Statement: EPDP recommendations/WHOIS privacy

Stephanie Perrin stephanie at DIGITALDISCRETION.CA
Fri Feb 15 09:32:09 EET 2019


precisely.  Lack of clarity about what is under ICANN control (through 
the policy) and what is solely under Registrar/registry control is 
making this messy.

Stephanie

On 2019-02-14 10:00, farzaneh badii wrote:
> Yeah but it didn’t have to be included in this policy which has 
> disclosure provisions.
>
> On Thu, Feb 14, 2019 at 9:59 AM Stephanie Perrin 
> <stephanie.perrin at mail.utoronto.ca 
> <mailto:stephanie.perrin at mail.utoronto.ca>> wrote:
>
>     Basically the contracted parties appear to be agreeing that
>     registries should be thin, unless the need for data transfer has
>     been proven.  Some of those registries have legitimate needs to
>     verify some data.  They ought to, of course, do a review under the
>     GDPR and limit the personal data...but that is up to them as
>     controllers.
>
>     Stephanie
>
>     On 2019-02-14 09:55, farzaneh badii wrote:
>>     Hi Kathy
>>
>>     Yes sorry I wanted the statement be brief. The additional data
>>     elements are what new gtld registries ask for from the
>>     registrants. For example .Lawyer might ask for a bar (law not
>>     liquor)  license. As the new gtlds expand these additional data
>>     elements can be hundreds of personal info such as driver's
>>     license, identification cards etc.
>>
>>     I am going to elaborate on this statement and the recommendations
>>     in the Google doc.
>>
>>
>>     Farzaneh
>>
>>
>>     On Thu, Feb 14, 2019 at 9:45 AM Kathy Kleiman <kathy at dnrc.tech>
>>     <mailto:kathy at dnrc.tech> wrote:
>>
>>         H Farzaneh,
>>
>>         Tx to the amazing work of the NCSG EPDP team, and for your
>>         posting below./Question: can you provide us with a bit more
>>         detail about the "additional potentially  personal and
>>         sensitive data elements that are 'identified by Registry
>>         Operator in its registration policy'"? //
>>         /
>>
>>         /What types of elements are being discussed? /
>>
>>         Best and tx, Kathy
>>
>>         On 2/13/2019 8:13 PM, farzaneh badii wrote:
>>>         Dear All,
>>>
>>>         The Council is going to vote on the motion to approve the
>>>         recommendations of EPDP tomorrow (Thursday). We are at the
>>>         final stages of our deliberations at EPDP and it is almost
>>>         done.
>>>
>>>         The council has to vote on this report (attached) as a whole
>>>         and cannot vote on recommendations separately. This makes
>>>         our work a bit difficult because we do not agree with all
>>>         the recommendations. One approach would be for NCSG
>>>         councilors to approve the report but make a short statement
>>>         for our own record.
>>>
>>>         I have been discussing the concerns for a couple of weeks on
>>>         this list so there is nothing new and I hope that we can
>>>         direct our councilors tomorrow to make this statement if
>>>         they can:
>>>
>>>
>>>         NCSG statement/ For GNSO Council Meeting, 14 February
>>>
>>>         Despite an unrealistic timeline, EPDP achieved its goal and
>>>         delivered the final report. We are positive about the final
>>>         report and our councilors have voted for its approval. But
>>>         we are concerned with some aspects of the report and would
>>>         like to record our concerns.
>>>
>>>
>>>          *
>>>
>>>             The report has included additional potentially  personal
>>>             and sensitive data elements that are “identified by
>>>             Registry Operator in its registration policy."  There
>>>             was no justifiable reason to include these additional
>>>             data elements in the report, nor was it justifiable to
>>>             formulate purposes that could relate to processing these
>>>             additional elements.  These additional data elements
>>>             were not included in Temp Spec either. We are concerned
>>>             about subjecting these additional data elements to this
>>>             policy and warn the ICANN community and domain name
>>>             registrants that due to this addition even more
>>>             sensitive and personal data might be disclosed to third
>>>             parties on a global scale.
>>>
>>>
>>>          *
>>>
>>>             Data protection should be provided for all domain name
>>>             registrants globally regardless of their location.
>>>             Discriminatory treatment of domain name registrants and
>>>             providing some with less data protection is not
>>>             justified, especially as we are moving towards
>>>             disclosing domain name registrants data to third parties
>>>             "globally".
>>>
>>>          *
>>>
>>>             We believe "disclosure" of data to third parties is not
>>>             an ICANN purpose for processing the data.
>>>
>>>
>>>         We thank the EPDP, its leadership and ICANN staff for
>>>         achieving this milestone. We hope that with this policy by
>>>         cultivating a privacy-respecting culture at ICANN,
>>>         protecting the personal data of domain name registrants
>>>         becomes a norm, and not remain an exception.
>>>
>>>
>>>
>>>         Link to the statement:
>>>
>>>
>>>         https://docs.google.com/document/d/1M8M0kaQSdQD3CC1HmpSTwMIKcufCT0ekVu7yHgx_f5w/edit?usp=sharing
>>>
>>>
>>>
>>>         Comments are welcome (I think we have some hours)  but since
>>>         Councilors are going to read this statement out I give them
>>>         the liberty of changing the tone or re-doing the statement.
>>>
>>>         Best
>>>
>>>
>>>
>>>
>>>
>>>         Farzaneh
>>
>>         -- 
>>         Kathy Kleiman
>>         Visiting Scholar, Center for Information Technology, Princeton University
>>         President (on leave), Domain Name Rights Coalition
>>
>>
>>         <https://www.avast.com/sig-email?utm_medium=email&utm_source=link&utm_campaign=sig-email&utm_content=emailclient&utm_term=icon>
>>         	Virus-free. www.avast.com
>>         <https://www.avast.com/sig-email?utm_medium=email&utm_source=link&utm_campaign=sig-email&utm_content=emailclient&utm_term=link>
>>
>>
> -- 
> Farzaneh
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://lists.ncsg.is/pipermail/ncsg-discuss/attachments/20190215/257bbf17/attachment.htm>


More information about the Ncsg-discuss mailing list