[INPUT REQUESTED] How do non-commercial Internet users use WHOIS?

Ayden Férdeline icann at FERDELINE.COM
Tue Jul 4 09:41:11 EEST 2017


Sorry if I wasn't clear, Kris. For now, we are seeking to understand how non-commercial Internet users use WHOIS today, if at all. I would find it helpful to read user stories where I am walked through the process, step-by-step, behind why someone would turn to WHOIS and how they'd interpret the output. It is not yet the time for us to consider the data elements individually, or other contractual obligations. Thanks!

Ayden Férdeline
[linkedin.com/in/ferdeline](http://www.linkedin.com/in/ferdeline)

> -------- Original Message --------
> Subject: Re: [INPUT REQUESTED] How do non-commercial Internet users use WHOIS?
> Local Time: July 4, 2017 3:34 PM
> UTC Time: July 4, 2017 2:34 PM
> From: seeburn.k at GMAIL.COM
> To: NCSG-DISCUSS at LISTSERV.SYR.EDU
> Thanks for the clarification. I think we first look what iCANN usually looks for at the whois level which forces registrars to align same but apart from that some gather IDs, Credit card info which is still in the system. We can start at these.
> https://whois.icann.org/en/history-whois
> Kris
>
>> On Jul 4, 2017, at 6:30 PM, Ayden Férdeline <icann at ferdeline.com> wrote:
>>
>> Kris, thank you, but we are taking things one step at a time and need more granularity. In order to prepare for future discussions with data protection authorities, and to gather the meaningful legal analysis that will help us understand the impact you mentioned, we first need to identify categories of WHOIS users and the data elements they use. For now I kindly request that user stories only consist of the following: the data elements you use, and the purpose behind why you use these data elements. This is the information that we will find useful in our discussions over the next week. Thanks!
>>
>> Ayden Férdeline
>> [linkedin.com/in/ferdeline](http://www.linkedin.com/in/ferdeline)
>>
>>> -------- Original Message --------
>>> Subject: Re: [INPUT REQUESTED] How do non-commercial Internet users use WHOIS?
>>> Local Time: July 4, 2017 3:22 PM
>>> UTC Time: July 4, 2017 2:22 PM
>>> From: seeburn.k at gmail.com
>>> To: Ayden Férdeline <icann at ferdeline.com>
>>> NCSG-DISCUSS at LISTSERV.SYR.EDU
>>> My take is just more general. GDRP is more of a one stop shop for the EU rather than having various ones.
>>> We still need to ascertain many things like the the impact of GDPR on other countries dealing with EU. Let’s say your domain is hosted somewhere other than EU but its a business that entertains many clients from EU as well. We need to find the right level of Balance between the varied laws of Data Protections that impacts all of us. I’d say we need to ensure a stability between all the different actionable laws around that not only impacts but helps our membership and all civil society understands the real view of the new landscape of the matter.
>>> We may need to :
>>>
>>> - https://en.wikipedia.org/wiki/General_Data_Protection_Regulation#Discussion_and_challenges
>>> -
>>> [Look at the key contents and look at the impact](https://en.wikipedia.org/wiki/General_Data_Protection_Regulation#Content)
>>>
>>> - 1Scope of the said law
>>> - 2Single set of rules and one-stop shop covering which areas
>>> - [3Responsibility and accountability](https://en.wikipedia.org/wiki/General_Data_Protection_Regulation#Responsibility_and_accountability)
>>> - [4Consent](https://en.wikipedia.org/wiki/General_Data_Protection_Regulation#Consent)
>>> - 5Data Protection Officer (How and what is required - I know the EU Data Commissioner has the ultimate power
>>> - [6Pseudonymisation](https://en.wikipedia.org/wiki/General_Data_Protection_Regulation#Pseudonymisation)
>>> - 7Data breaches (What is the impact on different jurisdiction)
>>> - 8Sanctions (How it really can be applied with different jurisdictions in play - extradition etc., is not at play here)
>>> - 9Right to erasure ( Hoe and under what terms and conditions)
>>> - 10Data portability (How can it be done without hampering the process)
>>> - 11Data protection by Design and by Default ( What basics are required in these terms)
>>> - 12Records of processing activities (Which records are be habilitated to to use)
>>>
>>> Last but not the least many countries are also aligning some data protection laws because of dealing with the EU. So we might as well map and ensure a stable rule that puts everyone in line.
>>>
>>> -
>>> The challenges being faced by the internet community —— as far as i know the application of the GDPR is as from 25 May 2018
>>> We can also not waste too much time as the date of application and its related timeline and challenges are just behind the door.
>>> Kris
>>>
>>>> On Jul 4, 2017, at 2:36 PM, Ayden Férdeline <icann at FERDELINE.COM> wrote:
>>>>
>>>> Greetings, all-
>>>> Along with Stephanie Perrin and Wendy Seltzer, I am a part of the ICANN GDPR Compliance Consultation Group. This group has been formed to help ICANN gather the information it needs to engage with data protection authorities and to obtain actionable legal advice.
>>>> I committed last week to keeping the NCSG updated on the activities of the Consultation Group over the coming months.
>>>> In our first meeting, we committed to participating in a data gathering exercise to identify the existing users of WHOIS, what data elements they use, and for what purpose. At this time we are not making the determination as to whether a purpose is legitimate or illegitimate, though that call will come, or if a data element comprises personally identifiable information. For now we are simply trying to include all user categories to get the most complete set of data points.
>>>> We are interested in understanding how non-commercial Internet users, who we in the NCSG purport to represent the interests of, use WHOIS. We have conducted some informal consultation among our peers and have been provided with a few use cases, but not too many. It is possible that end users do not use WHOIS widely [and that has been the assumption that has informed previous exercises like this one], but if you, as an end user, do use WHOIS, we would be curious to know for what purpose and which data elements you rely on. Please share your thoughts either on-list or with me privately, if you prefer.
>>>> We have a very short turnaround time for this exercise. Our next call is this Thursday, and ICANN staff envision this entire task being completed by next week. The time for you to provide input is thus now. Thanks!
>>>> Best wishes,
>>>>
>>>> Ayden Férdeline
>>>> [linkedin.com/in/ferdeline](http://www.linkedin.com/in/ferdeline)
>>>
>>> Kris Seeburn
>>> seeburn.k at gmail.com
>>>
>>> - www.linkedin.com/in/kseeburn/
>
> Kris Seeburn
> seeburn.k at gmail.com
>
> - www.linkedin.com/in/kseeburn/
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://lists.ncsg.is/pipermail/ncsg-discuss/attachments/20170704/ed5981b4/attachment.htm>


More information about the Ncsg-discuss mailing list