EPDP policy issues - [adding Kathy]

Mark Leiser markleiser at GMAIL.COM
Tue Apr 27 11:39:48 EEST 2021


Hello all,

I'm Assistant Professor in Law and Digital Technologies at Leiden
University in the Netherlands. I wanted to add a little European
perspective to this thread. I find it all a bit bizarre and some of the
arguments to be a little off point. Article 4(1) GDPR states that personal
data is 'any information related to an identifiable living person', The
Article 29 Working Party has made this clear - ANY information is to be
interpreted very broadly. This approach has been endorsed by the CJEU.
Furthermore, it matters not whether someone has given permission,
consented, or otherwise. It is still personal data and as far as the GDPR
goes, you need to have a valid ground for processing personal data -
otherwise you will be falling foul of the Regulation. Pseudonymous data is
also to be considered personal data. Either way, the Registrars will be
processing personal data if any information is related to a living
individual.

Let me answer Kathy's questions  -

a)      Is a name “personal data”? *YES*
b)      Is an address “personal data”? *YES - because it is 'any
information' 'relating to' a living individual (the people that live there)*
c)       Is a cell phone “personal data”? *YES - because it is information
that relates to a living individual*
d)      Is an email “personal data”? *YES - because most emails are related
to an identifiable person. Kathy's email above relates to her, therefore,
it is personal data. *

Therefore, info at myorg.org is personal data if someone behind it is
identifiable. If more than one person is running that account it would
amount to personal data about BOTH individuals. So Kathy is kind of right
here. As far as the GDPR goes, you are processing personal data.
Furthermore, even if someone is not identifiable, if the email is able to
be combined with data from another set to reveal the user of the account,
the email would still amount to 'personal data' within the meaning of
Article 4(1).

Stephanie's email made reference to the fact that employees do not know and
understand their rights. The GDPR offers the type of protection that makes
this irrelevant.. They are protected. The GDPR would also protect 'legal
persons' if there is a natural person behind the entity that is
identifiable. The confusion comes from Recital 14 of the GDPR which states
that it only applies to natural persons and does not cover the processing
of personal data concerning legal persons, in particular undertakings
established as legal persons or legal entities. This also includes the name
of the legal person, the form, and the contact details of the legal person.

But the second you start adding identifiers to these details, it stops
becoming the data of a 'legal person' and starts becoming personal data.

Secondly, I find this statement, "I think it is simplest to just say to the
registrant, if you’re a company and don’t mind (or even want) your data to
be published, check this box. If you’re not, or you do mind, don’t check
it."  to be BOTH perplexing and inaccurate.

Whether someone checks the box, or does not check the box is completely
irrelevant for determining whether it is personal data. Whether someone
checks the box is a question of CONSENT to processing AND publication, not
whether this amounts to personal data. So If MIlton's position (as
represented by Stephanie is true), if the Registrars overrule the
designation of a registrant or whether Stephanie's approach of 'erring on
the side of caution' is viable. Registrants must protect personal data as a
legal obligation - and must have a legal ground for processing personal
data in all instances. Remember the GDPR has extra-jurisdictional effects.
If a registrant chooses to self-designate as a legal person or not is
irrelevant for the purposes of the GDPR. If a registrar decides to identify
you, or take steps to do so then they are processing personal data and need
a legal basis for doing so. If the legal person becomes identifiable, then
the registrar is STILL processing personal data. And it would make sense
for them to have a LEGAL BASIS for doing so.

So without a lot of further discussion from me about the three emails in
this thread, I would just conclude that what you are all proposing is
somewhat irrelevant for compliance with European data privacy obligations.
If the person is identifiable from the data, the registrar will be
processing personal data if there is a living individual that is related to
that personal data. The Registrar might not want to be a data controller
and subject to the GDPR's obligations. Although a legal person might not be
considered 'personal data' under Recital 14, if this data can be combined
with additional data, it will become personal data. Therefore it is not a
question of whether they should designate as a legal person or not, it is
whether either a 'natural' person or a 'legal' person consents to the
publication of its data.

Finally, Kathy, MIlton, and Stephanie are confusing the regulatory
obligations under the GDPR, with the privacy rights of both the EU Charter
and the European Convention of Human Rights. Data Protection is a
STANDALONE fundamental right in Europe. While you may be compliant with the
GDPR but you have to ALSO be compliant with the privacy obligations of the
European Convention of Human Rights. Therefore, to build on Kathy's
suggestion in the email thread and to cover the GDPR's requirements and the
ECHR's privacy obligations, I would argue that the question needs to be at
least the following: 'do you consent to your domain name registration data
being published in the WHOIS/RDS database?'.  I would also argue that the
default should be 'no' in order to comply with both the GDPR and European
privacy obligations.

Happy to discuss further.

Regards,

Mark

*Dr Mark Leiser | Law and Digital Technologies | FRSA FHEA |*


On Mon, 26 Apr 2021 at 14:19, <kathy at dnrc.tech> wrote:

> Dear Milton,
> This is a very important conversation we are having.  I'll respond in
> order, but note that the most interesting thing you said was in your last
> sentence.  That's worth discussing!
>
> To my questions:
> a)      Is a name “personal data”?
> > b)      Is an address “personal data”?
> > c)       Is a cell phone “personal data”?
> > d)      Is an email “personal data”?
> >
>
> You believe "In a digital world, there is no hard, well-defined nugget of
> data that is “personal” and
> > everything else is not." *In the legal world, however, there hard but
> not fast answers. * That's why after being an attorney in this space for
> a long time, I can tell you that the answer is "it depends" to many of the
> questions above. Under EU rules, my email can be personal data since it
> includes my name.  Under EU rules, as I understand them, even
> info at myorg.org can be personal data if only person runs the "Info" desk
> of a hypothetical "myorg".
>
> These are not easy questions for anyone going through the fast process of
> domain name registrations (where questions should be clear and
> straightforward).
>
> Please do not underestimate the value of domain name data. SSN, driver's
> licenses and national ID cards all have high level of protection under
> national and state laws.  They are not available in 24*7 open and public
> databases as WHOIS has been (prior to GDPR-based redaction). More on this
> below.
>
>
>
>
>
> *But happily, you email ended on a stunning note: > So I think it is
> simplest to just say to the registrant, if you’re a > company and don’t
> mind (or even want) your data to be published, > check this box. If you’re
> not, or you do mind, don’t check it.*
>
> *Great - can we ask exactly what you said above?! * *Not the binary
> question: are you a legal or natural person (with its legal liability), but
> would you like like to have your domain name registration data published in
> the WHOIS/RDS database? * That way there are no traps for the unwary, no
> legal liability for wrong answers, and our NCSG members don't have to
> become great data protection scholars before registering a domain ame.
>
> I think we'll find that some companies, organizations and individuals will
> want their data published and some won't (banks were one of the biggest
> users of proxy/privacy services in the WHOIS I Review Team Studies). It's a
> clear question with no legal liability for wrong answers.
>
> Are we done?  Does this work?  It seems odd that it would be so simple,
> but I'm willing to take "yes" for an answer :-).
>
> -------------------------
>
> As for WHOIS/RDS data, please don't diminish its value.  On the first
> WHOIS Reveiw Team (I vice-chaired), we found great concern about
> then-massive publication of WHOIS data. The WHOIS/RDS databases were
> (before GDPR) a major place to associate a speaker and his/her speech.
> That's a huge issue, especially for speakers and organizations who are
> supposed to be assured privacy under freedom of expression, free speech and
> freedom of association laws.
>
> For our NCSG members, this is a real problem since this association can
> lead to jailing, fining, doxxing, and more of themselves or their
> familiers.  We are the human rights representatives in ICANN, among other
> groups and orgs we represent. No other Stakeholder Group faces the risks
> that our members - and those we speak for across the world - do.
>
> In our Review Team research, we also clear evidence of data miners
> gathering WHOIS data in large numbers. It was part of the large system of
> data mining and profiling - and the EU is right, IMHO, to work to shut this
> down.
>
> *So can we leave the binary question aside and ask the underlying
> question:  Do you want your data published?  It leads to a much clearer,
> cleaner, simpler answer without unintended legal liability and pitfalls.*
>
> Best regards,
> Kathy
>
>
>
> >
> Quoting "Mueller, Milton L" <milton at gatech.edu>:
>
> > Kathy,
> > Thanks for your helpful intervention. I especially liked your
> > discussion of this:
> >
> > a)      Is a name “personal data”?
> > b)      Is an address “personal data”?
> > c)       Is a cell phone “personal data”?
> > d)      Is an email “personal data”?
> >
> > Thinking about this problem – what is personal data – is what led me
> > to start modifying my position on this issue. In a digital world
> > there is no hard, well-defined nugget of data that is “personal” and
> > everything else is not. Your “personality” is reflected in a lot of
> > _activity_ on the net, and anyone who can gather and correlate all of
> > those footprints knows a lot of personal info about you. True, your
> > name and location, where you live, or your SSN or national identity
> > number of drivers’ license, provide a stronger basis for putting all
> > these correlations into an actionable identity. And that data is out
> > there in a number of places, whois is relatively small part of that
> > problem. A very small part, in fact
> >
> > This is one of the reasons I don’t like Stephanie’s proposed approach
> > (I will try to answer her message separately). Instead of a simple
> > self-designation as legal or natural (company or individual), they
> > want to try to force registrars into an elaborate process of
> > eliminating personal data from the record. But anything can be
> > personal data. OR some things that seem to be personal are not so
> > personal. I think such a process is going to make registering a
> > domain complicated and expensive and ultimately will not protect
> > much. Worse, such a process will also be a camel’s nose under the
> > tent process in which registrars assume more and more responsibility
> > for determining the accuracy of registration data and for verifying
> > the identity of everyone who registers.
> >
> > Let’s keep it simple and under the registrants’ control. The more you
> > involve third party rules and regulations in the registration
> > process, the more complicated and expensive it becomes, and the
> > privacy gains of such processes are miniscule, they are mostly
> > hypothetical and theoretical.
> >
> > So I think it is simplest to just say to the registrant, if you’re a
> > company and don’t mind (or even want) your data to be published,
> > check this box. If you’re not, or you do mind, don’t check it.
>
>
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://lists.ncsg.is/pipermail/ncsg-discuss/attachments/20210427/6e3d48f2/attachment.htm>


More information about the Ncsg-discuss mailing list