<div dir="ltr"><div>Hi Farzi,</div><div><br></div><div>I think your idea of providing examples of what could be considered the "market standard" of how to treat this kind of data would be the best way to approach the RDRS SC. Just to drop a few others, Meta (<a href="https://transparency.fb.com/reports/government-data-requests/country/">https://transparency.fb.com/reports/government-data-requests/country/</a>), Google (<a href="https://transparencyreport.google.com/user-data/overview?hl=en">https://transparencyreport.google.com/user-data/overview?hl=en</a>) and TikTok (<a href="https://www.tiktok.com/transparency/en-us/government-removal-requests-2023-1/">https://www.tiktok.com/transparency/en-us/government-removal-requests-2023-1/</a>) have interesting reports that could deter most arguments against implementing it for security reasons.</div><div><br></div><div>One could also point out that this isn't interesting just for human rights and civil liberties, but also for other interest groups to identify potentially problematic regions (f. ex., a country where, for some reason, there is a spike of registrations being used for criminal activities commonly identified as such all around the world).<br></div><div><br></div><div>Cordially,<br></div><div><br clear="all"><div><div dir="ltr" class="gmail_signature" data-smartmail="gmail_signature"><div dir="ltr"><span style="font-family:garamond,times new roman,serif"><font size="1"><font size="2"><b>Pedro de Perdigão Lana</b><br></font></font></span><div><span style="font-family:garamond,times new roman,serif"><font size="1"><font size="2"><a href="https://www.sistemafiep.org.br/" target="_blank">Lawyer</a>, </font></font></span><span style="font-family:garamond,times new roman,serif"><font size="1"><font size="2"><span style="font-family:garamond,times new roman,serif"><font size="1"><font size="2"><span style="font-family:garamond,times new roman,serif"><font size="1"><font size="2"><a href="https://www.gedai.com.br/" target="_blank">GEDAI/UFPR</a> Researcher</font></font></span></font></font></span></font></font></span></div><div><span style="font-family:garamond,times new roman,serif"><font size="1"><font size="2">PhD Candidate (UFPR), LLM in Business Law (UCoimbra)</font></font></span><span style="font-family:garamond,times new roman,serif"><font size="1"><font size="2"><span style="font-family:garamond,times new roman,serif"><font size="1"><font size="2"> </font></font></span></font></font></span></div><div><span style="font-family:garamond,times new roman,serif"><font size="1"><font size="2"><span style="font-family:garamond,times new roman,serif"></span></font></font></span></div><div><span style="font-family:garamond,times new roman,serif"><font size="1"><font size="2">Board Member @ <a href="https://br.creativecommons.net/" target="_blank">CC Brasil</a>, </font></font></span><span style="font-family:garamond,times new roman,serif"><font size="1"><font size="2"><span style="font-family:garamond,times new roman,serif"><font size="1"><font size="2"><a href="https://isoc.org.br/" target="_blank">ISOC BR</a></font></font></span> and <a href="https://ioda.org.br/" target="_blank">IODA</a></font></font></span></div><div><span style="font-family:garamond,times new roman,serif"></span></div><div><font size="1"><span style="font-family:garamond,times new roman,serif">This message is restricted to the sender and recipient(s). If received by mistake, please reply informing it.</span></font></div></div></div></div><br></div></div><br><div class="gmail_quote"><div dir="ltr" class="gmail_attr">Em sex., 5 de abr. de 2024 às 18:00, farzaneh badii <<a href="mailto:farzaneh.badii@gmail.com">farzaneh.badii@gmail.com</a>> escreveu:<br></div><blockquote class="gmail_quote" style="margin:0px 0px 0px 0.8ex;border-left:1px solid rgb(204,204,204);padding-left:1ex"><div dir="ltr"><div class="gmail_default" style="font-family:arial,sans-serif">Dear NCSG, </div><div class="gmail_default" style="font-family:arial,sans-serif">As you know RDRS (the system whereby requestors of domain name registrants personal data submit their request to access the data-it's a triage system) is now in operation. (been for a few months) There is a Standing Committee on RDRS that meets biweekly which discusses the technical issues of the system. In the report that RDRS issues, we usually can see the number of requests on behalf of law enforcement agencies but it does not specify which jurisdictions. </div><div class="gmail_default" style="font-family:arial,sans-serif">It is common practice for different Internet organizations and tech-companies to report at least on the jurisdiction. For example, Apple has been publishing the LEA transparency reports, for example you can see which countries and how many apps were requested to be removed from the App Store: <a href="https://www.apple.com/legal/more-resources/docs/2022-App-Store-Transparency-Report.pdf" target="_blank">https://www.apple.com/legal/more-resources/docs/2022-App-Store-Transparency-Report.pdf</a></div><div class="gmail_default" style="font-family:arial,sans-serif"><br></div><div class="gmail_default" style="font-family:arial,sans-serif">Other Internet organizations also report on which countries requested data, here is for example a RIPE NCC transparency report: <a href="https://www.ripe.net/publications/docs/ripe-794/" target="_blank">https://www.ripe.net/publications/docs/ripe-794/</a></div><div class="gmail_default" style="font-family:arial,sans-serif"><br></div><div class="gmail_default" style="font-family:arial,sans-serif">This topic has been of interest for NCSG for a long time because of its implications on human rights and civil liberty. </div><div class="gmail_default" style="font-family:arial,sans-serif"><br></div><div class="gmail_default" style="font-family:arial,sans-serif">I want to suggest that we bring this issue to RDRS SC and ask to open up the discussion on how we can have some minimal transparency in place. For example which countries the law enforcement agencies submit requests from. We can open up the conversation and also consider what measures to take not to disrupt ongoing investigations and come to a middle ground on this. This is not the only way we can request some minimal transparency but it could be a start. </div><div class="gmail_default" style="font-family:arial,sans-serif"><br></div><div class="gmail_default" style="font-family:arial,sans-serif">Stephanie is our representative on RDRS SC. Maybe she can bring up this issue in that group? </div><div class="gmail_default" style="font-family:arial,sans-serif"><br></div><div class="gmail_default" style="font-family:arial,sans-serif"><br></div><div class="gmail_default" style="font-family:arial,sans-serif"><br></div><div class="gmail_default" style="font-family:arial,sans-serif"><br></div><div class="gmail_default" style="font-family:arial,sans-serif"><br></div><div class="gmail_default" style="font-family:arial,sans-serif"> </div><div class="gmail_default" style="font-family:arial,sans-serif"><br></div><div class="gmail_default" style="font-family:arial,sans-serif"><br></div><div class="gmail_default" style="font-family:arial,sans-serif"><br></div><div><div dir="ltr" class="gmail_signature"><div dir="ltr"><div><font face="verdana, sans-serif">Farzaneh </font></div></div></div></div></div>
</blockquote></div>