<div dir="ltr">Dear Farzaneh, <div><br></div><div>Thank you for this interesting feedback</div></div><br><div class="gmail_quote gmail_quote_container"><div dir="ltr" class="gmail_attr">Le dim. 14 juin 2026 à 21:14, farzaneh badii <<a href="mailto:00001deb507b73c5-dmarc-request@listserv.syr.edu">00001deb507b73c5-dmarc-request@listserv.syr.edu</a>> a écrit :<br></div><blockquote class="gmail_quote" style="margin:0px 0px 0px 0.8ex;border-left:1px solid rgb(204,204,204);padding-left:1ex"><div dir="ltr"><div dir="ltr"><div><span class="gmail_default" style="font-family:arial,sans-serif">Hi everyone</span><br clear="all"></div><div><span class="gmail_default" style="font-family:arial,sans-serif"><br></span></div><div><span class="gmail_default" style="font-family:arial,sans-serif"><p>We held a good session on human rights impact assessment and Law enforcement access to registrants private data during ICANN 86. <a href="https://icann.zoom.us/rec/play/uaYj4X2b2pgGxI2ztGwrEZ6LRU8jPuwycFwZpeYGlDFtUxJq3Swuew659Paj0GZpOxE9hOHHIFWc53GE._9lB4eVcT4b7mfDa?accessLevel=meeting&canPlayFromShare=true&from=share_recording_detail&startTime=1781188336000&oldStyle=true&componentName=rec-play&originRequestUrl=https%3A%2F%2Ficann.zoom.us%2Frec%2Fshare%2Ff_IZ6MrLsGHxtl5vlotXEJuanGAd7F745yySsqoJu308OzZZ5YrVvdWKvTVJuNF-.wbg8AnhgUB2FGV86%3FstartTime%3D1781188336000" target="_blank">Find the recording here.</a> (The link is too long, if you have difficulties accessing it let me know) </p><p>Here is a brief update on the discussions surrounding DNS policies for law enforcement access to registrant data, followed by the specific data elements requested for authentication and authorization. Note that we are discussing these authorization and authentication forms and doing human rights impact assessment at the Supplemental Review Team on SSAD. So if you have comments, please do let us know. </p>
<p><strong>Brief Update</strong>
The recent Non-Commercial Stakeholder Group (NCSG) session highlighted the human rights risks associated with how registrars handle law enforcement requests for redacted domain name registrant data. A primary concern is that establishing an authentication mechanism might create a false sense of trust, leading registrars to automatically disclose sensitive data—especially during "urgent" requests—without conducting a proper human rights impact assessment.</p>
<p>We stress that a verified identity does not equate to a legally valid or proportionate request. Disclosing data without adequate authorization checks can lead to severe consequences for vulnerable targets, including journalists, activists, and dissidents, potentially resulting in profiling, deportation, torture, or irreversible fatal consequences if the requesting jurisdiction practices the death penalty. Therefore, there is a push to implement strict safeguards, mandatory fundamental rights balancing, and detailed transparency reporting to ensure data is only disclosed when absolutely necessary and legally justified.</p>
<p><strong>Data Elements for Authentication</strong>
Authentication aims to verify the identity and mandate of the requesting officer and agency to ensure the system is secure and not spoofed by impersonators or hackers. The proposed data elements include:</p>
<ul>
<li><strong>Officer Identity:</strong> Legal name, badge number, rank, department, official government domain email, and a direct callback phone number to a publicly listed agency line.</li>
<li><strong>Agency Identity:</strong> The agency's name and its specific type (e.g., criminal justice, administrative, or regulator) to help registrars understand its nature.</li>
<li><strong>Legislative Mandate:</strong> Information on whether the agency is legally empowered to demand sensitive private/domain registration data, and whether the agency operates under judicial or strictly administrative oversight.</li>
<li><strong>Cross-border Mechanisms:</strong> Relevant details for international requests.</li>
</ul>
<p><strong>Data Elements for Authorization</strong>
Authorization is the subsequent step where registrars decide whether the requested disclosure is legally valid, necessary, and proportionate based on a provided request form and authentication process and does the fundamental rights balancing. The requested data elements and commitments that we suggest include:</p>
<ul>
<li><strong>Legal Instrument:</strong> Supporting legal documentation, such as a subpoena (typically for basic subscriber info), a court order, or a search warrant.</li>
<li><strong>Necessity Statement:</strong> An explanation from law enforcement detailing what alternative investigative methods have already been exhausted and why this specific infrastructure-layer data is needed.</li>
<li><strong>Purpose Limitation:</strong> A clearly stated purpose for the data request, alongside binding commitments from the agency that there will be no secondary uses or onward transfers of the data to other jurisdictions.</li>
<li><strong>Retention and Deletion Commitments:</strong> An agreement to delete the data after a specified period.</li>
<li><strong>Data Scoping:</strong> Ensuring the requested data is strictly limited to the minimum necessary information.</li>
<li><strong>Human Rights Impact Assessment Indicators:</strong> Contextual data that helps registrars evaluate jurisdictional risks (e.g., if the requesting country has the death penalty or a history of torture) and registrant profile risks (e.g., if the user is a known activist or journalist).</li></ul></span></div><div><div dir="ltr" class="gmail_signature"><div dir="ltr"><div><font face="verdana, sans-serif">Farzaneh </font></div></div></div></div></div>
</div>
</blockquote></div>