EPDP: Legal/Natural Persons Question

Amr Elsadr aelsadr at ICANNPOLICY.NINJA
Sat Mar 28 10:25:20 EET 2020


Hi Farell,

Thanks for the questions. Responses inline:

> On Mar 28, 2020, at 4:55 PM, Farell FOLLY <farell at BENIN2POINT0.ORG> wrote:
>
> Dear Amr,
>
> Thanks very well for this explanation which puts the a brighter sport on that issue for me. However, I have two questions for my own understanding.
>
> - What does it mean personnel information of a legal person (I have found some definitions in literature but not really sure what it means the same thing here.

It is likely the same definition you’ve found. Although the scope of the European Union’s General Data Protection Regulation (GDPR) is primarily concerned with the protection of the rights of natural persons, more specifically, the protections are applicable to the personal information of a natural person (in the regulation itself, it is referred to as personal data, not personal information). The personal information of a legal person is pretty much the same thing (such as name, physical address, email address, and many more), only it is pertaining to a legal entity, not a natural person. The personal information (or data) of a legal person or entity falls outside the scope of the GDPR.

However, this does not mean that the personal information of a legal person falls outside of the scope of ICANN’s policy development, which is likely why Kathy asked the question in the first place. The NCSG reps to the EPDP Team have views on treating both types of personal information the same for a mix of both legal and policy reasons. In other words, there are compliance-with-law reasons why we’ve been advocating this position. This is mainly due to that implementation of a policy that requires differentiation will likely result in mistakes being made. This, in turn, would result in registrant privacy/data protection rights being violated, as well as creating legal liability for the Data Controllers (presumably, the Contracted Parties involved, as well as ICANN).

There are also policy reasons why we’ve advocated for the two types of personal information being treated the same. That is to say that these reasons are not motivated by compliance with GDPR, but rather by registrant interests falling outside of the scope of GDPR. I’ve mentioned some of those in my response to Kathy, as did she in her original email.

> - Secondly, I see in your first paragraph that Both the NCSG and the contracted parties (Registries and Registrars) advocated for the personal information to be treated equally for both types of persons, therefore; what justifies the bottleneck and the survey/study indicated afterwards? Especially when the costs issues with no benefit in return are added to..

The NCSG and the Contracted Parties (consisting of the gTLD Registries Stakeholder Group and the ICANN-accredited Registrars Stakeholder Group) are only 3 of several groups participating in the EPDP. Others include the GNSO’s Internet Providers and Connectivity Providers Constituency (ISPCP), which is also in agreement with us on this issue, the Intellectual Property Constituency (IPC) and the Business Constituency (BC) in addition to the ALAC, GAC and SSAC. All of these groups, with the exception of the ISPCP, are opposed to not differentiating between legal and natural persons, and no bloc of groups has managed to persuade the other from its views. That is why we have the deadlock.

> I am sorry if all answers are in your e-mail, but it does not appear clearly to me.

Not at all. I hope this helps.

Thanks.

Amr

>

> Thanks.
>
> @__f_f__
>
> Best Regards
>
> ____________________________________
>
> (Ekue) Farell FOLLY
> GNSO Councillor
> linkedin.com/in/farellf
>
>> On 28 Mar 2020, at 13:24, Amr Elsadr <aelsadr at ICANNPOLICY.NINJA> wrote:
>>
>> Hi Kathy,
>>
>> The topic of how to handle gTLD Registration Data of legal vs natural persons at ICANN was part of phase 1 of the EPDP, but was unresolved because of different groups within ICANN advocating for the Consensus Policy to treat the personal information of legal persons differently from that of natural persons. The NCSG, along with the Registrars Stakeholder Group and the Registries Stakeholder Group advocated for the personal information of legal persons to be treated the same as that of natural persons (that the requirements of redaction and processing be the same for both).
>>
>> We did make the arguments you outlined below, as well as others including that often, a Registrant identifying as a legal person is likely to have the personal information of a natural person included in its gTLD domain name registration data.
>>
>> Also, it is important to take in to consideration that the cost of implementation of the phase 1 policy recommendations, and those of phase 2 concerning the Standardized System for Access and Disclosure (SSAD) will likely be incredibly high with little to no benefit to any parties other than users of whois data (data requestors, or those who have normally engaged in whois lookups). The NCSG members of the EPDP Team did not believe that the cost of implementing differentiation of how legal and natural persons are treated is justifiable, we did not believe that natural persons would practically receive the protections they are afforded by law should differentiation take place, and therefore, we also did not believe that ICANN and its Contracted Parties would be protected against legal liability should a policy recommendation requiring differentiation be the status quo.
>>
>> These positions created a deadlock on the issue, as was the case with many topics…, well…, as is normally the case on any Policy Development Process Working Group. The compromise we reached in phase 1 was reflected in the final recommendation the EPDP Team made to the GNSO Council on this (check Recommendation 17 in the [Phase 1 Final Report](https://gnso.icann.org/sites/default/files/file/field-file-attach/epdp-gtld-registration-data-specs-final-20feb19-en.pdf)):
>>
>>> “1)  The EPDP Team recommends that Registrars and Registry Operators are permitted to differentiate between registrations of legal and natural persons, but are not obligated to do so.
>>> 2)  The EPDP Team recommends that as soon as possible ICANN Org undertakes a study, for which the terms of reference are developed in consultation with the community, that considers:
>>>
>>> • The feasibility and costs including both implementation and potential liability costs of differentiating between legal and natural persons;
>>>
>>> -
>>>
>>> Examples of industries or other organizations that have successfully differentiated between legal and natural persons;
>>>
>>> -
>>>
>>> Privacy risks to registered name holders of differentiating between legal and natural persons; and
>>>
>>> -
>>>
>>> Other potential risks (if any) to registrars and registries of not differentiating.
>>>
>>> 3) The EPDP Team will determine and resolve the Legal vs. Natural issue in Phase 2.”
>>
>> This compromise allows Contracted Parties to choose to differentiate between legal and natural persons, but does not obligate them to do so, pending the outcome in phase 2 of the EPDP, which is meant to also take in to consideration the study mentioned in the recommendation. This study has not yet been conducted, but ICANN org has stated that it plans on delivering the outcomes of this study sometime in May 2020. The outcome of the study is unlikely to change anything in terms of breaking the deadlock. There is no expectation that Contracted Parties will choose to differentiate, since this will present as a financial burden to them with no reward.
>>
>> To answer your question on when we need to comment on this, Kathy, the answer is now. Rafik just sent a notice of a public comment period opening 2-days ago (26 March, 2020) on the addendum to the phase 2 initial report. This is where the legal vs natural issue is going to be addressed. More details can be found here: https://www.icann.org/public-comments/epdp-phase-2-addendum-2020-03-26-en
>>
>> I hope this was helpful. Please do keep the questions coming, if you have more, Kathy. This, of course applies to anyone here. We have a significantly large team of NCSG members working on the EPDP, and we’re happy to answer questions or hold discussions as often as needed.
>>
>> Thanks.
>>
>> Amr
>>
>>> On Mar 26, 2020, at 4:39 AM, kathy at dnrc.tech <kathy at DNRC.TECH> wrote:
>>>
>>> Hi Amr, Milton and Stephanie,
>>>
>>> In the midst of so many things changing and taking place, it's hard to
>>> track deadlines in ICANN.  That said, I think there was an important
>>> EPDP question last week which may  have been extended to later this
>>> week.
>>>
>>> Can you help point us to a) where we would find the EPDP question
>>> about legal and natural persons and their privacy protection?
>>>
>>> b) whether there is still time to submit comments and
>>>
>>> c) what you recommend (including what positions may be consistent with
>>> past/current NCSG positions)?
>>>
>>> Many thanks!
>>>
>>> In my experience many small noncommercial organizations, including
>>> political minority groups, are run by a few individuals, have no
>>> independent location, and would have to list the home address of one
>>> of their members in the WHOIS.  Over the years, individuals have
>>> expressed concern to me that they may be targeted due to their views
>>> and the information or advocacy they are sharing online (and fear they
>>> may be exposing their families to reprisals).
>>>
>>> I certainly support privacy for many types of "legal persons,"
>>> especially in the nonprofit and organizational space.
>>>
>>> Best regards, Kathy
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://lists.ncsg.is/pipermail/ncsg-discuss/attachments/20200328/365d1440/attachment.htm>


More information about the Ncsg-discuss mailing list