[INPUT REQUESTED] How do non-commercial Internet users use WHOIS?

Kris Seeburn seeburn.k at GMAIL.COM
Tue Jul 4 09:54:15 EEST 2017


Ayden,

As far as i am concerned i always look at the whois for basic information that may concern ngo or other very small business users whom i help. Sometimes it does happen that of course before registering we need to check the availability of the domain and the owner. Then to options present we find another name or we try to see whether we can negotiate with the current owner. But you may find that these days many companies just buy what they see common or have found that a certain domain is been used for a long time and is popular and they get in and wait till the moment you miss your payment unless there is protection of the domain name. Many small users cannot always afford to protect the domain.

The biggest challenge is to be sure that these are correct :
Personal and/or business name
Business (physical) address
E-mail address
Phone number
Administrative and technical contacts.
But the real utility is :

By network administrators and others to find and fix system problems and maintain Internet stability.
For determining the availability of domain names.
To counter spamming or fraud and identify trademark infringements
To Enhance accountability of domain name registrants.
But even with these last four the challenge is greater than what it looks like.


> On Jul 4, 2017, at 6:41 PM, Ayden Férdeline <icann at ferdeline.com> wrote:
> 
> Sorry if I wasn't clear, Kris. For now, we are seeking to understand how non-commercial Internet users use WHOIS today, if at all. I would find it helpful to read user stories where I am walked through the process, step-by-step, behind why someone would turn to WHOIS and how they'd interpret the output. It is not yet the time for us to consider the data elements individually, or other contractual obligations. Thanks!
> 
> Ayden Férdeline
> linkedin.com/in/ferdeline <http://www.linkedin.com/in/ferdeline>
> 
> 
>> -------- Original Message --------
>> Subject: Re: [INPUT REQUESTED] How do non-commercial Internet users use WHOIS?
>> Local Time: July 4, 2017 3:34 PM
>> UTC Time: July 4, 2017 2:34 PM
>> From: seeburn.k at GMAIL.COM
>> To: NCSG-DISCUSS at LISTSERV.SYR.EDU
>> 
>> Thanks for the clarification. I think we first look what iCANN usually looks for at the whois level which forces registrars to align same but apart from that some gather IDs, Credit card info which is still in the system. We can start at these.
>> 
>> https://whois.icann.org/en/history-whois <https://whois.icann.org/en/history-whois>
>> 
>> 
>> Kris
>> 
>>> On Jul 4, 2017, at 6:30 PM, Ayden Férdeline <icann at ferdeline.com <mailto:icann at ferdeline.com>> wrote:
>>> 
>>> Kris, thank you, but we are taking things one step at a time and need more granularity. In order to prepare for future discussions with data protection authorities, and to gather the meaningful legal analysis that will help us understand the impact you mentioned, we first need to identify categories of WHOIS users and the data elements they use. For now I kindly request that user stories only consist of the following: the data elements you use, and the purpose behind why you use these data elements. This is the information that we will find useful in our discussions over the next week. Thanks!
>>> 
>>> Ayden Férdeline
>>> linkedin.com/in/ferdeline <http://www.linkedin.com/in/ferdeline>
>>> 
>>> 
>>>> -------- Original Message --------
>>>> Subject: Re: [INPUT REQUESTED] How do non-commercial Internet users use WHOIS?
>>>> Local Time: July 4, 2017 3:22 PM
>>>> UTC Time: July 4, 2017 2:22 PM
>>>> From: seeburn.k at gmail.com <mailto:seeburn.k at gmail.com>
>>>> To: Ayden Férdeline <icann at ferdeline.com <mailto:icann at ferdeline.com>>
>>>> NCSG-DISCUSS at LISTSERV.SYR.EDU <mailto:NCSG-DISCUSS at LISTSERV.SYR.EDU>
>>>> 
>>>> My take is just more general. GDRP is more of a one stop shop for the EU rather than having various ones.
>>>> 
>>>> We still need to ascertain many things like the the impact of GDPR on other countries dealing with EU. Let’s say your domain is hosted somewhere other than EU but its a business that entertains many clients from EU as well. We need to find the right level of Balance between the varied laws of Data Protections that impacts all of us. I’d say we need to ensure a stability between all the different actionable laws around that not only impacts but helps our membership and all civil society understands the real view of the new landscape of the matter.
>>>> 
>>>> We may need to :
>>>> 
>>>>  <https://en.wikipedia.org/wiki/General_Data_Protection_Regulation#Discussion_and_challenges>
>>>> Look at the key contents and look at the impact <https://en.wikipedia.org/wiki/General_Data_Protection_Regulation#Content>
>>>> 1Scope of the said law
>>>> 2Single set of rules and one-stop shop covering which areas
>>>> 3Responsibility and accountability <https://en.wikipedia.org/wiki/General_Data_Protection_Regulation#Responsibility_and_accountability>
>>>> 4Consent <https://en.wikipedia.org/wiki/General_Data_Protection_Regulation#Consent>
>>>> 5Data Protection Officer (How and what is required - I know the EU Data Commissioner has the ultimate power
>>>> 6Pseudonymisation <https://en.wikipedia.org/wiki/General_Data_Protection_Regulation#Pseudonymisation>
>>>> 7Data breaches (What is the impact on different jurisdiction)
>>>> 8Sanctions (How it really can be applied with different jurisdictions in play  - extradition etc., is not at play here)
>>>> 9Right to erasure ( Hoe and under what terms and conditions)
>>>> 10Data portability (How can it be done without hampering the process)
>>>> 11Data protection by Design and by Default ( What  basics are required in these terms)
>>>> 12Records of processing activities (Which records are be habilitated to to use)
>>>> 
>>>> Last but not the least many countries are also aligning some data protection laws because of dealing with the EU. So we might as well map and ensure a stable rule that puts everyone in line.
>>>> 
>>>> 
>>>> The challenges being faced by the internet community —— as far as i know the application of the GDPR is as from 25 May 2018
>>>> 
>>>> We can also not waste too much time as the date of application and its related timeline and challenges are just behind the door.
>>>> 
>>>> Kris 
>>>> 
>>>>> On Jul 4, 2017, at 2:36 PM, Ayden Férdeline <icann at FERDELINE.COM <mailto:icann at FERDELINE.COM>> wrote:
>>>>> 
>>>>> Greetings, all-
>>>>> 
>>>>> Along with Stephanie Perrin and Wendy Seltzer, I am a part of the ICANN GDPR Compliance Consultation Group. This group has been formed to help ICANN gather the information it needs to engage with data protection authorities and to obtain actionable legal advice.
>>>>> 
>>>>> I committed last week to keeping the NCSG updated on the activities of the Consultation Group over the coming months. 
>>>>> 
>>>>> In our first meeting, we committed to participating in a data gathering exercise to identify the existing users of WHOIS, what data elements they use, and for what purpose. At this time we are not making the determination as to whether a purpose is legitimate or illegitimate, though that call will come, or if a data element comprises personally identifiable information. For now we are simply trying to include all user categories to get the most complete set of data points.
>>>>> 
>>>>> We are interested in understanding how non-commercial Internet users, who we in the NCSG purport to represent the interests of, use WHOIS. We have conducted some informal consultation among our peers and have been provided with a few use cases, but not too many. It is possible that end users do not use WHOIS widely [and that has been the assumption that has informed previous exercises like this one], but if you, as an end user, do use WHOIS, we would be curious to know for what purpose and which data elements you rely on. Please share your thoughts either on-list or with me privately, if you prefer.
>>>>> 
>>>>> We have a very short turnaround time for this exercise. Our next call is this Thursday, and ICANN staff envision this entire task being completed by next week. The time for you to provide input is thus now. Thanks!
>>>>> 
>>>>> Best wishes,
>>>>> 
>>>>> Ayden Férdeline
>>>>> linkedin.com/in/ferdeline <http://www.linkedin.com/in/ferdeline>
>>>>> 
>>>>> 
>>>> 
>>>> 
>>>> Kris Seeburn
>>>> seeburn.k at gmail.com <mailto:seeburn.k at gmail.com>
>>>> www.linkedin.com/in/kseeburn/ <http://www.linkedin.com/in/kseeburn/>
>>>> 
>>>> 
>>> 
>> 
>> 
>> Kris Seeburn
>> seeburn.k at gmail.com <mailto:seeburn.k at gmail.com>
>> www.linkedin.com/in/kseeburn/ <http://www.linkedin.com/in/kseeburn/>
>> 
>> 
> 

Kris Seeburn
seeburn.k at gmail.com
www.linkedin.com/in/kseeburn/ <http://www.linkedin.com/in/kseeburn/>




-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://lists.ncsg.is/pipermail/ncsg-discuss/attachments/20170704/1a85a528/attachment.htm>


More information about the Ncsg-discuss mailing list