ICANN has appointed a Chief Data Protection Officer

Stephanie Perrin stephanie.perrin at MAIL.UTORONTO.CA
Mon Jul 31 07:35:31 EEST 2017


We have asked a similar line of questions (why doesn't ICANN have a 
privacy policy, why not a privacy officer) a few years ago.  We never 
really got a decent answer, as I recall.  I suspect that we will not get 
a great answer this time either, and I think we can depend upon it, 
ICANN management is getting a great deal of grief from the registrars 
and registries over the mess that they have dragged them into.  Remember 
that the contracted parties have very little leeway in their contract 
negotiations, the WHOIS conflicts with law policy does not work, and the 
contracted parties are considered data controllers under the EU 
law...although I would argue that ICANN is the data controller and they 
are only processors for any data which is mandated by the RAA.  So I am 
not sure our we-told-you-so and how-could-you-mess-this-up would be 
helpful at this point.  We should give Daniel a chance, he might be 
excellent.  Who knows, maybe he has been telling them all along that 
they really ought to comply with law, we are not likely to know that.

I just think if I were the CEO I would be asking for the risk management 
plan that had been developed to manage this risk.  I can assure you I 
have been reminding everyone on every working group I have been on of 
the impending regulation since I arrived here in 2013.

cheers Stephanie


On 2017-07-31 08:06, Michael Oghia wrote:
> I agree too Stephanie, excellent points David.
>
> Would anyone support us as the NCSG requesting a formal response to 
> David's points (and a formal explanation as to the motivation behind 
> Mr. Halloran's appointment)?
>
> Best,
> -Michael
>
> On Mon, Jul 31, 2017 at 1:51 PM, Stephanie Perrin 
> <stephanie.perrin at mail.utoronto.ca 
> <mailto:stephanie.perrin at mail.utoronto.ca>> wrote:
>
>     I totally agree David, and as someone who last worked in risk
>     management, if I were the CEO looking at this mess right now I
>     would be asking hard questions of the people who have advised the
>     Board to just ignore the data protection commissioners for the
>     past 17 years.  First position paper on WHOIS being illegal was in
>     2000.  Makes a heck of an easy case to take to Court....
>
>     Stephanie Perrin
>
>
>     On 2017-07-31 03:33, David Cake wrote:
>>     I admit I find this development disappointing.
>>     While it is a sign (along with the GDPR task force established at
>>     the last meeting) that ICANN has finally understood the
>>     significance of its downplaying and avoidance of the GDPR and
>>     other international data protection law over the last few years,
>>     it is disappointing that:
>>      a) ICANN is still not taking the issue that seriously, as it is
>>     in addition to existing Deputy General Counsel duties, so
>>     represents a limited allocation of resources to the issue;
>>     b) is a missed opportunity to bring additional experience and
>>     expertise into the organisation, expertise ICANN desperately
>>     needs (and is currently relying on its volunteers to provide);
>>     c) is continuing to the have the issue managed by the same team
>>     whose denial and obstinate avoidance of the issue has led to the
>>     organisation now facing a crisis;
>>     d) continues a pattern of having ICANN legal be put in charge of
>>     areas where it is largely responsible for continued organisation
>>     dysfunction, so effectively being given the opportunity to manage
>>     criticism but not given any strong inventive to admit to past
>>     mistakes. .
>>
>>     David
>>
>>
>>
>>>     On 29 Jul 2017, at 3:32 am, Ayden Férdeline <icann at ferdeline.com
>>>     <mailto:icann at ferdeline.com>> wrote:
>>>
>>>     ICANN has now appointed someone
>>>     <https://www.icann.org/news/blog/introducing-icann-s-chief-data-protection-officer-cdpo>
>>>     to the role of "Chief Data Protection Officer". Daniel Halloran,
>>>     who in his bio is described as "one of ICANN's longest-serving
>>>     employees" and reports directly to John Jeffrey, does not list
>>>     his experience in establishing privacy frameworks nor their
>>>     associated compliance structures in his bio. That said, I
>>>     wish him all the best in this new role and look forward to
>>>     seeing how ICANN's understanding of data protection law evolves
>>>     over the coming months now that this position has been created...
>>>
>>>     Best wishes, Ayden Férdeline
>>
>
>

-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://lists.ncsg.is/pipermail/ncsg-discuss/attachments/20170731/9e4bcbf1/attachment.htm>


More information about the Ncsg-discuss mailing list