EPDP policy issues
Mueller, Milton L
milton at GATECH.EDU
Sun Apr 25 16:05:22 EEST 2021
Stephanie:
I knew that you were against what I was proposing but until now I did not know what you were actually for. This is seemingly cleared up in the email below. In my response I will first clarify some of the misunderstandings you have about the issue, then I will take a critical look at the proposal you have made.
>At no time have I ever suggested that it would be acceptable for registrars to overrule my designation of >myself as a natural person, or in the case of a legal person, a statement that the contact data of employees >needs to be protected because it contains personal data.
I could provide evidence to the contrary. If you are backing away from that position now, it's good, we will have an easier time coming to an agreement. If we agree on this, you will then agree that the "3rd scenario" in the current Guidance should be deleted, as I have suggested? A yes or no would be good.
>So to push all data of legal persons into a published registry is neither necessary or sound policy.
But that is not what we are debating. My idea gives legal persons who do not want to identify themselves as legal persons the right not to. No one is being pushed.
>Now lets talk about how difficult it is to differentiate between legal persons and individuals. Milton makes it sound easy
Again, you seem to misunderstand the issue that is before us. We are not promoting a process of "differentiating between legal and natural persons" We are promoting an ability to "Self-designate" as a legal person, if you want to. That is not hard at all. That is tremendously easy, if you do it the way I am proposing. If you say you are a legal person, the RDS treats you as one. If you don't, it doesn't.
You go on to raise valid concerns about the complexity of registering a domain. Surprisingly, this is followed by a proposals that would make the situation worse!
Here is how I interpret what you are proposing: I am using your own words to characterize your position, so I think it should be correct, but if it's not let me know in your response:
a) individuals who register a domain must knowledgeably attest to one of the following statements
i. they are an individual, and if they choose to publish their personal information they are doing so in full knowledge of the risks and what will happen to their data
ii. that they are responsible for a legal person's registrations, and that they can attest to the fact that no personal information is being disclosed in the registration.
b) if the contracted parties feel there might be an error in the designation of "legal person" they should err on the side of caution and protect their customer's data
OK. Now we have a basis for comparison.
Note, first that item b) directly contradicts your claim that the registrant's decision cannot be overridden. The registrar would have the authority to look at what data they entered, decide it's wrong, and change it. This implies that the registrars are carefully reviewing every registrants' record at the point of registration, checking out what choices they make, and making a decision about its validity. This is not a slippery slope, you are at the bottom of the hill already. Note also how meaningless it is to say to "err on the side of caution". Many registrars will err on the side of the lowest expense. Other registrars may be told by their government to differentiate.
Note, too that your "attestations" in a) and b) are actually trying to differentiate between legal and natural persons. In your criticism of my proposal, you said it was really difficult to do that. You raised many complications and procedural non-uniformities in the registration process. You said that not all jurisdictions recognize the term, You said registrants can't understand all that stuff. But here we see that your solution doubles down on the process of differentiation and makes it all legally actionable.
You are forcing - pushing was your word - registrants to make two legally consequential attestations that are far more complicated than asking them whether they are a company. Then you are asking the registrar to check the accuracy of those attestations. I think we really want to avoid that. It is against the interests of both registrars and their customers.
What happens if the person making the registration and attests (as in b) that there is no personal information, and they turn out to be wrong? Are they legally liable for violating their attestation? Thanks, Steph, for criminalizing domain name registration.
>I believe that if the contracted parties, who are the data controllers in this situation and therefore own the >risk and the liability attendant with this decision, have to do this verification or trust the decision of the >registrant, we will see either rising costs of domain names (if they do it right) or the same kind of opt-in >situation we see throughout the world now, where people opt in to things without understanding their >risk.
The proposal of yours that I outlined above would make the registration process more risky to BOTH registrars and registrants. You are asking for legal attestations, creating administrative burden and risk, but you will not protect any more data. In fact, your option would likely protect fewer registrant records, because in my plan people who really are legal persons but don't want to declare as such can do so, whereas under your plan they are being put under the microscope and forced to make a legal attestation that they are one or the other.
This would also be drastically more costly. Two attestations by the registrant, a review of the choices made by the registrar, a possibility of the registrar overruling it, this is all really complicated, non-automatable stuff.
So I would have to conclude by saying that you need to reconsider your position, and take a closer look at the real consequences of it. Then compare it to mine. I look forward to your support on that.
Here is another key difference between us:
>There is no need to compromise, and while I understand Milton's desire to compromise,
>I see absolutely no need to do so here.
You say we just stick to our position. This is actually your strongest point and it's one we need to face directly. It probably overrides all the others. I will address it in another message.
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://lists.ncsg.is/pipermail/ncsg-discuss/attachments/20210425/6fb7e734/attachment.htm>
More information about the Ncsg-discuss
mailing list