Comments on the Whois compliance models

Kathy Kleiman kathy at KATHYKLEIMAN.COM
Mon Jan 29 14:00:25 EET 2018


Milton, I understand the comments below and I wish I could support them 
as the whole of the NCSG comments, but I cannot. However, I support much 
of them -- and let me share:

1. "The purpose of Whois must be strictly tied to ICANN's mission." ==> 
that's absolutely true but we don't have that purpose yet (and I have to 
tell you that the RDS Working Group is not doing a great job of analyzng 
"purpose" right now (it is not closely following the strict legal rules 
of the GDPR and other comprehensive data protection laws -- this will be 
debated on Tuesday). But we (ICANN) does not have that "purpose" yet, 
and won't in the next 3 months (since any recommendation of the RDS WG 
would take months for review and acceptance, and the WG is nowhere near 
publishing it). But right now, we do have an open and public WHOIS 
system - all available all the time (unless you have signed up for a 
proxy or privacy service) - with /unlimited "all you can eat access" by 
everyone, /including intellectual property attorneys and law 
enforcement. That is happily going to change!!

2. "Whois service, like the DNS itself, should be globally uniform and 
not vary by jurisdiction." ==> Yes, and that's what the ECO Model and 
Model 2B provide. But, unfortunately, that's Model 3 does not provide 
uniformity; Model 3 provide great differentiation of protection, with 
only private individuals being protected, and not the political, sexual, 
religious, educational groups that I discussed in one of my recent 
emails - the array of groups that we protect engaged in huge amount of 
controversial and critical speech and services. *The ICANN Model 3 here 
is very clear: *"*Display unless field includes personal data." (ICANN's 
Proposed Interim Models for Compliance, pages 12-14).*  Thus, for 
noncommercial organizations, exposure of Registrant/Admin/Tech name, 
address, phone and email will remain completely open. Model 2B and ECO 
do better and protect legal and natural persons. That's hugely important 
- and a tribute to our years of work on this subject!

3. "No tiered access solution that involves establishing new criteria 
for access can feasibly be created in the next 3 months." ==> We are 
unlikely to go from infinite public access to completely restricted 
private access right now. The Multistakeholder Process won't support 
that. But the ECO model does a lot to help on this particular issue. 
I'll outline in my next email.

Overall, it's great to have models and options. After fifteen years 
working in this WHOIS space, and I am optimistic that we are about to 
see the biggest change of our lifetimes coming up in this space. We have 
waited a long time!
Best,
Kathy

On 1/26/2018 6:00 PM, Mueller, Milton L wrote:
>
> I offer the following as a first draft of the NCSG position on the 12 
> January 2018 call for comments released by ICANN org.
>
> Principles
>
> Our evaluation of the models offered by ICANN are based on three 
> fundamental principles. No model that fails to conform to all three is 
> acceptable to the NCSG.
>
> 1. The purpose of whois must be strictly tied to ICANN's mission. That 
> is, the data that is collected and the data that are published must 
> directly and demonstrably contribute to ICANN's mission as defined in 
> Article 1 of its new bylaws. We reject any definition of Whois purpose 
> that is based on the way people happen to make use of data that can be 
> accessed indiscriminately in a public directory. The fact that certain 
> people currently use Whois for any purpose does not mean that the 
> purpose of Whois is to provide thick data about the domain and its 
> registrant to anyone who wants it for any reason.
>
> 2. Whois service, like the DNS itself, should be globally uniform and 
> not vary by jurisdiction. ICANN was created to provide globalized 
> governance of the DNS so that it would continue to be globally 
> compatible and coordinated. Any solution that involves fragmenting the 
> policies and practices of Whois along jurisdictional lines is not 
> desirable.
>
> 3. No tiered access solution that involves establishing new criteria 
> for access can feasibly be created in the next 3 months. We would 
> strongly resist throwing the community into a hopeless rush to come up 
> with entirely new policies, standards and practices involving tiered 
> access to data, and we do not want ICANN staff to invent a policy that 
> is not subject to community review and approval.
>
> Based on these three principles, we believe that Model 3 is the only 
> viable option available. Model 3 minimizes the data publicly displayed 
> to that which is required for maintaining the stability, security and 
> resiliency of the DNS. Model 3 could be applied across the board, and 
> would be presumptively legal regardless of which jurisdiction the 
> registrar, registry or registrant are in. And Model 3 relies on 
> established legal due process for gaining access to additional 
> information.
>
> There is room for discussion about how much data could be publicly 
> displayed under Model 3 consistent with ICANN's mission. E.g., it may 
> be within ICANN's mission to include additional data in the public 
> record, such as an email address for the technical contact and even 
> possibly the name of the registrant.
>
> The process of gaining access to additional data in Model 1 is 
> completely unacceptable. Self-certification by any third party 
> requestor is, we believe, not compliant with GDPR nor does is such 
> access justified by the purpose of Whois or ICANN's mission.
>
> Model 2 might possibly be acceptable if an suitable set of criteria 
> and processes were devised, but it simply is not feasible for such a 
> certification program to be developed in 3 months. A certification 
> program thrown together in a rush poses huge risks for loopholes, poor 
> procedures, and a legal challenge to ICANN, either from DPAs or from 
> individuals affected.
>
> Dr. Milton L. Mueller
>
> Professor, School of Public Policy
>
> Georgia Institute of Technology
>

-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://lists.ncsg.is/pipermail/ncsg-discuss/attachments/20180129/d303247d/attachment.htm>


More information about the Ncsg-discuss mailing list