Please Comment: Our Second Human Rights Impact Assessment on GAC Communique
farzaneh badii
farzaneh.badii at GMAIL.COM
Sun Sep 21 11:26:42 EEST 2025
Dear Shiva,
NCSG’s positions come from years of advocating for human rights and pushing
back against overreach in the name of safety and protection of
intellectual property rights. Many of our members also work on online
safety, but they join NCSG because they see that too often “safety
solutions” fail to protect victims while undermining digital rights.
We are not saying DNS abuse should not be mitigated. We are saying: don’t
rush into measures that put rights at risk, and where restrictions are
needed, there must be remedies and safeguards. In fact, on several of the
issues you raise, NCSG has constructively engaged through PDPs. We have
supported urgent request categories and even worked with law enforcement to
strengthen authentication, provided this is done transparently and in a
rights-respecting way.
What we cannot do is dilute our message by advocating for mechanisms that
lack safeguards, that pose clear human rights risks, and that in many cases
do not even solve the underlying safety problems. The recent GAC Communiqué
does not mention human rights/access to remedy a single time. That silence
is precisely why NCSG’s role is so critical.
Best regards,
Farzaneh
On Sun, Sep 21, 2025 at 8:41 AM Shiva Upadhyay <shiva.upadhyay at yahoo.com>
wrote:
> Dear Friends,
>
> I would like to share what my team of lawyers and I are witnessing every
> day. We are closely following court proceedings, remaining in continuous
> touch with law enforcement agencies, and engaging directly with victims and
> their families.
>
> Every day, we see the enormous challenges that arise when victims seek
> justice. Courts are under pressure to respond swiftly, yet perpetrators
> exploit loopholes by registering new domains almost overnight. Law
> enforcement struggles with incomplete or inaccurate WHOIS information,
> leaving them unable to track abusers effectively. Behind these systemic
> gaps are real people—parents in tears, young girls forced to abandon
> school, families whose lives are disrupted by relentless online abuse.
>
> While human rights and privacy must always be respected, we cannot ignore
> how anonymity is being misused as a shield for cybercriminals. In sensitive
> cases, such as child abuse, sexual exploitation, and morphing of images,
> the urgency of accurate and verified information cannot be overstated.
> Courts are ordering takedowns, yet without stronger obligations on
> registrars and intermediaries, the cycle simply repeats.
>
> Our collective responsibility is to find the right balance: protecting
> fundamental rights while ensuring that victims are not left helpless, and
> that LEAs and courts have the tools to deliver timely justice. A few
> suggestions we need to keep in mind while submitting our response:
>
> 1. *Expanded Law Enforcement Access (RDRS)*
>
> *NCSG Position:*
> Law enforcement’s increased use of the RDRS is framed as the normalization
> of access without safeguards. Mandatory registrar participation is seen as
> a rights risk.
>
> *Rebuttal:*
> This framing disregards governments’ real legal obligations. Courts hold
> governments accountable when law enforcement cannot trace cybercriminals.
> In India alone, thousands of *cases involving domain names distributing
> morphed images of girls* have been filed. Victims’ parents have testified
> in court while perpetrators exploit anonymity. Registrars’ refusal to
> comply leaves governments unable to enforce judicial orders.
>
> *Balanced Position:*
>
> -
>
> Mandatory RDRS participation is essential, but *tiered safeguards*
> should apply.
> -
>
> Urgent categories (child sexual abuse, gender-based crimes, imminent
> harm) require fast disclosure.
> -
>
> For non-urgent cases, safeguards such as *registrant notice, public
> reporting, and appeal rights* should apply.
>
> This balances registrant privacy with victims’ right to dignity and remedy.
> 2. *Urgent Requests for Disclosure (24-Hour Timeline)*
>
> *NCSG Position:*
> A 24-hour disclosure timeline lacks legal thresholds and risks misuse by
> repressive regimes.
>
> *Rebuttal:*
> The assumption ignores that *delays in disclosure directly harm children
> and women*. Courts order blocking or tracing within hours. Perpetrators
> reappear the next day with new domains (*example1, example2*). Without
> timely data, law enforcement cannot prevent ongoing abuse. Governments are
> answerable to courts, not abstract safeguards alone.
>
> *Balanced Position:*
>
> -
>
> Urgent disclosure timelines must remain, but paired with *authentication
> of LEA requests* and *post-facto audit trails*.
> -
>
> Safeguards should prevent political misuse, but not at the cost of *child
> safety and gender justice*.
>
> The higher human right is to protect minors from irreversible harm.
> 3. *Accuracy of Registration Data*
>
> *NCSG Position:*
> Shorter verification windows risk undermining anonymity; the distinction
> between contractability and identity is overlooked.
>
> *Rebuttal:*
> This overlooks how abusers weaponize *fake or stolen contact data*. When
> WHOIS contains unreachable numbers or disposable emails, investigations
> stall. Courts expect verified contactability. Without it, registrars enable
> criminal impunity.
>
> *Balanced Position:*
>
> -
>
> Support *minimum verification standards* (email + phone validation,
> periodic rechecks).
> -
>
> Clarify distinction: accuracy ensures *contactability*, not mandatory
> identity disclosure.
> -
>
> For high-risk categories (financial services, bulk registrations),
> stricter verification may be justified.
>
> Accuracy strengthens both consumer trust and abuse mitigation, while still
> protecting pseudonymity in low-risk contexts.
> 4. *DNS Abuse Mitigation*
>
> *NCSG Position:*
> GAC’s focus on enforcement risks overbroad takedowns and neglects civil
> society safeguards.
>
> *Rebuttal:*
> Governments daily confront systemic abuse: morphed images of girls,
> financial scams, and child exploitation. *Anonymity is repeatedly misused
> as a shield.* Thousands of women have lost dignity and trust in digital
> spaces. Dismissing enforcement undermines the *right to dignity,
> protection from exploitation, and access to remedy* under UDHR/ICCPR/CRC.
>
> *Balanced Position:*
>
> -
>
> Enforcement must be rapid for *child abuse, gender violence, and
> large-scale fraud*.
> -
>
> Safeguards should exist for small registrants and dissenting voices,
> including *appeals, contestation mechanisms, and transparency
> reporting*.
> -
>
> ICANN should enable *joint mechanisms* (governments + NGOs + civil
> society) to prevent misuse while ensuring proportionality.
>
> *Conclusion*
>
> NCSG’s draft emphasizes registrant rights but *misses the other half of
> the human rights equation, *the rights of women, children, and families
> devastated by unchecked domain abuse. Governments cannot ignore court
> orders or parental pleas. ICANN must take the *higher ground*: enable
> rapid enforcement in abuse cases while embedding due process safeguards.
> Privacy is vital, but so is dignity, justice, and protection from
> exploitation.
>
> Thanks & Regards,
> Shiva Upadhyay
> On Saturday 20 September, 2025 at 01:55:09 am IST, farzaneh badii <
> farzaneh.badii at gmail.com> wrote:
>
>
> Hi all,
>
> Here is our second HRIA on GAC communique:
> https://docs.google.com/document/d/1k32oTjH2bg2Gd5hEUExn6BoJZ89HluC3_vPDkks4vfg/edit?tab=t.0
>
>
> Please comment so that we finalize it and submit it to them and bring it
> up during our GAC meeting.
> We are aiming to finalize by Wednesday next week.
>
>
> Best regards,
>
>
> Farzaneh
>
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://lists.ncsg.is/pipermail/ncsg-discuss/attachments/20250921/4dec5c55/attachment.htm>
More information about the Ncsg-discuss
mailing list