Some update on EPDP work /Privacy in WHOIS
Amr Elsadr
aelsadr at ICANNPOLICY.NINJA
Mon Feb 4 06:16:03 EET 2019
Hi,
Farzaneh’s thoughts below seem to correctly reflect where we are on these issues to me. One clarification on the issue of implementing “thick” WHOIS may be that the EPDP Team’s final report isn’t recommending that the implementation of the “thick” WHOIS Consensus Policy is halted. However, two of the EPDP Team’s recommendations do address this policy.
Recommendation 5 addresses which data elements need to be transferred from a registrar to a registry. These pretty much include all the “thick” data. However, the draft final report also states that registrars, in their role as data controllers for this processing activity, need to assess whether or not there is a lawful basis to transfer this data to registry operators, or not. It has been argued that in most cases there is no lawful basis to do so. The lawful basis identified for transferring data from registrars to registries is GDPR Article 61b, meaning that if transferring this data is required in order to fulfill the contract between registrants and registrars, there is a legal basis to do so. In some cases, this might be true (such as specific gTLDs in which there is an eligibility criteria to fulfill in order to register a domain name under the gTLD). However, the most significant gTLD being operated using a “thin” registry is obviously .com. It is difficult to argue that transfer of the data is necessary to perform the contract between registrars and registrants, since .com registrations have been taking place for decades without the need to make these data transfers.
Recommendation 5 is supplemented by recommendation 22, which identifies the “thick” WHOIS Consensus Policy as one that will need to take into consideration some of the findings of the EPDP. Changes to this policy will need to be made to make it consistent with the recommendations of the EPDP Team, if they are adopted by the GNSO Council and the ICANN Board (big IF), and the GNSO Council and the “thick” WHOIS Implementation Review Team will need to consider GDPR compliance issues themselves anyway.
As Farzaneh says, it is likely that the “thick” WHOIS Consensus Policy will not be implemented has been foreseen. To what extent it will be abandoned, I am not yet certain. I am quite confident that the policy is not an appealing one at this point to contracted parties that need to implement it (from both a legal and a cost perspective), particularly those dealing with .com registrations.
Thanks.
Amr
>> On 3 Feb 2019, at 09:45, farzaneh badii <farzaneh.badii at gmail.com> wrote:
>>
>> Our update on EPDP work is overdue, so I thought I write my thoughts and report a bit on the developments, and others from EPDP team can chime in if they think I got something wrong.
>>
>> where we are at:
>> we are now finalizing the preliminary report and need to come to a consensus quickly and send the report off to the council for approval. So pressure is high. We have to come up with an interim policy plan to cover the gap between implementation and approval of the recs.
>>
>> Our principles:
>> - Maximum data protection for domain name registrants globally
>> - Accountable disclosure and accountable receipt of domain name registrants personal info
>> - Side with providing data protection when in doubt whether GDPR applies
>> - Keep ICANN's mission limited
>>
>> I have attached a PDF with markation of what we have problems with or doubts for the moment. I am still working on it but it's attached.
>>
>> Purposes for domain name registrants data processing -
>>
>> - Purpose 1. To establish registrants rights (generally is a good purpose, in favor of registrants). Note that some would like to add the word obligation of domain name registrants to this purpose which we have resisted and argued that if they want to do that they need a standalone purpose.
>> - Contributing to the maintenance of SSR through disclosure to lawful requests: we initially opposed this purpose because it's not a purpose for data processing. you don't collect data to disclose it later to third parties. Now the purpose has canged to: "Contributing to the maintenance of the security, stability, and resiliency of theDomain Name System in accordance with ICANN’s mission through enabling responses to lawful data disclosure requests." This is not a bad compromise. But the footnotes are not very helpful. The first footnote says that this purpose does not preclude IP based requests. Though this was a compromise makes me very worried. We have always said that SSR does not include IP issues and this footnote can make it easier to include IP in SSR in the future. My solution would be to re-word this and say: This purpose does not preclude lawful disclosure for non-SSR issues i.e. trademark infringement (in accordance with ICANN bylaws). The details of the disclosure will be discussed in phase two.
>>
>> What we have achieved so far (relatively):
>> 1. there might be no differentiation between legal and natural persons
>> 2.Tech admin contact might become optional
>> 3. There might be no differentiation in treating domain name registrants based on their geographical location
>> 4. Thin registries might not have to implement thick registries policy (unsure about that, please correct me if I am wrong)
>>
>> Farzaneh <EPDP Team Draft Final Report - Annotated.pdf>
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://lists.ncsg.is/pipermail/ncsg-discuss/attachments/20190204/af86bd91/attachment.htm>
More information about the Ncsg-discuss
mailing list