NCSG Ideation Workshop on Revised ICANN Procedure for Handling WHOIS Conflicts with Privacy Law on Monday 29 May 2017 at 13:00 UTC.
Farell Folly
farellfolly at GMAIL.COM
Mon May 29 17:03:45 EEST 2017
Indeed thanks to Ayden.
Thanks Ed For the clarification.
This situation that ICANN is facing is not new in the technlogy field. ITU
has been facing the same issues for years and many conflicts and disputes
had raised between telecommunication regulatory Authority and Operators.
Most of the time, due to countries sovereignty, ITU could not/cannot make
laws that apply to countries.. Instead, it can provide recommendations and
guidelines for operational contracts. Regulators are encouraged to
enforce ITU standards and norms, and if so, operators are forced to comply.
However, a country may not wish to follow an ITU recommandation, standard
or norm, and there will be no directly penalty (but market will decide)
A way to overcome this issue is to request countries' adherence before
enforcing a law. EU in Europe, AU in Africa or regional organisations such
as ECOWAS can vote laws and directives applicable to countries as per the
structure of those organisations (where countries representatives are
ministers and political. ...deciding in accordance to their parliament).
If this such a mecanism can be implemented in ICANN, it would be good.
ICANN can also approach those organisations and recommend to include its
contractual requirements within Information society laws.
Regards
@__f_f__
PhD Candidate, Universität der Bundeswehr München
Computer Security | Internet of Things
https://www.linkedin.com/in/farellf
________________________________.
Mail sent from my mobile phone. Excuse for brievety.
Le 29 mai 2017 21:38, "Edward Morris" <egmorris1 at toast.net> a écrit :
> Hi Ayden,
>
> Thank you so much for organising the ideation workshop today. It's the
> type of thing I believe we need to do more of going forward as public
> comments become more complicated and the NCSG becomes more diverse. I'm
> sorry I had conflicting commitments today ( a Bank Holiday in my part of
> the world) and look forward to listening to the recording and/or reading
> the transcript.
>
> In response to your request for input, let me start with one basic rule of
> contract law, both in the common law and civil law traditions: a
> contractual clause that is against the law is unenforceable in the
> jurisdiction in which it is illegal. So ICANN could contractually require
> Registrars to yearly have their employees take off their clothes, walk in
> the middle of the closest three lane highway and bow in the direction of
> ICANN headquarters chanting "Goran is God", but if that clause violated
> local laws concerning public nudity, traffic laws and blasphemy it would
> not be enforceable.
>
> Similarly, if ICANN were to insert into contracts contractual obligations
> that would cause any party to violate a law, such as ones related to
> privacy and data protection, those contractual clauses would be
> unenforceable and generally would be severed from the contract without
> affecting either parties unrelated contractual obligations (this is a broad
> generalisation; many exceptions do apply). That said, we do want clarity in
> contracts, obligations and commitments should be known, legal and
> enforceable (the later pertaining the the reason the contract exists). It's
> a good idea to deal with this issue up front.
>
> The proposal at hand, as I understand it, is nonsensical and a bit daft.
> Only a fool would go to a government agency and say "Hi guys, I just signed
> a contract that commits me to doing lots of illegal stuff. What do you
> think about it?". Not a good idea. Governments have guns and prisons: it's
> generally not a good idea to tell them you're contractually obliged to
> break their law.
>
> In many commercial contracts there are severability clauses attached to
> arbitration agreements. For example, I was once involved in an import
> transaction concerning several items, one of which we discovered violated
> an obscure E.U. prohibition. We couldn't import it. That impacted the
> pricing of the entire agreement. We had an arbitration clause, though, in
> the contract so we went into an arbitration proceeding with the exporter
> and the situation was resolved.
>
> I'd suggest we consider something smilier here. Here's a proposal to kick
> around:
>
> 1. If a Register or Registrar believes that any part of a contract it is
> obliged to sign with ICANN in order to maintain its core business
> operations is against the law in any jurisdiction in which it operates,
> that company shall obtain a legal opinion from any entity licensed to
> practice law within the jurisdiction involved stating same, giving precise
> reasons for that opinion, and send it to ICANN;
>
> 2. ICANN shall evaluate the submitted claim and: 1. either agree with it,
> thus nullifying the other parties obligation to perform that part of the
> contract, or 2. disagree with it, in which case
>
> 3. the matter shall be referred directly to an Independent Review Panel,
> per §4.3 of ICANN's Bylaws. I would note that said Bylaws section would
> have to be amended to allow for this process to occur. This arbitration
> would have to be binding. The IRP would, thus, make the final decision. An
> alternative would be to send the dispute to an international arbitrator not
> connected in any way with the ICANN IRP.
>
> Hope this is helpful.
>
> Kind Regards,
>
> Ed Morris
>
>
>
>
> ------------------------------
> *From*: "Ayden Férdeline" <icann at FERDELINE.COM>
> *Sent*: Monday, May 29, 2017 8:41 PM
> *To*: NCSG-DISCUSS at LISTSERV.SYR.EDU
> *Subject*: Re: NCSG Ideation Workshop on Revised ICANN Procedure for
> Handling WHOIS Conflicts with Privacy Law on Monday 29 May 2017 at 13:00
> UTC.
>
> Thanks to all who joined this ideation workshop today. I hope you found it
> useful. Just to bring a conversation to the list that we had briefly at the
> end of the call, I said something along the lines of, surely mitigating
> contractual clauses that run contrary to local laws is something that
> happens from time to time in other sectors? I asked how, outside of CANN,
> these issues would be handled. If anyone has an answer to this, I would be
> curious to hear it, as I think it might help us come up with better
> solutions in our comment on the proposed alteration to the WHOIS Conflicts
> with Privacy Law procedure.
>
> Thank you, Ayden
>
>
>
> -------- Original Message --------
> Subject: Attendance & Recording: NCSG Ideation Workshop on Revised ICANN
> Procedure for Handling WHOIS Conflicts with Privacy Law on Monday 29 May
> 2017 at 13:00 UTC.
> Local Time: May 29, 2017 4:48 PM
> UTC Time: May 29, 2017 3:48 PM
> From: maryam.bakoshi at ICANN.ORG
> To: NCSG-DISCUSS at LISTSERV.SYR.EDU
>
>
>
> Dear all,
>
>
>
> Please find attendance and recording of the *NCSG Ideation Workshop on
> Revised ICANN Procedure for Handling WHOIS Conflicts with Privacy Law on
> Monday 29 May 2017 at 13:00 UTC.*
>
>
>
> Transcript would be posted when it becomes available.
>
>
>
> *Attendance:* Dina Solveig Jalkanen, Farell Folly, Farzaneh Badii, Joan
> Kerr, Julf Helsingius, Rafik Dammak, David Cake, Bruna Santos, Louise Marie
> Hurel, Andreea Rusu, Stephanie Perrin, James Gannon, Arshad Mohammed
>
> *Staff: *Maryam Bakoshi
>
>
>
> *Mp3:
> https://audio.icann.org/gnso/whois-conflicts-privacy-law-ncsg-29may17-en.mp3[mailer.samanage.com]
> <https://urldefense.proofpoint.com/v2/url?u=http-3A__mailer.samanage.com_wf_click-3Fupn-3DBicbgE3FNUxHuHwOPdgXp7PxnHhpBITaBzfgAxdndi9IoZ8RzsFfvLRUW7puduYyT3QqyejmqLebLO8-2D2FaBYwOa7n9S-2D2BNF4iZTNJEAmb6p18OioHij8yTI6RHXBNl4dqO-5FFiroU9WATfGGQpGIbRb8NkCMVsuIUf2Oa7q-2D2B6QPGPd0P9ACvn3Y7Ub4pcSRvAWpR4eEu9NGmxpUPeW0JVeMqcxBkC1ajwg6Efba9JnrHuvaGkytYht-2D2BcRzRzRdO6GDE510ktfNBk9SsN-2D2BN0dEU5DFF3QEQ5iwAN6-2D2B-2D2BxBtC6uhITOohlogAogeBf50rZYVN91efCNDdqf2xJtlfeMsjjuK7MqqSHCN6imx8jpgEzEydwcWqu-2D2BfjdaIzcckkn6XuQWr9PFm7U90oJy2EKP0b8VEevVh0x8p-2D2BKUGwiGAR5YKKqLoMtb2KmjIKAv2GtOKlGlUXYzuHJZYFA8p6EAgsX8K59qIN97A-2D2B88klCmbFWwAVYZNdGwmN5AflCwwbw6NFcKtIUDZEy6Lw5btFQ2HbMuhg3tIvvNf2xPuI-2D2BbF0jj4KPbiTMkDQoUEMlpiFnR1mQ0C7ClpRgrbKF96ktBf27YH80P2k3ruvStINNE-2D2BJSGkyXRz48s4QkPA9MgZkY0wOBQ&d=DwMFaQ&c=FmY1u3PJp6wrcrwll3mSVzgfkbPSS6sJms7xcl4I5cM&r=1A9IIOkJia11FXDmJ1R4Jn7wGT4ExHiVuBF89mvNt_Q&m=vQbmbaWSwX_9c2WsUbHUdgoNAN-3QLL6u6EsuRVN9og&s=3WQwmPdBmgaf7JyLvtjt15jOJd_T2lZfr2PGYUVvi74&e=> *
>
>
>
> *AC Chat:*
>
> Nathalie Peregrine: Welcome all, to the NCSG Ideation Workshop on Revised
> ICANN Procedure for Handling WHOIS Conflicts with Privacy Law on Monday 29
> May 2017 at 13:00 UTC
>
>
>
> Ayden Férdeline: Hi all, thanks for coming today
>
>
>
> Farell FOLLY (africa 2.0): ok it works
>
>
>
> Ayden Férdeline: Here is a link to our draft comment, it isn't necessary
> to open the file just yet but we might look at it later.
> https://docs.google.com/document/d/1lA-O2jiPv5JMoCYpG5HD0S_
> 5O3yaiYkoRvfll3YsTX4/edit?usp=sharing
>
>
>
> Joan Kerr: Hello Everyone
>
>
>
> Ayden Férdeline: thanks for joining the call!
>
>
>
> Farell FOLLY (africa 2.0): hello Joan
>
>
>
> Joan Kerr: Hi Farell. How are you
>
>
>
> Ayden Férdeline: We will start in 3 minutes
>
>
>
> Louise Marie Hurel: Hi everyone!
>
>
>
> Andreea Rusu: Hello everyone!
>
>
>
> Stephanie Perrin: apologies for being late
>
>
>
> Bruna Santos: hello, everyone!
>
>
>
> Stephanie Perrin: Thanks for doing all the preparation for this Ayden and
> all!
>
>
>
> Louise Marie Hurel: +1 Stephanie
>
>
>
> Farzaneh Badii: yes
>
>
>
> Louise Marie Hurel: yes
>
>
>
> Farzaneh Badii: we can hear you
>
>
>
> Farzaneh Badii: I'd say we have a technical definition of public comment,
> which is publicly commenting as a group or an individual on a policy
> document
>
>
>
> Dina Solveig Jalkanen: On an entire document or smaller recent alterations
> to one.
>
>
>
> Louise Marie Hurel: yes
>
>
>
> Dina Solveig Jalkanen: Do all issues requesting a public comment receive
> one? If not, what is the percentage of those that go uncommented?
>
>
>
> James Gannon: All are put out for comment, most would recienve at least one
>
>
>
> Rafik: @Dina some topics revieves few comments. no necessarily because
> they are not relevant but because there are several in same time and people
> end up prioritizing...
>
>
>
> Dina Solveig Jalkanen: Working group is free to disregard the contents of
> a comment?
>
>
>
> James Gannon: There is no obligation to incorporate every comment no. But
> to consdider them yes
>
>
>
> James Gannon: *consider
>
>
>
> Rafik: @Dina staff summarize the comments , then working group review the
> comments, try to respond to them but not incorporating everythin
>
>
>
> David Cake: Whois we are talking about the existing registration data
> service
>
>
>
> Dina Solveig Jalkanen: lookup, but I think we should hear details from
> ICANN :)
>
>
>
> David Cake: rather than the protocol by which it is currently delivered
>
>
>
> Dina Solveig Jalkanen: Rafik, thank you, that makes sense
>
>
>
> James Gannon: "David Yes important distinction
>
>
>
> Stephanie Perrin: Consideration of comments, in my view, is much less
> rigorous than it is in some regulatory settings. I used to work on public
> comments that the Department of Communications/Industry has to publish in
> the federal register. one had to be very scrupulous in how those comments
> were disposed of, a but of course in that milieu there is a Minister
> responsbile to a parliament. ICANN is different, on occasion we have had
> our comments barely noted.
>
>
>
> James Gannon: https://whois.icann.org/en/primer
>
>
>
> James Gannon: WHOIS is 3 things
>
>
>
> James Gannon: The information that is collected at the time of
> registration of a domain name or IP numbering resource and subsequently
> made available via the WHOIS Service, and potentially updated throughout
> the life of the resource;The WHOIS Protocol itself, which is defined in RFC
> 3912; orThe WHOIS Services that provide public access to domain name
> registration information typically via applications that implement the
> WHOIS protocol or a web-based interfac
>
>
>
> Julf Helsingius (NCPH NCA): There are two very different issues - the
> access protocol and the actual data
>
>
>
> Dina Solveig Jalkanen: Could you repeat the question? (bad connection)
>
>
>
> Farzaneh Badii: oh now that I have Tapani's phone number from this WHOIS
> fIorm Ican call him up now and ask him to attend this call.
>
>
>
> Stephanie Perrin: Sorry I had to step away and take a call.
>
>
>
> Julf Helsingius (NCPH NCA): I guess we have to separate whois information
> about a single individual, and information about an organisation
>
>
>
> James Gannon: Depends on the country Julf
>
>
>
> Julf Helsingius (NCPH NCA): sure
>
>
>
> Stephanie Perrin: It is very awkward to do that although technically the
> difference is important under data protection law
>
>
>
> Julf Helsingius (NCPH NCA): but pretty much everything always depends on
> the country :)
>
>
>
> Stephanie Perrin: My own policy position, and one we advanced in the
> discussions on privacy proxy services (the PPSAI pdp) is that we should
> avoid trying to determine who is an individual and who is a company,
> although if a company wishes to declare itself they are welcome
>
>
>
> Bruna Santos: Brazil does not have a privacy law yet. There are
> discussions in both at the lower house and at the senate. But we have not
> yet come to a conclusion regarding the different proposals
>
>
>
> Stephanie Perrin: In most nations, the ability to protect groups depends
> on the constitution. More difficult that trying to interpret those rights
> under DP law
>
>
>
> Louise Marie Hurel: We have the Brazilian Internet Bill of Rights as a
> legal mechanism that actually upholds privacy as one of the guiding
> principles to Internet policy, development and governance -- also adding to
> the principle outlined in our Constitution. However, we are currently
> debating a specific framework for privacy and data protection.
>
>
>
> Louise Marie Hurel: Several proposals as Bruna said
>
>
>
> Farell FOLLY (africa 2.0): @stephanie but most of the time as of whois
> registration data, even company data will contain indiindividuals
> information
>
>
>
> Dina Solveig Jalkanen: It doesn't.
>
>
>
> Bruna Santos: For example, the concept of personal data is outlined by the
> Access to Information bill!
>
>
>
> Louise Marie Hurel: So our national panorama is one of comepting
> understandings so as to what are the interests that are guiding privacy law
>
>
>
> Bruna Santos: and jurisprudence
>
>
>
> James Gannon: @Ayden IMportant to note that that will be changing under
> PPSAI implementaion
>
>
>
> Julf Helsingius (NCPH NCA): Ayden - isn't that more an issue of
> transparency rather than an issue of existence of proxy services?
>
>
>
> Joan Kerr: The Personal Information Protection and Electronic Documents
> Act (PIPEDA) is federal legislation passed in 2001 and fully implemented on
> January 1, 2004. While some provinces have passed their own privacy
> legislation, Ontario has not, so the federal legislation applies here.
>
>
>
> Rafik: Tunisia has DP law to be updated since parliament just voted to
> ratify the convention 108
>
>
>
> David Cake: there is a national privacy act in Australia. it puts
> obligations on companies.
>
>
>
> James Gannon: I do belive that Stephanie in fact wrote a good chunk of
> PIPEDA =)
>
>
>
> David Cake: but discussion about legal changes such as a privacy tort are
> ongoing. waiting for data breach legislation.
>
>
>
> Bruna Santos: A curiosity is that when Marco Civil was written, the Idea
> of having privacy as one of the guiding principles to Internet policy,
> development and governance was to reinforce the need of an specific
> framework that the government was working on. (in a very soft power way)
>
>
>
> Bruna Santos: This Government proposal has been sent to the Senate and the
> debate now is between proposals (one from a Senator that is now in our
> Ministry of foreign affairs and the one that the government drafted)
>
>
>
> James Gannon: Ireland has a Data Protection Act in line with the EU
> Directives
>
>
>
> Joan Kerr: @Stephanie, we have always thought PIPEDA covered Ontarions\
>
>
>
> Stephanie Perrin: I think it sounds like the Brazilian framework idea is
> similar to what we were trying to do in Canada.
>
>
>
> Ayden Férdeline: https://docs.google.com/document/d/1lA-
> O2jiPv5JMoCYpG5HD0S_5O3yaiYkoRvfll3YsTX4/edit?usp=sharing
>
>
>
> Stephanie Perrin: We had quite a difficult debate in Canada about the
> scope of what the federal government ought to be doing
>
>
>
> Bruna Santos: Yes, Stephanie, I see some similarities in both processes
>
>
>
> Stephanie Perrin: I spent quite a few years looking at other federal
> states, did not look at Brazil because of my language issues....but it is
> interesting how federal states have intervened. US used their powers in
> interstate commerce to stop racial discrimination, a pretty creative use of
> the power that made our efforts look pretty easy in comparison.
>
>
>
> Bruna Santos: I believe in Brazil, both Marco Civil and the Personal Data
> draft bill have been an effort of the Federal Government against some
> terrible regulation attempts of both the Senate and the Lower House.
>
>
>
> Stephanie Perrin: In Canada we developed a standard for privacy protection
> first, through the Canadian Standards Association. We attempted then to
> take that managment standard to the ISO in order to have it form the basis
> for an international management standard, but were blocked by the US.
>
>
>
> Stephanie Perrin: in the meantime, we legislated compliance to that
> standard. There were many reasons for choosing a standards based approach
> (lawyers hate it) which I could go on and on about, if you are interested
> ....
>
>
>
> Bruna Santos: yes, please! Im interested on the subject! Mainly because I
> have followed a part of the drafting process while at the government
>
>
>
> Stephanie Perrin: Well lets take this offline....It might be a option for
> you if you are interested. Solves trade discrimination issues because
> compliance with it can be indepently audited without the need for
> regulation....
>
>
>
> Bruna Santos: definitely!
>
>
>
> Farell FOLLY (africa 2.0): what the trigger is in this context?
>
>
>
> Stephanie Perrin: The new trigger is a letter from a nationally respected
> law firm.
>
>
>
> Stephanie Perrin: FOrmerly, it was just a letter from a DPA with the
> authority to sanction (and not all dpas have that power, some have to take
> you to a tribunal or a court) telling you that you were breaking the law
>
>
>
> Farzaneh Badii: so it's now law firms enforcing the law?
>
>
>
> Joan Kerr: Who has the ultimate authority to enforce
>
>
>
> Farell FOLLY (africa 2.0): thanks Stéphanie
>
>
>
> Stephanie Perrin: TBH, I was so disgusted at the end of this I wrote my
> dissent and walked away. In order to participate in drafting this comment,
> I will have to go over the precise wording that we came up with in the
> final new trigger. the REgistrars said it would not work, they had an
> effort to block it at the GNSO, but then abandoned that and said yes we
> will pass it in return for starting a new,more broadly scoped cttee this
> fall. Just what we need, says I, another totally frustrating committee.....
>
>
>
> Farell FOLLY (africa 2.0): well
>
>
>
> Stephanie Perrin: I would say go to the website of the WHOIS conflicts
> with law....
>
>
>
> Stephanie Perrin: listen to a couple of the transcripts....
>
>
>
> Stephanie Perrin: we argued over the same issues for weeks on end, so I
> would say random selection ought to take you to some of the debate pretty
> quickly.
>
>
>
> Stephanie Perrin: Privacy impact assessment, privacy policy, legal risk
> assessement.....
>
>
>
> Stephanie Perrin: Normally, you don't force the regulated bodies to
> independently come up with what amounts to a legal risk assessment
> individually.
>
>
>
> Stephanie Perrin: Note that if one Irish registrar gets a waiver, it did
> not mean that all the others automatically got one, even though it was the
> same law and contract
>
>
>
> Dina Solveig Jalkanen: Stephanie, it was interesting to read your
> comments, thanks!
>
>
>
> Louise Marie Hurel: Thank you all
>
>
>
> Rafik: thnks Ayden
>
>
>
> Louise Marie Hurel: Thanks Ayden
>
>
>
> Farzaneh Badii: thanks a lot Ayden
>
>
>
> Stephanie Perrin: Thanks Ayden, great approach to doing comments!
>
>
>
> Joan Kerr: Thanks Ayden, All
>
>
>
> Maryam Bakoshi: Thanks all, good bye
>
>
>
> Farell FOLLY (africa 2.0): thanks well done
>
>
>
> Many thanks,
>
> --
>
> Maryam Bakoshi
>
> Secretariat Support – NCSG/NCUC/NPOC
>
> Internet Corporation for Assigned Names and Numbers (ICANN)
>
> S: maryam.bakoshi.icann
>
> T: +44 7737698036 <+44%207737%20698036>
>
>
>
>
>
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://lists.ncsg.is/pipermail/ncsg-discuss/attachments/20170529/0cd74546/attachment.htm>
More information about the Ncsg-discuss
mailing list