[Public Comments] Call for Volunteers for NCSG Comment on Draft PTI FY21-24 Strategic Plan
Raphael Beauregard-Lacroix
rbeauregardlacroix at GMAIL.COM
Sat May 23 10:18:44 EEST 2020
Hi Amr
Thanks for the detailed comment. By and large I agree with your second
point, and that is what I tried to convey. They certainly have to be
proactive, and that is what they should emphasize. If they can mitigate
that risk themselves, why bring it up as a risk? My point may boil down to
their phrasing being bad optics in the end, which is not a major problem.
I.e. we may all be in agreement on the substance here. Feel free to suggest
alternative wording :)
As for your first point, I think it reaches to the comment Rafik made
directly in the document as well. My response to that is: I'm not quite
clear right now who PTI is/will be in the future, in the whole chain of
command under data protection law. Probably just a data processor, taking
orders (from an agency law perspective) from the controller which would be
ICANN Org in this case. And my understanding is that the substance of such
orders ultimately come from policy decisions, many of which are made by the
community.
I think PTI cares about the trust of the community because ultimately the
community has an influence over whether ICANN renews its contract. It is
true that only the registries and registrars are customers, and certainly
their voice my carry further than our voice for example, were they to deem
PTI untrustworthy (or trustworthy, for that matter.)
But if you are right on the interpretation of the language from the report
to start with (i.e. their point is about a standalone, not community-bound
risk,) I agree with your point overall. I will try over this weekend to
incorporate it under a more general umbrella of "what you (PTI) have
written there is difficult to understand to start with, so here's
alternative interpretations with alternative implications...) Or if you
prefer, I can let you go ahead with that! Let me know.
Have a nice day,
On Sat, May 23, 2020 at 8:30 AM Amr Elsadr <aelsadr at icannpolicy.ninja>
wrote:
> Hi,
>
> I believe that some risks have been conflated in the draft NCSG response.
> The draft PTI Strategic Plan didn’t identify evolving data privacy
> regulation as a community-related risk. Rather, the risk identified was a
> stand-alone issue unrelated to the development of policy recommendations by
> the community. What PTI seems to believe may be a risk is the fact that an
> evolution in the data privacy regulation landscape exists to begin with. I
> think they’re very wrong in considering this a risk at all.
>
> I’m wading into territory that I have little understanding of, so please
> correct me if I’m mistaken, but the PTI’s concerns with an erosion of its
> trust and accountability should be focused on how its direct customers
> perceive its trustworthiness and accountability. If PTI’s customers are
> gTLD and ccTLD Registry Operators and Registrars, then where is the erosion
> of trust it refers to coming from?
>
> The way I see it, privacy/data protection laws have in the past not been
> sufficiently enforceable or harmonized, and that has had a negative impact
> on the certainty of the environment in which Registries and Registrars have
> operated. Now that it has changed, there is a more solid understanding of
> (or a more solid desire to understand and comply with) these laws and
> regulations.
>
> PTI’s own customers are themselves working towards variable degrees of
> changes to the way in which they operate to comply with these regulations,
> and there’s no reason why PTI should perceive this as a threat. The only
> threat in this context that I can see is for PTI’s customers to not comply
> with regulations, and cause damage both to themselves and the Registrants
> they serve. This should still have no impact on PTI’s role in carrying out
> the IANA functions, as far as I can tell. Unless there’s more to this
> potential “risk” that I don’t understand, it reads a little like hyperbole
> to me. PTI should probably just focus on continuing to serve its customers,
> and stay out of issues it is not mandated to deal with.
>
> Community-related risks in the draft operating plan and budget are another
> matter altogether, and I don’t understand the level of true risks involved,
> but would not discount them out-of-hand. For example, one community-related
> risk identified was simply the workload created by new policies developed
> by the community, and the possibility of PTI lacking the capacity to keep
> up with this workload. If this is a real issue, then it is right for PTI to
> flag it, and take the necessary steps to mitigate against it.
>
> Another community-related risk identified is the concern that PTI will be
> unable to meet all the community’s *“expectations and community
> deliverables due to dependency on ICANN Operating Plan and Budget”*.
> Again…, I don’t know if this is actually an issue, or not, but they’ve
> flagged it, so worth looking in to. If ICANN’s Operating Plan and Budget is
> a constraint on PTI’s ability to perform the IANA functions to the
> satisfaction of its customers, then something will clearly need to be done
> about it. If it is an exaggeration, and things may proceed without
> incident, then grand. I really don’t know, but I’m sure others here do.
>
> In any case, I don’t see PTI setting itself up to be an arbiter on policy
> recommendations developed by the community in any way. I don’t believe this
> is the risk or concern that they are trying to convey.
>
> I hope this helps.
>
> Thanks.
>
> Amr
>
> On May 23, 2020, at 2:15 AM, Raphael Beauregard-Lacroix <
> rbeauregardlacroix at GMAIL.COM> wrote:
>
> Hi Tomslin,
>
> Thanks for jumping in!
>
> If I understand you correctly, your point is that the risk evoked here is
> that of conflicting data protection rules? I agree that this is a risk
> somewhere out there, but I don't quite make the link between a hypothetical
> "hard" conflict of laws and the trust of the community in PTI; would you
> have some language to suggest, either to add or modify what is in the
> comment already?
>
> Have a nice day,
>
> On Fri, May 22, 2020 at 7:52 PM Tomslin Samme-Nlar <mesumbeslin at gmail.com>
> wrote:
>
>> Thanks for the draft comment Raphael. Much appreciated!
>>
>> In the comment regarding "evolving data privacy regulation landscape
>> may have impacts on the level of transparency for the IANA
>> registries, which may erode trust and accountability" being a risk
>> to *Maintain stakeholders’ trust that IANA is the proper home
>> for enabling global interoperability through unique identifier
>> coordination,*
>> you wrote ".....to imply, for example, that data protection policies
>> (including those seemingly developed by the community in the context of the
>> Expedited Policy Development Process) may adversely affect “transparency,”
>> “trust,” or “accountability,” represents a value judgement. This is
>> problematic because PTI is not the final arbiter when it comes to the
>> implementation of those values into the policies; the community is."
>>
>> In my opinion, I think it is fair for PTI to put that as risk,
>> understanding that risk is a function of probability and impact. What they
>> are saying there in my view is the fact that there is potential for
>> different jurisdictional regulations to affect their ability to maintain
>> stakeholders' trust.
>>
>> Cheers,
>> Tomslin
>>
>>
>> On Mon., 11 May 2020, 23:58 Raphael Beauregard-Lacroix, <
>> rbeauregardlacroix at gmail.com> wrote:
>>
>>> Hi all
>>>
>>> I have drafted a comment. Comments, suggestions, edits are welcome. The
>>> strategic plan itself is quite short so feel free to have a look too!
>>>
>>> Let's give it a week here so that the PC also have ample time for
>>> review.
>>>
>>> Have a nice day,
>>>
>>> On Mon, Apr 20, 2020 at 7:34 PM Rafik Dammak <rafik.dammak at gmail.com>
>>> wrote:
>>>
>>>> Hi all,
>>>>
>>>> PTI just published a public consultation on Draft PTI FY21-24 Strategic
>>>> Plan and asking for input. We commented previously on PTI budget and
>>>> operating plan and so it is important for us to review this strategic plan.
>>>> You can find here all the details here :
>>>> https://www.icann.org/public-comments/draft-pti-fy21-24-strategic-plan-2020-04-20-en
>>>>
>>>> I created this google doc to be used during the drafting and accessible
>>>> to all in order to kick off the discussion and comments:
>>>> https://docs.google.com/document/d/1yjqC4fh-X9ISzJQWcxxwE75fHrNmnRuF93lCaweBjck/edit
>>>>
>>>>
>>>> Please let me offline if you want to volunteer to participate in
>>>> drafting the NCSG comment, join the drafting team and collaborating with
>>>> finance committee .
>>>>
>>>> You can find previous public comments submitted by NCSG in this wiki
>>>> page
>>>> https://community.icann.org/display/gnsononcomstake/Public+Comments+-+2020 and
>>>> listing those who drafted them or volunteered.
>>>>
>>>> Best Regards,
>>>>
>>>> Rafik Dammak
>>>>
>>>> NCSG Policy Committee Chair
>>>>
>>>
>
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://lists.ncsg.is/pipermail/ncsg-discuss/attachments/20200523/b8e783a5/attachment.htm>
More information about the Ncsg-discuss
mailing list