Data Protection and Privacy Update: Seeking Community Feedback on Proposed Compliance Models

Ayden Férdeline icann at FERDELINE.COM
Tue Jan 16 11:23:13 EET 2018


Hi Sam,

Of the three proposed models that ICANN is now seeking comments on, which do you think would best allow ICANN to apply the KISSP principle?

Thanks,

Ayden

Sent from ProtonMail Mobile

On Wed, Jan 17, 2018 at 02:59, Sam Lanfranco <lanfran at YORKU.CA> wrote:

> A short follow up to Ayden's comment "..do not see a need for this issue to be dealt with jurisdiction-by-jurisdiction".
>
> Of course ICANN should not put itself in a position to have to deal "jurisdiction-by-jurisdiction". But, there is no way to reduce that interaction to zero on the part of Registrars operating in various national jurisdictions. However, ICANN can reduce the burden on Registrars by (a) a minimalist approach to what data to collect, and (b) building that minimal set while remaining aware of the state data privacy legislation. This is a good area to apply the KISS principle, or more properly the KISSP (Keep it Simple Smart People) principle.
>
> Sam L.
>
> On 1/16/2018 5:02 AM, Ayden Férdeline wrote:
>
>> I too do not see a need for this issue to be dealt with jurisdiction-by-jurisdiction. As Rafik and Stephanie have said, there is already a common data protection standard — and I would like to introduce a piece of research which says that it is indeed the GDPR.
>>
>> [In a paper](https://papers.ssrn.com/sol3/papers.cfm?abstract_id=3102810) opened for peer review today by Professor Graham Greenleaf, he begins by quoting a White Paper released by the Committee of Experts on a Data Protection Framework for India:
>>
>> "there are two distinct models in the field of data protection’ (an EU model, and a US model) (p. 10), and ... the ‘EU model appears to be the preferred mode in several countries who have adopted data protection legislations recently’ (p. 12)."
>>
>> Greenleaf responds to this statement by noting:
>>
>> "This is a considerable understatement and a misunderstanding. Over 120 countries have now enacted data privacy laws that meet or exceed the ‘1st generation’ standard of the 1980s OECD Guidelines and Council of Europe Convention 108. Of the 67 of these 120 countries outside Europe their average implementation of the ten ‘2nd Generation’ ‘European’ principles (ie those in the EU Directive of 1995 that go beyond the OECD Guidelines), is at least 6/10 principles... The reality, therefore, is that the current global standard of data privacy laws even outside Europe, is closer to the EU Directive than the OECD Guidelines. The US, with no general data privacy laws, is completely out of step with the rest of the world. There is one global standard – and then there is the US, increasingly isolated."
>>
>> Emphasis added. References and supporting documents are in the [open access paper](https://papers.ssrn.com/sol3/papers.cfm?abstract_id=3102810).
>>
>> WHOIS complying with the GDPR would not see ICANN setting new privacy standards; in most cases, it would simply see ICANN complying with the letter of the law.
>>
>> — Ayden
>>
>>> -------- Original Message --------
>>> Subject: Re: Data Protection and Privacy Update: Seeking Community Feedback on Proposed Compliance Models
>>> Local Time: 15 January 2018 10:32 PM
>>> UTC Time: 15 January 2018 21:32
>>> From: lanfran at YORKU.CA
>>> To: NCSG-DISCUSS at LISTSERV.SYR.EDU
>>>
>>> John, et. al.,
>>>
>>> I don't see a conflict here. The name, WHOIS, RDS, etc. is not the issue, nor are accuracy and public access. The "data base" (let's call it RDS for short) needs to indeed be accurate, and we are mainly talking about the ungated (public) version. The basic issue is what constitutes an adequate accurate publicly accessible "RDS".  The push for a minimal set of fields is specifically a strategy to "...stay as close to that as possible in every national jurisdiction where that (that data) is legally allowed". Does this leave issues for registrars to sort out in various jurisdictions? Sure, just as that is true for other businesses in other fields. A minimal data set reduces the scope for ICANN's contracts to get tangled up in regulations, jurisdiction by jurisdiction.
>>>
>>> Another issue, where I am odd person out, is the distinction between what are legitimate reasons for collection, and what are legitimate reasons for use. I sort of have "form follows function" baked into my strategy bones. I would have preferred reversing the process and starting with legitimate uses and working back to what to collect, but that boat left port a long time ago.
>>>
>>> Sam L.
>>>
>>> On 1/15/2018 2:03 PM, John Carr wrote:
>>>
>>>> In the "Affirmation of Commitments"" didn’t ICANN promise to maintain WHOIS as an accurate and public data base? Shouldn’t the objective be to stay as close to that as possible in every national jurisdiction where that is legally allowed?
>>>>
>>>> Or has ICANN decided that the promise it made in the Affirmation should now be formally abandoned or changed?
>
> --
> ------------------------------------------------
> "It is a disgrace to be rich and honoured
> in an unjust state" -Confucius
>  邦有道,贫且贱焉,耻也。邦无道,富且贵焉,耻也
> ------------------------------------------------
> Dr Sam Lanfranco (Prof Emeritus & Senior Scholar)
> Econ, York U., Toronto, Ontario, CANADA - M3J 1P3
> email:
> Lanfran at Yorku.ca
> Skype: slanfranco
> blog:
> https://samlanfranco.blogspot.com
> Phone: +1 613-476-0429 cell: +1 416-816-2852
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://lists.ncsg.is/pipermail/ncsg-discuss/attachments/20180116/b4e82750/attachment.htm>


More information about the Ncsg-discuss mailing list