Please Comment: Our Second Human Rights Impact Assessment on GAC Communique
Shiva Upadhyay
shiva.upadhyay at YAHOO.COM
Sun Sep 21 13:05:12 EEST 2025
Dear Farzaneh,
Thank you for your thoughtful response. I greatly value the long-standing efforts of NCSG in ensuring that human rights, digital freedoms, and safeguards remain central to ICANN’s work. Your reminder that “safety solutions” can sometimes fail victims while also undermining rights is an important caution, and one that should not be ignored.
At the same time, I feel that a balanced approach is essential. From what we see in courts and through law enforcement, the realities of victims, particularly women and children facing online exploitation, are very stark. Anonymity is often weaponized to perpetuate abuse, and governments are held accountable in courts when they cannot act. In underserved regions, where families cannot afford legal services, the absence of timely remedies makes the harm even more devastating.
Therefore, our role should not be to dismiss GAC’s concerns outright, but rather to acknowledge where they raise valid issues (such as accuracy, urgent disclosures, and RDRS participation), while also pressing for checks, balances, and procedural safeguards. By doing this, we ensure both victim protection and registrant rights are addressed.
I believe our submissions can say: “Yes, these issues are important and need to be addressed, but the solutions must incorporate due process, proportionality, and remedies for registrants.” Such language would strengthen NCSG’s credibility as a user-centric group that recognizes both sets of human rights, those of registrants seeking privacy, and those of vulnerable users seeking dignity and justice.
This balanced framing, in my view, can help build a more constructive relationship with the GAC and other SOs/ACs, and avoid the perception that NCSG is one-sided. In the end, we all want the same thing: an Internet that is both safe and rights-respecting.
Warm regards,
Shiva Upadhyay
On Sunday 21 September, 2025 at 09:57:27 pm IST, farzaneh badii <farzaneh.badii at gmail.com> wrote:
Dear Shiva,
NCSG’s positions come from years of advocating for human rights and pushing back against overreach in the name of safety and protection of intellectual property rights. Many of our members also work on online safety, but they join NCSG because they see that too often “safety solutions” fail to protect victims while undermining digital rights.
We are not saying DNS abuse should not be mitigated. We are saying: don’t rush into measures that put rights at risk, and where restrictions are needed, there must be remedies and safeguards. In fact, on several of the issues you raise, NCSG has constructively engaged through PDPs. We have supported urgent request categories and even worked with law enforcement to strengthen authentication, provided this is done transparently and in a rights-respecting way.
What we cannot do is dilute our message by advocating for mechanisms that lack safeguards, that pose clear human rights risks, and that in many cases do not even solve the underlying safety problems. The recent GAC Communiqué does not mention human rights/access to remedy a single time. That silence is precisely why NCSG’s role is so critical.
Best regards,
Farzaneh
On Sun, Sep 21, 2025 at 8:41 AM Shiva Upadhyay <shiva.upadhyay at yahoo.com> wrote:
Dear Friends,
I would like to share what my team of lawyers and I are witnessing every day. We are closely following court proceedings, remaining in continuous touch with law enforcement agencies, and engaging directly with victims and their families.
Every day, we see the enormous challenges that arise when victims seek justice. Courts are under pressure to respond swiftly, yet perpetrators exploit loopholes by registering new domains almost overnight. Law enforcement struggles with incomplete or inaccurate WHOIS information, leaving them unable to track abusers effectively. Behind these systemic gaps are real people—parents in tears, young girls forced to abandon school, families whose lives are disrupted by relentless online abuse.
While human rights and privacy must always be respected, we cannot ignore how anonymity is being misused as a shield for cybercriminals. In sensitive cases, such as child abuse, sexual exploitation, and morphing of images, the urgency of accurate and verified information cannot be overstated. Courts are ordering takedowns, yet without stronger obligations on registrars and intermediaries, the cycle simply repeats.
Our collective responsibility is to find the right balance: protecting fundamental rights while ensuring that victims are not left helpless, and that LEAs and courts have the tools to deliver timely justice. A few suggestions we need to keep in mind while submitting our response:
1. Expanded Law Enforcement Access (RDRS)
NCSG Position:
Law enforcement’s increased use of the RDRS is framed as the normalization of access without safeguards. Mandatory registrar participation is seen as a rights risk.
Rebuttal:
This framing disregards governments’ real legal obligations. Courts hold governments accountable when law enforcement cannot trace cybercriminals. In India alone, thousands of cases involving domain names distributing morphed images of girls have been filed. Victims’ parents have testified in court while perpetrators exploit anonymity. Registrars’ refusal to comply leaves governments unable to enforce judicial orders.
Balanced Position:
-
Mandatory RDRS participation is essential, but tiered safeguards should apply.
-
Urgent categories (child sexual abuse, gender-based crimes, imminent harm) require fast disclosure.
-
For non-urgent cases, safeguards such as registrant notice, public reporting, and appeal rights should apply.
This balances registrant privacy with victims’ right to dignity and remedy.
2. Urgent Requests for Disclosure (24-Hour Timeline)
NCSG Position:
A 24-hour disclosure timeline lacks legal thresholds and risks misuse by repressive regimes.
Rebuttal:
The assumption ignores that delays in disclosure directly harm children and women. Courts order blocking or tracing within hours. Perpetrators reappear the next day with new domains (example1, example2). Without timely data, law enforcement cannot prevent ongoing abuse. Governments are answerable to courts, not abstract safeguards alone.
Balanced Position:
-
Urgent disclosure timelines must remain, but paired with authentication of LEA requests and post-facto audit trails.
-
Safeguards should prevent political misuse, but not at the cost of child safety and gender justice.
The higher human right is to protect minors from irreversible harm.
3. Accuracy of Registration Data
NCSG Position:
Shorter verification windows risk undermining anonymity; the distinction between contractability and identity is overlooked.
Rebuttal:
This overlooks how abusers weaponize fake or stolen contact data. When WHOIS contains unreachable numbers or disposable emails, investigations stall. Courts expect verified contactability. Without it, registrars enable criminal impunity.
Balanced Position:
-
Support minimum verification standards (email + phone validation, periodic rechecks).
-
Clarify distinction: accuracy ensures contactability, not mandatory identity disclosure.
-
For high-risk categories (financial services, bulk registrations), stricter verification may be justified.
Accuracy strengthens both consumer trust and abuse mitigation, while still protecting pseudonymity in low-risk contexts.
4. DNS Abuse Mitigation
NCSG Position:
GAC’s focus on enforcement risks overbroad takedowns and neglects civil society safeguards.
Rebuttal:
Governments daily confront systemic abuse: morphed images of girls, financial scams, and child exploitation. Anonymity is repeatedly misused as a shield. Thousands of women have lost dignity and trust in digital spaces. Dismissing enforcement undermines the right to dignity, protection from exploitation, and access to remedy under UDHR/ICCPR/CRC.
Balanced Position:
-
Enforcement must be rapid for child abuse, gender violence, and large-scale fraud.
-
Safeguards should exist for small registrants and dissenting voices, including appeals, contestation mechanisms, and transparency reporting.
-
ICANN should enable joint mechanisms (governments + NGOs + civil society) to prevent misuse while ensuring proportionality.
Conclusion
NCSG’s draft emphasizes registrant rights but misses the other half of the human rights equation, the rights of women, children, and families devastated by unchecked domain abuse. Governments cannot ignore court orders or parental pleas. ICANN must take the higher ground: enable rapid enforcement in abuse cases while embedding due process safeguards. Privacy is vital, but so is dignity, justice, and protection from exploitation.
Thanks & Regards,Shiva Upadhyay On Saturday 20 September, 2025 at 01:55:09 am IST, farzaneh badii <farzaneh.badii at gmail.com> wrote:
Hi all,
Here is our second HRIA on GAC communique: https://docs.google.com/document/d/1k32oTjH2bg2Gd5hEUExn6BoJZ89HluC3_vPDkks4vfg/edit?tab=t.0
Please comment so that we finalize it and submit it to them and bring it up during our GAC meeting.We are aiming to finalize by Wednesday next week.
Best regards,
Farzaneh
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://lists.ncsg.is/pipermail/ncsg-discuss/attachments/20250921/88588fbf/attachment.htm>
More information about the Ncsg-discuss
mailing list