[Ncsg-discuss] Law enforcement. Authentication and Authorization

farzaneh badii 00001deb507b73c5-dmarc-request at LISTSERV.SYR.EDU
Sun Jun 14 23:13:47 EEST 2026


Hi everyone

We held a good session on human rights impact assessment and Law
enforcement access to registrants private data during ICANN 86. Find the
recording here.
<https://icann.zoom.us/rec/play/uaYj4X2b2pgGxI2ztGwrEZ6LRU8jPuwycFwZpeYGlDFtUxJq3Swuew659Paj0GZpOxE9hOHHIFWc53GE._9lB4eVcT4b7mfDa?accessLevel=meeting&canPlayFromShare=true&from=share_recording_detail&startTime=1781188336000&oldStyle=true&componentName=rec-play&originRequestUrl=https%3A%2F%2Ficann.zoom.us%2Frec%2Fshare%2Ff_IZ6MrLsGHxtl5vlotXEJuanGAd7F745yySsqoJu308OzZZ5YrVvdWKvTVJuNF-.wbg8AnhgUB2FGV86%3FstartTime%3D1781188336000>
(The
link is too long, if you have difficulties accessing it let me know)

Here is a brief update on the discussions surrounding DNS policies for law
enforcement access to registrant data, followed by the specific data
elements requested for authentication and authorization. Note that we are
discussing these authorization and authentication forms and doing human
rights impact assessment at the Supplemental Review Team on SSAD. So if you
have comments, please do let us know.

*Brief Update* The recent Non-Commercial Stakeholder Group (NCSG) session
highlighted the human rights risks associated with how registrars handle
law enforcement requests for redacted domain name registrant data. A
primary concern is that establishing an authentication mechanism might
create a false sense of trust, leading registrars to automatically disclose
sensitive data—especially during "urgent" requests—without conducting a
proper human rights impact assessment.

We stress that a verified identity does not equate to a legally valid or
proportionate request. Disclosing data without adequate authorization
checks can lead to severe consequences for vulnerable targets, including
journalists, activists, and dissidents, potentially resulting in profiling,
deportation, torture, or irreversible fatal consequences if the requesting
jurisdiction practices the death penalty. Therefore, there is a push to
implement strict safeguards, mandatory fundamental rights balancing, and
detailed transparency reporting to ensure data is only disclosed when
absolutely necessary and legally justified.

*Data Elements for Authentication* Authentication aims to verify the
identity and mandate of the requesting officer and agency to ensure the
system is secure and not spoofed by impersonators or hackers. The proposed
data elements include:

   - *Officer Identity:* Legal name, badge number, rank, department,
   official government domain email, and a direct callback phone number to a
   publicly listed agency line.
   - *Agency Identity:* The agency's name and its specific type (e.g.,
   criminal justice, administrative, or regulator) to help registrars
   understand its nature.
   - *Legislative Mandate:* Information on whether the agency is legally
   empowered to demand sensitive private/domain registration data, and whether
   the agency operates under judicial or strictly administrative oversight.
   - *Cross-border Mechanisms:* Relevant details for international requests.

*Data Elements for Authorization* Authorization is the subsequent step
where registrars decide whether the requested disclosure is legally valid,
necessary, and proportionate based on a provided request form and
authentication process and does the fundamental rights balancing. The
requested data elements and commitments that we suggest include:

   - *Legal Instrument:* Supporting legal documentation, such as a subpoena
   (typically for basic subscriber info), a court order, or a search warrant.
   - *Necessity Statement:* An explanation from law enforcement detailing
   what alternative investigative methods have already been exhausted and why
   this specific infrastructure-layer data is needed.
   - *Purpose Limitation:* A clearly stated purpose for the data request,
   alongside binding commitments from the agency that there will be no
   secondary uses or onward transfers of the data to other jurisdictions.
   - *Retention and Deletion Commitments:* An agreement to delete the data
   after a specified period.
   - *Data Scoping:* Ensuring the requested data is strictly limited to the
   minimum necessary information.
   - *Human Rights Impact Assessment Indicators:* Contextual data that
   helps registrars evaluate jurisdictional risks (e.g., if the requesting
   country has the death penalty or a history of torture) and registrant
   profile risks (e.g., if the user is a known activist or journalist).

Farzaneh
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://lists.ncsg.is/pipermail/ncsg-discuss/attachments/20260614/911a9278/attachment-0001.htm>


More information about the Ncsg-discuss mailing list