[NCUC-DISCUSS] Update #1 GNSO EPDP on Temporary Specification for gTLD Registration Data

Stephanie Perrin stephanie.perrin at MAIL.UTORONTO.CA
Sun Aug 5 17:29:32 EEST 2018


Amr is correct, in that the GDPR is not the key factor here.  If a 
Chinese Court or law enforcement authority wants to get data they have a 
right to get according to Chinese law, all they have to do is ask the 
registrar for it, and provide evidence of their authority.  They most 
certainly do not have to ask the Article 29 committee, nor the European 
Data Protection Board which replaces it.  They also are not limited to 
China-based registrars and registries, if an action is required 
concerning a .com registration, for instance, they may certainly inquire 
at the relevant registrar.

The only thing that has changed is that ICANN cannot force a registrar 
to break the data protection law by publishing personal data in the 
WHOIS.  This was always true, but the consequences of breaking the law 
(fines) and the likelihood of enforcement have radically changed under 
the GDPR.

Stephanie Perrin

On 2018-08-05 18:00, Amr Elsadr wrote:
> Hi Zhou Heng,
>
> I’m not subscribed to the NCUC-DISCUSS list, so I hope you don’t mind 
> me switching the recipient of this email to NCSG-DISCUSS.
>
> If I understand your comment below correctly, I don’t agree with it. 
> Let me explain why.
>
> The topic of this EPDP (Expedited Policy Development Process) has a 
> very narrow scope as set by the Charter 
> <https://community.icann.org/display/EOTSFGRD/EPDP+Team+Charter> adopted 
> by the GNSO Council, which is to review the temporary specification on 
> gTLD registration data 
> <https://www.icann.org/resources/pages/gtld-registration-data-specs-en> adopted 
> by the ICANN Board. The EPDP Team is tasked to recommend whether this 
> specification should be adopted via a GNSO process as-is, or whether 
> changes should be recommended. The whole purpose of the temporary 
> specification was to ensure that ICANN, through its contracts with 
> contracted parties (gTLD Registry Operators and Registrars) does not 
> require these parties to process and disclose gTLD domain name 
> registration data in a manner that conflicts with the EU GDPR. So the 
> narrow scope here does not cover other privacy/data protection 
> regimes, and a narrowly scoped policy issue is required in order for 
> the GNSO Council to initiate an Expedited PDP, as opposed to a 
> traditional PDP.
>
> However, this does not mean that only EU-based actors need to be 
> consulted. Note that there are several non-EU based members on the 
> EPDP Team, as the GDPR affects not only contracted parties that are 
> geographically based in the EU, but also any party that serves 
> EU-based customers, as well as stakeholders around the world that have 
> an interest in accessing this data.
>
> Furthermore, the hypothetical scenario that you describe is not 
> accurate. If a Chinese court requires a China-based registrar to 
> disclose data on a registrant located in China, the GDPR is not to my 
> knowledge at all applicable. That would mean that in this scenario, 
> this temporary specification is also not applicable.
>
> I’m multitasking right now, so hope that my explanation is helpful and 
> clear enough, and that I have not misrepresented the facts. I am happy 
> to be corrected, if I am wrong. Perhaps others would like to weigh in.
>
> Thanks.
>
> Amr
>
>> On Aug 5, 2018, at 2:47 PM, Zhou Heng <socata at ruc.edu.cn 
>> <mailto:socata at ruc.edu.cn>> wrote:
>>
>> Dear Community and EPDP WG members,
>>
>> I would like to make one comment towards the Temporary Specification:
>>
>> 26.PleaseconsiderAppendixA:RegistrationDataDirectoryServices
>>
>> 4.1.RegistrarandRegistryOperatorMUSTprovidereasonableaccesstoPersonalDatainRegistrationDatatothirdpartiesonthebasisofalegitimateinterestspursuedbythethirdparty,exceptwheresuchinterestsareoverriddenbytheinterestsorfundamentalrightsandfreedomsoftheRegisteredNameHolderordatasubjectpursuanttoArticle6(1)(f)GDPR.
>>
>> 4.2.NotwithstandingSection4.1ofthisAppendix,RegistrarandRegistryOperatorMUSTprovidereasonable 
>> access toPersonal Datain Registration Datato athird party 
>> wheretheArticle 29 
>> WorkingParty/EuropeanDataProtectionBoard,courtorderofarelevantcourtofcompetentjurisdictionconcerningtheGDPR, 
>> applicable legislation or regulation has provided guidance that the 
>> provision of specified 
>> non-publicelementsofRegistrationDatatoaspecifiedclassofthirdpartyforaspecifiedpurposeislawful.
>> RegistrarandRegistryOperatorMUSTprovidesuchreasonableaccesswithin90daysofthe
>>
>> dateICANNpublishesanysuchguidance,unlesslegalrequirementsotherwisedemandanearlierimplementation.
>>
>>
>> As I have said in this mail-list, ICANN is an organization running 
>> for the Global Internet Key infrastructure Resource; hence, the 
>> regulation made by ICANN should consider the opinion not only from 
>> EU, but from the Global Community. The expression from article 4.1/ 
>> 4.2 of appendix A here indicates that even if a court from China 
>> wants the details data from a registrar based in China, they may 
>> require the permission from Article 29 WG or follow the instruction 
>> from article 6(1)(f) of GDPR, which would be probably inappropriate.
>>
>> If I have any  misunderstanding towards this regulation, or you have 
>> any words towards this issue, please do not hesitate to contact me. I 
>> am looking forward the response, thanks!
>>
>> Best regards
>>
>>
>>
>> --
>> Zhou Heng
>> Ph.d Candidate
>> Renmin University of China
>>
>> 在 2018-08-03 22:40:54,Amr Elsadr <aelsadr at ICANNPOLICY.NINJA 
>> <mailto:aelsadr at ICANNPOLICY.NINJA>> 写道:
>>
>>     Hi,
>>
>>     The first GNSO EPDP on Temporary Specification for gTLD
>>     Registration Data took place on Wednesday, 1 August 2018. The
>>     notes, action items and recordings for this call can be found on
>>     the meeting’s wiki page here: https://community.icann.org/x/ugBpBQ
>>
>>     As per action item 5 (which I believe should be action item 6),
>>     the NCSG appointed members and alternates are considering our
>>     responses to the first part of a 4-part survey. The first part of
>>     the survey is due on Monday, 6 August 2018 at 19:00 UTC. This
>>     deadline is in a few days, as the responses provided by the
>>     different GNSO SGs/Cs, as well as the different ICANN SOs/ACs
>>     participating in the EPDP will be reviewed during the next EPDP
>>     Team call on Tuesday, 7 August 2018.
>>
>>     We’ve created a google doc to collaborate on the responses we
>>     submit. You can find this google doc here:
>>     https://docs.google.com/document/d/1GcE0Q_Fq8rXF8_Dt_bcNDdp5-1uKwcRRJjKmQbnkvoQ/edit?usp=sharing
>>
>>     Permission rights for the google doc only allow NCSG-appointed
>>     members and alternates of the EPDP Team to comment and edit the
>>     document, but anyone with the link can view it. So if anyone
>>     within the broader NCSG membership has comments or input, please
>>     start a new thread to share and discuss those here on NCSG-DISCUSS.
>>
>>     For those who don’t have access to google services, staff have
>>     exported the survey questions to a MS Word document, which is
>>     attached to this email. You won’t be able to view any edits or
>>     comments made on the google doc, but this is the best we could
>>     right now (apologies for that).
>>
>>     If you have any additional questions for your representatives on
>>     the EPDP Team, please don’t hesitate to ask.
>>
>>     Thanks.
>>
>>     Amr
>>
>>
>> _______________________________________________
>> Ncuc-discuss mailing list
>> Ncuc-discuss at lists.ncuc.org <mailto:Ncuc-discuss at lists.ncuc.org>
>> https://lists.ncuc.org/cgi-bin/mailman/listinfo/ncuc-discuss
>
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://lists.ncsg.is/pipermail/ncsg-discuss/attachments/20180805/748bffee/attachment.htm>


More information about the Ncsg-discuss mailing list