[Ncsg-discuss] Law enforcement. Authentication and Authorization

Pascal Bekono 0000217625ac83ff-dmarc-request at LISTSERV.SYR.EDU
Sun Jun 14 23:54:15 EEST 2026


Dear Farzaneh,

Thank you for this interesting feedback

Le dim. 14 juin 2026 à 21:14, farzaneh badii <
00001deb507b73c5-dmarc-request at listserv.syr.edu> a écrit :

> Hi everyone
>
> We held a good session on human rights impact assessment and Law
> enforcement access to registrants private data during ICANN 86. Find the
> recording here.
> <https://icann.zoom.us/rec/play/uaYj4X2b2pgGxI2ztGwrEZ6LRU8jPuwycFwZpeYGlDFtUxJq3Swuew659Paj0GZpOxE9hOHHIFWc53GE._9lB4eVcT4b7mfDa?accessLevel=meeting&canPlayFromShare=true&from=share_recording_detail&startTime=1781188336000&oldStyle=true&componentName=rec-play&originRequestUrl=https%3A%2F%2Ficann.zoom.us%2Frec%2Fshare%2Ff_IZ6MrLsGHxtl5vlotXEJuanGAd7F745yySsqoJu308OzZZ5YrVvdWKvTVJuNF-.wbg8AnhgUB2FGV86%3FstartTime%3D1781188336000> (The
> link is too long, if you have difficulties accessing it let me know)
>
> Here is a brief update on the discussions surrounding DNS policies for law
> enforcement access to registrant data, followed by the specific data
> elements requested for authentication and authorization. Note that we are
> discussing these authorization and authentication forms and doing human
> rights impact assessment at the Supplemental Review Team on SSAD. So if you
> have comments, please do let us know.
>
> *Brief Update* The recent Non-Commercial Stakeholder Group (NCSG) session
> highlighted the human rights risks associated with how registrars handle
> law enforcement requests for redacted domain name registrant data. A
> primary concern is that establishing an authentication mechanism might
> create a false sense of trust, leading registrars to automatically disclose
> sensitive data—especially during "urgent" requests—without conducting a
> proper human rights impact assessment.
>
> We stress that a verified identity does not equate to a legally valid or
> proportionate request. Disclosing data without adequate authorization
> checks can lead to severe consequences for vulnerable targets, including
> journalists, activists, and dissidents, potentially resulting in profiling,
> deportation, torture, or irreversible fatal consequences if the requesting
> jurisdiction practices the death penalty. Therefore, there is a push to
> implement strict safeguards, mandatory fundamental rights balancing, and
> detailed transparency reporting to ensure data is only disclosed when
> absolutely necessary and legally justified.
>
> *Data Elements for Authentication* Authentication aims to verify the
> identity and mandate of the requesting officer and agency to ensure the
> system is secure and not spoofed by impersonators or hackers. The proposed
> data elements include:
>
>    - *Officer Identity:* Legal name, badge number, rank, department,
>    official government domain email, and a direct callback phone number to a
>    publicly listed agency line.
>    - *Agency Identity:* The agency's name and its specific type (e.g.,
>    criminal justice, administrative, or regulator) to help registrars
>    understand its nature.
>    - *Legislative Mandate:* Information on whether the agency is legally
>    empowered to demand sensitive private/domain registration data, and whether
>    the agency operates under judicial or strictly administrative oversight.
>    - *Cross-border Mechanisms:* Relevant details for international
>    requests.
>
> *Data Elements for Authorization* Authorization is the subsequent step
> where registrars decide whether the requested disclosure is legally valid,
> necessary, and proportionate based on a provided request form and
> authentication process and does the fundamental rights balancing. The
> requested data elements and commitments that we suggest include:
>
>    - *Legal Instrument:* Supporting legal documentation, such as a
>    subpoena (typically for basic subscriber info), a court order, or a search
>    warrant.
>    - *Necessity Statement:* An explanation from law enforcement detailing
>    what alternative investigative methods have already been exhausted and why
>    this specific infrastructure-layer data is needed.
>    - *Purpose Limitation:* A clearly stated purpose for the data request,
>    alongside binding commitments from the agency that there will be no
>    secondary uses or onward transfers of the data to other jurisdictions.
>    - *Retention and Deletion Commitments:* An agreement to delete the
>    data after a specified period.
>    - *Data Scoping:* Ensuring the requested data is strictly limited to
>    the minimum necessary information.
>    - *Human Rights Impact Assessment Indicators:* Contextual data that
>    helps registrars evaluate jurisdictional risks (e.g., if the requesting
>    country has the death penalty or a history of torture) and registrant
>    profile risks (e.g., if the user is a known activist or journalist).
>
> Farzaneh
>
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://lists.ncsg.is/pipermail/ncsg-discuss/attachments/20260614/1e64992d/attachment.htm>


More information about the Ncsg-discuss mailing list