EDPD policy options

kathy at DNRC.TECH kathy at DNRC.TECH
Tue Apr 27 16:05:20 EEST 2021


Tx to Mark Leiser for fascinating input!

Milton,
Tx for laying this out. I agree we have to be strategic - and I would  
add consistent with NCSG's history and advocacy on this topic too.  We  
have a long history on WHOIS and privacy.

/So let me ask the strategic questions: WHERE ARE THE OTHER  
STAKEHOLDER GROUPS (AND RELEVANT OTHER GROUPS) ON THESE 4 options?  
Could you tell us who is backing each of the options below?/

In particular, where are other SGs with whom NCSG EPDP has been  
working most closely over the years?  Judging from a meeting I dropped  
into in Marrakech 2019, that would be Registrars and Registries.   
/WHERE ARE THE RYS AND RRS ON THESE FOUR OPTIONS? /

It would also be useful to know: /Is there a split between those in  
EU/comprehensive data protection countries including Brazil, Canada  
and Japan and the sectoral privacy countries like the US?  Is there a  
legal split or are the EPDP participants of the SGs pretty aligned? /

/TX MILTON, AND TO ALL NCSG EPDP MEMBERS WHO WOULD LIKE TO RESPOND!
BEST, KATHY/

 
Quoting "Mueller, Milton L" <milton at gatech.edu>:

> So I think we have exchanged views and have a pretty good idea of
> where people stand and what the issues are.
> The next step is to define a position in the EPDP that all of our
> members can adhere to.
> Let me emphasize that defining a viable position is strategic and not
> simply a matter of standing up for some abstract principle.
>
> I will try to identify the set of real options below
>
> Option 1
> ------------
> Under the phase 1 agreement there is no requirement to differentiate
> between legal and natural persons, but Contracted Parties (CPs) can
> do so if they want to.  We are working on possible "guidance" for CPs
> who do try to differentiate.
> One possibility is to leave things as they are.
> No guidance. No requirement to differentiate. Let the status quo
> stand. CPs can do whatever they want.
> Benefits: most data will probably remain redacted
> Risks/problems:
>   - we are already working on guidance, this may no longer be an option
> - some registrars could impose differentiation on their customers
> - GAC, including European Commission, IPC, BC, ALAC, SSAC will be
> unhappy and apparent lack of consensus could lead to board or
> legislative override
>
> Option 2:
> ------------
> (Stephanie's approach)
> Develop Guidance, but make it non-binding
> No legal or natural differentiation, focus on presence or absence of
> personal data
> Registrant must make attestations re personal data; more difficult
> and costly process
> CP involvement in and liability for decisions
>
> Option 3:
> -----------
> (Milton's approach)
> Develop Guidance, but make it non-binding
> Ask for self-designation as legal at point of registration;
> registrant is informed of consequences
> CP can alter record only at request of Registrant
> CP liability and responsibility for contents of reg records is minimized
>
> Option 4:
> ------------
> Develop guidance for differentiation and make it a requirement
> Many different options under here.
>
> This is not an exhaustive list, but it will get us started.
> We need to move beyond posturing and offer specific proposals that
> can gain traction in the actual EPDP group.
>
> Dr. Milton L Mueller
> Georgia Institute of Technology
> School of Public Policy
> [IGP_logo_gold block]
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://lists.ncsg.is/pipermail/ncsg-discuss/attachments/20210427/83673130/attachment.htm>


More information about the Ncsg-discuss mailing list