<html>
<head>
<meta http-equiv="Content-Type" content="text/html; charset=iso-8859-1">
<style type="text/css" style="display:none;"> P {margin-top:0;margin-bottom:0;} </style>
</head>
<body dir="ltr">
<div style="font-family: Calibri, Arial, Helvetica, sans-serif; font-size: 12pt; color: rgb(0, 0, 0);">
Thanks, Farzaneh</div>
<div style="font-family: Calibri, Arial, Helvetica, sans-serif; font-size: 12pt; color: rgb(0, 0, 0);">
A bit surprised that yours is the only comment but perhaps it's the holidays and the rest of the SG will wake up.
<br>
</div>
<div style="font-family: Calibri, Arial, Helvetica, sans-serif; font-size: 12pt; color: rgb(0, 0, 0);">
<br>
</div>
<div style="font-family: Calibri, Arial, Helvetica, sans-serif; font-size: 12pt; color: rgb(0, 0, 0);">
Regarding your first comment, we cannot have a precise estimate of the cost because cost depends on usage and usage depends on how costly it is to use and what the alternatives are, which we won't know for sure until it is implemented.</div>
<div style="font-family: Calibri, Arial, Helvetica, sans-serif; font-size: 12pt; color: rgb(0, 0, 0);">
<br>
</div>
<div style="font-family: Calibri, Arial, Helvetica, sans-serif; font-size: 12pt; color: rgb(0, 0, 0);">
The risk of re-litigating issues is real, but I think ICANN and various SGs have made it clear that the final disclosure decision has to be made by the contracted parties. So you are right, the SSAD is basically a triage of requests + accreditation.
<br>
</div>
<div style="font-family: Calibri, Arial, Helvetica, sans-serif; font-size: 12pt; color: rgb(0, 0, 0);">
<br>
</div>
<div style="font-family: Calibri, Arial, Helvetica, sans-serif; font-size: 12pt; color: rgb(0, 0, 0);">
I agree with you that the whole issue of accrediting governments (and major users such as brand protection and so-called cybersecurity researchers) is concerning and problematic. That is why I would like to find a way to dump accreditation altogether and slim
 down the SSAD into nothing more than a centralized request system. I am afraid that accreditation will confer some kind of de facto expectation or right to disclosure, and to mass, automated requests. Especially for governments.
<br>
</div>
<div style="font-family: Calibri, Arial, Helvetica, sans-serif; font-size: 12pt; color: rgb(0, 0, 0);">
<br>
</div>
<div style="font-family: Calibri, Arial, Helvetica, sans-serif; font-size: 12pt; color: rgb(0, 0, 0);">
I know that some privacy advocates believe that accreditation is going to be protective rather than enabling. I think this is an incorrect view and needs to be more realistic about what will happen if ICANN creates a globalized accreditation and access system.<br>
</div>
<div>
<div id="appendonsend"></div>
<div style="font-family:Calibri,Arial,Helvetica,sans-serif; font-size:12pt; color:rgb(0,0,0)">
<br>
</div>
<div style="font-family:Calibri,Arial,Helvetica,sans-serif; font-size:12pt; color:rgb(0,0,0)">
If we (you, me, NCSG) can agree on that, we can then discuss what next steps would help us get to that goal (the goal being a slimmed down SSAD basically a centralized intake system for requests).
<br>
</div>
<div style="font-family:Calibri,Arial,Helvetica,sans-serif; font-size:12pt; color:rgb(0,0,0)">
<br>
</div>
<div style="font-family:Calibri,Arial,Helvetica,sans-serif; font-size:12pt; color:rgb(0,0,0)">
--MM<br>
</div>
<hr tabindex="-1" style="display:inline-block; width:98%">
<div id="divRplyFwdMsg" dir="ltr"><font style="font-size:11pt" face="Calibri, sans-serif" color="#000000"><b>From:</b> farzaneh badii <farzaneh.badii@gmail.com><br>
<b>Sent:</b> Tuesday, January 4, 2022 4:49 PM<br>
<b>To:</b> Mueller, Milton L <milton@gatech.edu><br>
<b>Cc:</b> NCSG List <NCSG-DISCUSS@listserv.syr.edu><br>
<b>Subject:</b> Re: Whois/privacy and the SSAD</font>
<div> </div>
</div>
<div>
<div dir="ltr">
<div class="x_gmail_default" style="font-family:arial,sans-serif">Hi Milton,</div>
<div class="x_gmail_default" style="font-family:arial,sans-serif"><br>
</div>
<div class="x_gmail_default" style="font-family:arial,sans-serif">
<div class="x_gmail_default">I looked at the cost report of this and they really don't have enough information and data to actually estimate the cost. Obviously the Intellectual property crowd claims they submit "many" requests but others say otherwise.  I
 am more inclined to see if they can pilot an implementation and see what sort of problems they face (as laid out in the note you sent). Opening another EPDP or getting back to council and EPDP is going to risk re-litigating issues for sure. If we have to take
 one of those paths, I go with number 1 (reluctantly, because I don't know how the Board is going to articulate the reasons)</div>
<div class="x_gmail_default"></div>
</div>
<div class="x_gmail_default" style="font-family:arial,sans-serif"><br>
</div>
<div class="x_gmail_default" style="font-family:arial,sans-serif">Isn't this system just a "triage" of request and an accreditation model? That the final decision is by the registries and registrars? I hear a lot of people thinking this is "disclosure" mechanism,
 which adds to the complexity. </div>
<div class="x_gmail_default" style="font-family:arial,sans-serif"><br>
</div>
<div class="x_gmail_default" style="font-family:arial,sans-serif">There are many unknown issues about the implementation of SSAD. Even the governments don't want to accredit their own law enforcement themselves (as mentioned in a letter from the GAC chair,
 they just want to verify identity). <a href="https://gnso.icann.org/sites/default/files/file/field-file-attach/ismail-to-fouquart-15dec21-en.pdf">https://gnso.icann.org/sites/default/files/file/field-file-attach/ismail-to-fouquart-15dec21-en.pdf</a></div>
<div class="x_gmail_default" style="font-family:arial,sans-serif"><br>
</div>
<div class="x_gmail_default" style="font-family:arial,sans-serif">And anyhow that recommendation that governments each get to accredit their own law enforcement is unfortunately a terrible idea. And what will happen to sanctioned countries that are usually
 authoritarian and have law enforcement to suppress opposition? will they get access to personal information of people while people suffer from sanctions? Or perhaps the contracted parties deny them access. (I raised the issue at an NCSG meeting last year,implicitly,
 but I guess the ship has sailed)</div>
<div class="x_gmail_default" style="font-family:arial,sans-serif"><br>
</div>
<div class="x_gmail_default" style="font-family:arial,sans-serif"><br>
</div>
<div class="x_gmail_default" style="font-family:arial,sans-serif">Best regards, </div>
<div class="x_gmail_default" style="font-family:arial,sans-serif"><br>
</div>
<div class="x_gmail_default" style="font-family:arial,sans-serif"><br>
</div>
<div>
<div dir="ltr" class="x_gmail_signature">
<div dir="ltr">
<div><font face="verdana, sans-serif">Farzaneh </font></div>
</div>
</div>
</div>
<br>
</div>
<br>
<div class="x_gmail_quote">
<div dir="ltr" class="x_gmail_attr">On Tue, Jan 4, 2022 at 3:04 PM Mueller, Milton L <<a href="mailto:milton@gatech.edu">milton@gatech.edu</a>> wrote:<br>
</div>
<blockquote class="x_gmail_quote" style="margin:0px 0px 0px 0.8ex; border-left:1px solid rgb(204,204,204); padding-left:1ex">
<div dir="ltr">
<div style="font-family:Calibri,Arial,Helvetica,sans-serif; font-size:12pt; color:rgb(0,0,0)">
Greetings all and happy new year. <br>
</div>
<div style="font-family:Calibri,Arial,Helvetica,sans-serif; font-size:12pt; color:rgb(0,0,0)">
As one of your representatives on the EPDP dealing with Whois and privacy, I want to inform you of the latest development.
<br>
</div>
<div style="font-family:Calibri,Arial,Helvetica,sans-serif; font-size:12pt; color:rgb(0,0,0)">
<br>
</div>
<div style="font-family:Calibri,Arial,Helvetica,sans-serif; font-size:12pt; color:rgb(0,0,0)">
You will remember that a lot of sensitive domain name registration data is now redacted (hidden), because ICANN had to come into compliance with GDPR. The SSAD (Standardized System of Access and Disclosure) was an elaborate mechanism developed by the EPDP to
 allow people who want to see the hidden data to request its disclosure. The proposed SSAD had an elaborate mechanism for accrediting users of the system, including a process for each national government to accredit its own law enforcement and government agencies.
<br>
</div>
<div style="font-family:Calibri,Arial,Helvetica,sans-serif; font-size:12pt; color:rgb(0,0,0)">
<br>
</div>
<div style="font-family:Calibri,Arial,Helvetica,sans-serif; font-size:12pt; color:rgb(0,0,0)">
ICANN Org has done a study of the costs of the proposed SSAD and estimates that it will be very expensive and will take a long time to implement. The ICANN board has indicated that it may not approve the SSAD recommendation because of these problems.
<br>
</div>
<div style="font-family:Calibri,Arial,Helvetica,sans-serif; font-size:12pt; color:rgb(0,0,0)">
<br>
</div>
<div style="font-family:Calibri,Arial,Helvetica,sans-serif; font-size:12pt; color:rgb(0,0,0)">
So now we are faced with a question about what to do next. <br>
</div>
<div style="font-family:Calibri,Arial,Helvetica,sans-serif; font-size:12pt; color:rgb(0,0,0)">
<br>
</div>
<div style="font-family:Calibri,Arial,Helvetica,sans-serif; font-size:12pt; color:rgb(0,0,0)">
There are basically two options being presented to us:</div>
<div style="font-family:Calibri,Arial,Helvetica,sans-serif; font-size:12pt; color:rgb(0,0,0)">
<ol>
<li><span>Let the <span>ICANN Board formally refuse to adopt the recommendation, tell us what's wrong with it, and then let the Council and the EPDP adopt a supplemental recommendation that fixes the problems</span></span></li><li><span><span>Re-convene the EPDP and work out its own modification of the recommendation.
<br>
</span></span></li></ol>
</div>
<div style="font-family:Calibri,Arial,Helvetica,sans-serif; font-size:12pt; color:rgb(0,0,0)">
I've attached a more detailed analysis of the options that the ICANN staff circulated today. I have my own opinion about this - I think the SSAD does need to be simplified and agree with the staff's concerns about its complexity and cost. But I am not sure
 what is the best way procedurally to fix this problem. Hope we can discuss this as a SG and reach a unified position.
<br>
</div>
<div style="font-family:Calibri,Arial,Helvetica,sans-serif; font-size:12pt; color:rgb(0,0,0)">
<br>
</div>
<div style="font-family:Calibri,Arial,Helvetica,sans-serif; font-size:12pt; color:rgb(0,0,0)">
Cheers,<br>
</div>
<div>
<div style="font-family:Calibri,Arial,Helvetica,sans-serif; font-size:12pt; color:rgb(0,0,0)">
<br>
</div>
<div id="x_gmail-m_6482575050224301035Signature">
<div>
<div id="x_gmail-m_6482575050224301035divtagdefaultwrapper" dir="ltr" style="font-size:12pt; color:rgb(0,0,0); font-family:Calibri,Helvetica,sans-serif">
<p style="margin-top:0px; margin-bottom:0px">Dr Milton L Mueller, Professor</p>
<p style="margin-top:0px; margin-bottom:0px">School of Public Policy</p>
<p style="margin-top:0px; margin-bottom:0px">Georgia Institute of Technology</p>
<p style="margin-top:0px; margin-bottom:0px"><a href="https://internetgovernance.org" target="_blank">Internet Governance Project</a> </p>
<p style="margin-top:0px; margin-bottom:0px"><br>
</p>
</div>
</div>
</div>
</div>
</div>
</blockquote>
</div>
</div>
</div>
</body>
</html>