Data Protection and Privacy Update: Seeking Community Feedback on Proposed Compliance Models

Sam Lanfranco lanfran at YORKU.CA
Tue Jan 16 10:59:47 EET 2018


A short follow up to Ayden's comment "..do not see a need for this issue 
to be dealt with jurisdiction-by-jurisdiction".

Of course ICANN should not put itself in a position to have to deal 
"jurisdiction-by-jurisdiction". But, there is no way to reduce that 
interaction to zero on the part of Registrars operating in various 
national jurisdictions. However, ICANN can reduce the burden on 
Registrars by (a) a minimalist approach to what data to collect, and (b) 
building that minimal set while remaining aware of the state data 
privacy legislation. This is a good area to apply the KISS principle, or 
more properly the KISSP (Keep it Simple Smart People) principle.

Sam L.


On 1/16/2018 5:02 AM, Ayden Férdeline wrote:
> I too do not see a need for this issue to be dealt with 
> jurisdiction-by-jurisdiction. As Rafik and Stephanie have said, there 
> is already a common data protection standard — and I would like to 
> introduce a piece of research which says that it is indeed the GDPR.
>
> In a paper 
> <https://papers.ssrn.com/sol3/papers.cfm?abstract_id=3102810> opened 
> for peer review today by Professor Graham Greenleaf, he begins by 
> quoting a White Paper released by the Committee of Experts on a Data 
> Protection Framework for India:
>
> /"there are two distinct models in the field of data protection’ (an 
> EU model, and a US model) (p. 10), and ... the ‘EU model appears to be 
> the preferred mode in several countries who have adopted data 
> protection legislations recently’ (p. 12)."/
>
> Greenleaf responds to this statement by noting:
>
> /"This is a considerable understatement and a misunderstanding. Over 
> 120 countries have now enacted data privacy laws that meet or exceed 
> the ‘1st generation’ standard of the 1980s OECD Guidelines and Council 
> of Europe Convention 108. Of the 67 of these 120 countries outside 
> Europe their average implementation of the ten ‘2nd Generation’ 
> ‘European’ principles (ie those in the EU Directive of 1995 that go 
> beyond the OECD Guidelines), is at least 6/10 principles... The 
> reality, therefore, is that *the current global standard of data 
> privacy laws even outside Europe, is closer to the EU Directive than 
> the OECD Guidelines. The US, with no general data privacy laws, is 
> completely out of step with the rest of the world. There is one global 
> standard *– and then there is the US, increasingly isolated."/
>
> Emphasis added. References and supporting documents are in the open 
> access paper 
> <https://papers.ssrn.com/sol3/papers.cfm?abstract_id=3102810>.
>
> WHOIS complying with the GDPR would not see ICANN setting new privacy 
> standards; in most cases, it would simply see ICANN complying with the 
> letter of the law.
>
> — Ayden
>
>
>> -------- Original Message --------
>> Subject: Re: Data Protection and Privacy Update: Seeking Community 
>> Feedback on Proposed Compliance Models
>> Local Time: 15 January 2018 10:32 PM
>> UTC Time: 15 January 2018 21:32
>> From: lanfran at YORKU.CA
>> To: NCSG-DISCUSS at LISTSERV.SYR.EDU
>>
>>
>> John, et. al.,
>>
>> I don't see a conflict here. The name, WHOIS, RDS, etc. is not the 
>> issue, nor are accuracy and public access. The "data base" (let's 
>> call it RDS for short) needs to indeed be accurate, and we are mainly 
>> talking about the ungated (public) version. The basic issue is what 
>> constitutes an adequate accurate publicly accessible "RDS".  The push 
>> for a minimal set of fields is specifically a strategy to ".../stay 
>> as close to that as possible in every national jurisdiction where 
>> that (that data) is legally allowed/". Does this leave issues for 
>> registrars to sort out in various jurisdictions? Sure, just as that 
>> is true for other businesses in other fields. A minimal data set 
>> reduces the scope for ICANN's contracts to get tangled up in 
>> regulations, jurisdiction by jurisdiction.
>>
>> Another issue, where I am odd person out, is the distinction between 
>> what are legitimate reasons for collection, and what are legitimate 
>> reasons for use. I sort of have "form follows function" baked into my 
>> strategy bones. I would have preferred reversing the process and 
>> starting with legitimate uses and working back to what to collect, 
>> but that boat left port a long time ago.
>>
>> Sam L.
>>
>>
>> On 1/15/2018 2:03 PM, John Carr wrote:
>>>
>>> In the “Affirmation of Commitments”” didn’t ICANN promise to 
>>> maintain WHOIS as an accurate and public data base? Shouldn’t the 
>>> objective be to stay as close to that as possible in every national 
>>> jurisdiction where that is legally allowed?
>>>
>>>
>>> Or has ICANN decided that the promise it made in the Affirmation 
>>> should now be formally abandoned or changed?
>>>
>

-- 
------------------------------------------------
"It is a disgrace to be rich and honoured
in an unjust state" -Confucius
  邦有道,贫且贱焉,耻也。邦无道,富且贵焉,耻也
------------------------------------------------
Dr Sam Lanfranco (Prof Emeritus & Senior Scholar)
Econ, York U., Toronto, Ontario, CANADA - M3J 1P3
email: Lanfran at Yorku.ca   Skype: slanfranco
blog:  https://samlanfranco.blogspot.com
Phone: +1 613-476-0429 cell: +1 416-816-2852

-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://lists.ncsg.is/pipermail/ncsg-discuss/attachments/20180116/bffa6ed7/attachment.htm>


More information about the Ncsg-discuss mailing list