Comments on the Whois compliance models

Stephanie Perrin stephanie.perrin at MAIL.UTORONTO.CA
Mon Jan 29 19:47:39 EET 2018


I agree with Kathy, there is no overnight solution.  Here is my latest 
draft comment, rewritten as coming from me not NCSG.  Happy to get your 
feedback, but I will send it shortly so as to make sure I get it in by 
the deadline.  AS you can see, I am proposing to send them two more 
sections as a followup.

cheers Stephanie Perrin

On 2018-01-29 14:00, Kathy Kleiman wrote:
>
> Milton, I understand the comments below and I wish I could support 
> them as the whole of the NCSG comments, but I cannot. However, I 
> support much of them -- and let me share:
>
> 1. "The purpose of Whois must be strictly tied to ICANN's mission." 
> ==> that's absolutely true but we don't have that purpose yet (and I 
> have to tell you that the RDS Working Group is not doing a great job 
> of analyzng "purpose" right now (it is not closely following the 
> strict legal rules of the GDPR and other comprehensive data protection 
> laws -- this will be debated on Tuesday). But we (ICANN) does not have 
> that "purpose" yet, and won't in the next 3 months (since any 
> recommendation of the RDS WG would take months for review and 
> acceptance, and the WG is nowhere near publishing it). But right now, 
> we do have an open and public WHOIS system - all available all the 
> time (unless you have signed up for a proxy or privacy service) - with 
> /unlimited "all you can eat access" by everyone, /including 
> intellectual property attorneys and law enforcement. That is happily 
> going to change!!
>
> 2. "Whois service, like the DNS itself, should be globally uniform and 
> not vary by jurisdiction." ==> Yes, and that's what the ECO Model and 
> Model 2B provide. But, unfortunately, that's Model 3 does not provide 
> uniformity; Model 3 provide great differentiation of protection, with 
> only private individuals being protected, and not the political, 
> sexual, religious, educational groups that I discussed in one of my 
> recent emails - the array of groups that we protect engaged in huge 
> amount of controversial and critical speech and services. *The ICANN 
> Model 3 here is very clear: *"*Display unless field includes personal 
> data." (ICANN's Proposed Interim Models for Compliance, pages 
> 12-14).*  Thus, for noncommercial organizations, exposure of 
> Registrant/Admin/Tech name, address, phone and email will remain 
> completely open. Model 2B and ECO do better and protect legal and 
> natural persons. That's hugely important - and a tribute to our years 
> of work on this subject!
>
> 3. "No tiered access solution that involves establishing new criteria 
> for access can feasibly be created in the next 3 months."  ==> We are 
> unlikely to go from infinite public access to completely restricted 
> private access right now. The Multistakeholder Process won't support 
> that. But the ECO model does a lot to help on this particular issue. 
> I'll outline in my next email.
>
> Overall, it's great to have models and options. After fifteen years 
> working in this WHOIS space, and I am optimistic that we are about to 
> see the biggest change of our lifetimes coming up in this space. We 
> have waited a long time!
> Best,
> Kathy
>
> On 1/26/2018 6:00 PM, Mueller, Milton L wrote:
>>
>> I offer the following as a first draft of the NCSG position on the 12 
>> January 2018 call for comments released by ICANN org.
>>
>> Principles
>>
>> Our evaluation of the models offered by ICANN are based on three 
>> fundamental principles. No model that fails to conform to all three 
>> is acceptable to the NCSG.
>>
>> 1. The purpose of whois must be strictly tied to ICANN's mission. 
>> That is, the data that is collected and the data that are published 
>> must directly and demonstrably contribute to ICANN's mission as 
>> defined in Article 1 of its new bylaws. We reject any definition of 
>> Whois purpose that is based on the way people happen to make use of 
>> data that can be accessed indiscriminately in a public directory. The 
>> fact that certain people currently use Whois for any purpose does not 
>> mean that the purpose of Whois is to provide thick data about the 
>> domain and its registrant to anyone who wants it for any reason.
>>
>> 2. Whois service, like the DNS itself, should be globally uniform and 
>> not vary by jurisdiction. ICANN was created to provide globalized 
>> governance of the DNS so that it would continue to be globally 
>> compatible and coordinated. Any solution that involves fragmenting 
>> the policies and practices of Whois along jurisdictional lines is not 
>> desirable.
>>
>> 3. No tiered access solution that involves establishing new criteria 
>> for access can feasibly be created in the next 3 months. We would 
>> strongly resist throwing the community into a hopeless rush to come 
>> up with entirely new policies, standards and practices involving 
>> tiered access to data, and we do not want ICANN staff to invent a 
>> policy that is not subject to community review and approval.
>>
>> Based on these three principles, we believe that Model 3 is the only 
>> viable option available. Model 3 minimizes the data publicly 
>> displayed to that which is required for maintaining the stability, 
>> security and resiliency of the DNS. Model 3 could be applied across 
>> the board, and would be presumptively legal regardless of which 
>> jurisdiction the registrar, registry or registrant are in. And Model 
>> 3 relies on established legal due process for gaining access to 
>> additional information.
>>
>> There is room for discussion about how much data could be publicly 
>> displayed under Model 3 consistent with ICANN's mission. E.g., it may 
>> be within ICANN's mission to include additional data in the public 
>> record, such as an email address for the technical contact and even 
>> possibly the name of the registrant.
>>
>> The process of gaining access to additional data in Model 1 is 
>> completely unacceptable. Self-certification by any third party 
>> requestor is, we believe, not compliant with GDPR nor does is such 
>> access justified by the purpose of Whois or ICANN's mission.
>>
>> Model 2 might possibly be acceptable if an suitable set of criteria 
>> and processes were devised, but it simply is not feasible for such a 
>> certification program to be developed in 3 months. A certification 
>> program thrown together in a rush poses huge risks for loopholes, 
>> poor procedures, and a legal challenge to ICANN, either from DPAs or 
>> from individuals affected.
>>
>> Dr. Milton L. Mueller
>>
>> Professor, School of Public Policy
>>
>> Georgia Institute of Technology
>>
>
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://lists.ncsg.is/pipermail/ncsg-discuss/attachments/20180129/0fa648a5/attachment.htm>
-------------- next part --------------
A non-text attachment was scrubbed...
Name: 4Comments on GDPR Interim Compliance Models for WHOIS-1.docx
Type: application/vnd.openxmlformats-officedocument.wordprocessingml.document
Size: 183178 bytes
Desc: not available
URL: <http://lists.ncsg.is/pipermail/ncsg-discuss/attachments/20180129/0fa648a5/attachment.docx>


More information about the Ncsg-discuss mailing list