Comments on the Whois compliance models
Stephanie Perrin
stephanie.perrin at MAIL.UTORONTO.CA
Mon Jan 29 19:47:39 EET 2018
I agree with Kathy, there is no overnight solution. Here is my latest
draft comment, rewritten as coming from me not NCSG. Happy to get your
feedback, but I will send it shortly so as to make sure I get it in by
the deadline. AS you can see, I am proposing to send them two more
sections as a followup.
cheers Stephanie Perrin
On 2018-01-29 14:00, Kathy Kleiman wrote:
>
> Milton, I understand the comments below and I wish I could support
> them as the whole of the NCSG comments, but I cannot. However, I
> support much of them -- and let me share:
>
> 1. "The purpose of Whois must be strictly tied to ICANN's mission."
> ==> that's absolutely true but we don't have that purpose yet (and I
> have to tell you that the RDS Working Group is not doing a great job
> of analyzng "purpose" right now (it is not closely following the
> strict legal rules of the GDPR and other comprehensive data protection
> laws -- this will be debated on Tuesday). But we (ICANN) does not have
> that "purpose" yet, and won't in the next 3 months (since any
> recommendation of the RDS WG would take months for review and
> acceptance, and the WG is nowhere near publishing it). But right now,
> we do have an open and public WHOIS system - all available all the
> time (unless you have signed up for a proxy or privacy service) - with
> /unlimited "all you can eat access" by everyone, /including
> intellectual property attorneys and law enforcement. That is happily
> going to change!!
>
> 2. "Whois service, like the DNS itself, should be globally uniform and
> not vary by jurisdiction." ==> Yes, and that's what the ECO Model and
> Model 2B provide. But, unfortunately, that's Model 3 does not provide
> uniformity; Model 3 provide great differentiation of protection, with
> only private individuals being protected, and not the political,
> sexual, religious, educational groups that I discussed in one of my
> recent emails - the array of groups that we protect engaged in huge
> amount of controversial and critical speech and services. *The ICANN
> Model 3 here is very clear: *"*Display unless field includes personal
> data." (ICANN's Proposed Interim Models for Compliance, pages
> 12-14).* Thus, for noncommercial organizations, exposure of
> Registrant/Admin/Tech name, address, phone and email will remain
> completely open. Model 2B and ECO do better and protect legal and
> natural persons. That's hugely important - and a tribute to our years
> of work on this subject!
>
> 3. "No tiered access solution that involves establishing new criteria
> for access can feasibly be created in the next 3 months." ==> We are
> unlikely to go from infinite public access to completely restricted
> private access right now. The Multistakeholder Process won't support
> that. But the ECO model does a lot to help on this particular issue.
> I'll outline in my next email.
>
> Overall, it's great to have models and options. After fifteen years
> working in this WHOIS space, and I am optimistic that we are about to
> see the biggest change of our lifetimes coming up in this space. We
> have waited a long time!
> Best,
> Kathy
>
> On 1/26/2018 6:00 PM, Mueller, Milton L wrote:
>>
>> I offer the following as a first draft of the NCSG position on the 12
>> January 2018 call for comments released by ICANN org.
>>
>> Principles
>>
>> Our evaluation of the models offered by ICANN are based on three
>> fundamental principles. No model that fails to conform to all three
>> is acceptable to the NCSG.
>>
>> 1. The purpose of whois must be strictly tied to ICANN's mission.
>> That is, the data that is collected and the data that are published
>> must directly and demonstrably contribute to ICANN's mission as
>> defined in Article 1 of its new bylaws. We reject any definition of
>> Whois purpose that is based on the way people happen to make use of
>> data that can be accessed indiscriminately in a public directory. The
>> fact that certain people currently use Whois for any purpose does not
>> mean that the purpose of Whois is to provide thick data about the
>> domain and its registrant to anyone who wants it for any reason.
>>
>> 2. Whois service, like the DNS itself, should be globally uniform and
>> not vary by jurisdiction. ICANN was created to provide globalized
>> governance of the DNS so that it would continue to be globally
>> compatible and coordinated. Any solution that involves fragmenting
>> the policies and practices of Whois along jurisdictional lines is not
>> desirable.
>>
>> 3. No tiered access solution that involves establishing new criteria
>> for access can feasibly be created in the next 3 months. We would
>> strongly resist throwing the community into a hopeless rush to come
>> up with entirely new policies, standards and practices involving
>> tiered access to data, and we do not want ICANN staff to invent a
>> policy that is not subject to community review and approval.
>>
>> Based on these three principles, we believe that Model 3 is the only
>> viable option available. Model 3 minimizes the data publicly
>> displayed to that which is required for maintaining the stability,
>> security and resiliency of the DNS. Model 3 could be applied across
>> the board, and would be presumptively legal regardless of which
>> jurisdiction the registrar, registry or registrant are in. And Model
>> 3 relies on established legal due process for gaining access to
>> additional information.
>>
>> There is room for discussion about how much data could be publicly
>> displayed under Model 3 consistent with ICANN's mission. E.g., it may
>> be within ICANN's mission to include additional data in the public
>> record, such as an email address for the technical contact and even
>> possibly the name of the registrant.
>>
>> The process of gaining access to additional data in Model 1 is
>> completely unacceptable. Self-certification by any third party
>> requestor is, we believe, not compliant with GDPR nor does is such
>> access justified by the purpose of Whois or ICANN's mission.
>>
>> Model 2 might possibly be acceptable if an suitable set of criteria
>> and processes were devised, but it simply is not feasible for such a
>> certification program to be developed in 3 months. A certification
>> program thrown together in a rush poses huge risks for loopholes,
>> poor procedures, and a legal challenge to ICANN, either from DPAs or
>> from individuals affected.
>>
>> Dr. Milton L. Mueller
>>
>> Professor, School of Public Policy
>>
>> Georgia Institute of Technology
>>
>
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://lists.ncsg.is/pipermail/ncsg-discuss/attachments/20180129/0fa648a5/attachment.htm>
-------------- next part --------------
A non-text attachment was scrubbed...
Name: 4Comments on GDPR Interim Compliance Models for WHOIS-1.docx
Type: application/vnd.openxmlformats-officedocument.wordprocessingml.document
Size: 183178 bytes
Desc: not available
URL: <http://lists.ncsg.is/pipermail/ncsg-discuss/attachments/20180129/0fa648a5/attachment.docx>
More information about the Ncsg-discuss
mailing list