EPDP policy issues - [adding Kathy]

kathy at DNRC.TECH kathy at DNRC.TECH
Mon Apr 26 08:17:46 EEST 2021


Dear Milton,
This is a very important conversation we are having.  I'll respond in  
order, but note that the most interesting thing you said was in your  
last sentence.  That's worth discussing!

To my questions:
a)      Is a name “personal data”?
> b)      Is an address “personal data”?
> c)       Is a cell phone “personal data”?
> d)      Is an email “personal data”?
>

You believe "In a digital world, there is no hard, well-defined nugget  
of data that is “personal” and
> everything else is not." /In the legal world, however, there hard  
> but not fast answers.  /That's why after being an attorney in this  
> space for a long time, I can tell you that the answer is "it  
> depends" to many of the questions above. Under EU rules, my email  
> can be personal data since it includes my name.  Under EU rules, as  
> I understand them, even info at myorg.org can be personal data if only  
> person runs the "Info" desk of a hypothetical "myorg".

These are not easy questions for anyone going through the fast process  
of domain name registrations (where questions should be clear and  
straightforward).

Please do not underestimate the value of domain name data. SSN,  
driver's licenses and national ID cards all have high level of  
protection under national and state laws.  They are not available in  
24*7 open and public databases as WHOIS has been (prior to GDPR-based  
redaction). More on this below.

BUT HAPPILY, YOU EMAIL ENDED ON A STUNNING NOTE:

> SO I THINK IT IS SIMPLEST TO JUST SAY TO THE REGISTRANT, IF YOU’RE A
> COMPANY AND DON’T MIND (OR EVEN WANT) YOUR DATA TO BE PUBLISHED,
> CHECK THIS BOX. IF YOU’RE NOT, OR YOU DO MIND, DON’T CHECK IT.

/GREAT - CAN WE ASK EXACTLY WHAT YOU SAID ABOVE?!  /NOT THE BINARY  
QUESTION: ARE YOU A LEGAL OR NATURAL PERSON (WITH ITS LEGAL  
LIABILITY), BUT /WOULD YOU LIKE LIKE TO HAVE YOUR DOMAIN NAME  
REGISTRATION DATA PUBLISHED IN THE WHOIS/RDS DATABASE?  /That way  
there are no traps for the unwary, no legal liability for wrong  
answers, and our NCSG members don't have to become great data  
protection scholars before registering a domain ame.

I think we'll find that some companies, organizations and individuals  
will want their data published and some won't (banks were one of the  
biggest users of proxy/privacy services in the WHOIS I Review Team  
Studies). It's a clear question with no legal liability for wrong  
answers.

Are we done?  Does this work?  It seems odd that it would be so  
simple, but I'm willing to take "yes" for an answer :-).

-------------------------

As for WHOIS/RDS data, please don't diminish its value.  On the first  
WHOIS Reveiw Team (I vice-chaired), we found great concern about  
then-massive publication of WHOIS data. The WHOIS/RDS databases were  
(before GDPR) a major place to associate a speaker and his/her  
speech.  That's a huge issue, especially for speakers and  
organizations who are supposed to be assured privacy under freedom of  
expression, free speech and freedom of association laws. 

For our NCSG members, this is a real problem since this association  
can lead to jailing, fining, doxxing, and more of themselves or their  
familiers.  We are the human rights representatives in ICANN, among  
other groups and orgs we represent. No other Stakeholder Group faces  
the risks that our members - and those we speak for across the world -  
do.

In our Review Team research, we also clear evidence of data miners  
gathering WHOIS data in large numbers. It was part of the large system  
of data mining and profiling - and the EU is right, IMHO, to work to  
shut this down.

/So can we leave the binary question aside and ask the underlying  
question:  Do you want your data published?  It leads to a much  
clearer, cleaner, simpler answer without unintended legal liability  
and pitfalls./

Best regards,
Kathy

>
Quoting "Mueller, Milton L" <milton at gatech.edu>:

> Kathy,
> Thanks for your helpful intervention. I especially liked your
> discussion of this:
>
> a)      Is a name “personal data”?
> b)      Is an address “personal data”?
> c)       Is a cell phone “personal data”?
> d)      Is an email “personal data”?
>
> Thinking about this problem – what is personal data – is what led me
> to start modifying my position on this issue. In a digital world
> there is no hard, well-defined nugget of data that is “personal” and
> everything else is not. Your “personality” is reflected in a lot of
> _activity_ on the net, and anyone who can gather and correlate all of
> those footprints knows a lot of personal info about you. True, your
> name and location, where you live, or your SSN or national identity
> number of drivers’ license, provide a stronger basis for putting all
> these correlations into an actionable identity. And that data is out
> there in a number of places, whois is relatively small part of that
> problem. A very small part, in fact
>
> This is one of the reasons I don’t like Stephanie’s proposed approach
> (I will try to answer her message separately). Instead of a simple
> self-designation as legal or natural (company or individual), they
> want to try to force registrars into an elaborate process of
> eliminating personal data from the record. But anything can be
> personal data. OR some things that seem to be personal are not so
> personal. I think such a process is going to make registering a
> domain complicated and expensive and ultimately will not protect
> much. Worse, such a process will also be a camel’s nose under the
> tent process in which registrars assume more and more responsibility
> for determining the accuracy of registration data and for verifying
> the identity of everyone who registers.
>
> Let’s keep it simple and under the registrants’ control. The more you
> involve third party rules and regulations in the registration
> process, the more complicated and expensive it becomes, and the
> privacy gains of such processes are miniscule, they are mostly
> hypothetical and theoretical.
>
> So I think it is simplest to just say to the registrant, if you’re a
> company and don’t mind (or even want) your data to be published,
> check this box. If you’re not, or you do mind, don’t check it.
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://lists.ncsg.is/pipermail/ncsg-discuss/attachments/20210426/2fe8e32b/attachment.htm>


More information about the Ncsg-discuss mailing list