Please Comment: Our Second Human Rights Impact Assessment on GAC Communique

farzaneh badii farzaneh.badii at GMAIL.COM
Mon Sep 22 20:43:10 EEST 2025


Dear Shiva,

Thanks again for the  message. I want to respond clearly on one point: NCSG
has never opposed DNS abuse mitigation. Nowhere in the HRIA we say DNS
abuse mitigation should not happen. We’ve agreed to urgent disclosure
categories, authentication work with law enforcement, and action against
phishing and CSAM. Some activists are affected by phishing attacks done by
nation states (the very law enforcement that is supposedly there to
protect), so we work on combating phishing and some of our members work on
children rights.


I don’t think it’s accurate to say we’re “one-sided.” Our role isn’t to
constantly compromise to appear “balanced.” Our role is to hold the line on
rights. That’s the contribution we make in this system.


The idea that there are two sides to human rights, privacy on one side and
dignity or justice on the other doesn’t sit right with me. Human rights
don’t work like that. They’re interconnected. And we’re not forgetting one
side we’re insisting that any mechanism claiming to solve these harms be
rights-respecting from the start.


Also, we need to be very clear about what DNS abuse mitigation can and
can’t do. Yes, CSAM should be taken down immediately—registrars and
registries already are legally obligated to do that. But things like
gender-based violence aren’t even always DNS issues. Trying to solve them
through technical enforcement tools risks creating systems that don’t help
victims and also undermine rights.


So no I don’t think the burden is on us to be more “balanced.” Governments
 need to support solutions that are actually effective and don’t encroach
on rights. We’re here to make sure those positions don’t come at the
expense of fundamental freedoms.
I will make it clear in our HRIA that we are not against DNS abuse
mitigation and debunk that myth.

Farzaneh


On Sun, Sep 21, 2025 at 2:05 PM Shiva Upadhyay <shiva.upadhyay at yahoo.com>
wrote:

> Dear Farzaneh,
>
> Thank you for your thoughtful response. I greatly value the long-standing
> efforts of NCSG in ensuring that human rights, digital freedoms, and
> safeguards remain central to ICANN’s work. Your reminder that “safety
> solutions” can sometimes fail victims while also undermining rights is an
> important caution, and one that should not be ignored.
>
> At the same time, I feel that a balanced approach is essential. From what
> we see in courts and through law enforcement, the realities of victims,
> particularly women and children facing online exploitation, are very stark.
> Anonymity is often weaponized to perpetuate abuse, and governments are held
> accountable in courts when they cannot act. In underserved regions, where
> families cannot afford legal services, the absence of timely remedies makes
> the harm even more devastating.
>
> Therefore, our role should not be to dismiss GAC’s concerns outright, but
> rather to acknowledge where they raise valid issues (such as accuracy,
> urgent disclosures, and RDRS participation), while also pressing for
> checks, balances, and procedural safeguards. By doing this, we ensure both
> victim protection and registrant rights are addressed.
>
> I believe our submissions can say: *“Yes, these issues are important and
> need to be addressed, but the solutions must incorporate due process,
> proportionality, and remedies for registrants.”* Such language would
> strengthen NCSG’s credibility as a user-centric group that recognizes *both
> sets of human rights, *those of registrants seeking privacy, and those of
> vulnerable users seeking dignity and justice.
>
> This balanced framing, in my view, can help build a more constructive
> relationship with the GAC and other SOs/ACs, and avoid the perception that
> NCSG is one-sided. In the end, we all want the same thing: an Internet that
> is both safe and rights-respecting.
>
> Warm regards,
> Shiva Upadhyay
>
>
> On Sunday 21 September, 2025 at 09:57:27 pm IST, farzaneh badii <
> farzaneh.badii at gmail.com> wrote:
>
>
> Dear Shiva,
>
> NCSG’s positions come from years of advocating for human rights and
> pushing back against overreach in the name of safety and protection of
> intellectual property rights. Many of our members also work on online
> safety, but they join NCSG because they see that too often “safety
> solutions” fail to protect victims while undermining digital rights.
>
> We are not saying DNS abuse should not be mitigated. We are saying: don’t
> rush into measures that put rights at risk, and where restrictions are
> needed, there must be remedies and safeguards. In fact, on several of the
> issues you raise, NCSG has constructively engaged through PDPs. We have
> supported urgent request categories and even worked with law enforcement to
> strengthen authentication, provided this is done transparently and in a
> rights-respecting way.
>
> What we cannot do is dilute our message by advocating for mechanisms that
> lack safeguards, that pose clear human rights risks, and that in many cases
> do not even solve the underlying safety problems. The recent GAC Communiqué
> does not mention human rights/access to remedy  a single time. That silence
> is precisely why NCSG’s role is so critical.
> Best regards,
>
> Farzaneh
>
>
> On Sun, Sep 21, 2025 at 8:41 AM Shiva Upadhyay <shiva.upadhyay at yahoo.com>
> wrote:
>
> Dear Friends,
>
> I would like to share what my team of lawyers and I are witnessing every
> day. We are closely following court proceedings, remaining in continuous
> touch with law enforcement agencies, and engaging directly with victims and
> their families.
>
> Every day, we see the enormous challenges that arise when victims seek
> justice. Courts are under pressure to respond swiftly, yet perpetrators
> exploit loopholes by registering new domains almost overnight. Law
> enforcement struggles with incomplete or inaccurate WHOIS information,
> leaving them unable to track abusers effectively. Behind these systemic
> gaps are real people—parents in tears, young girls forced to abandon
> school, families whose lives are disrupted by relentless online abuse.
>
> While human rights and privacy must always be respected, we cannot ignore
> how anonymity is being misused as a shield for cybercriminals. In sensitive
> cases, such as child abuse, sexual exploitation, and morphing of images,
> the urgency of accurate and verified information cannot be overstated.
> Courts are ordering takedowns, yet without stronger obligations on
> registrars and intermediaries, the cycle simply repeats.
>
> Our collective responsibility is to find the right balance: protecting
> fundamental rights while ensuring that victims are not left helpless, and
> that LEAs and courts have the tools to deliver timely justice. A few
> suggestions we need to keep in mind while submitting our response:
>
> 1. *Expanded Law Enforcement Access (RDRS)*
>
> *NCSG Position:*
> Law enforcement’s increased use of the RDRS is framed as the normalization
> of access without safeguards. Mandatory registrar participation is seen as
> a rights risk.
>
> *Rebuttal:*
> This framing disregards governments’ real legal obligations. Courts hold
> governments accountable when law enforcement cannot trace cybercriminals.
> In India alone, thousands of *cases involving domain names distributing
> morphed images of girls* have been filed. Victims’ parents have testified
> in court while perpetrators exploit anonymity. Registrars’ refusal to
> comply leaves governments unable to enforce judicial orders.
>
> *Balanced Position:*
>
>    -
>
>    Mandatory RDRS participation is essential, but *tiered safeguards*
>    should apply.
>    -
>
>    Urgent categories (child sexual abuse, gender-based crimes, imminent
>    harm) require fast disclosure.
>    -
>
>    For non-urgent cases, safeguards such as *registrant notice, public
>    reporting, and appeal rights* should apply.
>
> This balances registrant privacy with victims’ right to dignity and remedy.
> 2. *Urgent Requests for Disclosure (24-Hour Timeline)*
>
> *NCSG Position:*
> A 24-hour disclosure timeline lacks legal thresholds and risks misuse by
> repressive regimes.
>
> *Rebuttal:*
> The assumption ignores that *delays in disclosure directly harm children
> and women*. Courts order blocking or tracing within hours. Perpetrators
> reappear the next day with new domains (*example1, example2*). Without
> timely data, law enforcement cannot prevent ongoing abuse. Governments are
> answerable to courts, not abstract safeguards alone.
>
> *Balanced Position:*
>
>    -
>
>    Urgent disclosure timelines must remain, but paired with *authentication
>    of LEA requests* and *post-facto audit trails*.
>    -
>
>    Safeguards should prevent political misuse, but not at the cost of *child
>    safety and gender justice*.
>
> The higher human right is to protect minors from irreversible harm.
> 3. *Accuracy of Registration Data*
>
> *NCSG Position:*
> Shorter verification windows risk undermining anonymity; the distinction
> between contractability and identity is overlooked.
>
> *Rebuttal:*
> This overlooks how abusers weaponize *fake or stolen contact data*. When
> WHOIS contains unreachable numbers or disposable emails, investigations
> stall. Courts expect verified contactability. Without it, registrars enable
> criminal impunity.
>
> *Balanced Position:*
>
>    -
>
>    Support *minimum verification standards* (email + phone validation,
>    periodic rechecks).
>    -
>
>    Clarify distinction: accuracy ensures *contactability*, not mandatory
>    identity disclosure.
>    -
>
>    For high-risk categories (financial services, bulk registrations),
>    stricter verification may be justified.
>
> Accuracy strengthens both consumer trust and abuse mitigation, while still
> protecting pseudonymity in low-risk contexts.
> 4. *DNS Abuse Mitigation*
>
> *NCSG Position:*
> GAC’s focus on enforcement risks overbroad takedowns and neglects civil
> society safeguards.
>
> *Rebuttal:*
> Governments daily confront systemic abuse: morphed images of girls,
> financial scams, and child exploitation. *Anonymity is repeatedly misused
> as a shield.* Thousands of women have lost dignity and trust in digital
> spaces. Dismissing enforcement undermines the *right to dignity,
> protection from exploitation, and access to remedy* under UDHR/ICCPR/CRC.
>
> *Balanced Position:*
>
>    -
>
>    Enforcement must be rapid for *child abuse, gender violence, and
>    large-scale fraud*.
>    -
>
>    Safeguards should exist for small registrants and dissenting voices,
>    including *appeals, contestation mechanisms, and transparency
>    reporting*.
>    -
>
>    ICANN should enable *joint mechanisms* (governments + NGOs + civil
>    society) to prevent misuse while ensuring proportionality.
>
> *Conclusion*
>
> NCSG’s draft emphasizes registrant rights but *misses the other half of
> the human rights equation, *the rights of women, children, and families
> devastated by unchecked domain abuse. Governments cannot ignore court
> orders or parental pleas. ICANN must take the *higher ground*: enable
> rapid enforcement in abuse cases while embedding due process safeguards.
> Privacy is vital, but so is dignity, justice, and protection from
> exploitation.
>
> Thanks & Regards,
> Shiva Upadhyay
> On Saturday 20 September, 2025 at 01:55:09 am IST, farzaneh badii <
> farzaneh.badii at gmail.com> wrote:
>
>
> Hi all,
>
> Here is our second HRIA on GAC communique:
> https://docs.google.com/document/d/1k32oTjH2bg2Gd5hEUExn6BoJZ89HluC3_vPDkks4vfg/edit?tab=t.0
>
>
> Please comment so that we finalize it and submit it to them and bring it
> up during our GAC meeting.
> We are aiming to finalize by Wednesday next week.
>
>
> Best regards,
>
>
> Farzaneh
>
>
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://lists.ncsg.is/pipermail/ncsg-discuss/attachments/20250922/24e8b5bc/attachment.htm>


More information about the Ncsg-discuss mailing list