EPDP policy issues
Stephanie E Perrin
stephanie.perrin at MAIL.UTORONTO.CA
Tue May 4 10:38:59 EEST 2021
thanks Tapani, I think you have put your finger on the fundamental
"disagreement" here between myself and Milton. I certainly, as I have
said, do not endorse the registrars using this "designation" as legal or
natural as an excuse to release more personal data. Milton is worried
about that, and he is quite right to worry about it.
In an effort to simplify the reams of material that have appeared both
on this list and in the discussions on the EPDP list, chats and skype
channels, Kathy Kleiman and I came up with this relatively short
statement after Volker read into the record last Thursday, the position
of the registrars. Here it is, I hope folks agree with us:
Fellow NCSG members,
We would like to work together to share our rationale for Option 1 –
maintaining the status quo and not asking further follow-up questions,
mandatory or otherwise, about legal and natural persons. While the EPDP
phase 2a discussions have been an educational and interesting exercise,
we are not under any obligation to change the existing policy, or
further complicate it.
As we have all discussed, legal/natural person questions/are very
complicated for many of our members/ who are often noncommercial and
non-profit organizations whose structure and ways of obtaining domain
names do not resemble those of the large corporations other stakeholder
groups represent. Our members may have many layers of privacy protection
in less-well-known sections of the GDPR, other local law, Constitutions
and international conventions.
We learned that recent studies show that 50% of gTLD domain name
registrations are for natural persons – and at least 25% more have
overlapping entity and personal data (e.g., the organization name has
personal data in it and is thus protected as personal data).
Stephanie and Kathy shared their concerns for legal/natural person
questions during our long work on the Proxy and PrivacyAccreditation
Working Group.We worked closely with the Registrars Stakeholder Group to
protect registrant privacy – including Battered Women’s Shelters, family
planning clinics, and girls educational institutions – all of which may
be legal entities, but have protectable data due to obvious danger from
disclosure in certain countries.
*/In light of the complicated world around us, we support Option 1- the
Status Quo./*We ask the NCSG to adopt this as our stance. *Based on the
existing policy which makes differentiation of legal/natural persons
optional for each registrar, we believe we already have the *
-*best way to fight DNS Abuse, *
-*best way to protect individuals and noncommercial organizations, and *
-*best way to follow GDPR and other applicable human rights and free
speech laws *
*/Therefore, we recommend NCSG “hold the line” and stick with Option 1. /*
/As the Registrars wrote in their EPDP Statement on Thursday April 29:
*We have heard plenty of vocal support in this group to [differentiate
between legal and natural persons in a mandatory fashion], but to date
the RrSG have not heard any compelling reason to create policy that
makes this dramatic shift to the domain registration landscape.*/
*We agree.*Nothing will stop other stakeholder groups from demanding
further disclosure of data, and lobbying other parties including
governments. *What we can do in ICANN is come up with the best solution
for us at this time.*
Many thanks to the members of our NCSG EPDP Team for your hard work.
This has been a long road.With new studies, new information and legal
opinions, we think we have a clear and strategic path forward.We believe
our position to be closely aligned with that of the Registrar
Stakeholder Group, which they articulated on April 29 (see below).
Best, Kathy Kleiman and Stephanie Perrin
*/The Registrar Stakeholder Group issued their position statement on
Thursday (4/29):/*
/The members of the RrSG EPDP team have participated in this process in
good faith since day one and will continue to do so; however, we need to
be crystal clear that members of our Stakeholder Group, whom we are here
to represent, have voiced and recently reconfirmed their strong
opposition to any policy coming out of this group that makes
differentiation between natural and legal persons for domain
registrations mandatory./
//
/We have heard plenty of vocal support in this group to do just that,
but to date the RrSG have not heard any compelling reason to create
policy that makes this dramatic shift to the domain registration
landscape. The Contracted Party can make the most accurate assessment of
their own legal, technical, and commercial risks and obligations, and is
the only party that can determine what level of risk they should assume.
The scope of this EPDP Phase 2a is to consider if changes are required
for the relevant Recommendation; it has become clear through this
process that no such changes are required/
//
/To the extent this group can focus its energies on guidance to
contracted parties which choose on their own to make this
differentiation, we continue to believe that is a worthwhile exercise.
We believe that guidance materials including educational information
provided by ICANN in multiple languages would help contracted parties
educate registrants and this would be a valuable effort./
//
/That said, based on analysis done by our stakeholder group's members,
we reject the notion that the majority of registered domain names are
registered to legal entities. We further remind this team that we have
not yet seen evidence that increased publication of registration data
will address any of the problems which have been mentioned so far in
this phase, and that the registration data is reliably and promptly
available to those who do have a legitimate reason to access it./
//
/Finally we note that this statement represents the official position of
the Registrar Stakeholder group, and statements from members of other
groups participating in the EPDP do not represent our group’s position./
/(Source: Transcript of EPDP-Phase 2A Team Call, 29 April 2021,
Statement of Volker Greimann on behalf of the Registrars Stakeholder
Group read into the record)/
___________
On 2021-05-04 12:34 a.m., Tapani Tarvainen wrote:
> EXTERNAL EMAIL:
>
> On Sun, Apr 25, 2021 at 07:54:43PM +0000, Mueller, Milton L (milton at GATECH.EDU) wrote:
>
>> The one thing I want to prevent when it comes to legal and natural
>> distinction is to enable some stakeholders to use the distinction as
>> an excuse for making more registrants data public and accessible.
> Entering this discussion a bit late, having read the long thread,
> I find myself in perfect agreement with Milton on that point.
>
> Indeed the very idea that the legal vs. natural person distinction
> could be used that way is fundamentally broken. It is based on a
> (possibly deliberate) misreading of the GDPR.
>
> When GDPR says it doesn't apply to legal persons, it does *not* mean
> that if some data is about a legal person it follows that it isn't
> personal and therefore out of scope for GDPR.
>
> What it means is that if the data is about a legal person it does
> not follow that it is personal data - but it could still be, as
> Mark Leiser well explained. Same piece of data can be both about
> a legal and a natural person (or several) at the same time.
>
> But this cannot be fixed by letting registrants choose whether or not
> to declare themselves as legal or natural persons, or decline to do
> either. Nor does it help to let registrars determine that by other
> means.
>
> The status of some data as personal or not cannot be determined on the
> basis of whether or not it is about a legal person.
>
> It could be used as a data point, but it's really a useless one.
>
> If we divide registrants into three categories:
>
> (1) natural persons,
>
> (2) legal persons whose data nonetheless is personal so
> that GDPR applies and
>
> (3) legal persons whose data is non-personal,
>
> there's no need to distinguish between (1) and (2) and attempting to
> do so will only confuse the issue. Whatever process is used to
> distinguish between (2) and (3) will, if done right, automatically
> take care of (1) as well.
>
> A registrar that assumes a registrant's data is non-personal because
> the registrant is a legal person will be in violation of the GDPR.
>
> Really the only right solution is to forgo the very idea of asking
> registrants if they're legal or natural persons. That distinction can
> not be used in any useful way by the registrars, it can only be abused
> (and almost certainly will).
>
> I haven't followed the EPDP much so I don't know if that can still be
> done there, but if not, I expect ICANN will find itself staring at the
> pointy end of an EU court decision once more.
>
> --
> Tapani Tarvainen
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://lists.ncsg.is/pipermail/ncsg-discuss/attachments/20210504/f75c373c/attachment.htm>
More information about the Ncsg-discuss
mailing list