Public Comment Call for Volunteers - Input on the Initial Report of the Phase 2A EPDP

Zhou Heng socata at RUC.EDU.CN
Tue Jul 20 02:28:17 EEST 2021


Dear Milton Mueller,


Thanks for your response. It helps me learn a lot. I think I can make furthur clarification.


China’s national law has no authority over the root server – indeed, it is destructive and impossible for any national government to try to impose its national law on this globally shared resource. China’s law also has no authority over TLD operators who do not serve Chinese customers. China’s “real name” law can ONLY apply to registrars serving Chinese customers, because that is where individuals with “real names” intersect with the domain name system.


I agree with you that China's law has no authority over TLD operators who do not serve Chinese customers. However, any TLD have business in China should deal with China Security Law. I don't feel quote China Security Law as a Legal Consideration is irrelevent.

You may not understand what you are talking about here – how would a TLD operator provide a “real name” when it is a company, not a person, and when its records contain tens of thousands or millions of names of registrants? Are you saying that Chinese law requires every TLD operator and registrar in the world to turn over personally identifiable information of all their customers to the Chinese government? I think no one in this stakeholder group, or any other, would support this, and none of the world’s governments would accept it, either.


That's not I am talking about. What I am talking about in the first email is that, ICANN, registry and registrar with business in China, they need to require the registrant to provide a real identification, not simply let them choose their identification. There are many other ways in practice to achieve such result, for example, a statement from registrant about their registration information is real. There is no such a requirement from Chinese government about requiring every TLD operator and registrar in the world to turn over personally identifiable information of all their customers to the Chinese government.


My intents it to point out right now the practice in EPDP Team Phase 2A Initial Report may have potential compliance risk in China.


These are ICANN policies, not European ones.


I agree that. However, I also want to mention that in Page 3 of EPDP Team Phase 2A Initial Report, the whole GNSO PDP is initiated by the board action about complying with the European Union’s GDPR.


EU law does not override Chinese law, but Chinese law cannot bind what the rest of the world does, either. I Hope that’s clear.


I also understand that. However, the question 8 of EPDP Team Phase 2A Initial Report is to seek the question 8 of EPDP Team Question for Community Input is to seek the legal and regulatory considerations not yet considered in this Initial Report. If China's Cybersecurity is not qualified to be mentioned as a legal consideration, what kind of law or regulation might be suitable to be mentioned for this question? UN's resolution? Or, Only legal consideration from EU? I hope get instruction about that.


 It is not relevant, but you can make this comment to ICANN as an individual. Are you commenting on behalf of the Chinese government? Maybe you should work with your GAC representative.


No, I am not on behalf of the Chinese government. Right now, I am an independant researcher working in a pure research institute. I am not a staff of Chinese government.
I have made this commet in public comment forum as an individual a few days ago. 
In my first email, I made it very clear that I want to provide some information about China Network Security Law(中华人民共和国网络安全法), even though it may not be suitable to present it as a NCSG Comment. I am not seeking to put my viewpoint into NCSG comment. The reason why I bought it up is that I hope to bring information to the NCSG community. I think communication between different culture background might help us have better understanding about each other, and those information might also help the community.


Best regards,


--
Zhou Heng
Assistant Researcher 
Hunan Academy of Social Science



发件人:"Mueller, Milton L" <milton at GATECH.EDU>
发送日期:2021-07-19 22:52:25
收件人:NCSG-DISCUSS at LISTSERV.SYR.EDU
主题:Re: Public Comment Call for Volunteers - Input on the Initial Report of the Phase 2A EPDP
 

>According to article 2 of China Domain Name Registration Regulation(互联网域名管理办法),
>the domain name service is not only about the basic domain name registration service provided
> by registar, but also contains the operation of root server and TLD.
 
China’s national law has no authority over the root server – indeed, it is destructive and impossible for any national government to try to impose its national law on this globally shared resource. China’s law also has no authority over TLD operators who do not serve Chinese customers. China’s “real name” law can ONLY apply to registrars serving Chinese customers, because that is where individuals with “real names” intersect with the domain name system.
 
You may not understand what you are talking about here – how would a TLD operator provide a “real name” when it is a company, not a person, and when its records contain tens of thousands or millions of names of registrants? Are you saying that Chinese law requires every TLD operator and registrar in the world to turn over personally identifiable information of all their customers to the Chinese government? I think no one in this stakeholder group, or any other, would support this, and none of the world’s governments would accept it, either.
 

I certainly understand ICANN is a global governance regime not a national one. However, if I am not having misunderstood about EPDP, the whole issue is raised because of GDPR. 
 
These are ICANN policies, not European ones.
 
I don't think EU GDPR is superior than China Cybersecurity Law or any other country's national law
 
EU law does not override Chinese law, but Chinese law cannot bind what the rest of the world does, either. I Hope that’s clear.
 

Since the question 8 of EPDP Team Question for Community Input is to seek the legal and regulatory considerations not yet considered in this Initial Report, I certainly believe to mention about China Cybersecurity Law as a legal considerations is not a misunderstanding.

 
It is not relevant, but you can make this comment to ICANN as an individual. Are you commenting on behalf of the Chinese government? Maybe you should work with your GAC representative.
 








-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://lists.ncsg.is/pipermail/ncsg-discuss/attachments/20210720/31355e2a/attachment.htm>


More information about the Ncsg-discuss mailing list