Data Protection and Privacy Update: Seeking Community Feedback on Proposed Compliance Models
Sam Lanfranco
lanfran at YORKU.CA
Sun Jan 14 10:58:53 EET 2018
Colleagues,
I may have an overly simplistic view of the issue here, but I would like
to put it on the table. ICANN has a narrow remit within the growing area
of global, regional (e.g. EU), and national Internet governance. It
exercises that remit through a serious of contracts with entities
(registrars and registries) that operate under diverse national Internet
governance jurisdictions.
With differing specific data protection language in diverse contexts, it
is highly unlikely that ICANN can draft “higher standard” contract
language that will satisfy the data privacy regulations of all, most, or
even many, national data privacy regimes. So, what is the path forward here?
There seem to be two components of a path forward. First, ICANN must
figure out how it exercises ICANN agency as a stakeholder in the various
legislative policy venues in which data privacy and other Internet
governance policy is debated and where regulations are formed. Some
ICANN stakeholders already “have skin in those games” and are already
present in those policy debates. ICANN writes contract language and
needs to be engaged as a stakeholder.
Second, in contrast to seeking “higher standard” contract language,
ICANN may need to look for “minimum conditions” contract language that
offers contracted parties maximum freedom to negotiate with and meet the
conditions of national Internet governance policies. At the same time
ICANN can use its agency as a stakeholder to press for “higher standard”
national policies that harmonize regulations, and facilitate the work
and interests of various stakeholders in the Internet ecosystem.
In short, the path forward may be (a) more ICANN agency as a
stakeholder, and (b) minimal contract language to maximize the ability
of contracted parties to deal with national policies and regulations.
Sam L.
On 1/14/2018 10:02 AM, Ayden Férdeline wrote:
> Hi Caleb,
>
> While I appreciate that not all countries have data protection laws,
> privacy remains a fundamental human right. My suggestion is thus that
> we should adopt the highest level of protection for all domain name
> registrants. And I suspect it is a lot easier to implement one model,
> rather than fragmented models for different jurisdictions.
>
> Please also remember that ICANN sets policy by contract; i.e.
> registries, registrars, and registrants agree by contract to follow
> the rules and policies created by ICANN, and these policies can be
> revised and deleted. So while ICANN must of course comply with the
> law, it can adopt and impose a higher standard on the contracted parties.
>
> Many thanks,
>
> Ayden
>
>
>
>> -------- Original Message --------
>> Subject: Re: Data Protection and Privacy Update: Seeking Community
>> Feedback on Proposed Compliance Models
>> Local Time: 14 January 2018 3:56 PM
>> UTC Time: 14 January 2018 14:56
>> From: muyiwacaleb at GMAIL.COM
>> To: NCSG-DISCUSS at LISTSERV.SYR.EDU
>>
>> Hello Badii and Ayden,
>>
>> For me, i think the Model 2A serves the purposes. Don't forget that
>> not all countries have data protection laws or policy in place.
>> Hence, based on jurisdiction, they cannot be governed by laws that is
>> peculiar to a certain continent or sovereign state.
>>
>> Caleb Ogundele
>>
>> On Sun, Jan 14, 2018 at 3:36 PM, Ayden Férdeline <icann at ferdeline.com
>> <mailto:icann at ferdeline.com>> wrote:
>>
>> I could live with the second model.
>>
>> The key differentiation between Model 2A and 2B is its
>> applicability: 2A applies only "where the registrant, registry,
>> registrar or a processor are located in the European Economic
>> Area"; 2B "applies to all registrations on a global basis without
>> regard to location of registry, registrar registrant, and
>> processing activities"
>>
>> On this basis I think Model 2B is the best path forward. To have
>> fragmented approaches for different regions would be a mistake,
>> in my opinion.
>>
>> Given the short turnaround time here (we need to agree on a
>> position and submit a comment by 29 January) and other obstacles
>> between now and then (Intersessional, GNSO Council Strategic
>> Planning Session), may I suggest that we schedule a call next
>> week to discuss our response?
>>
>> Best wishes, Ayden
>>
>>
>>> -------- Original Message --------
>>> Subject: Data Protection and Privacy Update: Seeking Community
>>> Feedback on Proposed Compliance Models
>>> Local Time: 13 January 2018 7:40 PM
>>> UTC Time: 13 January 2018 18:40
>>> From: farzaneh.badii at GMAIL.COM <mailto:farzaneh.badii at GMAIL.COM>
>>> To: NCSG-DISCUSS at LISTSERV.SYR.EDU
>>> <mailto:NCSG-DISCUSS at LISTSERV.SYR.EDU>
>>>
>>> Please see the CEO blog on Data protection and privacy:
>>>
>>> https://www.icann.org/news/blog/data-protection-and-privacy-update-seeking-community-feedback-on-proposed-compliance-models
>>> <https://www.icann.org/news/blog/data-protection-and-privacy-update-seeking-community-feedback-on-proposed-compliance-models>
>>>
>>> We should understand these models, discuss them and provide
>>> feedback.
>>>
>>> Best
>>> Farzaneh
>>
>>
>>
>>
>> --
>> *Ogundele Olumuyiwa Caleb*
>> /*muyiwacaleb at gmail.com <mailto:muyiwacaleb at gmail.com>*/
>> /*234 - 8077377378*/
>> /*234 - 07030777969*/
>
--
------------------------------------------------
"It is a disgrace to be rich and honoured
in an unjust state" -Confucius
邦有道,贫且贱焉,耻也。邦无道,富且贵焉,耻也
------------------------------------------------
Dr Sam Lanfranco (Prof Emeritus & Senior Scholar)
Econ, York U., Toronto, Ontario, CANADA - M3J 1P3
email: Lanfran at Yorku.ca Skype: slanfranco
blog: https://samlanfranco.blogspot.com
Phone: +1 613-476-0429 cell: +1 416-816-2852
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://lists.ncsg.is/pipermail/ncsg-discuss/attachments/20180114/735689b3/attachment.htm>
More information about the Ncsg-discuss
mailing list