<div style="line-height:1.7;color:#000000;font-size:14px;font-family:Arial"><div>Dear Milton Mueller,</div><div><br /></div><div>Thanks for your response. It helps me learn a lot. I think I can make furthur clarification.</div><div><br /></div><div><span style="color: rgb(31, 73, 125); font-family: Calibri, sans-serif; font-size: 14.6667px;">China’s national law has no authority over the root server – indeed, it is destructive and impossible for any national government to try to impose its national law on this globally shared resource. China’s law also has no authority over TLD operators who do not serve Chinese customers. China’s “real name” law can ONLY apply to registrars serving Chinese customers, because that is where individuals with “real names” intersect with the domain name system.</span></div><div><br /></div><div>I agree with you that China's law has no authority over TLD operators who do not serve Chinese customers. However, any TLD have business in China should deal with China Security Law. I don't feel quote China Security Law as a Legal Consideration is irrelevent.</div><br /><div><span style="color: rgb(31, 73, 125); font-family: Calibri, sans-serif; font-size: 14.6667px;">You may not understand what you are talking about here – how would a TLD operator provide a “real name” when it is a company, not a person, and when its records contain tens of thousands or millions of names of registrants? Are you saying that Chinese law requires every TLD operator and registrar in the world to turn over personally identifiable information of all their customers to the Chinese government? I think no one in this stakeholder group, or any other, would support this, and none of the world’s governments would accept it, either.</span></div><div><br /></div><div>That's not I am talking about. What I am talking about in the first email is that, ICANN, registry and registrar with business in China, they need to require the registrant to provide a real identification, not simply let them choose their identification. There are many other ways in practice to achieve such result, for example, a statement from registrant about their registration information is real. There is <b>no such a requirement</b> from Chinese government about requiring <span style="color: rgb(31, 73, 125); font-family: Calibri, sans-serif; font-size: 14.6667px;">every TLD operator and registrar in the world to turn over personally identifiable information of all their customers to the Chinese government.</span></div><div style="position:relative;zoom:1"><br /></div><div style="position:relative;zoom:1">My intents it to point out right now the practice in EPDP Team Phase 2A Initial Report may have potential compliance risk in China.</div><div style="position:relative;zoom:1"><br /></div><div style="position:relative;zoom:1"><span style="color: rgb(31, 73, 125); font-family: Calibri, sans-serif; font-size: 14.6667px;">These are ICANN policies, not European ones.</span></div><div style="position:relative;zoom:1"><br /></div><div style="position:relative;zoom:1">I agree that. However, I also want to mention that in Page 3 of EPDP Team Phase 2A Initial Report, the whole GNSO PDP is initiated by the board action about complying with the European
Union’s GDPR.</div><div style="position:relative;zoom:1"><br /></div><div style="position:relative;zoom:1"><span style="color: rgb(31, 73, 125); font-family: Calibri, sans-serif; font-size: 14.6667px;">EU law does not override Chinese law, but Chinese law cannot bind what the rest of the world does, either. I Hope that’s clear.</span></div><div style="position:relative;zoom:1"><br /></div><div style="position:relative;zoom:1">I also understand that. However, the question 8 of EPDP Team Phase 2A Initial Report is to seek <span style="font-family: Arial, sans-serif;">the question 8 of EPDP Team Question for Community Input is to seek the legal and regulatory considerations not yet considered in this Initial Report</span>. If China's Cybersecurity is not qualified to be mentioned as a legal consideration, what kind of law or regulation might be suitable to be mentioned for this question? UN's resolution? Or, Only legal consideration from EU? I hope get instruction about that.</div><div style="position:relative;zoom:1"><br /></div><div style="position:relative;zoom:1"> <span style="color: rgb(31, 73, 125); font-family: Calibri, sans-serif; font-size: 14.6667px;">It is not relevant, but you can make this comment to ICANN as an individual. Are you commenting on behalf of the Chinese government? Maybe you should work with your GAC representative.</span></div><div style="position:relative;zoom:1"><br /></div><div style="position:relative;zoom:1">No, I am not on behalf of the Chinese government. Right now, I am an independant researcher working in a pure research institute. I am not a staff of Chinese government.</div><div style="position:relative;zoom:1">I have made this commet in public comment forum as an individual a few days ago. </div><div style="position:relative;zoom:1">In my first email, I made it very clear that <b>I want to provide some information about China Network Security Law(中华人民共和国网络安全法), even though it may not be suitable to present it as a NCSG Comment.</b> I am not seeking to put my viewpoint into NCSG comment. The reason why I bought it up is that I hope to bring information to the NCSG community. I think communication between different culture background might help us have better understanding about each other, and those information might also help the community.</div><div style="position:relative;zoom:1"><br /></div><div style="position:relative;zoom:1">Best regards,</div><div style="position:relative;zoom:1"><br /></div><div style="position:relative;zoom:1">--<br /><div>Zhou Heng</div><div>Assistant Researcher </div><div>Hunan Academy of Social Science</div><div style="clear:both"></div></div><br />发件人:"Mueller, Milton L" <milton@GATECH.EDU><br />发送日期:2021-07-19 22:52:25<br />收件人:NCSG-DISCUSS@LISTSERV.SYR.EDU<br />主题:Re: Public Comment Call for Volunteers - Input on the Initial Report of the Phase 2A EPDP<br /><blockquote id="isReplyContent" style="PADDING-LEFT: 1ex; MARGIN: 0px 0px 0px 0.8ex; BORDER-LEFT: #ccc 1px solid">
<style></style>
<div class="WordSection1">
<div>
<div>
<div>
<p class="MsoNormal"><span style="font-size:10.5pt;font-family:"Arial",sans-serif;color:black"><o:p> </o:p></span></p>
</div>
<div>
<p class="MsoNormal"><span style="font-size:10.5pt;font-family:"Arial",sans-serif;color:#1F497D">></span><span style="font-size:10.5pt;font-family:"Arial",sans-serif;color:black">According to article 2 of China Domain Name Registration Regulation(</span><span style="font-size:10.5pt;font-family:"MS Gothic";color:black">互</span><span style="font-size:10.5pt;font-family:"Microsoft JhengHei",sans-serif;color:black">联网域名管理办法</span><span style="font-size:10.5pt;font-family:"Arial",sans-serif;color:black">),
</span><span style="font-size:10.5pt;font-family:"Arial",sans-serif;color:#1F497D"><o:p></o:p></span></p>
<p class="MsoNormal"><span style="font-size:11.0pt;font-family:"Calibri",sans-serif;color:#1F497D">></span><span style="font-size:10.5pt;font-family:"Arial",sans-serif;color:black">the domain name service is not only about the basic domain name registration
service provided </span><span style="font-size:10.5pt;font-family:"Arial",sans-serif;color:#1F497D"><o:p></o:p></span></p>
<p class="MsoNormal"><span style="font-size:11.0pt;font-family:"Calibri",sans-serif;color:#1F497D">>
</span><span style="font-size:10.5pt;font-family:"Arial",sans-serif;color:black">by registar, but also contains the operation of root server and TLD.</span><span style="font-size:10.5pt;font-family:"Arial",sans-serif;color:#1F497D"><o:p></o:p></span></p>
<p class="MsoNormal"><span style="font-size:11.0pt;font-family:"Calibri",sans-serif;color:#1F497D"><o:p> </o:p></span></p>
<p class="MsoNormal"><span style="font-size:11.0pt;font-family:"Calibri",sans-serif;color:#1F497D">China’s national law has no authority over the root server – indeed, it is destructive and impossible for any national government to try to impose its national
law on this globally shared resource. China’s law also has no authority over TLD operators who do not serve Chinese customers. China’s “real name” law can ONLY apply to registrars serving Chinese customers, because that is where individuals with “real names”
intersect with the domain name system. <o:p></o:p></span></p>
<p class="MsoNormal"><span style="font-size:11.0pt;font-family:"Calibri",sans-serif;color:#1F497D"><o:p> </o:p></span></p>
<p class="MsoNormal"><span style="font-size:11.0pt;font-family:"Calibri",sans-serif;color:#1F497D">You may not understand what you are talking about here – how would a TLD operator provide a “real name” when it is a company, not a person, and when its records
contain tens of thousands or millions of names of registrants? Are you saying that Chinese law requires every TLD operator and registrar in the world to turn over personally identifiable information of all their customers to the Chinese government? I think
no one in this stakeholder group, or any other, would support this, and none of the world’s governments would accept it, either.
<o:p></o:p></span></p>
<p class="MsoNormal"><span style="font-size:11.0pt;font-family:"Calibri",sans-serif;color:#1F497D"><o:p> </o:p></span></p>
</div>
<div>
<p class="MsoNormal"><span style="font-size:10.5pt;font-family:"Arial",sans-serif;color:black">I certainly understand ICANN is</span><span style="font-size:11.0pt;font-family:"Arial",sans-serif;color:black"> a global governance regime not a national one. However,
if I am not having misunderstood about EPDP, the whole issue is raised because of GDPR. </span><span style="font-size:11.0pt;font-family:"Arial",sans-serif;color:#1F497D"><o:p></o:p></span></p>
<p class="MsoNormal"><span style="font-size:11.0pt;font-family:"Calibri",sans-serif;color:#1F497D"><o:p> </o:p></span></p>
<p class="MsoNormal"><span style="font-size:11.0pt;font-family:"Calibri",sans-serif;color:#1F497D">These are ICANN policies, not European ones.<o:p></o:p></span></p>
<p class="MsoNormal"><span style="font-size:11.0pt;font-family:"Calibri",sans-serif;color:#1F497D"><o:p> </o:p></span></p>
<p class="MsoNormal"><span style="font-size:11.0pt;font-family:"Arial",sans-serif;color:black">I don't think EU GDPR is superior than </span><span style="font-size:10.5pt;font-family:"Arial",sans-serif;color:black">China Cybersecurity Law or any other country's
national law</span><span style="font-size:10.5pt;font-family:"Arial",sans-serif;color:#1F497D"><o:p></o:p></span></p>
<p class="MsoNormal"><span style="font-size:11.0pt;font-family:"Calibri",sans-serif;color:#1F497D"><o:p> </o:p></span></p>
<p class="MsoNormal"><span style="font-size:11.0pt;font-family:"Calibri",sans-serif;color:#1F497D">EU law does not override Chinese law, but Chinese law cannot bind what the rest of the world does, either. I Hope that’s clear.<o:p></o:p></span></p>
<p class="MsoNormal"><span style="font-size:11.0pt;font-family:"Calibri",sans-serif;color:#1F497D"><o:p> </o:p></span></p>
</div>
<div>
<p class="MsoNormal"><span style="font-size:10.5pt;font-family:"Arial",sans-serif;color:black">Since the question 8 of EPDP Team Question for Community Input is to seek the legal and regulatory considerations not yet considered in this Initial Report, I certainly
believe to mention about China Cybersecurity Law as a legal considerations is not a misunderstanding.<o:p></o:p></span></p>
</div>
<div>
<p class="MsoNormal"><span style="font-size:10.5pt;font-family:"Arial",sans-serif;color:#1F497D"><o:p> </o:p></span></p>
<p class="MsoNormal"><span style="font-size:11.0pt;font-family:"Calibri",sans-serif;color:#1F497D">It is not relevant, but you can make this comment to ICANN as an individual. Are you commenting on behalf of the Chinese government? Maybe you should work with
your GAC representative.<o:p></o:p></span></p>
<p class="MsoNormal"><span style="font-size:11.0pt;font-family:"Calibri",sans-serif;color:#1F497D"><o:p> </o:p></span></p>
</div>
</div>
</div>
</div>
</blockquote></div><br>