ICANN Response to Art 29 WP

Ayden Férdeline icann at FERDELINE.COM
Fri Apr 13 07:23:45 EEST 2018


It is disappointing (but sadly not surprising) that ICANN would issue this biased media release. I only wish they had read the advice that the Article 29 Working Party shared in their letter, and which ICANN has been asking for, as it clearly states (emphasis added):

"ICANN should take care in defining purposes in a manner which corresponds to its own organisational mission and mandate, which is to coordinate the stable operation of the Internet’s unique identifier systems. Purposes pursued by other interested third parties should not determine the purposes pursued by ICANN. The WP29 cautions ICANN not to conflate its own purposes with the interests of third parties, nor with the lawful grounds of processing which may be applicable in a particular case."

So their scenarios are irrelevant. And as Rubens Kuhl noted on the GNSO Council mailing list yesterday, "[WHOIS is already fragmented today.](https://mm.icann.org/pipermail/council/2018-April/021182.html)"

ICANN org's strategy here is very unclear, and it is certainly my impression that it is not informed by good legal advice or any consultation with data protection experts.

Ayden Férdeline

‐‐‐‐‐‐‐ Original Message ‐‐‐‐‐‐‐
On 13 April 2018 2:00 PM, Collin Kurre <collin at ARTICLE19.ORG> wrote:

> This is a topic that has the potential to draw the attention of actors with little to no knowledge about ICANN’s structure and remit. With that in mind, one of the (many) things that I find problematic about this response the imprecision in language, particularly in the bulleted list of “potentially adverse scenarios”.
>
> Take the last point for example: that a fragmented WHOIS would “make it significantly harder to identify fake news and impact the ability to take action against bad actors.” Who is the agent of action here, real or perceived? What is the role of WHOIS and ICANN in determining or rectifying fake news? The lack of clarity could easily be interpreted as an invitation to actors seeking to leverage the DNS for content regulation.
>
> Disappointing to see such a knee-jerk response to Article 29’s thorough contribution.
>
> Best,
> Collin Kurre
>
>> On Apr 12, 2018, at 11:06 PM, farzaneh badii <[farzaneh.badii at GMAIL.COM](mailto:farzaneh.badii at gmail.com)> wrote:
>>
>> And here is ICANN's response to Article 29 WP.
>>
>> Farzaneh
>>
>> ----
>>
>> Please see our [most recent announcement](https://www.icann.org/news/announcement-2018-04-12-en) regarding the [letter](https://www.icann.org/en/system/files/correspondence/jelinek-to-marby-11apr18-en.pdf) from the Article 29 Working Party. The letter was published on our [main Correspondence page](https://www.icann.org/resources/pages/correspondence), and linked to our [Data Protection/Privacy page](https://www.icann.org/dataprotectionprivacy).
>>
>> ----------------------------------
>>
>> ICANN Receives Data Protection/Privacy Guidance from Article 29 Working Party
>>
>> LOS ANGELES – 12 April 2018 – The Internet Corporation for Assigned Names and Numbers ("ICANN") today announced that it has received a [letter from the Article 29 Working Party (WP29)](https://www.icann.org/en/system/files/correspondence/jelinek-to-marby-11apr18-en.pdf) [PDF, 400 KB] that provides guidance on the European Union's General Data Protection Regulation (GDPR) and its impact on the collection, retention and publication of domain name registration data and the WHOIS system. ICANN organization’s response to the letter from the Article 29 Working Party will be published shortly [here](https://www.icann.org/resources/pages/correspondence).
>>
>> “We appreciate the guidance provided by the Article 29 Working Party on this important issue and have accepted an invitation to meet with the WP29 Technology Subgroup in Brussels on 23 April for further discussions,” said Göran Marby, ICANN president and CEO. “However, we are disappointed that the letter does not mention our request for a moratorium on enforcement of the law until we implement a model. Without a moratorium on enforcement, WHOIS will become fragmented and we must take steps to mitigate this issue. As such, we are studying all available remedies, including legal action in Europe to clarify our ability to continue to properly coordinate this important global information resource. We will provide more information in the coming days.”
>>
>> A moratorium on enforcement action by DPAs would potentially allow for the introduction of an agreed-upon accreditation model and for the registries and registrars to implement the accreditation model in conjunction with the measures in the agreed final interim compliance model. It will also allow for reconciliation between the advice ICANN has received from its Governmental Advisory Committee (GAC) and the Article 29 Working Party. Unless there is a moratorium, we may no longer be able to give instructions to the contracted parties through our agreements to maintain WHOIS. Without resolution of these issues, the WHOIS system will become fragmented until the interim compliance model and the accreditation model are implemented.
>>
>> A fragmented WHOIS would no longer employ a common framework for generic top-level domain (gTLD) registration directory services. Registries and registrars would likely implement varying levels of access to data depending on their interpretations of the law.
>>
>> “In parallel, we will carefully consider this advice, along with all of the input we have received from the multistakeholder community, before making changes to the current iteration of the [proposed interim model](https://www.icann.org/en/system/files/files/gdpr-compliance-interim-model-08mar18-en.pdf),” Marby continued. “As a part of this, we will explore all options as we continue dialogues with DPAs and the interested parties that comprise the multistakeholder community.”
>>
>> It’s important to balance the right to privacy with the need for information. While ICANN recognizes the importance of the GDPR and its goal of protecting personal data, parts of the ICANN community have noted the negative impact of a fragmented WHOIS. For example, it will hinder the ability of law enforcement to get important information and the anti-spam community to help ensure the Internet protects end-users. It will also:
>>
>> - Protect the identity of criminals who may register hundreds of domain names specifically for use in cyberattacks;
>> - Hamper the ability of consumer protection agencies who track the traffic patterns of illicit businesses;
>> - Stymie trademark holders from protecting intellectual property; and
>> - Make it significantly harder to identify fake news and impact the ability to take action against bad actors.
>>
>> These are just a few examples from a long list of potentially adverse scenarios.
>>
>> Marby also requested that the DPAs include ICANN in any proceedings relating to WHOIS, and asks that it be included in all discussions and actions of the privacy regulators with the other WHOIS data controllers. He also said that ICANN org is continuing its efforts to prepare for implementation of a new model. Additional information on ICANN’s data protection/privacy activities, including legal analyses, proposed compliance models, and community feedback is published [here](https://www.icann.org/dataprotectionprivacy).
>>
>> We encourage the community to provide feedback and continue our dialogues on future activities. You may share your views with us via email at gdpr at icann.org.
>>
>> _______________________________________________
>> So-ac-sg-cleaders mailing list
>> So-ac-sg-cleaders at icann.org
>> https://mm.icann.org/mailman/listinfo/so-ac-sg-cleaders
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://lists.ncsg.is/pipermail/ncsg-discuss/attachments/20180413/41cad68e/attachment.htm>


More information about the Ncsg-discuss mailing list