EPDP policy issues

Stephanie E Perrin stephanie.perrin at MAIL.UTORONTO.CA
Mon Apr 26 07:40:27 EEST 2021


Manju, thanks so much for this very helpful summary!  I think you have 
seized most of the key elements, as Milton and I continue to talk past 
each other, it would seem.  I consulted one of our long time members, 
Kim von Arx, who replied but seems to have been unable to post to the 
list.  Dr von Arx practices law in London, and has considerable 
experience in GDPR compliance and as former legal counsel at CIRA, the 
Canadian cctld.  Here is his response, I think he sees the delta of our 
differing views in a similar way to your own summary.

Kind regards, Stephanie Perrin



Dear Noncommercials,

I have not participated in the discussions and activities of the NCSG 
for quite a few years, but I have seen this recent discussion between 
Stephanie and Milton and being a tech, privacy, and IP lawyer myself 
this topic is very close to my heart.

I can see both sides of the argument to a degree and as I understand it, 
the delta between the two views is really not that big at all.  I 
understand and if I am correct I completely agree with both positions:

1. Milton suggests that the natural RANT should be entitled to make 
his/her/their own determination re: his/her/their status;
2. Stephanie suggests that the natural RANT should be entitled to make 
his/her/their own determination re: his/her/their status, *BUT* argues 
that RARs should keep a vigilant eye out to make sure that the natural 
RANT has not selected legal RANT status by accident or out of 
ignorance.  This, of course does not and must not apply the other way.  
Therefore, this is a safety net for the natural RANT.

I think this makes sense and protects the natural RANT.  At the end of 
the day our position should aways be “err on the side of protecting”.  
As Stephanie pointed out correctly this does not mean it is now locked 
in Fort Knox or some such, but that it is protected from quick and dirty 
exploitation by and because of administrative protection. The magic will 
be, btw, how this is going to be implemented in the real world, i.e., 
how RARs make the determination and assessment and introduces the checks 
and balances.  I suggest the one way may be:

1. self selection; and if legal RANT, then
2. Have a double check online binary questionnaire that will then 
determine, based on the responses, whether he/she/they self selected 
properly as legal RAR.

Anyway, if it was my call, I would, as I had implemented CIRA’s privacy 
practice back in the early 2000s, start with the position of all 
information is protected until there is clear reason for not doing so 
and, of course, a clear process to get access to the information if 
there is good reason to do so.  But, as I said, we should always err on 
the side of protecting PII provided there is always a legitimate and 
auditable process to have access to it for good and sound reasons.

Anyway, my two cents on this.

Best wishes,

Kim

kim at vonarx.ca <mailto:kim at vonarx.ca>
+44 7473 506060
On 2021-04-25 10:52 p.m., 陳曼茹 Manju Chen wrote:
> *EXTERNAL EMAIL:*
> Hi everyone,
>
> This is Manju Chen. I'm also one of your representatives on the EPDP. 
> I'm happy to see this thread going as it clears many misunderstandings 
> and confusions. I have to admit I wasn't sure about what either Milton 
> or Stephanie's proposal was about before seeing their elaboration on 
> the mailing list.
>
> Thinking people might feel as confused as I did, below I will try to 
> provide a summary of the disagreements in the hope of furthering the 
> group's discussion on the issue.
>
> First of all, I think the disagreement boils down to 2 major questions.
>
>  1. Should we allow the 3rd scenario in the current guidance write-up?
>  2. Should we concede to the 'legal vs. natural' distinction?
>
>
> To discuss question 1, we have to firstly know what 'the 3rd scenario' 
> is about.
> In the EPDP, we are currently discussing a 'guidance' (not a 
> requirement) for CPs who wish to distinguish between legal vs. natural 
> persons. 3 scenarios were proposed in the guidance:
>
>  1. Registrant (data subject) self-identification at time of data
>     collection / registration
>  2. Registrant (data subject) self-identification after initial collection
>  3. Registrar determines type based on data provided
>
>
> The 3rd scenario is where we're having problems with. To give more 
> context, the current 3rd scenario write-up is as below:
>
>   * The Registrar collects Registration Data and provisionally redacts
>     the data.
>   * The Registrar uses collected data to infer legal or natural person
>     type.
>   * If legal person is inferred by the Registrar and subsequently the
>     Registrant (data subject) is informed (per guidance #3 above) and
>     confirms that no personal data is present, the Registrar should
>     (i) contact the provided contact details to verify the Registrant
>     claim (ii) sets the registration data set to automated disclosure
>     in response to SSAD queries and (iii) publishes the data.
>   * If the Registrar has inferred natural person or has detected
>     personal data, the Registrar must not disclose registration data
>     unless the Registrant provides consent for publication or the
>     Registrar Discloses the data in response to a legitimate
>     disclosure request.
>
> Milton thinks we should not allow this scenario because it denies 
> registrants the right to self-designation. A counterpoint might be 
> made that staff has added the instruction for registrars to 'contact 
> the registrant to verify' to mitigate the harm of possible wrong 
> designation by the registrars.
>
> Stephanie seems to be OK with this scenario. (This was my impression, 
> I might be wrong. Please feel free to correct me if I am Stephanie.) 
> Her argument is that registrars should be able to reduce their risk by 
> adjusting registrants' wrong self-designation. The counterpoint here 
> is that this is not a 'registrant identifies and then checked by 
> registrars' scenario.
>
> In summary, I think the question we should answer here is:
>
>   * *_Does the NCSG allow the scenario where 'registrars determine
>     registrant's person type without providing registrants the option
>     of doing it themselves first'?_*
>
>
> Now we come to question 2. The current guidance proposes a 2-step 
> approach to distinguish between natural vs. legal persons:
>
>  1. Ask registrant to identify as natural or legal.
>  2. If legal, ask registrant to confirm whether there is personal
>     information in the data provided. If yes, data redacted. If no,
>     data published.
>
> Note that this is a 'guidance', not mandatory requirements. Registrars 
> will only do it when they wish to make the distinction. Also note that 
> we're arguing for publish as 'automatic disclosure via SSAD', not 
> publicly available online for everyone.
>
> The disagreement here:
>
> Milton supports the 2-step approach. He agrees with the first step 
> because it is the necessary political compromise to make to reach 
> consensus within EPDP. (Again, please feel free to correct me if I 
> misunderstood.)
>
> Stephanie opposes the 2-step approach. She argues that person type is 
> hard to define, which leads to 2 points: a) we should just ask whether 
> the data contains personal data, and b) registrars should be able to 
> overrule registrant's self-designation to protect them.
>
> In summary, the questions we are asking here:
>
>   * *_Do we agree with the 2-step approach on the premise that a) it
>     stays as only guidance and b) registrants are given the option to
>     'not identify as either'?_*
>   * *_Or, do we stick to 'no distinction between natural and legal
>     persons, only check the data types'?_*
>   * *_Do we agree registrars should be able to overrule registrants'
>     self-designation? This has to be on the premise of 'registrar only
>     overrules to hide and not disclose', but currently there's no such
>     language in the policy._*
>
>
> Hope this helps!
>
> Best,
> Manju
>
> On Mon, Apr 26, 2021 at 5:11 AM Mueller, Milton L <milton at gatech.edu 
> <mailto:milton at gatech.edu>> wrote:
>
>     Stephanie:
>
>     I knew that you were against what I was proposing but until now I
>     did not know what you were actually for. This is seemingly cleared
>     up in the email below. In my response I will first clarify some of
>     the misunderstandings you have about the issue, then I will take a
>     critical look at the proposal you have made.
>
>     >At no time have I ever suggested that it would be acceptable for
>     registrars to overrule my designation of >myself as a natural
>     person, or in the case of a legal person, a statement that the
>     contact data of employees >needs to be protected because it
>     contains personal data.
>
>     I could provide evidence to the contrary. If you are backing away
>     from that position now, it’s good, we will have an easier time
>     coming to an agreement.  If we agree on this, you will then agree
>     that the “3^rd scenario” in the current Guidance should be
>     deleted, as I have suggested? A yes or no would be good.
>
>     >So to push all data of legal persons into a published registry is
>     neither necessary or sound policy.
>
>     But that is not what we are debating. My idea gives legal persons
>     who do not want to identify themselves as legal persons the right
>     not to. No one is being pushed.
>
>     >Now lets talk about how difficult it is to differentiate between
>     legal persons and individuals.Milton makes it sound easy
>
>     Again, you seem to misunderstand the issue that is before us. We
>     are not promoting a process of “differentiating between legal and
>     natural persons” We are promoting an ability to “Self-designate”
>     as a legal person, if you want to. That is not hard at all. That
>     is tremendously easy, if you do it the way I am proposing. If you
>     say you are a legal person, the RDS treats you as one. If you
>     don’t, it doesn’t.
>
>     You go on to raise valid concerns about the complexity of
>     registering a domain. Surprisingly, this is followed by a
>     proposals that would make the situation worse!
>
>     Here is how I interpret what you are proposing: I am using your
>     own words to characterize your position, so I think it should be
>     correct, but if it’s not let me know in your response:
>
>     a)individuals who register a domain must knowledgeably attest to
>     one of the following statements
>
>     i.they are an individual, and if they choose to publish their
>     personal information they are doing so in full knowledge of the
>     risks and what will happen to their data
>
>     ii.that they are responsible for a legal person's registrations,
>     and that they can attest to the fact that no personal information
>     is being disclosed in the registration.
>
>     b)if the contracted parties feel there might be an error in the
>     designation of "legal person" they should err on the side of
>     caution and protect their customer's data
>
>     OK. Now we have a basis for comparison.
>
>     Note, first that item b) directly contradicts your claim that the
>     registrant’s decision cannot be overridden. The registrar would
>     have the authority to look at what data they entered, decide it’s
>     wrong, and change it. This implies that the registrars are
>     carefully reviewing every registrants’ record at the point of
>     registration, checking out what choices they make, and making a
>     decision about its validity. This is not a slippery slope, you are
>     at the bottom of the hill already. Note also how meaningless it is
>     to say to “err on the side of caution”. Many registrars will err
>     on the side of the lowest expense. Other registrars may be told by
>     their government to differentiate.
>
>     Note, too that your “attestations” in a) and b) are actually
>     trying to differentiate between legal and natural persons. In your
>     criticism of my proposal, you said it was really difficult to do
>     that. You raised many complications and procedural
>     non-uniformities in the registration process. You said that not
>     all jurisdictions recognize the term, You said registrants can’t
>     understand all that stuff. But here we see that your solution
>     doubles down on the process of differentiation and makes it all
>     legally actionable.
>
>     You are forcing – pushing was your word - registrants to make two
>     legally consequential attestations that are far more complicated
>     than asking them whether they are a company. Then you are asking
>     the registrar to check the accuracy of those attestations. I think
>     we really want to avoid that. It is against the interests of both
>     registrars and their customers.
>
>     What happens if the person making the registration and attests (as
>     in b) that there is no personal information, and they turn out to
>     be wrong? Are they legally liable for violating their attestation?
>     Thanks, Steph, for criminalizing domain name registration. __
>
>     >I believe that if the contracted parties, who are the data
>     controllers in this situation and therefore own the >risk and the
>     liability attendant with this decision, have to do this
>     verification or trust the decision of the >registrant, we will see
>     either rising costs of domain names (if they do it right) or the
>     same kind of opt-in >situation we see throughout the world now,
>     where people opt in to things without understanding their >risk.
>
>     The proposal of yours that I outlined above would make the
>     registration process more risky to BOTH registrars and
>     registrants. You are asking for legal attestations, creating
>     administrative burden and risk, but you will not protect any more
>     data. In fact, your option would likely protect fewer registrant
>     records, because in my plan people who really are legal persons
>     but don’t want to declare as such can do so, whereas under your
>     plan they are being put under the microscope and forced to make a
>     legal attestation that they are one or the other.
>
>     This would also be drastically more costly. Two attestations by
>     the registrant, a review of the choices made by the registrar, a
>     possibility of the registrar overruling it, this is all really
>     complicated, non-automatable stuff.
>
>     So I would have to conclude by saying that you need to reconsider
>     your position, and take a closer look at the real consequences of
>     it. Then compare it to mine. I look forward to your support on that.
>
>     Here is another key difference between us:
>
>     >There is no need to compromise, and while I understand Milton's
>     desire to compromise,
>
>     >I see absolutely no need to do so here.
>
>     You say we just stick to our position. This is actually your
>     strongest point and it’s one we need to face directly. It probably
>     overrides all the others. I will address it in another message.
>
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://lists.ncsg.is/pipermail/ncsg-discuss/attachments/20210426/91fdd084/attachment.htm>


More information about the Ncsg-discuss mailing list