Canadian eTA & Visa Requirements

Sam Lanfranco lanfran at YORKU.CA
Sun Feb 3 16:23:35 EET 2019


 

	My sympathies to Farzaneh for not being able to attend a Toronto meeting. 


	I am helping organize an early summer conference in Toronto, so I am up to
date on Canadian immigration requirements. I will share information with
ICANN colleagues traveling to (or through) Canada. [If you follow world
press you will know that “in transit” in Canada can be complicated].  

	This is particularly important since ICANN66 is scheduled for 2-7 Nov,
2019 in Montréal, ten months from today.  

	The major change is the new requirement for obtaining an Electronic Travel
Authorization (eTA), if you do not require a visa. Most people need either
a visa or an Electronic Travel Authorization (eTA) to travel to Canada. If
you have a passport that does not require a Canadian visa, it most likely
still requires an eTA, which can be obtained in advance and online. Also,
for any significant event, where a number of people will require eTA’s,
the organizers have to register the event with Canadian immigration at
least six months in advance of the event. 
	I hope ICANN Travel is on top of this.  

	Sam L.  

	------------------------------------------------ "It is a disgrace to be
rich and honored in an unjust state" -Confucius
邦有道,贫且贱焉,耻也。邦无道,富且贵焉,耻也
------------------------------------------------ Visiting Prof, Xi'an
Jiaotong-Liverpool Univ, Suzhou, China Dr Sam Lanfranco (Prof Emeritus),
Econ, York U., CANADA email: sam at lanfranco.net (mailto:sam at lanfranco.net)
Skype: slanfranco blog: https://samlanfranco.blogspot.com
(https://samlanfranco.blogspot.com) Phone: +1 613-476-0429 cell: +1
416-816-2852

---- Original Message ----
From: farzaneh badii 
To: NCSG-DISCUSS at LISTSERV.SYR.EDU
Sent: Sun, Feb 3, 2019, 3:13 PM
Subject: Re: Some update on EPDP work /Privacy in WHOIS
I had suggested that we ask the law firm whether purpose two is crafted
rightly and is actually legal. Dont know if we asked that. Bird and Bird
rep was present during re crafting this purpose at Toronto meeting. Her
suggestions I think were mostly discarded. One was to add the term “where
necessary”.
Also note that the CEO once during the LA meeting told the CPs we are
trying to diminish your liability. Is that a bad thing? While this might
not be legally viable if ICANN take on a lot of risk to disclose personal
info then this purpose is unfortunately a terrible purpose. But
interestingly while ICANN wants to diminish cps liability, seems like ICANN
org doesnt want to be the joint controller, but perhaps wants to be
independent controller. It is very ambiguous. 
But we had to compromise. I find the addition of footnote to this purpose
extremely risky and will note my objection( though seems like NCSG as a
whole does not want to object , i dont know) . I find the mention of SSR
dangerous. But I couldnt get anywhere with my objections. 
 I had to attend F2F remotely because I didnt get my Canadian visa on time
since the chair of epdp decided that he should favor one person over 4
others and hold the meeting outside of the US (wonder why that never
happens to me). So I invite others who were present to correct the record
if I am wrong somewhere. 
On Sun, Feb 3, 2019 at 11:17 AM James Gannon  wrote:
  Interesting, as (I assume) one of the few people on this list who is
registered as a DPO I think its very interesting to see the group come to
those conclusions, its certainly not a risk I would accept in the firm that
I am DPO for, will be interesting to see how ICANN navigates that with the
various DPAs who are surely going to test that interpretation of legitimate
interest.
On 3 Feb 2019, at 17:13, Ayden Férdeline  wrote: 
The EPDP team does have external counsel (Bird & Bird), who have issued
advice on some topics, including interpretation of 6(1)(b) (contractual
necessity) and other pieces of the GDPR where our Legal Committee has
thought it necessary to seek clarification from counsel. However in this
particular instance, from what I recall, the EPDP team felt comfortable
making the analysis ourselves. I am personally comfortable with the
language. Note that there is a balancing test; the disclosure of
registration data to a third party is not automatic, and only occurs if the
contracted party assesses the harm to the registrant is outweighed by the
legitimate interests of the third party. I happen to think this is a high
bar, and that most contracted parties will be risk-adverse, so registration
data is unlikely to be disclosed too freely. I don't think you can rely on
consent here, because the circumstances in which I think data should be
disclosed (i.e. legitimate investigations of abuse, fraud) are unlikely to
result in bad actors consenting to the disclosure of their registration
data.
Ayden 
‐‐‐‐‐‐‐ Original Message ‐‐‐‐‐‐‐
On Sunday, February 3, 2019 10:58 AM, James Gannon  wrote:
I think ICANN will struggle to find a DPO who will work under the assertion
that the disclosure of registration data is an activity covered under
legitimate interest. 
Has the EPDP received external legal advise on any of these?
On 3 Feb 2019, at 16:56, Ayden Férdeline  wrote:
Hi James,
For purpose 2, the EPDP team has completed four lawfulness of processing
tests, one for each of the following activities:
	* collection of registration data
	* transfer of registration data from registrar to registry
	* disclosure of non-public registration data to third parties
	* retention of registration data by registrar
In the case of the disclosure of registration data to third parties, we are
not relying on consent, therefore Article 7 does not apply. We have
assessed this as being a 6(1)(f) (legitimate interest) processing activity.
However, in recognition of the fact that such a disclosure is not
technically necessary to perform the registration contract between the
registrant and registrar, the contracted party would still need to perform
the requisite balancing test to ensure the third party's legitimate
interests override the fundamental rights and freedoms of the data subject,
before registration data is disclosed.
Best wishes,
Ayden  
‐‐‐‐‐‐‐ Original Message ‐‐‐‐‐‐‐
On Sunday, February 3, 2019 4:08 AM, James Gannon  wrote:
Would love to know how purpose 2 is defined on a legal basis and also how
it complies with Art 7 section 4.
On 3 Feb 2019, at 09:45, farzaneh badii  wrote:
  Our update on EPDP work is overdue, so I thought I write my thoughts and
report a bit on the developments, and others from EPDP team can chime in if
they think I got something wrong. 
  where we are at:
  we are now finalizing the preliminary report and need to come to a
consensus quickly and send the report off to the council for approval. So
pressure is high. We have to come up with an interim policy plan  to cover
the gap between implementation and approval of the recs. 
  Our principles: 
  - Maximum data protection for domain name registrants globally
  - Accountable disclosure and accountable receipt  of domain name
registrants personal info
  - Side with providing data protection when in doubt whether GDPR applies
  - Keep ICANN's mission limited 
  I have attached a PDF with markation of what we have problems with or
doubts for the moment. I am still working on it but it's attached. 
   Purposes for domain name registrants data processing -
	* Purpose 1. To establish registrants rights (generally is a good purpose,
in favor of registrants). Note that some would like to add the word
obligation of domain name registrants to this purpose which we have
resisted and argued that if they want to do that they need a standalone
purpose. 
	* Contributing to the maintenance of SSR through disclosure to lawful
requests: we initially opposed this purpose because it's not a purpose for
data processing. you don't collect data to disclose it later to third
parties. Now the purpose has canged to: "Contributing to the maintenance of
the security, stability, and  resiliency of theDomain Name System in
accordance with ICANN’s mission through enabling responses to lawful data
disclosure requests." This is not a bad compromise. But the footnotes are
not very helpful. The first footnote says that this purpose does not
preclude IP based requests. Though this was a compromise makes me very
worried. We have always said that SSR does not include IP issues and this
footnote can make it easier to include IP in SSR in the future. My solution
would be to re-word this and say: This purpose does not preclude lawful
disclosure for non-SSR issues i.e. trademark infringement (in accordance
with ICANN bylaws). The details of the disclosure will be discussed in
phase two. 
What we have achieved so far (relatively):
1. there might be no differentiation between legal and natural persons 
2.Tech admin contact might become optional 
3. There might be no differentiation in treating domain name registrants
based on their geographical location
4. Thin registries might not have to implement thick registries policy
(unsure about that, please correct me if I am wrong)
Farzaneh
  -- 

Farzaneh 
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://lists.ncsg.is/pipermail/ncsg-discuss/attachments/20190203/ba5eaf50/attachment.htm>


More information about the Ncsg-discuss mailing list