EPDP policy issues

Stephanie E Perrin stephanie.perrin at MAIL.UTORONTO.CA
Tue May 4 10:38:59 EEST 2021


thanks Tapani, I think you have put your finger on the fundamental 
"disagreement" here between myself and Milton.  I certainly, as I have 
said, do not endorse the registrars using this "designation" as legal or 
natural as an excuse to release more personal data.  Milton is worried 
about that, and he is quite right to worry about it.

In an effort to simplify the reams of material that have appeared both 
on this list and in the discussions on the EPDP list, chats and skype 
channels, Kathy Kleiman and I came up with this relatively short 
statement after Volker read into the record last Thursday, the position 
of the registrars.  Here it is, I hope folks agree with us:

Fellow NCSG members,

We would like to work together to share our rationale for Option 1 – 
maintaining the status quo and not asking further follow-up questions, 
mandatory or otherwise, about legal and natural persons. While the EPDP 
phase 2a discussions have been an educational and interesting exercise, 
we are not under any obligation to change the existing policy, or 
further complicate it.

As we have all discussed, legal/natural person questions/are very 
complicated for many of our members/ who are often noncommercial and 
non-profit organizations whose structure and ways of obtaining domain 
names do not resemble those of the large corporations other stakeholder 
groups represent. Our members may have many layers of privacy protection 
in less-well-known sections of the GDPR, other local law, Constitutions 
and international conventions.

We learned that recent studies show that 50% of gTLD domain name 
registrations are for natural persons – and at least 25% more have 
overlapping entity and personal data (e.g., the organization name has 
personal data in it and is thus protected as personal data).

Stephanie and Kathy shared their concerns for legal/natural person 
questions during our long work on the Proxy and PrivacyAccreditation 
Working Group.We worked closely with the Registrars Stakeholder Group to 
protect registrant privacy – including Battered Women’s Shelters, family 
planning clinics, and girls educational institutions – all of which may 
be legal entities, but have protectable data due to obvious danger from 
disclosure in certain countries.

*/In light of the complicated world around us, we support Option 1- the 
Status Quo./*We ask the NCSG to adopt this as our stance. *Based on the 
existing policy which makes differentiation of legal/natural persons 
optional for each registrar, we believe we already have the *

-*best way to fight DNS Abuse, *

-*best way to protect individuals and noncommercial organizations, and *

-*best way to follow GDPR and other applicable human rights and free 
speech laws *

*/Therefore, we recommend NCSG “hold the line” and stick with Option 1. /*

/As the Registrars wrote in their EPDP Statement on Thursday April 29: 
*We have heard plenty of vocal support in this group to [differentiate 
between legal and natural persons in a mandatory fashion], but to date 
the RrSG have not heard any compelling reason to create policy that 
makes this dramatic shift to the domain registration landscape.*/

*We agree.*Nothing will stop other stakeholder groups from demanding 
further disclosure of data, and lobbying other parties including 
governments. *What we can do in ICANN is come up with the best solution 
for us at this time.*

Many thanks to the members of our NCSG EPDP Team for your hard work. 
This has been a long road.With new studies, new information and legal 
opinions, we think we have a clear and strategic path forward.We believe 
our position to be closely aligned with that of the Registrar 
Stakeholder Group, which they articulated on April 29 (see below).

Best, Kathy Kleiman and Stephanie Perrin

*/The Registrar Stakeholder Group issued their position statement on 
Thursday (4/29):/*

/The members of the RrSG EPDP team have participated in this process in 
good faith since day one and will continue to do so; however, we need to 
be crystal clear that members of our Stakeholder Group, whom we are here 
to represent, have voiced and recently reconfirmed their strong 
opposition to any policy coming out of this group that makes 
differentiation between natural and legal persons for domain 
registrations mandatory./

//

/We have heard plenty of vocal support in this group to do just that, 
but to date the RrSG have not heard any compelling reason to create 
policy that makes this dramatic shift to the domain registration 
landscape. The Contracted Party can make the most accurate assessment of 
their own legal, technical, and commercial risks and obligations, and is 
the only party that can determine what level of risk they should assume. 
The scope of this EPDP Phase 2a is to consider if changes are required 
for the relevant Recommendation; it has become clear through this 
process that no such changes are required/

//

/To the extent this group can focus its energies on guidance to 
contracted parties which choose on their own to make this 
differentiation, we continue to believe that is a worthwhile exercise. 
We believe that guidance materials including educational information 
provided by ICANN in multiple languages would help contracted parties 
educate registrants and this would be a valuable effort./

//

/That said, based on analysis done by our stakeholder group's members, 
we reject the notion that the majority of registered domain names are 
registered to legal entities. We further remind this team that we have 
not yet seen evidence that increased publication of registration data 
will address any of the problems which have been mentioned so far in 
this phase, and that the registration data is reliably and promptly 
available to those who do have a legitimate reason to access it./

//

/Finally we note that this statement represents the official position of 
the Registrar Stakeholder group, and statements from members of other 
groups participating in the EPDP do not represent our group’s position./

/(Source: Transcript of EPDP-Phase 2A Team Call, 29 April 2021, 
Statement of Volker Greimann on behalf of the Registrars Stakeholder 
Group read into the record)/

___________


On 2021-05-04 12:34 a.m., Tapani Tarvainen wrote:
> EXTERNAL EMAIL:
>
> On Sun, Apr 25, 2021 at 07:54:43PM +0000, Mueller, Milton L (milton at GATECH.EDU) wrote:
>
>> The one thing I want to prevent when it comes to legal and natural
>> distinction is to enable some stakeholders to use the distinction as
>> an excuse for making more registrants data public and accessible.
> Entering this discussion a bit late, having read the long thread,
> I find myself in perfect agreement with Milton on that point.
>
> Indeed the very idea that the legal vs. natural person distinction
> could be used that way is fundamentally broken. It is based on a
> (possibly deliberate) misreading of the GDPR.
>
> When GDPR says it doesn't apply to legal persons, it does *not* mean
> that if some data is about a legal person it follows that it isn't
> personal and therefore out of scope for GDPR.
>
> What it means is that if the data is about a legal person it does
> not follow that it is personal data - but it could still be, as
> Mark Leiser well explained. Same piece of data can be both about
> a legal and a natural person (or several) at the same time.
>
> But this cannot be fixed by letting registrants choose whether or not
> to declare themselves as legal or natural persons, or decline to do
> either. Nor does it help to let registrars determine that by other
> means.
>
> The status of some data as personal or not cannot be determined on the
> basis of whether or not it is about a legal person.
>
> It could be used as a data point, but it's really a useless one.
>
> If we divide registrants into three categories:
>
> (1) natural persons,
>
> (2) legal persons whose data nonetheless is personal so
>      that GDPR applies and
>
> (3) legal persons whose data is non-personal,
>
> there's no need to distinguish between (1) and (2) and attempting to
> do so will only confuse the issue. Whatever process is used to
> distinguish between (2) and (3) will, if done right, automatically
> take care of (1) as well.
>
> A registrar that assumes a registrant's data is non-personal because
> the registrant is a legal person will be in violation of the GDPR.
>
> Really the only right solution is to forgo the very idea of asking
> registrants if they're legal or natural persons. That distinction can
> not be used in any useful way by the registrars, it can only be abused
> (and almost certainly will).
>
> I haven't followed the EPDP much so I don't know if that can still be
> done there, but if not, I expect ICANN will find itself staring at the
> pointy end of an EU court decision once more.
>
> --
> Tapani Tarvainen
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://lists.ncsg.is/pipermail/ncsg-discuss/attachments/20210504/f75c373c/attachment.htm>


More information about the Ncsg-discuss mailing list