<div dir="ltr">Hey all, <div><br></div><div>We are currently discussing the SSAD Governmental Accreditation process/model at the policy committee meeting and - considering the current discussions taking place here on the thread and among our councilors and EPDP member - i wanted to suggest for us to start drafting a call raising some of our concerns about the process and so on. <br><br>Would it be ok for all of you? I understand when Stephanie raises questions pertaining to the relevance of such central process, but Farzaneh and others also have highly concerning points about (a) costs and (b) dynamics with law enforcement authorities in more problematic governments and regimes. <br><br>Last question is if anyone else would like to help me draft this statement and who do you think we should be directing this one too - just the board ? Board and Org ? <br><br>Best, </div><div>Bruna </div></div><br><div class="gmail_quote"><div dir="ltr" class="gmail_attr">On Tue, Jan 11, 2022 at 9:43 PM Tomslin Samme-Nlar <<a href="mailto:mesumbeslin@gmail.com">mesumbeslin@gmail.com</a>> wrote:<br></div><blockquote class="gmail_quote" style="margin:0px 0px 0px 0.8ex;border-left:1px solid rgb(204,204,204);padding-left:1ex"><div dir="ltr"><div><br></div><div>Thanks for sharing Milton.</div><div><br></div><div>Procedurally, personally I think there are too many unknowns to risk starting working on a supplemental recommendation before a board decision and report to the GNSO council. We need at least the Operational Design Assessment (ODA) expected to be published in February for us to get a bit more details.</div><div><br></div><div>On the substance, my understanding is that there are two aspects to the system. Validating the requestors (accreditation) and validating the requests for correctness (triage). You say you're "afraid that accreditation will confer some kind of de facto expectation or right to disclosure, and to mass, automated requests". As I understand it, the current policy doesn't confer this expectation. Is your fear therefore that if the EPDP group is consulted for either a supplemental recommendation or modification of the recommendation, text might be added which confers such expectations? <br></div><div>Usually, validation of the requestor is done before or as part of the triage process of a request. How do you envision the whole process working practically without the validation of the requestors bit?<br></div><div><div><div dir="ltr"><div dir="ltr"><div><div dir="ltr"><div><div dir="ltr"><div dir="ltr"><div dir="ltr"><div dir="ltr"><div dir="ltr"><div dir="ltr"><div><br></div>Tomslin<div><span style="color:rgb(0,0,0);font-size:12.8px">@Twitter: <a href="https://twitter.com/tomsleen" target="_blank">https://twitter.com/tomsleen</a></span></div><div><span style="color:rgb(0,0,0);font-size:12.8px">@LinkedIn: <a href="https://www.linkedin.com/in/tomslin/" target="_blank">https://www.linkedin.com/in/tomslin/</a><br></span></div></div></div></div></div></div></div></div></div></div></div></div></div><br></div></div><br><div class="gmail_quote"><div dir="ltr" class="gmail_attr">On Wed, 5 Jan 2022 at 07:04, Mueller, Milton L <<a href="mailto:milton@gatech.edu" target="_blank">milton@gatech.edu</a>> wrote:<br></div><blockquote class="gmail_quote" style="margin:0px 0px 0px 0.8ex;border-left:1px solid rgb(204,204,204);padding-left:1ex">
<div dir="ltr">
<div style="font-family:Calibri,Arial,Helvetica,sans-serif;font-size:12pt;color:rgb(0,0,0)">
Greetings all and happy new year. <br>
</div>
<div style="font-family:Calibri,Arial,Helvetica,sans-serif;font-size:12pt;color:rgb(0,0,0)">
As one of your representatives on the EPDP dealing with Whois and privacy, I want to inform you of the latest development.
<br>
</div>
<div style="font-family:Calibri,Arial,Helvetica,sans-serif;font-size:12pt;color:rgb(0,0,0)">
<br>
</div>
<div style="font-family:Calibri,Arial,Helvetica,sans-serif;font-size:12pt;color:rgb(0,0,0)">
You will remember that a lot of sensitive domain name registration data is now redacted (hidden), because ICANN had to come into compliance with GDPR. The SSAD (Standardized System of Access and Disclosure) was an elaborate mechanism developed by the EPDP to
allow people who want to see the hidden data to request its disclosure. The proposed SSAD had an elaborate mechanism for accrediting users of the system, including a process for each national government to accredit its own law enforcement and government agencies.
<br>
</div>
<div style="font-family:Calibri,Arial,Helvetica,sans-serif;font-size:12pt;color:rgb(0,0,0)">
<br>
</div>
<div style="font-family:Calibri,Arial,Helvetica,sans-serif;font-size:12pt;color:rgb(0,0,0)">
ICANN Org has done a study of the costs of the proposed SSAD and estimates that it will be very expensive and will take a long time to implement. The ICANN board has indicated that it may not approve the SSAD recommendation because of these problems.
<br>
</div>
<div style="font-family:Calibri,Arial,Helvetica,sans-serif;font-size:12pt;color:rgb(0,0,0)">
<br>
</div>
<div style="font-family:Calibri,Arial,Helvetica,sans-serif;font-size:12pt;color:rgb(0,0,0)">
So now we are faced with a question about what to do next. <br>
</div>
<div style="font-family:Calibri,Arial,Helvetica,sans-serif;font-size:12pt;color:rgb(0,0,0)">
<br>
</div>
<div style="font-family:Calibri,Arial,Helvetica,sans-serif;font-size:12pt;color:rgb(0,0,0)">
There are basically two options being presented to us:</div>
<div style="font-family:Calibri,Arial,Helvetica,sans-serif;font-size:12pt;color:rgb(0,0,0)">
<ol>
<li><span>Let the <span>ICANN Board formally refuse to adopt the recommendation, tell us what's wrong with it, and then let the Council and the EPDP adopt a supplemental recommendation that fixes the problems</span></span></li><li><span><span>Re-convene the EPDP and work out its own modification of the recommendation.
<br>
</span></span></li></ol>
</div>
<div style="font-family:Calibri,Arial,Helvetica,sans-serif;font-size:12pt;color:rgb(0,0,0)">
I've attached a more detailed analysis of the options that the ICANN staff circulated today. I have my own opinion about this - I think the SSAD does need to be simplified and agree with the staff's concerns about its complexity and cost. But I am not sure
what is the best way procedurally to fix this problem. Hope we can discuss this as a SG and reach a unified position.
<br>
</div>
<div style="font-family:Calibri,Arial,Helvetica,sans-serif;font-size:12pt;color:rgb(0,0,0)">
<br>
</div>
<div style="font-family:Calibri,Arial,Helvetica,sans-serif;font-size:12pt;color:rgb(0,0,0)">
Cheers,<br>
</div>
<div>
<div style="font-family:Calibri,Arial,Helvetica,sans-serif;font-size:12pt;color:rgb(0,0,0)">
<br>
</div>
<div id="gmail-m_-1475966515312515256gmail-m_-216019719370834602Signature">
<div>
<div id="gmail-m_-1475966515312515256gmail-m_-216019719370834602divtagdefaultwrapper" dir="ltr" style="font-size:12pt;color:rgb(0,0,0);font-family:Calibri,Helvetica,sans-serif">
<p style="margin-top:0px;margin-bottom:0px">Dr Milton L Mueller, Professor</p>
<p style="margin-top:0px;margin-bottom:0px">School of Public Policy</p>
<p style="margin-top:0px;margin-bottom:0px">Georgia Institute of Technology</p>
<p style="margin-top:0px;margin-bottom:0px"><a href="https://internetgovernance.org" target="_blank">Internet Governance Project</a> </p>
<p style="margin-top:0px;margin-bottom:0px"><br>
</p>
</div>
</div>
</div>
</div>
</div>
</blockquote></div>
</blockquote></div><br clear="all"><div><br></div>-- <br><div dir="ltr" class="gmail_signature"><div dir="ltr"><div dir="ltr"><div dir="ltr"><div dir="ltr"><div dir="ltr"><div><b><i>Bruna Martins dos Santos <br></i></b><div dir="ltr" style="color:rgb(34,34,34)"><br></div><p style="color:rgb(34,34,34);margin:0cm 0cm 0.0001pt"><span style="font-family:arial,sans-serif"><font color="#000000"><span style="font-size:11px"></span></font></span></p><p style="margin:0cm 0cm 0.0001pt"><font size="2" style="color:rgb(34,34,34)"><span style="font-family:arial,sans-serif"><font color="#000000">German Chancellor Fellow 21' (</font></span></font><font color="#000000" face="arial, sans-serif">Bundeskanzler-Stipendiatin</font><span style="color:rgb(0,0,0);font-family:arial,sans-serif">) | <a href="https://www.humboldt-foundation.de/" target="_blank">Alexander von Humboldt Foundation</a></span></p><p style="margin:0cm 0cm 0.0001pt">Visiting Researcher (Gastwissenschaftlerin) | <a href="https://wzb.eu/en" target="_blank">Wissenschaftszentrum Berlin für Sozialforschung (WZB)</a><br></p><p style="color:rgb(34,34,34);margin:0cm 0cm 0.0001pt"><font size="2"><span style="font-family:arial,sans-serif"><font color="#000000">Member | <a href="https://direitosnarede.org.br/" target="_blank">Coalizão Direitos na Rede</a> <br>Chair</font></span></font><span style="color:rgb(0,0,0);font-family:arial,sans-serif"> | <a href="https://gnso.icann.org/en/about/stakeholders-constituencies/ncsg" target="_blank">Non-Commercial Stakeholder Group at ICANN</a><br></span><font size="2"><span style="font-family:arial,sans-serif"><font color="#000000">Co-Coordinator</font></span></font><span style="color:rgb(0,0,0);font-family:arial,sans-serif"> | <a href="https://igcaucus.org/" target="_blank">Internet Governance Caucus </a><br></span><font size="2"><span style="font-family:arial,sans-serif"><font color="#000000"><br></font></span></font></p><div style="color:rgb(34,34,34)"><span style="font-family:arial,sans-serif"><font size="1" color="#000000"><font size="2">Twitter: <a href="https://twitter.com/boomartins" target="_blank"><font color="#1155cc">@</font>boomartins</a> // </font></font></span><span style="color:rgb(32,33,36)">Skype: bruna.martinsantos</span></div></div><div><font color="#0000ee" size="1"><u><a href="mailto:bruna.martinsdossantos@wzb.eu" target="_blank">bruna.martinsdossantos@wzb.eu</a></u></font><font size="1"> and <a href="mailto:bruna.mrtns@gmail.com" target="_blank">bruna.mrtns@gmail.com</a></font></div></div></div></div></div></div></div>