<div dir="ltr"><div><div class="gmail_default" style="font-family:arial,sans-serif">Dear Shiva, </div><div class="gmail_default" style="font-family:arial,sans-serif"><br></div><div class="gmail_default" style="font-family:arial,sans-serif"><p>NCSG’s positions come from years of advocating for human rights and pushing back against overreach in the name of safety and protection of intellectual property rights. Many of our members also work on online safety, but they join NCSG because they see that too often “safety solutions” fail to protect victims while undermining digital rights.</p>
<p>We are not saying DNS abuse should not be mitigated. We are saying: don’t rush into measures that put rights at risk, and where restrictions are needed, there must be remedies and safeguards. In fact, on several of the issues you raise, NCSG has constructively engaged through PDPs. We have supported urgent request categories and even worked with law enforcement to strengthen authentication, provided this is done transparently and in a rights-respecting way. </p>
<p>What we cannot do is dilute our message by advocating for mechanisms that lack safeguards, that pose clear human rights risks, and that in many cases do not even solve the underlying safety problems. The recent GAC Communiqué does not mention human rights/access to remedy  a single time. That silence is precisely why NCSG’s role is so critical.</p></div><div class="gmail_default" style="font-family:arial,sans-serif">Best regards, </div><br clear="all"></div><div><div dir="ltr" class="gmail_signature" data-smartmail="gmail_signature"><div dir="ltr"><div><font face="verdana, sans-serif">Farzaneh </font></div></div></div></div><br></div><br><div class="gmail_quote gmail_quote_container"><div dir="ltr" class="gmail_attr">On Sun, Sep 21, 2025 at 8:41 AM Shiva Upadhyay <<a href="mailto:shiva.upadhyay@yahoo.com">shiva.upadhyay@yahoo.com</a>> wrote:<br></div><blockquote class="gmail_quote" style="margin:0px 0px 0px 0.8ex;border-left:1px solid rgb(204,204,204);padding-left:1ex"><div><div style="font-family:"Helvetica Neue",Helvetica,Arial,sans-serif;font-size:13px"><div></div>
        <div dir="ltr"><div><p>Dear Friends,</p>
<p>I would like to share what my team of lawyers and I are witnessing every day. We are closely following court proceedings, remaining in continuous touch with law enforcement agencies, and engaging directly with victims and their families.</p>
<p>Every day, we see the enormous challenges that arise when victims seek justice. Courts are under pressure to respond swiftly, yet perpetrators exploit loopholes by registering new domains almost overnight. Law enforcement struggles with incomplete or inaccurate WHOIS information, leaving them unable to track abusers effectively. Behind these systemic gaps are real people—parents in tears, young girls forced to abandon school, families whose lives are disrupted by relentless online abuse.</p>
<p>While human rights and privacy must always be respected, we cannot ignore how anonymity is being misused as a shield for cybercriminals. In sensitive cases, such as child abuse, sexual exploitation, and morphing of images, the urgency of accurate and verified information cannot be overstated. Courts are ordering takedowns, yet without stronger obligations on registrars and intermediaries, the cycle simply repeats.</p>
<p>Our collective responsibility is to find the right balance: protecting fundamental rights while ensuring that victims are not left helpless, and that LEAs and courts have the tools to deliver timely justice. A few suggestions we need to keep in mind while submitting our response: <br><br></p><h2>1. <strong>Expanded Law Enforcement Access (RDRS)</strong></h2><p><strong>NCSG Position:</strong><br>
Law enforcement’s increased use of the RDRS is framed as the normalization of access without safeguards. Mandatory registrar participation is seen as a rights risk.</p><p><strong>Rebuttal:</strong><br>
This framing disregards governments’ real legal obligations. Courts hold governments accountable when law enforcement cannot trace cybercriminals. In India alone, thousands of <strong>cases involving domain names distributing morphed images of girls</strong> have been filed. Victims’ parents have testified in court while perpetrators exploit anonymity. Registrars’ refusal to comply leaves governments unable to enforce judicial orders.</p><p><strong>Balanced Position:</strong></p><ul>
<li>
<p>Mandatory RDRS participation is essential, but <strong>tiered safeguards</strong> should apply.</p>
</li>
<li>
<p>Urgent categories (child sexual abuse, gender-based crimes, imminent harm) require fast disclosure.</p>
</li>
<li>
<p>For non-urgent cases, safeguards such as <strong>registrant notice, public reporting, and appeal rights</strong> should apply.</p>
</li>
</ul><p>This balances registrant privacy with victims’ right to dignity and remedy.</p><h2>2. <strong>Urgent Requests for Disclosure (24-Hour Timeline)</strong></h2><p><strong>NCSG Position:</strong><br>
A 24-hour disclosure timeline lacks legal thresholds and risks misuse by repressive regimes.</p><p><strong>Rebuttal:</strong><br>
The assumption ignores that <strong>delays in disclosure directly harm children and women</strong>. Courts order blocking or tracing within hours. Perpetrators reappear the next day with new domains (<em>example1, example2</em>). Without timely data, law enforcement cannot prevent ongoing abuse. Governments are answerable to courts, not abstract safeguards alone.</p><p><strong>Balanced Position:</strong></p><ul>
<li>
<p>Urgent disclosure timelines must remain, but paired with <strong>authentication of LEA requests</strong> and <strong>post-facto audit trails</strong>.</p>
</li>
<li>
<p>Safeguards should prevent political misuse, but not at the cost of <strong>child safety and gender justice</strong>.</p>
</li>
</ul><p>The higher human right is to protect minors from irreversible harm.</p><h2>3. <strong>Accuracy of Registration Data</strong></h2><p><strong>NCSG Position:</strong><br>
Shorter verification windows risk undermining anonymity; the distinction between contractability and identity is overlooked.</p><p><strong>Rebuttal:</strong><br>
This overlooks how abusers weaponize <strong>fake or stolen contact data</strong>. When WHOIS contains unreachable numbers or disposable emails, investigations stall. Courts expect verified contactability. Without it, registrars enable criminal impunity.</p><p><strong>Balanced Position:</strong></p><ul>
<li>
<p>Support <strong>minimum verification standards</strong> (email + phone validation, periodic rechecks).</p>
</li>
<li>
<p>Clarify distinction: accuracy ensures <strong>contactability</strong>, not mandatory identity disclosure.</p>
</li>
<li>
<p>For high-risk categories (financial services, bulk registrations), stricter verification may be justified.</p>
</li>
</ul><p>Accuracy strengthens both consumer trust and abuse mitigation, while still protecting pseudonymity in low-risk contexts.</p><h2>4. <strong>DNS Abuse Mitigation</strong></h2><p><strong>NCSG Position:</strong><br>
GAC’s focus on enforcement risks overbroad takedowns and neglects civil society safeguards.</p><p><strong>Rebuttal:</strong><br>
Governments daily confront systemic abuse: morphed images of girls, financial scams, and child exploitation. <strong>Anonymity is repeatedly misused as a shield.</strong> Thousands of women have lost dignity and trust in digital spaces. Dismissing enforcement undermines the <strong>right to dignity, protection from exploitation, and access to remedy</strong> under UDHR/ICCPR/CRC.</p><p><strong>Balanced Position:</strong></p><ul>
<li>
<p>Enforcement must be rapid for <strong>child abuse, gender violence, and large-scale fraud</strong>.</p>
</li>
<li>
<p>Safeguards should exist for small registrants and dissenting voices, including <strong>appeals, contestation mechanisms, and transparency reporting</strong>.</p>
</li>
<li>
<p>ICANN should enable <strong>joint mechanisms</strong> (governments + NGOs + civil society) to prevent misuse while ensuring proportionality.</p></li></ul><h2><strong>Conclusion</strong></h2><p>



























</p><div>NCSG’s draft emphasizes registrant rights but <strong>misses the other half of the human rights equation, </strong>the rights of women, children, and families devastated by unchecked domain abuse. Governments cannot ignore court orders or parental pleas. ICANN must take the <strong>higher ground</strong>: enable rapid enforcement in abuse cases while embedding due process safeguards. Privacy is vital, but so is dignity, justice, and protection from exploitation.</div></div><br></div><div dir="ltr">Thanks & Regards,</div><div dir="ltr">Shiva Upadhyay</div>
        
        </div><div id="m_-8113854382084941966yahoo_quoted_9111611001">
            <div style="font-family:"Helvetica Neue",Helvetica,Arial,sans-serif;font-size:13px;color:rgb(38,40,42)">
                
                <div>
                        On Saturday 20 September, 2025 at 01:55:09 am IST, farzaneh badii <<a href="mailto:farzaneh.badii@gmail.com" target="_blank">farzaneh.badii@gmail.com</a>> wrote:
                    </div>
                    <div><br></div>
                    <div><br></div>
                
                
                <div><div id="m_-8113854382084941966yiv3487516010"><div dir="ltr"><div><div style="font-family:arial,sans-serif">Hi all,</div><div style="font-family:arial,sans-serif"><br></div><div style="font-family:arial,sans-serif">Here is our second HRIA on GAC communique:  <a rel="nofollow noopener noreferrer" href="https://docs.google.com/document/d/1k32oTjH2bg2Gd5hEUExn6BoJZ89HluC3_vPDkks4vfg/edit?tab=t.0" target="_blank">https://docs.google.com/document/d/1k32oTjH2bg2Gd5hEUExn6BoJZ89HluC3_vPDkks4vfg/edit?tab=t.0</a> </div><div style="font-family:arial,sans-serif"><br></div><div style="font-family:arial,sans-serif">Please comment so that we finalize it and submit it to them and bring it up during our GAC meeting.</div><div style="font-family:arial,sans-serif">We are aiming to finalize by Wednesday next week. </div><div style="font-family:arial,sans-serif"><br></div><div style="font-family:arial,sans-serif"><br></div><div style="font-family:arial,sans-serif">Best regards, </div><div style="font-family:arial,sans-serif"><br></div><br clear="all"></div><div><div dir="ltr"><div dir="ltr"><div><font face="verdana, sans-serif">Farzaneh </font></div></div></div></div></div>
</div></div>
            </div>
        </div></div></blockquote></div>