EPDP policy issues
陳曼茹 Manju Chen
manju at NII.ORG.TW
Sun Apr 25 21:52:22 EEST 2021
Hi everyone,
This is Manju Chen. I'm also one of your representatives on the EPDP. I'm
happy to see this thread going as it clears many misunderstandings and
confusions. I have to admit I wasn't sure about what either Milton or
Stephanie's proposal was about before seeing their elaboration on the
mailing list.
Thinking people might feel as confused as I did, below I will try to
provide a summary of the disagreements in the hope of furthering the
group's discussion on the issue.
First of all, I think the disagreement boils down to 2 major questions.
1. Should we allow the 3rd scenario in the current guidance write-up?
2. Should we concede to the 'legal vs. natural' distinction?
To discuss question 1, we have to firstly know what 'the 3rd scenario' is
about.
In the EPDP, we are currently discussing a 'guidance' (not a requirement)
for CPs who wish to distinguish between legal vs. natural persons. 3
scenarios were proposed in the guidance:
1. Registrant (data subject) self-identification at time of data
collection / registration
2. Registrant (data subject) self-identification after initial collection
3. Registrar determines type based on data provided
The 3rd scenario is where we're having problems with. To give more context,
the current 3rd scenario write-up is as below:
- The Registrar collects Registration Data and provisionally redacts the
data.
- The Registrar uses collected data to infer legal or natural person
type.
- If legal person is inferred by the Registrar and subsequently the
Registrant (data subject) is informed (per guidance #3 above) and confirms
that no personal data is present, the Registrar should (i) contact the
provided contact details to verify the Registrant claim (ii) sets the
registration data set to automated disclosure in response to SSAD queries
and (iii) publishes the data.
- If the Registrar has inferred natural person or has detected personal
data, the Registrar must not disclose registration data unless the
Registrant provides consent for publication or the Registrar Discloses the
data in response to a legitimate disclosure request.
Milton thinks we should not allow this scenario because it denies
registrants the right to self-designation. A counterpoint might be made
that staff has added the instruction for registrars to 'contact the
registrant to verify' to mitigate the harm of possible wrong designation by
the registrars.
Stephanie seems to be OK with this scenario. (This was my impression, I
might be wrong. Please feel free to correct me if I am Stephanie.) Her
argument is that registrars should be able to reduce their risk by
adjusting registrants' wrong self-designation. The counterpoint here is
that this is not a 'registrant identifies and then checked by registrars'
scenario.
In summary, I think the question we should answer here is:
- *Does the NCSG allow the scenario where 'registrars determine
registrant's person type without providing registrants the option of doing
it themselves first'?*
Now we come to question 2. The current guidance proposes a 2-step approach
to distinguish between natural vs. legal persons:
1. Ask registrant to identify as natural or legal.
2. If legal, ask registrant to confirm whether there is personal
information in the data provided. If yes, data redacted. If no, data
published.
Note that this is a 'guidance', not mandatory requirements. Registrars will
only do it when they wish to make the distinction. Also note that we're
arguing for publish as 'automatic disclosure via SSAD', not publicly
available online for everyone.
The disagreement here:
Milton supports the 2-step approach. He agrees with the first step because
it is the necessary political compromise to make to reach consensus within
EPDP. (Again, please feel free to correct me if I misunderstood.)
Stephanie opposes the 2-step approach. She argues that person type is hard
to define, which leads to 2 points: a) we should just ask whether the data
contains personal data, and b) registrars should be able to overrule
registrant's self-designation to protect them.
In summary, the questions we are asking here:
- *Do we agree with the 2-step approach on the premise that a) it stays
as only guidance and b) registrants are given the option to 'not identify
as either'?*
- *Or, do we stick to 'no distinction between natural and legal persons,
only check the data types'?*
- *Do we agree registrars should be able to overrule registrants'
self-designation? This has to be on the premise of 'registrar only
overrules to hide and not disclose', but currently there's no such language
in the policy.*
Hope this helps!
Best,
Manju
On Mon, Apr 26, 2021 at 5:11 AM Mueller, Milton L <milton at gatech.edu> wrote:
> Stephanie:
>
> I knew that you were against what I was proposing but until now I did not
> know what you were actually for. This is seemingly cleared up in the email
> below. In my response I will first clarify some of the misunderstandings
> you have about the issue, then I will take a critical look at the proposal
> you have made.
>
> >At no time have I ever suggested that it would be acceptable for
> registrars to overrule my designation of >myself as a natural person, or
> in the case of a legal person, a statement that the contact data of
> employees >needs to be protected because it contains personal data.
>
> I could provide evidence to the contrary. If you are backing away from
> that position now, it’s good, we will have an easier time coming to an
> agreement. If we agree on this, you will then agree that the “3rd
> scenario” in the current Guidance should be deleted, as I have suggested? A
> yes or no would be good.
>
> >So to push all data of legal persons into a published registry is
> neither necessary or sound policy.
>
> But that is not what we are debating. My idea gives legal persons who do
> not want to identify themselves as legal persons the right not to. No one
> is being pushed.
>
> >Now lets talk about how difficult it is to differentiate between legal
> persons and individuals. Milton makes it sound easy
>
> Again, you seem to misunderstand the issue that is before us. We are not
> promoting a process of “differentiating between legal and natural persons”
> We are promoting an ability to “Self-designate” as a legal person, if you
> want to. That is not hard at all. That is tremendously easy, if you do it
> the way I am proposing. If you say you are a legal person, the RDS treats
> you as one. If you don’t, it doesn’t.
>
> You go on to raise valid concerns about the complexity of registering a
> domain. Surprisingly, this is followed by a proposals that would make the
> situation worse!
>
> Here is how I interpret what you are proposing: I am using your own words
> to characterize your position, so I think it should be correct, but if it’s
> not let me know in your response:
>
> a) individuals who register a domain must knowledgeably attest to
> one of the following statements
>
> i. they are an individual,
> and if they choose to publish their personal information they are doing so
> in full knowledge of the risks and what will happen to their data
>
> ii. that they are responsible
> for a legal person's registrations, and that they can attest to the fact
> that no personal information is being disclosed in the registration.
>
> b) if the contracted parties feel there might be an error in the
> designation of "legal person" they should err on the side of caution and
> protect their customer's data
>
> OK. Now we have a basis for comparison.
>
> Note, first that item b) directly contradicts your claim that the
> registrant’s decision cannot be overridden. The registrar would have the
> authority to look at what data they entered, decide it’s wrong, and change
> it. This implies that the registrars are carefully reviewing every
> registrants’ record at the point of registration, checking out what choices
> they make, and making a decision about its validity. This is not a slippery
> slope, you are at the bottom of the hill already. Note also how meaningless
> it is to say to “err on the side of caution”. Many registrars will err on
> the side of the lowest expense. Other registrars may be told by their
> government to differentiate.
>
> Note, too that your “attestations” in a) and b) are actually trying to
> differentiate between legal and natural persons. In your criticism of my
> proposal, you said it was really difficult to do that. You raised many
> complications and procedural non-uniformities in the registration process.
> You said that not all jurisdictions recognize the term, You said
> registrants can’t understand all that stuff. But here we see that your
> solution doubles down on the process of differentiation and makes it all
> legally actionable.
>
> You are forcing – pushing was your word - registrants to make two legally
> consequential attestations that are far more complicated than asking them
> whether they are a company. Then you are asking the registrar to check the
> accuracy of those attestations. I think we really want to avoid that. It is
> against the interests of both registrars and their customers.
>
> What happens if the person making the registration and attests (as in b)
> that there is no personal information, and they turn out to be wrong? Are
> they legally liable for violating their attestation? Thanks, Steph, for
> criminalizing domain name registration.
>
> >I believe that if the contracted parties, who are the data controllers
> in this situation and therefore own the >risk and the liability attendant
> with this decision, have to do this verification or trust the decision of
> the >registrant, we will see either rising costs of domain names (if they
> do it right) or the same kind of opt-in >situation we see throughout the
> world now, where people opt in to things without understanding their >
> risk.
>
> The proposal of yours that I outlined above would make the registration
> process more risky to BOTH registrars and registrants. You are asking for
> legal attestations, creating administrative burden and risk, but you will
> not protect any more data. In fact, your option would likely protect fewer
> registrant records, because in my plan people who really are legal persons
> but don’t want to declare as such can do so, whereas under your plan they
> are being put under the microscope and forced to make a legal attestation
> that they are one or the other.
>
> This would also be drastically more costly. Two attestations by the
> registrant, a review of the choices made by the registrar, a possibility of
> the registrar overruling it, this is all really complicated,
> non-automatable stuff.
>
> So I would have to conclude by saying that you need to reconsider your
> position, and take a closer look at the real consequences of it. Then
> compare it to mine. I look forward to your support on that.
>
> Here is another key difference between us:
>
> >There is no need to compromise, and while I understand Milton's desire
> to compromise,
>
> >I see absolutely no need to do so here.
>
> You say we just stick to our position. This is actually your strongest
> point and it’s one we need to face directly. It probably overrides all the
> others. I will address it in another message.
>
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://lists.ncsg.is/pipermail/ncsg-discuss/attachments/20210425/dd26247b/attachment.htm>
More information about the Ncsg-discuss
mailing list