Data Protection and Privacy Update: Seeking Community Feedback on Proposed Compliance Models
Kathy Kleiman
kathy at KATHYKLEIMAN.COM
Tue Jan 16 11:13:16 EET 2018
+1 to Jyoti's comments. I've read the same article and in fact, 2015
was the "tipping point" when more countries in the world had adopted
comprehensive data protection laws (following the model of Europe) than
sectoral privacy laws (following the model of the US). Countries outside
of Europe with *comprehensive data protection laws *include Japan,
Canada, Indonesia, Israel, Qatar, Antigua & Barbuda, Chad, Bermuda,
Malawi and many more. And as Jyoti points out, the number is growing
with Panama and other countries in the process of drafting their
comprehensive data protection laws.
I also agree with Ayden that Model 2B best covers both the current trend
in data protection laws, and the current comprehensive data protection
laws adopted by a majority of countries around the world. +1 that for
ICANN to have "fragmented approaches for different regions would be a
mistake."
Best, Kathy
On 1/16/2018 6:41 AM, Jyoti Panday wrote:
> Hi,
>
> Research by Graham Greeleaf analyzing data privacy laws in over 120
> countries shows that current global standard of data privacy laws even
> outside Europe is closer to the EU Directive than the OECD Guidelines
> and suggests how the US standard is increasingly isolated.
> The article concludes that expansion of Convention 108 beyond Europe,
> reinforced by developments in EU and African Union make it the only
> viable global data privacy treaty standard. However, he cautions that
> the international environment provides no guarantee that this
> expansion will continue.
>
> https://papers.ssrn.com/sol3/papers.cfm?abstract_id=2993035
>
> Jyoti.
>
> On 15/01/2018 07:24, Rafik Dammak wrote:
>> Hi,
>>
>> GDPR is not that different from data protection legislation following
>> the Council of Europe 109 Convention (which is signed by several
>> countries outside Europe including mine) and so it is a common
>> standard in many of its principles. it added more enforcement.
>> Following it would make more sense in term of implementation and
>> offering a stronger protections to registrants.
>> GDPR has the merit to highlight how whois is misused in the first
>> place and how it put user rights in danger. We have to move from this
>> situation and ensure a better data protection for all registrants,
>> something that is is among our advocacy goals.
>>
>> Best,
>>
>> Rafik
>>
>> 2018-01-15 0:58 GMT+09:00 Sam Lanfranco <lanfran at yorku.ca
>> <mailto:lanfran at yorku.ca>>:
>>
>> Colleagues,
>>
>> I may have an overly simplistic view of the issue here, but I
>> would like to put it on the table. ICANN has a narrow remit
>> within the growing area of global, regional (e.g. EU), and
>> national Internet governance. It exercises that remit through a
>> serious of contracts with entities (registrars and registries)
>> that operate under diverse national Internet governance
>> jurisdictions.
>>
>> With differing specific data protection language in diverse
>> contexts, it is highly unlikely that ICANN can draft “higher
>> standard” contract language that will satisfy the data privacy
>> regulations of all, most, or even many, national data privacy
>> regimes. So, what is the path forward here?
>>
>> There seem to be two components of a path forward. First, ICANN
>> must figure out how it exercises ICANN agency as a stakeholder in
>> the various legislative policy venues in which data privacy and
>> other Internet governance policy is debated and where regulations
>> are formed. Some ICANN stakeholders already “have skin in those
>> games” and are already present in those policy debates. ICANN
>> writes contract language and needs to be engaged as a stakeholder.
>>
>> Second, in contrast to seeking “higher standard” contract
>> language, ICANN may need to look for “minimum conditions”
>> contract language that offers contracted parties maximum freedom
>> to negotiate with and meet the conditions of national Internet
>> governance policies. At the same time ICANN can use its agency as
>> a stakeholder to press for “higher standard” national policies
>> that harmonize regulations, and facilitate the work and interests
>> of various stakeholders in the Internet ecosystem.
>>
>> In short, the path forward may be (a) more ICANN agency as a
>> stakeholder, and (b) minimal contract language to maximize the
>> ability of contracted parties to deal with national policies and
>> regulations.
>>
>> Sam L.
>>
>>
>>
>> On 1/14/2018 10:02 AM, Ayden Férdeline wrote:
>>> Hi Caleb,
>>>
>>> While I appreciate that not all countries have data protection
>>> laws, privacy remains a fundamental human right. My suggestion
>>> is thus that we should adopt the highest level of protection for
>>> all domain name registrants. And I suspect it is a lot easier to
>>> implement one model, rather than fragmented models for different
>>> jurisdictions.
>>>
>>> Please also remember that ICANN sets policy by contract; i.e.
>>> registries, registrars, and registrants agree by contract to
>>> follow the rules and policies created by ICANN, and these
>>> policies can be revised and deleted. So while ICANN must of
>>> course comply with the law, it can adopt and impose a higher
>>> standard on the contracted parties.
>>>
>>> Many thanks,
>>>
>>> Ayden
>>>
>>>
>>>
>>>> -------- Original Message --------
>>>> Subject: Re: Data Protection and Privacy Update: Seeking
>>>> Community Feedback on Proposed Compliance Models
>>>> Local Time: 14 January 2018 3:56 PM
>>>> UTC Time: 14 January 2018 14:56
>>>> From: muyiwacaleb at GMAIL.COM <mailto:muyiwacaleb at GMAIL.COM>
>>>> To: NCSG-DISCUSS at LISTSERV.SYR.EDU
>>>> <mailto:NCSG-DISCUSS at LISTSERV.SYR.EDU>
>>>>
>>>> Hello Badii and Ayden,
>>>>
>>>> For me, i think the Model 2A serves the purposes. Don't forget
>>>> that not all countries have data protection laws or policy in
>>>> place.
>>>> Hence, based on jurisdiction, they cannot be governed by laws
>>>> that is peculiar to a certain continent or sovereign state.
>>>>
>>>> Caleb Ogundele
>>>>
>>>> On Sun, Jan 14, 2018 at 3:36 PM, Ayden Férdeline
>>>> <icann at ferdeline.com <mailto:icann at ferdeline.com>> wrote:
>>>>
>>>> I could live with the second model.
>>>>
>>>> The key differentiation between Model 2A and 2B is its
>>>> applicability: 2A applies only "where the registrant,
>>>> registry, registrar or a processor are located in the
>>>> European Economic Area"; 2B "applies to all registrations
>>>> on a global basis without regard to location of registry,
>>>> registrar registrant, and processing activities"
>>>>
>>>> On this basis I think Model 2B is the best path forward. To
>>>> have fragmented approaches for different regions would be a
>>>> mistake, in my opinion.
>>>>
>>>> Given the short turnaround time here (we need to agree on a
>>>> position and submit a comment by 29 January) and other
>>>> obstacles between now and then (Intersessional, GNSO
>>>> Council Strategic Planning Session), may I suggest that we
>>>> schedule a call next week to discuss our response?
>>>>
>>>> Best wishes, Ayden
>>>>
>>>>
>>>>> -------- Original Message --------
>>>>> Subject: Data Protection and Privacy Update: Seeking
>>>>> Community Feedback on Proposed Compliance Models
>>>>> Local Time: 13 January 2018 7:40 PM
>>>>> UTC Time: 13 January 2018 18:40
>>>>> From: farzaneh.badii at GMAIL.COM
>>>>> <mailto:farzaneh.badii at GMAIL.COM>
>>>>> To: NCSG-DISCUSS at LISTSERV.SYR.EDU
>>>>> <mailto:NCSG-DISCUSS at LISTSERV.SYR.EDU>
>>>>>
>>>>> Please see the CEO blog on Data protection and privacy:
>>>>>
>>>>> https://www.icann.org/news/blog/data-protection-and-privacy-update-seeking-community-feedback-on-proposed-compliance-models
>>>>> <https://www.icann.org/news/blog/data-protection-and-privacy-update-seeking-community-feedback-on-proposed-compliance-models>
>>>>>
>>>>> We should understand these models, discuss them and
>>>>> provide feedback.
>>>>>
>>>>> Best
>>>>> Farzaneh
>>>>
>>>>
>>>>
>>>>
>>>> --
>>>> *Ogundele Olumuyiwa Caleb*
>>>> /*muyiwacaleb at gmail.com <mailto:muyiwacaleb at gmail.com>*/
>>>> /*234 - 8077377378*/
>>>> /*234 - 07030777969 <tel:070-3077-7969>*/
>>>
>>
>> --
>> ------------------------------------------------
>> "It is a disgrace to be rich and honoured
>> in an unjust state" -Confucius
>> 邦有道,贫且贱焉,耻也。邦无道,富且贵焉,耻也
>> ------------------------------------------------
>> Dr Sam Lanfranco (Prof Emeritus & Senior Scholar)
>> Econ, York U., Toronto, Ontario, CANADA - M3J 1P3
>> email:Lanfran at Yorku.ca <mailto:Lanfran at Yorku.ca> Skype: slanfranco
>> blog:https://samlanfranco.blogspot.com <https://samlanfranco.blogspot.com>
>> Phone:+1 613-476-0429 <tel:+1%20613-476-0429> cell:+1 416-816-2852 <tel:+1%20416-816-2852>
>>
>>
>
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://lists.ncsg.is/pipermail/ncsg-discuss/attachments/20180116/a98abf47/attachment.htm>
More information about the Ncsg-discuss
mailing list