Data Protection and Privacy Update: Seeking Community Feedback on Proposed Compliance Models
Sam Lanfranco
lanfran at YORKU.CA
Tue Jan 16 10:59:47 EET 2018
A short follow up to Ayden's comment "..do not see a need for this issue
to be dealt with jurisdiction-by-jurisdiction".
Of course ICANN should not put itself in a position to have to deal
"jurisdiction-by-jurisdiction". But, there is no way to reduce that
interaction to zero on the part of Registrars operating in various
national jurisdictions. However, ICANN can reduce the burden on
Registrars by (a) a minimalist approach to what data to collect, and (b)
building that minimal set while remaining aware of the state data
privacy legislation. This is a good area to apply the KISS principle, or
more properly the KISSP (Keep it Simple Smart People) principle.
Sam L.
On 1/16/2018 5:02 AM, Ayden Férdeline wrote:
> I too do not see a need for this issue to be dealt with
> jurisdiction-by-jurisdiction. As Rafik and Stephanie have said, there
> is already a common data protection standard — and I would like to
> introduce a piece of research which says that it is indeed the GDPR.
>
> In a paper
> <https://papers.ssrn.com/sol3/papers.cfm?abstract_id=3102810> opened
> for peer review today by Professor Graham Greenleaf, he begins by
> quoting a White Paper released by the Committee of Experts on a Data
> Protection Framework for India:
>
> /"there are two distinct models in the field of data protection’ (an
> EU model, and a US model) (p. 10), and ... the ‘EU model appears to be
> the preferred mode in several countries who have adopted data
> protection legislations recently’ (p. 12)."/
>
> Greenleaf responds to this statement by noting:
>
> /"This is a considerable understatement and a misunderstanding. Over
> 120 countries have now enacted data privacy laws that meet or exceed
> the ‘1st generation’ standard of the 1980s OECD Guidelines and Council
> of Europe Convention 108. Of the 67 of these 120 countries outside
> Europe their average implementation of the ten ‘2nd Generation’
> ‘European’ principles (ie those in the EU Directive of 1995 that go
> beyond the OECD Guidelines), is at least 6/10 principles... The
> reality, therefore, is that *the current global standard of data
> privacy laws even outside Europe, is closer to the EU Directive than
> the OECD Guidelines. The US, with no general data privacy laws, is
> completely out of step with the rest of the world. There is one global
> standard *– and then there is the US, increasingly isolated."/
>
> Emphasis added. References and supporting documents are in the open
> access paper
> <https://papers.ssrn.com/sol3/papers.cfm?abstract_id=3102810>.
>
> WHOIS complying with the GDPR would not see ICANN setting new privacy
> standards; in most cases, it would simply see ICANN complying with the
> letter of the law.
>
> — Ayden
>
>
>> -------- Original Message --------
>> Subject: Re: Data Protection and Privacy Update: Seeking Community
>> Feedback on Proposed Compliance Models
>> Local Time: 15 January 2018 10:32 PM
>> UTC Time: 15 January 2018 21:32
>> From: lanfran at YORKU.CA
>> To: NCSG-DISCUSS at LISTSERV.SYR.EDU
>>
>>
>> John, et. al.,
>>
>> I don't see a conflict here. The name, WHOIS, RDS, etc. is not the
>> issue, nor are accuracy and public access. The "data base" (let's
>> call it RDS for short) needs to indeed be accurate, and we are mainly
>> talking about the ungated (public) version. The basic issue is what
>> constitutes an adequate accurate publicly accessible "RDS". The push
>> for a minimal set of fields is specifically a strategy to ".../stay
>> as close to that as possible in every national jurisdiction where
>> that (that data) is legally allowed/". Does this leave issues for
>> registrars to sort out in various jurisdictions? Sure, just as that
>> is true for other businesses in other fields. A minimal data set
>> reduces the scope for ICANN's contracts to get tangled up in
>> regulations, jurisdiction by jurisdiction.
>>
>> Another issue, where I am odd person out, is the distinction between
>> what are legitimate reasons for collection, and what are legitimate
>> reasons for use. I sort of have "form follows function" baked into my
>> strategy bones. I would have preferred reversing the process and
>> starting with legitimate uses and working back to what to collect,
>> but that boat left port a long time ago.
>>
>> Sam L.
>>
>>
>> On 1/15/2018 2:03 PM, John Carr wrote:
>>>
>>> In the “Affirmation of Commitments”” didn’t ICANN promise to
>>> maintain WHOIS as an accurate and public data base? Shouldn’t the
>>> objective be to stay as close to that as possible in every national
>>> jurisdiction where that is legally allowed?
>>>
>>>
>>> Or has ICANN decided that the promise it made in the Affirmation
>>> should now be formally abandoned or changed?
>>>
>
--
------------------------------------------------
"It is a disgrace to be rich and honoured
in an unjust state" -Confucius
邦有道,贫且贱焉,耻也。邦无道,富且贵焉,耻也
------------------------------------------------
Dr Sam Lanfranco (Prof Emeritus & Senior Scholar)
Econ, York U., Toronto, Ontario, CANADA - M3J 1P3
email: Lanfran at Yorku.ca Skype: slanfranco
blog: https://samlanfranco.blogspot.com
Phone: +1 613-476-0429 cell: +1 416-816-2852
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://lists.ncsg.is/pipermail/ncsg-discuss/attachments/20180116/bffa6ed7/attachment.htm>
More information about the Ncsg-discuss
mailing list