<div dir="ltr"><div><p><span style="font-family:arial,sans-serif">As you know I am your rep on RDRS SC, which is the triage system for sending the disclosure of domain name registrants data to the registrar. It's a pilot project. </span></p><p><span class="gmail_default" style="font-family:arial,sans-serif">We are providing our report and based on the result of the experiment we are providing the recommendations for consideration of SSAD(the disclosure policy that was adopted in the past). </span></p><p><span class="gmail_default" style="font-family:arial,sans-serif"><b></b>For NCSG a few things matter: privacy of the domain name registrants, accountability and transparency of the system, the requesters and the registrars.</span><br></p><p><span class="gmail_default" style="font-family:arial,sans-serif">One of the issues that we are discussing is accreditation of non LEAs. See the brief below, and my question is: what should we decide? Should we insist on full accreditation of non LEAs or should we settle on having some lightweight authentication and ask ICANN and registrars to report on the requests. I lay out the pros and cons of the approaches below.</span><br></p><p><strong>Background:</strong><br>
As part of the ongoing evaluation of the Registration Data Request Service (RDRS), several concerns have emerged regarding requestor validation and accreditation, particularly in relation to non-law enforcement third parties.</p>
<p><strong>EPDP Phase 2 Context:</strong><br>
The EPDP Phase 2 Final Report recommended the creation or designation of an <strong>Accreditation Authority</strong> as a critical component of any long-term solution for lawful disclosure of domain registration data. This recommendation has significant implications for the <span class="gmail_default" style="font-family:arial,sans-serif"> disclosure system</span></p>
<p><strong><span class="gmail_default" style="font-family:arial,sans-serif"></span>S<span class="gmail_default" style="font-family:arial,sans-serif">ome observations</span></strong></p><p><strong><span class="gmail_default" style="font-family:arial,sans-serif">Why LEA authentication is needed:</span></strong></p>
<ol>
<li>
<p><strong>Misclassification of Requests:</strong><br>
RDRS experience indicates that a number of data disclosure requests were improperly categorized as originating from law enforcement authorities, raising concerns about the accuracy and integrity of requestor self-identification.</p>
</li>
<li>
<p><b>Lack of Requestor Validation:</b><br>
The absence of an accreditation or identity validation mechanism may have contributed to delayed responses from registrars, who are unable to confidently assess the requestor’s legal standing and purpose.</p>
</li>
<li>
<p><strong>Authentication vs. Disclosure Balancing:</strong><br>
<span class="gmail_default" style="font-family:arial,sans-serif"></span>N<span class="gmail_default" style="font-family:arial,sans-serif">ote </span>that authentication <span class="gmail_default" style="font-family:arial,sans-serif">is</span> not inherently difficult. The core challenge lies in balancing a validated requestor’s documented purpose against the registrant’s right to privacy, particularly in borderline or ambiguous cases.</p>
</li></ol><div><div class="gmail_default" style="font-family:arial,sans-serif"><b>Non LEAs</b></div><br></div><ol>
<li>
<p><strong>Risk of Abuse by Authenticated Non-LEAs:</strong><br>
<span class="gmail_default" style="font-family:arial,sans-serif"></span>W<span class="gmail_default" style="font-family:arial,sans-serif">e have concerns </span>about the <strong>potential for misuse of access</strong> by authenticated third-party requestors, especially those operating in jurisdictions with weak human rights protections. Authentication alone does not safeguard against disproportionate or abusive requests.</p>
</li>
</ol>
<p><strong>Recommendations for Follow-up System Design:</strong></p>
<ul>
<li>
<p><strong>Initial Focus on Law Enforcement :</strong><br>
<span class="gmail_default" style="font-family:arial,sans-serif"></span>I<span class="gmail_default" style="font-family:arial,sans-serif"> think we should</span> generally agree that future iterations or alternatives to RDRS should prioritize <strong><span class="gmail_default" style="font-family:arial,sans-serif"></span>a<span class="gmail_default" style="font-family:arial,sans-serif">uthentication</span> of law enforcement requestors</strong> as a first step, both to build trust and to test implementation.</p></li>
<li>
<p><b>Need for Further Policy </b><span class="gmail_default" style="font-family:arial,sans-serif"><b>refinement: </b>Discuss how to refine accreditation for third party non LEAs so that we bring transparency and accountability but also not be entangled in a "trusted flagger" system where accreditation could lead to positive answers from the registrars without any balance of fundamental rights and disclosure. </span></p></li></ul></div><div><div dir="ltr" class="gmail_signature" data-smartmail="gmail_signature"><div dir="ltr"><div><font face="verdana, sans-serif">Farzaneh </font></div></div></div></div></div>