Fwd: [NCSG-PC] EPDP policy issues
Akinremi Peter Taiwo
compsoftnet at GMAIL.COM
Thu Apr 29 09:35:53 EEST 2021
Just checking that I sent directly to Milton. Now sharing on the list
---------- Forwarded message ---------
From: Akinremi Peter Taiwo <compsoftnet at gmail.com>
Date: Tue, Apr 27, 2021 at 11:05 AM
Subject: Re: [NCSG-PC] EPDP policy issues
To: Mueller, Milton L <milton at gatech.edu>
Thanks to the EPDP team especially Milton and Stephanie for bringing this
issue to the members attention. As said by Tatiana, we are all aware of
natural and legal debate especially for those that have been following the
EPDP conversations. While there is no one size fit answer to address the
issues of natural vs legal privacy protection, NCSG should have a position
that is driven by consensus.
While thanking the EPDP team that represents NCSG, it is expected of the
team to have discussed among themselves having a common approach feeding to
the EPDP conversations rather than having our members openly disagreeing
with each other. That could be done on our list to help us have a common
ground, but not on other working groups where we are nominated to represent
NCSG.
Our position on the natural and legal persons privacy conversation should
be driven by the core values of NCSG. We need long standing members of the
NCSG to comment and other experts for us to determine NCSG position to the
current EPDP discussions. PC should take this seriously and explore what is
best for the people we represent and not what individuals think is best.
Registrants’ information should be protected and any opportunity for its
exploitation should not be allowed nor granted. Whatever mechanism that is
in discussion should have privacy by design and default. That should apply
to either natural or legal persons. Registrants PII should not be published
and should not fall into wrong hands and its usage. Registrants who are the
data subjects (individual, employees) should be in control, have their
privacy respected and preserved, and should decide how their data is
processed. Registrars should not be given the privilege to decide for the
registrants or influence data subjects' decisions on how their data is
processed.
Our concern should be that registrants’ information is not publicly
published which is the current reflection of whois directory. Whois
directory should not be abused. NCSG should not be cut in the web of these
discussions but should have a firm positioned on the privacy rights of the
registrants. Influence is on the increase on what the whois should contain
and not. Why the growing interest by the CPs differentiating natural and
legal persons? what will happen in the years to come if that is done?
My thoughts !
On Sat, Apr 24, 2021 at 10:45 PM Mueller, Milton L <milton at gatech.edu>
wrote:
> Dear Noncommercials,
>
> I am one of your representatives of the EPDP, and ICANN working group that
> is trying to bring ICANN’s Whois policy into compliance with privacy
> principles.
>
> Just yesterday we received this statement from the current chair of the
> group, Keith Drazek:
>
> The EPDP Team is a representative group – you have all been
> appointed by your respective groups to represent them in this effort. As a
> result, any proposals and interventions you make are expected to be on
> behalf of your group. We understand that this requires significant
> coordination which is not always possible in real-time but it is important
> that we do not find ourselves in a situation where a specific proposal or
> suggestion is debated to then find that other members of the same group do
> not stand behind the proposal or suggestion.
>
>
>
> I suspect Keith found it necessary to say this because lately another NCSG
> representative on the EPDP, Stephanie, and I have been openly disagreeing.
> Let me explain what the disagreement is about. We will have to appeal to
> the Policy Committee, and the membership, to help resolve it.
>
>
>
> Privacy protections under the GDPR only apply to natural persons, that is
> to say living breathing humans, not to legal persons, i.e. corporations or
> companies. And in most cases, we do not mind if company data is published
> in their domain record. In many cases it can even help with economic and
> legal accountability. However, we both recognize that there is a large gray
> area of small companies or home offices where the line between personal and
> legal is thin, blurry or nonexistent. A registrant that is formally a legal
> person may want the privacy protection of a natural person.
>
>
>
> One of the issues we are dealing with in Phase 2 is whether and how
> registrars should differentiate between those two types of registrants.
> Under the current Phase 1 agreement, contracted parties are not required to
> differentiate between registrants who are legal or natural persons, but
> they can do so if they wish to. I believe both Stephanie and I (and the
> contracted parties) agree on NOT requiring them to differentiate.
>
>
>
> But if registrars DO choose to differentiate, we have to worry about HOW
> they do it. Currently, the EPDP is working on a guidance document that will
> set out ways to do it. I want to make sure that the guidance protects the
> rights of registrants.
>
>
>
> My position is that registrants should be given a clear choice to
> self-designate as a legal person or not. When given that choice, they must
> be clearly told that their data will be published, and if they don’t want
> the data published, they should not self-designate as a legal person. Under
> my view, the registrant, and the registrant alone, should decide for
> themselves whether to declare as legal person or not.
>
>
>
> Stephanie’s position is that registrants are not smart enough to make this
> choice for themselves. Worse, her belief that registrants cannot look out
> for their own interests makes her in favor of the idea that REGISTRARS
> should be able to make the choice for them. In other words, a commercial
> registrar, based on their own information about you, could decide that you
> are registering a domain name on behalf of a company and classify you as a
> legal person without your participation or consent.
>
>
>
> In my view, this is a very bad idea, even a dangerous one. It makes the
> registrar responsible for verifying certain aspects of your identity. We
> already know that those who want more surveillance and control of
> registrants want registrars to be more restrictive and take on a bigger
> role vetting who is registering domains. This idea is also very bad for the
> registrars, because if a registrar is making the decision about whether you
> are a legal or natural person, then the registrar will be legally liable
> for the decision. Further down the road, those who want a more restrictive
> internet will love the precedent set, they will ask the registrars to do
> more and more to vet and regulate their customers.
>
>
>
> I believe that Stephanie has good motives for her position; as I
> understand it she thinks that if registrars have this ability to decide for
> the registrant, they will err on the side of non-disclosure. But this is
> very naïve. Yes, some of the registrars we are dealing with in EPDP are
> sincere supporters of their customers privacy. But others are not. Further,
> Stephanie is forgetting about the fact that many registrars are operating
> in authoritarian countries where individual rights are not respected. I am
> also deeply troubled by a position that registrants are children who cannot
> take care of themselves. I think Stephanie’s position is also motivated by
> the view that we are better off if there is no differentiation at all. This
> may be true, but it is unrealistic. The default policy, ALREADY, is that
> registrars will be able to differentiate if they want to. I am trying to
> plan for the possibility that many of them will want to. If they do, we
> want registrants to be in control of their status, not registrars or any
> other third party allegedly acting on their behalf.
>
>
>
> My hope is that the membership and the PC will resolve this issue in favor
> of the “registrant in control” position.
>
>
>
> Sorry for the long message
>
>
>
> Dr. Milton L Mueller
>
> Georgia Institute of Technology
>
> School of Public Policy
>
> [image: IGP_logo_gold block]
>
>
> _______________________________________________
> NCSG-PC mailing list
> NCSG-PC at lists.ncsg.is
> https://lists.ncsg.is/mailman/listinfo/ncsg-pc
>
--
Best regards
*Taiwo Peter Akinremi*
------ ------ ------- ------ ------ ------- ------ ------ ------- ------
------ ------- ------ ------ ------
IT Manager/Advisory
*Phone*; +2348187476292, +2347063830177 *Skype*: akinremi.taiwo
*Email:* info at compsoftnet.com.ng *Website:* www.compsoftnet.com.ng
___________________________________________
--
Best regards
*Taiwo Peter Akinremi*
------ ------ ------- ------ ------ ------- ------ ------ ------- ------
------ ------- ------ ------ ------
IT Manager/Advisory
*Phone*; +2348187476292, +2347063830177 *Skype*: akinremi.taiwo
*Email:* info at compsoftnet.com.ng *Website:* www.compsoftnet.com.ng
___________________________________________
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://lists.ncsg.is/pipermail/ncsg-discuss/attachments/20210429/da7810d1/attachment.htm>
-------------- next part --------------
A non-text attachment was scrubbed...
Name: image002.png
Type: image/png
Size: 16925 bytes
Desc: not available
URL: <http://lists.ncsg.is/pipermail/ncsg-discuss/attachments/20210429/da7810d1/attachment.png>
More information about the Ncsg-discuss
mailing list