Statement: EPDP recommendations/WHOIS privacy
Stephanie Perrin
stephanie at DIGITALDISCRETION.CA
Fri Feb 15 09:32:09 EET 2019
precisely. Lack of clarity about what is under ICANN control (through
the policy) and what is solely under Registrar/registry control is
making this messy.
Stephanie
On 2019-02-14 10:00, farzaneh badii wrote:
> Yeah but it didn’t have to be included in this policy which has
> disclosure provisions.
>
> On Thu, Feb 14, 2019 at 9:59 AM Stephanie Perrin
> <stephanie.perrin at mail.utoronto.ca
> <mailto:stephanie.perrin at mail.utoronto.ca>> wrote:
>
> Basically the contracted parties appear to be agreeing that
> registries should be thin, unless the need for data transfer has
> been proven. Some of those registries have legitimate needs to
> verify some data. They ought to, of course, do a review under the
> GDPR and limit the personal data...but that is up to them as
> controllers.
>
> Stephanie
>
> On 2019-02-14 09:55, farzaneh badii wrote:
>> Hi Kathy
>>
>> Yes sorry I wanted the statement be brief. The additional data
>> elements are what new gtld registries ask for from the
>> registrants. For example .Lawyer might ask for a bar (law not
>> liquor) license. As the new gtlds expand these additional data
>> elements can be hundreds of personal info such as driver's
>> license, identification cards etc.
>>
>> I am going to elaborate on this statement and the recommendations
>> in the Google doc.
>>
>>
>> Farzaneh
>>
>>
>> On Thu, Feb 14, 2019 at 9:45 AM Kathy Kleiman <kathy at dnrc.tech>
>> <mailto:kathy at dnrc.tech> wrote:
>>
>> H Farzaneh,
>>
>> Tx to the amazing work of the NCSG EPDP team, and for your
>> posting below./Question: can you provide us with a bit more
>> detail about the "additional potentially personal and
>> sensitive data elements that are 'identified by Registry
>> Operator in its registration policy'"? //
>> /
>>
>> /What types of elements are being discussed? /
>>
>> Best and tx, Kathy
>>
>> On 2/13/2019 8:13 PM, farzaneh badii wrote:
>>> Dear All,
>>>
>>> The Council is going to vote on the motion to approve the
>>> recommendations of EPDP tomorrow (Thursday). We are at the
>>> final stages of our deliberations at EPDP and it is almost
>>> done.
>>>
>>> The council has to vote on this report (attached) as a whole
>>> and cannot vote on recommendations separately. This makes
>>> our work a bit difficult because we do not agree with all
>>> the recommendations. One approach would be for NCSG
>>> councilors to approve the report but make a short statement
>>> for our own record.
>>>
>>> I have been discussing the concerns for a couple of weeks on
>>> this list so there is nothing new and I hope that we can
>>> direct our councilors tomorrow to make this statement if
>>> they can:
>>>
>>>
>>> NCSG statement/ For GNSO Council Meeting, 14 February
>>>
>>> Despite an unrealistic timeline, EPDP achieved its goal and
>>> delivered the final report. We are positive about the final
>>> report and our councilors have voted for its approval. But
>>> we are concerned with some aspects of the report and would
>>> like to record our concerns.
>>>
>>>
>>> *
>>>
>>> The report has included additional potentially personal
>>> and sensitive data elements that are “identified by
>>> Registry Operator in its registration policy." There
>>> was no justifiable reason to include these additional
>>> data elements in the report, nor was it justifiable to
>>> formulate purposes that could relate to processing these
>>> additional elements. These additional data elements
>>> were not included in Temp Spec either. We are concerned
>>> about subjecting these additional data elements to this
>>> policy and warn the ICANN community and domain name
>>> registrants that due to this addition even more
>>> sensitive and personal data might be disclosed to third
>>> parties on a global scale.
>>>
>>>
>>> *
>>>
>>> Data protection should be provided for all domain name
>>> registrants globally regardless of their location.
>>> Discriminatory treatment of domain name registrants and
>>> providing some with less data protection is not
>>> justified, especially as we are moving towards
>>> disclosing domain name registrants data to third parties
>>> "globally".
>>>
>>> *
>>>
>>> We believe "disclosure" of data to third parties is not
>>> an ICANN purpose for processing the data.
>>>
>>>
>>> We thank the EPDP, its leadership and ICANN staff for
>>> achieving this milestone. We hope that with this policy by
>>> cultivating a privacy-respecting culture at ICANN,
>>> protecting the personal data of domain name registrants
>>> becomes a norm, and not remain an exception.
>>>
>>>
>>>
>>> Link to the statement:
>>>
>>>
>>> https://docs.google.com/document/d/1M8M0kaQSdQD3CC1HmpSTwMIKcufCT0ekVu7yHgx_f5w/edit?usp=sharing
>>>
>>>
>>>
>>> Comments are welcome (I think we have some hours) but since
>>> Councilors are going to read this statement out I give them
>>> the liberty of changing the tone or re-doing the statement.
>>>
>>> Best
>>>
>>>
>>>
>>>
>>>
>>> Farzaneh
>>
>> --
>> Kathy Kleiman
>> Visiting Scholar, Center for Information Technology, Princeton University
>> President (on leave), Domain Name Rights Coalition
>>
>>
>> <https://www.avast.com/sig-email?utm_medium=email&utm_source=link&utm_campaign=sig-email&utm_content=emailclient&utm_term=icon>
>> Virus-free. www.avast.com
>> <https://www.avast.com/sig-email?utm_medium=email&utm_source=link&utm_campaign=sig-email&utm_content=emailclient&utm_term=link>
>>
>>
> --
> Farzaneh
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://lists.ncsg.is/pipermail/ncsg-discuss/attachments/20190215/257bbf17/attachment.htm>
More information about the Ncsg-discuss
mailing list