ICANN Thumbs Its Nose at National Data Protection Authorities - Refuses to Comply with Privacy Laws Protecting Citizens
Mark Leiser
markleiser at GMAIL.COM
Tue Jul 16 11:18:31 EEST 2013
Sorry - my understanding is this. The Article 29 WG is NOT a regulator,
therefore is not a suitable authority. It is a guidance provider and not
anything more than this.
Its website makes this clear.
"The material (opinions, working documents, letters etc.) issued by the
Article 29 Working Party (Art. 29 WP), available on this website reflect
the views only of the Art. 29 WP which has an advisory status and acts
independently. They do not reflect the position of the European Commission."
http://ec.europa.eu/justice/data-protection/article-29/
*Therefore, the regulators that make up part of the Article 29 working
party have more authority separately than when acting in the capacity of
the Article 29 WG. *
Mark Leiser
Mark R. Leiser, Phd Student
School of Law, Humanities & Social Sciences Faculty
PGR Room, Lord Hope Building
University of Strathclyde
141 St James Road,
Glasgow G4 0LT Scotland
Mobile: +44 (0) 7719739090
Email: markleiser at gmail.com
Twitter: http://twitter.com/#!/mleiser
LinkedIN: http://www.linkedin.com/profile/view?id=189149411&trk=tab_pro
Google+: https://plus.google.com/u/0/105289982691060086995/posts
On Tue, Jul 16, 2013 at 1:52 AM, Andrew A. Adams <aaa at meiji.ac.jp> wrote:
> Milton wrote:
> > Is there any way that EPIC or other privacy organizations with
> > litigation experience can advise us on or European colleagues on how
> > to sue ICANN to show that it does have legal effect?
>
> There is no way really to premptively bring this to a court. If ICANN does
> not regard the Art 29 WP as a suitable authority, then it may also not
> recognise the individual regulators as competent authorities. In its
> current
> form, i.e. the data protection directive, it is up to individual member
> states to set up appropriate legislation in each country to implement the
> directive. (As a side-note the proposed new regulation is much simpler in
> that regulations pretty much get direct effect in member states.) We'd have
> to know what ICANN would regard as sufficient legal authority. Perhaps they
> would regard individual rulings by each regulator as having sufficient
> effect
> (since this appears to have been a unanimous decision by the ART29WP which
> includes representatives of all the regulators as well as some other
> advisors, that actually should be feasible). However, ICANN could just as
> easily then turn around and say that this is still not sufficient, in which
> case we'd have to wait for:
>
> An EU-based registrar to comply with thick whois, and make the information
> available as per the ICANN rules;
> someone subject to that registry to make a complaint to the regulator in
> their country; OR for the relevant DPA to intervene on their own
> recognisance
> to order the registrar to stop such activity;
> the registrar to appeal to the relevant tribunal or court;
> the relevant tribunal or court to rule that the data protection authority
> is
> correct;
> further appeals up the chain to the member state top court, and for them to
> refer the matter to the ECJ (European Court of Justice) for an EU-level
> opinion binding on all EU jurisdictions.
>
> THat would take, on conservative estimates, about five years to complete.
> In
> the meantime all registrars in EU member states would be caught between the
> rock of ICANN rules and the hard place of their own regulators'
> interpretations of EU rules.
>
> Plus, in the meantime, the new EU DP Regulations will probably become EU
> law
> this year or next. Luckily for us, this wouldn't then have any further
> delay
> in transposition into member states laws.
>
>
>
> We need to know whether ICANN would regard individual statements from
> relevant DPAs in the various EU member states would be regarded as
> sufficient, or whether they would push registrars into the ridiculous
> position of having to ignore the advice of their DP authority (which opens
> them to significant fines in many cases) or ICANN's rules (which runs the
> risk of them beign suspended by their registry IIRC).
>
>
>
> --
> Professor Andrew A Adams aaa at meiji.ac.jp
> Professor at Graduate School of Business Administration, and
> Deputy Director of the Centre for Business Information Ethics
> Meiji University, Tokyo, Japan http://www.a-cubed.info/
>
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://lists.ncsg.is/pipermail/ncsg-discuss/attachments/20130716/368c5819/attachment.htm>
More information about the Ncsg-discuss
mailing list