
<p style="mso-margin-top-alt:0in;margin-right:0in;margin-bottom:0in;margin-left:.5in;margin-bottom:.0001pt;text-indent:-.25in;mso-list:l1 level1 lfo7;vertical-align:baseline">
<![if !supportLists]><span style="font-family:"Calibri",sans-serif;color:black"><span style="mso-list:Ignore">3.<span style="font:7.0pt "Times New Roman"">
</span></span></span><![endif]><span style="font-family:"Calibri",sans-serif;color:black">Registrar determines type based on data provided<o:p></o:p></span></p>
<p style="mso-margin-top-alt:0in;margin-right:0in;margin-bottom:0in;margin-left:.75in;margin-bottom:.0001pt;text-indent:-.25in;mso-list:l1 level2 lfo8;vertical-align:baseline">
<![if !supportLists]><span style="font-family:"Calibri",sans-serif;color:black"><span style="mso-list:Ignore">a.<span style="font:7.0pt "Times New Roman"">
</span></span></span><![endif]><span style="font-family:"Calibri",sans-serif;color:black">The Registrar collects Registration Data and provisionally redacts the data.<o:p></o:p></span></p>
<p style="mso-margin-top-alt:0in;margin-right:0in;margin-bottom:0in;margin-left:.75in;margin-bottom:.0001pt;text-indent:-.25in;mso-list:l1 level2 lfo8;vertical-align:baseline">
<![if !supportLists]><span style="font-family:"Calibri",sans-serif;color:black"><span style="mso-list:Ignore">b.<span style="font:7.0pt "Times New Roman"">
</span></span></span><![endif]><span style="font-family:"Calibri",sans-serif;color:black">The Registrar uses collected data to infer legal or natural person type.<o:p></o:p></span></p>
<p style="mso-margin-top-alt:0in;margin-right:0in;margin-bottom:0in;margin-left:.75in;margin-bottom:.0001pt;text-indent:-.25in;mso-list:l1 level2 lfo8;vertical-align:baseline">
<![if !supportLists]><span style="font-family:"Calibri",sans-serif;color:black"><span style="mso-list:Ignore">c.<span style="font:7.0pt "Times New Roman"">
</span></span></span><![endif]><span style="font-family:"Calibri",sans-serif;color:black">If legal person is inferred by the Registrar and subsequently the Registrant (data subject) is informed (per guidance #3 above) and confirms that no personal data is present,
the Registrar should (i) contact the provided contact details to verify the Registrant claim (ii) (i) sets the registration data set to automated disclosure in response to SSAD queries and (iii) Ppublishes the data. <o:p></o:p></span></p>
<p style="mso-margin-top-alt:0in;margin-right:0in;margin-bottom:0in;margin-left:.75in;margin-bottom:.0001pt;text-indent:-.25in;mso-list:l1 level2 lfo8;vertical-align:baseline">
<![if !supportLists]><span style="font-family:"Calibri",sans-serif;color:black"><span style="mso-list:Ignore">d.<span style="font:7.0pt "Times New Roman"">
</span></span></span><![endif]><span style="font-family:"Calibri",sans-serif;color:black">If the Registrar has inferred natural person or has detected personal data, the Registrar must not disclose registration data unless the Registrant provides consent for
publication or the Registrar Discloses the data in response to a legitimate disclosure request.<o:p></o:p></span></p>
<p class="MsoNormal"><o:p> </o:p></p>
<p style="margin:0in;margin-bottom:.0001pt"><span style="font-family:"Calibri",sans-serif;color:black">Registrars shall not be prohibited from voluntarily utilizing a third party to verify that a registrant has correctly identified its data, provided that provided
such verification is compliant with applicable data protection regulations. </span><o:p></o:p></p>
<p class="MsoNormal"><o:p> </o:p></p>
<p style="margin:0in;margin-bottom:.0001pt"><span style="font-family:"Calibri",sans-serif;color:black">The EPDP Team recognizes that in all of the above scenarios, there is the possibility of misidentification, which may result in the inadvertent disclosure
of personal data. In this regard, </span><a href="https://community.icann.org/download/attachments/155191493/ICANN%20-%20EPDP%20Phase%202a%20-%20Memo%20re.%20VSC%20and%20consent%20options%20-%2020210406.docx?version=1&modificationDate=1617804552000&api=v2"><span style="font-family:"Calibri",sans-serif">Bird
& Bird</span></a><span style="font-family:"Calibri",sans-serif;color:black"> has noted the following:</span><o:p></o:p></p>
<p style="mso-margin-top-alt:0in;margin-right:0in;margin-bottom:0in;margin-left:.5in;margin-bottom:.0001pt">
<i><span style="font-family:"Calibri",sans-serif;color:black"><o:p> </o:p></span></i></p>
<p style="mso-margin-top-alt:0in;margin-right:0in;margin-bottom:0in;margin-left:.5in;margin-bottom:.0001pt">
<br>
<br>
<i><span style="font-family:"Calibri",sans-serif;color:black"><o:p></o:p></span></i></p>
<p style="mso-margin-top-alt:0in;margin-right:0in;margin-bottom:0in;margin-left:.5in;margin-bottom:.0001pt">
<i><span style="font-family:"Calibri",sans-serif;color:black">11.11.1 If the (person representing the) Registrant incorrectly characterises personal data as non-personal, then the verification process this triggers should confer reasonable protection against
GDPR Accuracy Principle liability for Contracted Parties, as explained at paragraph 11.7 above, as might the legal argument set out at paragraph 11.8 above.</span></i><o:p></o:p></p>
<p style="mso-margin-top-alt:0in;margin-right:0in;margin-bottom:0in;margin-left:.5in;margin-bottom:.0001pt">
<i><span style="font-family:"Calibri",sans-serif;color:black">11.11.2 Alternatively, if the (person representing the) Registrant incorrectly characterises non-personal data as personal data, then whether or not they subsequently consent to its publication,
the data would still not actually be personal data, so GDPR liability cannot arise</span></i><i><span style="font-size:11.0pt;font-family:"Calibri",sans-serif;color:black">. </span></i><o:p></o:p></p>
<p class="MsoNormal"><o:p> </o:p></p>
<p style="margin:0in;margin-bottom:.0001pt"><span style="font-size:11.0pt;font-family:"Calibri",sans-serif;color:black">(…)</span><o:p></o:p></p>
<p class="MsoNormal"><o:p> </o:p></p>
<p style="mso-margin-top-alt:0in;margin-right:0in;margin-bottom:0in;margin-left:.5in;margin-bottom:.0001pt">
<i><span style="font-family:"Calibri",sans-serif;color:black">13. However, in our view the risk to Contracted Parties seems low, if they take the measures described in the question presented, to avoid personal data being (or if reported, staying) published
in Registration Data.</span></i><o:p></o:p></p>
<p class="MsoNormal"><o:p> </o:p></p>
<p style="margin:0in;margin-bottom:.0001pt"><span style="font-size:11.0pt;font-family:"Calibri",sans-serif;color:black">(…)</span><o:p></o:p></p>
<p class="MsoNormal"><o:p> </o:p></p>
<p style="mso-margin-top-alt:0in;margin-right:0in;margin-bottom:0in;margin-left:.5in;margin-bottom:.0001pt">
<i><span style="font-family:"Calibri",sans-serif;color:black">14.3 The data in question is likely to be low sensitivity. The scenario being envisaged here (mistaken inclusion of personal data in published Registration Data) seems to be most likely to occur
when a legal entity (e.g. a company or non-profit organisation) is registering / maintaining its own domains. In those scenarios, we assume the personal data that could be disclosed would ordinarily relate to an employee’s work details (e.g. a company email
address), not an individual’s private life. Although the GDPR confers protection even in the workplace, the data in question here may arguably be less capable of causing harm to an individual than data relating to the data subject’s private life.</span></i><i><sup><span style="font-size:7.0pt;font-family:"Calibri",sans-serif;color:black">
</span></sup></i><i><span style="font-family:"Calibri",sans-serif;color:black"> </span></i><o:p></o:p></p>
<p class="MsoNormal"><o:p> </o:p></p>
<p style="margin:0in;margin-bottom:.0001pt"><span style="font-size:11.0pt;font-family:"Calibri",sans-serif;color:black">(…)</span><o:p></o:p></p>
<p class="MsoNormal"><o:p> </o:p></p>
<p style="mso-margin-top-alt:0in;margin-right:0in;margin-bottom:0in;margin-left:.5in;margin-bottom:.0001pt">
<i><span style="font-family:"Calibri",sans-serif;color:black">18. We cannot exclude the possibility of some courts or regulators seeing things differently. Even then, an order to correct the issue (likely accompanied by a reasonable period in which to implement
changes), rather than a fine, seems most likely, having regard to the GDPR Article 83(2) factors discussed at paragraph 8 above. Having checked in a selection of Member States, we can find no examples of enforcement in relation to this. Accordingly, there
is little guidance available besides what is set out in the GDPR itself.</span></i><o:p></o:p></p>
<div>
<p class="MsoNormal"><o:p> </o:p></p>
</div>
<div>
<p class="MsoNormal"><o:p> </o:p></p>
</div>
<div>
<p class="MsoNormal"><o:p> </o:p></p>
</div>
<div>
<p class="MsoNormal">On 2021-05-05 12:01 p.m., Mueller, Milton L wrote:<o:p></o:p></p>
</div>
<div>
<p class="MsoNormal"><o:p> </o:p></p>
</div>
<blockquote style="margin-top:5.0pt;margin-bottom:5.0pt">
<p class="MsoNormal"><span style="font-size:11.0pt;font-family:"Calibri",sans-serif;color:#1F497D">Kathy,</span><o:p></o:p></p>
<p style="margin-bottom:12.0pt"><span style="font-size:10.5pt;font-family:"Arial",sans-serif;color:#1F497D">>
</span><span style="font-size:10.5pt;font-family:"Arial",sans-serif">You have given us options and we chose not to differentiate legal and natural persons.
</span><o:p></o:p></p>
<p style="margin-bottom:12.0pt"><span style="font-size:11.0pt;font-family:"Calibri",sans-serif;color:#1F497D">Sorry if you misinterpreted this. As I explained, no differentiation is _<i>not</i>_ an option anymore.
</span><o:p></o:p></p>
<p style="margin-bottom:12.0pt"><span style="font-size:11.0pt;font-family:"Calibri",sans-serif;color:#1F497D">The actual choice is, Do contracted parties get to decide entirely on their own whether and how to differentiate? Or do we offer them guidance?
</span><o:p></o:p></p>
<p style="margin-bottom:12.0pt"><strong><span style="font-size:10.5pt;font-family:"Arial",sans-serif;color:#1F497D">></span></strong><span style="font-size:10.5pt;font-family:"Arial",sans-serif">. As Stephanie says, “The moment you drag anything into policy,
it will become mandatory.”</span><o:p></o:p></p>
<p style="margin-bottom:12.0pt"><span style="font-size:11.0pt;font-family:"Calibri",sans-serif;color:#1F497D">Nope. The EPDP will develop guidance. After it does so, there will be a vote on whether it should be mandatory or not. We, the CPs, and ISPs will vote
against that, the other crew will vote for it. There will not be consensus, ergo it will not be mandatory. There is no way guidance that has been explicitly deemed not mandatory can suddenly become mandatory without a new PDP.
</span><o:p></o:p></p>
<p style="margin-bottom:12.0pt"><span style="font-size:11.0pt;font-family:"Calibri",sans-serif;color:#1F497D">Technically, it is possible for NCSG to suddenly turn against offering any guidance, but I don’t think there is NCSG support for that. Both Manju and
I have opposed it. Anyone else on the EPDP care to speak up? </span><o:p></o:p></p>
<p style="margin-bottom:12.0pt"><span style="font-size:10.5pt;font-family:"Arial",sans-serif"><br>
--------------------------------------------------------------------<br>
<br>
Quoting "Mueller, Milton L" <<a href="mailto:milton@gatech.edu">milton@gatech.edu</a>>:<br>
<br>
> Kathy, Stephanie, and NCSG members:<br>
><br>
> Personally, I would have no problem falling in line with your<br>
> position. But there are two fatal flaws that you need to address.<br>
> First, you are describing only what _we_ want and not thinking at all<br>
> about how you get consensus. Second, your description of what we want<br>
> does NOT correspond to what will actually happen if we “hold the<br>
> line.” As much as I would like to promote harmony and unity among<br>
> NCSG EPDP representatives, I don’t think you have thought things<br>
> through.<br>
><br>
> I know perfectly well that we don’t want any differentiation and that<br>
> the registrars don’t either. What you are overlooking is that the<br>
> other half of the EPDP does want it, and the board will see the EPDP<br>
> as deadlocked. So Option 1 will make you feel very self-righteous in<br>
> the short term, but what happens next? You are, as I will show,<br>
> leading us down a blind alley.<br>
><br>
> I can think of 3 scenarios we can discuss as a basis for action.<br>
><br>
> Scenario 1.<br>
> We “hold the line,” and we revert to Phase 1 recommendations<br>
> unchanged. There is _no guidance_. The other half of the EPDP just<br>
> gives up and accepts it. This result is not bad, I admit, if that<br>
> last bit happens.<br>
> But what are the Phase 1 recommendations? You have misrepresented the<br>
> “status quo” as not differentiating legal and natural. WRONG. What<br>
> will happen under this option is that any registrar or registry can<br>
> choose to differentiate in any way they like. And there will be no<br>
> guidance that you can appeal to if they do it wrong. You say you<br>
> don’t want registrars asking users whether they are legal or natural.<br>
> Well, sorry, that can happen under your Option 1. A deadlock on EPDP<br>
> means that differentiation is neither prohibited or required, it is<br>
> up to the contracted parties. Many registrars won’t do it, but some<br>
> will. Registries could do it, too. This is the “let the market<br>
> decide” option. Stephanie has become a libertarian, I guess.<br>
><br>
> Scenario 2<br>
> Scenario 1 assumes the other side accepts defeat. But what if we<br>
> “hold the line,” and the other half of the EPDP doesn’t accept it?<br>
> The European Commission, the US justice department, the GAC, SSAC,<br>
> and of course the IPC/BC and ALAC join a strong chorus telling the<br>
> board “something must be done.” The Board is influenced, and refuses<br>
> to accept the recommendation, as it has done with the SSAD (which the<br>
> same group of stakeholders opposed). We have seen the Board cave to<br>
> GAC and governmental demands again and again, the latest example<br>
> being “curative rights” for IGO acronyms, which the GNSO never<br>
> approved. Worse, the EC may modify its NIS2 legislation to require<br>
> ICANN to differentiate. The US congress could intervene. The issue<br>
> festers for another three – five years. Several powerful players<br>
> start attacking the multistakeholder process. Maybe ICANN corrupts<br>
> its process once again.<br>
><br>
> Scenario 3<br>
> Scenario 3 is that we don’t require differentiation of legal persons,<br>
> but we develop consensus guidance on how contracted parties should do<br>
> it if they choose to do it. This is the most likely scenario, and<br>
> it’s one that your position paper completely ignores. If you do want<br>
> guidance, the approach to guidance that I have suggested is best,<br>
> because it is a very lightweight process of self-identification by<br>
> registrants. By offering some differentiation it may defuse the<br>
> opposition of the other stakeholders. On the other hand Stephanie’s<br>
> complicated, expensive and power-surrendering approach is not the<br>
> kind of guidance we want.<br>
><br>
> By now it should be clear to anyone who’s read this far that Scenario<br>
> 1 is not as wonderful as you say and may not be possible. The EPDP is<br>
> already deeply invested in developing guidance about how registrars<br>
> should and should not differentiate. We have been working on it for<br>
> weeks. Unless something changes radically in the next week, we will<br>
> actually produce some guidance about differentiation. So, I suggest<br>
> that we confine our debate to Scenario 2: the developing of<br>
> nonbinding guidance. I suggest again that allowing registrants to<br>
> choose to identify their registration as one of a legal person, with<br>
> their data published or automatically available via SSAD, creates a<br>
> path to consensus and to resolving the issue, whereas your preferred<br>
> path does not.<br>
><br>
> To conclude, I call your attention to a pathology that is paralyzing<br>
> nearly all of ICANN’s working groups. Defining your position and<br>
> “holding the line” is a strategy that all the SGs and ACs seem to<br>
> adopt now. It turns all these deliberations into a bunch of people<br>
> re-stating their position again and again for 3-4 years,<br>
> re-litigating issues endlessly, avoiding any serious middle ground.<br>
> No thought is given to finding a solution that achieves a critical<br>
> mass of consensus.<br>
><br>
> Anyone who wants to be a serious participant in developing the NCSG’s<br>
> position in EPDP has to answer a very basic question:<br>
><br>
> How does this end?<br>
> What is your scenario for achieving the level of agreement needed to<br>
> pass a policy?<br>
><br>
> Looking forward to your response.<br>
><br>
> Dr. Milton L Mueller<br>
> Georgia Institute of Technology<br>
> School of Public Policy<br>
> Internet Governance Project<<a href="https://internetgovernance.org/" target="_blank">https://internetgovernance.org/</a>><br>
><br>
><br>
><br>
> From: NCSG-Discuss <<a href="mailto:NCSG-DISCUSS@LISTSERV.SYR.EDU">NCSG-DISCUSS@LISTSERV.SYR.EDU</a>> On Behalf Of<br>
> <a href="mailto:kathy@DNRC.TECH">kathy@DNRC.TECH</a><br>
> Sent: Tuesday, May 4, 2021 5:35 PM<br>
> To: <a href="mailto:NCSG-DISCUSS@LISTSERV.SYR.EDU">NCSG-DISCUSS@LISTSERV.SYR.EDU</a><br>
> Subject: Option 1<br>
><br>
><br>
> Tx to Milton, Stephanie, Manju, Tapani, Farzi, Mark Leiser, Kim von<br>
> Arx and everyone else who commented on our dicussion of options for<br>
> the EPDP.<br>
><br>
> As it's time to wrap up this issue so our EPDP members can present<br>
> our view to the EPDP Group, I co-wrote the email Stephanie posted<br>
> earlier today (attached below too). Best regards, Kathy<br>
> ------------------------------------------------------------------------<br>
><br>
> Fellow NCSG members,<br>
><br>
>> We would like to work together to share our rationale for Option 1 –<br>
><br>
> maintaining the status quo and not asking further follow-up<br>
> questions, mandatory or otherwise, about legal and natural persons.<br>
> While the EPDP phase 2a discussions have been an educational and<br>
> interesting exercise, we are not under any obligation to change the<br>
> existing policy, or further complicate it.<br>
><br>
> As we have all discussed, legal/natural person questions are very<br>
> complicated for many of our members who are often noncommercial and<br>
> non-profit organizations whose structure and ways of obtaining domain<br>
> names do not resemble those of the large corporations other<br>
> stakeholder groups represent. Our members may have many layers of<br>
> privacy protection in less-well-known sections of the GDPR, other<br>
> local law, Constitutions and international conventions.<br>
><br>
> We learned that recent studies show that 50% of gTLD domain name<br>
> registrations are for natural persons – and at least 25% more have<br>
> overlapping entity and personal data (e.g., the organization name has<br>
> personal data in it and is thus protected as personal data).<br>
><br>
> Stephanie and Kathy shared their concerns for legal/natural person<br>
> questions during our long work on the Proxy and Privacy <br>
> Accreditation Working Group. We worked closely with the Registrars<br>
> Stakeholder Group to protect registrant privacy – including Battered<br>
> Women’s Shelters, family planning clinics, and girls educational<br>
> institutions – all of which may be legal entities, but have<br>
> protectable data due to obvious danger from disclosure in certain<br>
> countries.<br>
><br>
> In light of the complicated world around us, we support Option 1- the<br>
> Status Quo. We ask the NCSG to adopt this as our stance. Based on<br>
> the existing policy which makes differentiation of legal/natural<br>
> persons optional for each registrar, we believe we already have the<br>
><br>
> - best way to fight DNS Abuse,<br>
><br>
> - best way to protect individuals and noncommercial organizations, and<br>
><br>
> - best way to follow GDPR and other applicable human rights<br>
> and free speech laws<br>
><br>
> Therefore, we recommend NCSG “hold the line” and stick with Option 1.<br>
><br>
> As the Registrars wrote in their EPDP Statement on Thursday April 29:<br>
> We have heard plenty of vocal support in this group to <br>
> [differentiate between legal and natural persons in a mandatory<br>
> fashion], but to date the RrSG have not heard any compelling reason<br>
> to create policy that makes this dramatic shift to the domain<br>
> registration landscape.<br>
><br>
> We agree. Nothing will stop other stakeholder groups from demanding<br>
> further disclosure of data, and lobbying other parties including<br>
> governments. What we can do in ICANN is come up with the best<br>
> solution for us at this time.<br>
><br>
> Many thanks to the members of our NCSG EPDP Team for your hard work.<br>
> This has been a long road. With new studies, new information and<br>
> legal opinions, we think we have a clear and strategic path forward. <br>
> We believe our position to be closely aligned with that of the<br>
> Registrar Stakeholder Group, which they articulated on April 29 (see<br>
> below).<br>
><br>
> Best, Kathy Kleiman and Stephanie Perrin<br>
><br>
> ---------------------------------------------------------<br>
> The Registrar Stakeholder Group issued their position statement on<br>
> Thursday (4/29):<br>
><br>
> The members of the RrSG EPDP team have participated in this process<br>
> in good faith since day one and will continue to do so; however, we<br>
> need to be crystal clear that members of our Stakeholder Group, whom<br>
> we are here to represent, have voiced and recently reconfirmed their<br>
> strong opposition to any policy coming out of this group that makes<br>
> differentiation between natural and legal persons for domain<br>
> registrations mandatory.<br>
><br>
> We have heard plenty of vocal support in this group to do just that,<br>
> but to date the RrSG have not heard any compelling reason to create<br>
> policy that makes this dramatic shift to the domain registration<br>
> landscape. The Contracted Party can make the most accurate assessment<br>
> of their own legal, technical, and commercial risks and obligations,<br>
> and is the only party that can determine what level of risk they<br>
> should assume. The scope of this EPDP Phase 2a is to consider if<br>
> changes are required for the relevant Recommendation; it has become<br>
> clear through this process that no such changes are required<br>
><br>
> To the extent this group can focus its energies on guidance to<br>
> contracted parties which choose on their own to make this<br>
> differentiation, we continue to believe that is a worthwhile<br>
> exercise. We believe that guidance materials including educational<br>
> information provided by ICANN in multiple languages would help<br>
> contracted parties educate registrants and this would be a valuable<br>
> effort.<br>
><br>
> That said, based on analysis done by our stakeholder group's members,<br>
> we reject the notion that the majority of registered domain names are<br>
> registered to legal entities. We further remind this team that we<br>
> have not yet seen evidence that increased publication of registration<br>
> data will address any of the problems which have been mentioned so<br>
> far in this phase, and that the registration data is reliably and<br>
> promptly available to those who do have a legitimate reason to access<br>
> it.<br>
><br>
> Finally we note that this statement represents the official position<br>
> of the Registrar Stakeholder group, and statements from members of<br>
> other groups participating in the EPDP do not represent our group’s<br>
> position.<br>
><br>
> (Source: Transcript of EPDP-Phase 2A Team Call, 29 April 2021,<br>
> Statement of Volker Greimann on behalf of the Registrars Stakeholder<br>
> Group read into the record)</span><o:p></o:p></p>
</blockquote>
</div>
</body>
</html>