<div dir="auto">Thanks for Stephanie, for the Insight.</div><br><div class="gmail_quote"><div dir="ltr" class="gmail_attr">On Mon, 26 Feb 2024, 4:47 pm Stephanie E Perrin, <<a href="mailto:stephanie@digitaldiscretion.ca">stephanie@digitaldiscretion.ca</a>> wrote:<br></div><blockquote class="gmail_quote" style="margin:0 0 0 .8ex;border-left:1px #ccc solid;padding-left:1ex"><u></u>
<div>
<p>I am very sorry to have missed the discussion today. Thanks very
much for your informative summary Ken. I will listen to the
recording of the session today when it arrives, and chime in on
the list. I have been sitting on the RDRS group for some time.</p>
<p>I hope that the issue of ICANN's controllership came up, and the
cost issues. ICANN has been reluctant to take on the
responsibility of controllership for personal information of
registrants, so the registrars and registries are the data
controllers....which means they get to decide whether and when to
release personal data, absent a court order. Persons whose
information is being processed (and released) do indeed have a
right to know on what basis that data is being released, and to
whom. To me this is the crux of the matter, the extent to which
ICANN wanted to assume more of a controller role and set policy on
how much data has to be released, what prices could be charged,
when the individual would be told of the release etc. Arguably
all the years that it ignored data protection law it was assuming
a controller role, because it insisted that the data be released,
and any registrar (who clearly are controllers and collect a lot
more data which is more useful, notably financial data) who wished
to comply with local data protection law had to make a case for
doing so and appeal to ICANN's legal department for permission. <br>
</p>
<p>We argued that requestors do not have a right to get personal
information of individuals. I expect we will continue to have to
argue that as and when ICANN moves forward with the scoping team
on accuracy of data. The GNSO Council just voted to kick that can
down the road for a few more months, but the demand for more
accurate data persists. Statistics from the current exercise will
be useful when that exercise gets going.</p>
<p>Kind regards <br>
</p>
<p>Stephanie Perrin<br>
</p>
<div>On 2024-02-23 12:51 p.m., Ken Herman
wrote:<br>
</div>
<blockquote type="cite">
<div>
<p class="MsoNormal"><span style="font-size:11.0pt">Thanks,
Farzaneh, for the clarifications. Always a learning
experience for me. It’s likely I didn’t quite capture all
the nuances, and it’s also possible that these points
weren’t addressed.<u></u><u></u></span></p>
<p class="MsoNormal"><span style="font-size:11.0pt"><u></u> <u></u></span></p>
<p class="MsoNormal"><span style="font-size:11.0pt">Regarding
the processes used by registrars, that sounds to me like the
crux of the issue. Regardless of the system, it is left to
the registrars to validate the requestors and it doesn’t
appear that there are any standards or really anything that
will help registrants know if their registrar is likely to
reveal their private, sensitive personal information.<u></u><u></u></span></p>
<p class="MsoNormal"><span style="font-size:11.0pt"><u></u> <u></u></span></p>
<p class="MsoNormal"><span style="font-size:11.0pt">It would be
terrific if you can participate on Monday as I’m sure other
comments like yours will surface. <u></u><u></u></span></p>
<p class="MsoNormal"><span style="font-size:11.0pt"><u></u> <u></u></span></p>
<p class="MsoNormal"><span style="font-size:11.0pt">And, well,
maybe “ignore” wasn’t one of the options used, but it sure
seemed that way to me, as in “maybe we won’t get to this”
And maybe the registrars aren’t “obliged” to respond, but
statistics on responses are being kept. Probably I could
have phrased that better.<u></u><u></u></span></p>
<p class="MsoNormal"><span style="font-size:11.0pt"><u></u> <u></u></span></p>
<p class="MsoNormal"><span style="font-size:11.0pt">Ken<u></u><u></u></span></p>
<p class="MsoNormal"><span style="font-size:11.0pt"><u></u> <u></u></span></p>
<div style="border:none;border-top:solid #e1e1e1 1.0pt;padding:3.0pt 0in 0in 0in">
<p class="MsoNormal"><b><span style="font-size:11.0pt;font-family:"Calibri",sans-serif">From:</span></b><span style="font-size:11.0pt;font-family:"Calibri",sans-serif">
farzaneh badii <a href="mailto:farzaneh.badii@gmail.com" target="_blank" rel="noreferrer"><farzaneh.badii@gmail.com></a> <br>
<b>Sent:</b> Friday, February 23, 2024 12:12 PM<br>
<b>To:</b> Ken Herman <a href="mailto:ken@kherman.com" target="_blank" rel="noreferrer"><ken@kherman.com></a><br>
<b>Cc:</b> NCSG-Discuss
<a href="mailto:NCSG-DISCUSS@listserv.syr.edu" target="_blank" rel="noreferrer"><NCSG-DISCUSS@listserv.syr.edu></a>;
<a href="mailto:ncuc-discuss@lists.ncuc.org" target="_blank" rel="noreferrer">ncuc-discuss@lists.ncuc.org</a><br>
<b>Subject:</b> Re: [NCUC-DISCUSS] RDRS Special Event
Summary<u></u><u></u></span></p>
</div>
<p class="MsoNormal"><u></u> <u></u></p>
<div>
<div>
<div>
<p class="MsoNormal"><span style="font-family:"Arial",sans-serif">Ken<u></u><u></u></span></p>
</div>
<div>
<p class="MsoNormal"><span style="font-family:"Arial",sans-serif">Just
a quick reaction to this: <u></u><u></u></span></p>
</div>
<ul style="margin-top:0in" type="disc">
<li style="margin-top:0in;margin-bottom:0in"><span style="font-family:"Times New Roman",serif" lang="EN-GB">Registration data, knowing who owns what
domain name and how that owner can be contacted, is a
central component of the Internet.</span><span style="font-family:"Times New Roman",serif"><u></u><u></u></span></li>
</ul>
<div>
<p class="MsoNormal"><span><span style="font-family:"Arial",sans-serif">Registration
of data was never ever about "who owns" the domain
name. It was about contactibility of registrant. We
have been correcting ICANN board and others on this
issue since the beginning of these discussions. </span></span><u></u><u></u></p>
</div>
<div>
<ul style="margin-top:0in" type="disc">
<li style="margin-top:0in;margin-bottom:0in"><span style="font-family:"Times New Roman",serif" lang="EN-GB">Prior
to 2018, ownership data was easily available and
public. After the EU GDPR in 2018, Ownership data
became redacted.</span><span style="font-family:"Times New Roman",serif"><u></u><u></u></span></li>
</ul>
<div>
<p class="MsoNormal"><span><span style="font-family:"Arial",sans-serif">The
term ownership is interesting. Never ever
ownership was redacted. Domain name registrant is
not even necessarily the owner. Also are
registrars accepting that domain names are
property to be owned? Great. but domain name
registration data is not the ownership ledger. </span></span><u></u><u></u></p>
</div>
</div>
<div>
<p class="MsoNormal"><u></u> <u></u></p>
</div>
<div>
<ul style="margin-top:0in" type="disc">
<li style="margin-top:0in;margin-bottom:0in"><span style="font-family:"Times New Roman",serif" lang="EN-GB">As
privacy laws like the GDPR began to restrict access
to the information about owners and operators of
domain names, new systems, like the RDRS, were
developed to manage the process of revealing private
information to those with a need to know it.</span><span style="font-family:"Times New Roman",serif"><u></u><u></u></span></li>
</ul>
<div>
<p class="MsoNormal"><span><span style="font-family:"Arial",sans-serif">it
was never about access to information. It was
access to private, sensitive personal information
of people. Also the system was developed to give
access to people who actually have a legitimate
interest not people with a need to know it!!</span></span><u></u><u></u></p>
</div>
</div>
<div>
<p class="MsoNormal"><u></u> <u></u></p>
</div>
<div>
<ul style="margin-top:0in" type="disc">
<li style="margin-top:0in;margin-bottom:0in"><b><span style="font-family:"Times New Roman",serif" lang="EN-GB">Each
registrar has its own process for validating
requestors, with no input or guidance from ICANN.</span></b><span style="font-family:"Times New Roman",serif"><u></u><u></u></span></li>
</ul>
<div>
<p class="MsoNormal"><span><span style="font-family:"Arial",sans-serif">Can
we at least know what those processes are? </span></span><u></u><u></u></p>
</div>
</div>
<div>
<p class="MsoNormal"><u></u> <u></u></p>
</div>
<div>
<p class="MsoNormal"><span><span style="font-family:"Arial",sans-serif">How
are registrars obliged to respond but can ignore the
request? Do they tell the requestor: hey we are
ignoring you? </span></span><u></u><u></u></p>
</div>
<div>
<p class="MsoNormal"><u></u> <u></u></p>
</div>
<div>
<p class="MsoNormal"><u></u> <u></u></p>
</div>
<div>
<p class="MsoNormal"><u></u> <u></u></p>
</div>
<div>
<p class="MsoNormal"><u></u> <u></u></p>
</div>
<div>
<p class="MsoNormal"><u></u> <u></u></p>
</div>
<div>
<p class="MsoNormal"><span style="font-family:"Arial",sans-serif"><u></u> <u></u></span></p>
</div>
<div>
<div>
<div>
<div>
<p class="MsoNormal"><span style="font-family:"Verdana",sans-serif">Farzaneh </span><u></u><u></u></p>
</div>
</div>
</div>
</div>
<p class="MsoNormal"><u></u> <u></u></p>
</div>
<p class="MsoNormal"><u></u> <u></u></p>
<div>
<div>
<p class="MsoNormal">On Fri, Feb 23, 2024 at 12:01<span style="font-family:"Arial",sans-serif"> </span>PM
Ken Herman <<a href="mailto:ken@kherman.com" target="_blank" rel="noreferrer">ken@kherman.com</a>>
wrote:<u></u><u></u></p>
</div>
<blockquote style="border:none;border-left:solid #cccccc 1.0pt;padding:0in 0in 0in 6.0pt;margin-left:4.8pt;margin-right:0in">
<div>
<div>
<div>
<p class="MsoNormal"><span lang="EN-GB">Hello NCSG and NCUC members. </span><u></u><u></u></p>
<p class="MsoNormal"><span lang="EN-GB"> </span><u></u><u></u></p>
<p class="MsoNormal"><span lang="EN-GB">Thanks to everyone who was able to
attend this week’s briefing on ICANN’s Remote
Data Request System (RDRS). </span><u></u><u></u></p>
<p class="MsoNormal"><span lang="EN-GB"> </span><u></u><u></u></p>
<p class="MsoNormal"><span lang="EN-GB">After an introduction by Wisdom,
Kathy provided background and was followed by a
presentation by Ms. Diana Middleton of ICANN.
The session then invited Ms. Sarah Wyld and Ms.
Reg Levy, both from the registrar Tucows, to
offer their perspective. </span><u></u><u></u></p>
<p class="MsoNormal"><span lang="EN-GB"> </span><u></u><u></u></p>
<p class="MsoNormal"><span lang="EN-GB">The purpose of the session was to
gather facts and provide an opportunity for
members of the non-commercial community to learn
about the RDRS, both from the perspective of
ICANN and the point of view of a registrar.</span><u></u><u></u></p>
<p class="MsoNormal"><span lang="EN-GB"> </span><u></u><u></u></p>
<p class="MsoNormal"><span lang="EN-GB">The presenters shared a lot of
information about the RDRS and the processes. I
attached the slides from the ICANN presentation
as well as the latest ICANN RDRS statistics
report.</span><u></u><u></u></p>
<p class="MsoNormal"><span lang="EN-GB"> </span><u></u><u></u></p>
<p class="MsoNormal"><span lang="EN-GB">I have put here some (not all!) of
the points presented, and I encourage anyone who
attended (or reviewed the transcript) to add
anything important that would be useful to
share.</span><u></u><u></u></p>
<ul type="disc">
<li><span lang="EN-GB">Registration data, knowing who
owns what domain name and how that owner can
be contacted, is a central component of the
Internet.</span><u></u><u></u></li>
<li><span lang="EN-GB">Prior to 2018, ownership data was
easily available and public. After the EU GDPR
in 2018, Ownership data became redacted. </span><u></u><u></u></li>
<li><span lang="EN-GB">As privacy laws like the GDPR
began to restrict access to the information
about owners and operators of domain names,
new systems, like the RDRS, were developed to
manage the process of revealing private
information to those with a need to know it.</span><u></u><u></u></li>
<li><span lang="EN-GB">RDRS is a pilot, intended to run
for 2 years so the board can gather statistics
and experience before making any further
decisions about its future.</span><u></u><u></u></li>
<li><span lang="EN-GB">The RDRS was developed to
simplify the process used by interested
parties to request redacted data.</span><u></u><u></u></li>
<li><span lang="EN-GB">Demand for the system is unknown;
that is the reason for the pilot.</span><u></u><u></u></li>
<li><span lang="EN-GB">Originally, a System for
Standardized Access and Disclosure (SSAD) was
proposed, which included many features, but
deemed too complex so the RDRS was created
instead.</span><u></u><u></u></li>
<li><span lang="EN-GB">Parties interested in redacted
data must register on the system and identify
their role (law enforcement, government
agencies, intellectual property professionals,
cybersecurity researchers, et al.) </span><u></u><u></u></li>
<li><span lang="EN-GB">The system presents these
registered parties with a form to describe
their interest in a specific domain name.</span><u></u><u></u></li>
<li><span lang="EN-GB">Registrars, which are the
custodians of personal data) are invited by
ICANN to participate, but not all do.
Participating registrars also have access to
the system and can view and are obliged to act
upon requests.</span><u></u><u></u></li>
<li><span lang="EN-GB">Participating registrars review
the requests and decide what to do with them,
to either comply, reject or ignore. For
requests that would go to non-participating
registrars, requestors have the option of
printing a pdf of the request to send to the
appropriate registrar.</span><u></u><u></u></li>
<li><span lang="EN-GB">Some registrars, like Tucows,
already had a system to respond to requests
for redacted data. </span><u></u><u></u></li>
<li><b><span lang="EN-GB">Each participating registrar
decides how to handle requests. This
includes validating the requestor’s
credentials and determining whether or not
to comply with the request, taking into
account their understanding of the request
and compliance with local laws. </span></b><u></u><u></u></li>
<li><b><span lang="EN-GB">Each registrar has its own
process for validating requestors, with no
input or guidance from ICANN.</span></b><u></u><u></u></li>
<li><b><span lang="EN-GB">ICANN’s role is to accept the
requests and tabulate the responses by
registrars.</span></b><u></u><u></u></li>
<li><b><span lang="EN-GB">ICANN knows the details the
requestor placed on the form.</span></b><u></u><u></u></li>
</ul>
<p><span lang="EN-GB"> </span><u></u><u></u></p>
<p class="MsoNormal"><span lang="EN-GB">ICANN publishes a monthly report
with RDRS statistics. The second report covers
from the period from inception to January 31,
and is attached, but it can also be found at: <a href="https://www.icann.org/en/system/files/files/rdrs-usage-metrics-16feb24-en.pdf" target="_blank" rel="noreferrer">https://www.icann.org/en/system/files/files/rdrs-usage-metrics-16feb24-en.pdf</a>.</span><u></u><u></u></p>
<p class="MsoNormal"><span lang="EN-GB"> </span><u></u><u></u></p>
<p class="MsoNormal"><span lang="EN-GB">Some interesting statistics:</span><u></u><u></u></p>
<ul type="disc">
<li><span lang="EN-GB">510 requests submitted to
participating registrars.</span><u></u><u></u></li>
<li><span lang="EN-GB">274 requests submitted
(estimated) to non-participating registrars.</span><u></u><u></u></li>
<li><span lang="EN-GB">35.5% of requests received from
requestors self-identified as IP holders.</span><u></u><u></u></li>
<li><span lang="EN-GB">11% of requests received from
requestors self-identified as law enforcement.</span><u></u><u></u></li>
<li><span lang="EN-GB">72% of requests received were
denied.</span><u></u><u></u></li>
<li><span lang="EN-GB">29% of denied requests were
denied due to “Contracted party cannot
disclose the data due to applicable law” (the
most of all reasons).</span><u></u><u></u></li>
</ul>
<p class="MsoNormal"><span lang="EN-GB"> </span><u></u><u></u></p>
<p class="MsoNormal"><b><span lang="EN-GB">All members are invited to join a
follow-up session scheduled for Monday,
February 26 at 15:00 UTC. </span></b><span lang="EN-GB">This is intended to be an informal
opportunity for community members to discuss the
information provided and to identify any further
questions to follow-up with ICANN for
information that might be useful.</span><u></u><u></u></p>
<p class="MsoNormal"><span lang="EN-GB"> </span><u></u><u></u></p>
<p class="MsoNormal"><span lang="EN-GB">Thanks again to all who
participated with special thanks to our
speakers, Diana Middleton from ICANN and Sarah
Wyld and Reg Levy from Tucows, as well as our
own Kathy Kleiman, who provided the necessary
background and Wisdom who ably acted as Master
of Ceremony for the event. Also, we are grateful
to Andrea or arranging the Zoom link and keeping
track of questions in the chat. She posted the
link to the recording for those interested but
could not attend.</span><u></u><u></u></p>
<p class="MsoNormal"><span lang="EN-GB"> </span><u></u><u></u></p>
<p class="MsoNormal"><span lang="EN-GB">Ken</span><u></u><u></u></p>
<p class="MsoNormal"><span style="font-size:11.0pt"> </span><u></u><u></u></p>
</div>
</div>
<p class="MsoNormal">_______________________________________________<br>
Ncuc-discuss mailing list<br>
<a href="mailto:Ncuc-discuss@lists.ncuc.org" target="_blank" rel="noreferrer">Ncuc-discuss@lists.ncuc.org</a><br>
<a href="https://lists.ncuc.org/cgi-bin/mailman/listinfo/ncuc-discuss" target="_blank" rel="noreferrer">https://lists.ncuc.org/cgi-bin/mailman/listinfo/ncuc-discuss</a><u></u><u></u></p>
</div>
</blockquote>
</div>
</div>
</div>
</blockquote>
</div>
</blockquote></div>