<html><body style="word-wrap: break-word; -webkit-nbsp-mode: space; -webkit-line-break: after-white-space; ">All,<div><br></div><div>The Council of Europe has also responded to NCUC's privacy letter (attached) and stated that it shares our concerns about ICANN's compliance with privacy rights.</div><div><br><div>Best,</div><div>Robin</div><div><br></div><div><br><div>Begin forwarded message:</div><br class="Apple-interchange-newline"><blockquote type="cite"><div style="margin-top: 0px; margin-right: 0px; margin-bottom: 0px; margin-left: 0px; "><font face="Helvetica" size="3" color="#000000" style="font: 12.0px Helvetica; color: #000000"><b>From: </b></font><font face="Helvetica" size="3" style="font: 12.0px Helvetica">KWASNY Sophie <<a href="mailto:Sophie.KWASNY@coe.int">Sophie.KWASNY@coe.int</a>></font></div><div style="margin-top: 0px; margin-right: 0px; margin-bottom: 0px; margin-left: 0px; "><font face="Helvetica" size="3" color="#000000" style="font: 12.0px Helvetica; color: #000000"><b>Date: </b></font><font face="Helvetica" size="3" style="font: 12.0px Helvetica">October 11, 2012 5:42:39 AM PDT</font></div><div style="margin-top: 0px; margin-right: 0px; margin-bottom: 0px; margin-left: 0px; "><font face="Helvetica" size="3" color="#000000" style="font: 12.0px Helvetica; color: #000000"><b>To: </b></font><font face="Helvetica" size="3" style="font: 12.0px Helvetica">"'<a href="mailto:robin@ipjustice.org">robin@ipjustice.org</a>'" <<a href="mailto:robin@ipjustice.org">robin@ipjustice.org</a>></font></div><div style="margin-top: 0px; margin-right: 0px; margin-bottom: 0px; margin-left: 0px; "><font face="Helvetica" size="3" color="#000000" style="font: 12.0px Helvetica; color: #000000"><b>Cc: </b></font><font face="Helvetica" size="3" style="font: 12.0px Helvetica">THACI Elvana <<a href="mailto:Elvana.THACI@coe.int">Elvana.THACI@coe.int</a>></font></div><div style="margin-top: 0px; margin-right: 0px; margin-bottom: 0px; margin-left: 0px; "><font face="Helvetica" size="3" color="#000000" style="font: 12.0px Helvetica; color: #000000"><b>Subject: </b></font><font face="Helvetica" size="3" style="font: 12.0px Helvetica"><b>RE: Urgent Request from Non-Commercial Users Constituency for Council of Europe to review ICANN contract for privacy compliance</b></font></div> <div class="OutlookMessageHeader" lang="en-us" dir="ltr" align="left"><span class="747031612-11102012"><font face="Arial" color="#0000ff" size="2">Dear Mr Gross, </font></span></div> <div class="OutlookMessageHeader" lang="en-us" dir="ltr" align="left"><span class="747031612-11102012"></span> </div> <div class="OutlookMessageHeader" lang="en-us" dir="ltr" align="left"><span class="747031612-11102012"><font face="Arial" color="#0000ff" size="2">Please find attached a letter of the Chair of the Consultative Committee of Convention 108 for your attention.</font></span></div> <div class="OutlookMessageHeader" lang="en-us" dir="ltr" align="left"><span class="747031612-11102012"><font face="Arial" color="#0000ff" size="2"></font></span> </div> <div class="OutlookMessageHeader" lang="en-us" dir="ltr" align="left"><span class="747031612-11102012"><font face="Arial" color="#0000ff" size="2">Should you need any complementary information, please do not hesitate to contact me.</font></span></div> <div class="OutlookMessageHeader" lang="en-us" dir="ltr" align="left"><span class="747031612-11102012"><font face="Arial" color="#0000ff" size="2"></font></span> </div> <div class="OutlookMessageHeader" lang="en-us" dir="ltr" align="left"><span class="747031612-11102012"><font face="Arial" color="#0000ff" size="2">Best regards, </font></span></div> <div class="OutlookMessageHeader" lang="en-us" dir="ltr" align="left"><span class="747031612-11102012"><font face="Arial" color="#0000ff" size="2"><!-- Converted from text/rtf format --><p><span lang="en-gb"><font face="Arial" color="#808080" size="2">Sophie Kwasny</font></span> <br> <span lang="en-gb"><font face="Arial" color="#800080" size="2">Data Protection Unit</font></span> <br> <span lang="en-gb"><font face="Arial" color="#800080" size="2">Human Rights and Rule of Law (DG I)</font></span> <br> <span lang="en-gb"><font face="Arial" color="#800080" size="2">CONSEIL DE L'EUROPE - COUNCIL OF EUROPE</font></span> <br> <span lang="en-gb"><font face="Arial" color="#800080" size="2">tel : + 33(0) 3 90 21 43 39</font></span> </p> </font><p><font face="Arial" color="#0000ff" size="2"><span lang="en-gb"><font face="Arial" color="#800080" size="2">www.coe.int/dataprotection</font></span><span lang="fr"></span> </font></p> </span></div> <div class="OutlookMessageHeader" lang="en-us" dir="ltr" align="left"> <hr tabindex="-1"> </div> <div class="OutlookMessageHeader" lang="en-us" dir="ltr" align="left"><font face="Tahoma" size="2"><b>From:</b> Robin Gross [<a href="mailto:robin@ipjustice.org">mailto:robin@ipjustice.org</a>] <br> <b>Sent:</b> Sunday 22 July 2012 22:20<br> <b>To:</b> THACI Elvana<br> <b>Cc:</b> David Cake (<a href="mailto:dave@difference.com.au">dave@difference.com.au</a>) (<a href="mailto:dave@difference.com.au">dave@difference.com.au</a>); Wolfgang Kleinwächter<br> <b>Subject:</b> Urgent Request from Non-Commercial Users Constituency for Council of Europe to review ICANN contract for privacy compliance<br> </font><br> </div> <div></div> <div style="WORD-WRAP: break-word"> <div class="x_column"><p><span style="FONT-SIZE: 11pt; FONT-FAMILY: Calibri">Dear Thaci Elvana:</span></p><p><span style="FONT-SIZE: 11pt; FONT-FAMILY: Calibri">I am writing to you as a matter of urgency concerning online privacy. I represent the Non-Commercial </span><span style="FONT-SIZE: 11pt; FONT-FAMILY: Calibri">Users Constituency of ICANN and have concerns regarding ICANN’s the current consultation relating </span><span style="FONT-SIZE: 11pt; FONT-FAMILY: Calibri">to contracts with Registrars. A short letter from your office would help greatly to balance the negotiation discussion. I ask you to send correspondence to the ICANN Board Chair and CEO.</span></p><p><span style="FONT-SIZE: 11pt; FONT-FAMILY: Calibri">As you will be aware, the international management of Internet naming and addressing is conducted by ICANN, </span><span style="FONT-SIZE: 11pt; FONT-FAMILY: Calibri">the Internet Corporation for Assigned Names and Numbers. As part of ICANN’s work, </span><span style="FONT-SIZE: 11pt; FONT-FAMILY: Calibri">contractual arrangements are entered into with private corporations to offer particular Internet </span><span style="FONT-SIZE: 11pt; FONT-FAMILY: Calibri">domain names to the public. These private corporations (“Registrars”) in </span><span style="FONT-SIZE: 11pt; FONT-FAMILY: Calibri">turn undertake to manage </span><span style="FONT-SIZE: 11pt; FONT-FAMILY: Calibri">the personal details of their customers (“Registrants”) in accordance with the requirements of their </span><span style="FONT-SIZE: 11pt; FONT-FAMILY: Calibri">contract with ICANN.</span></p><p><span style="FONT-SIZE: 11pt; FONT-FAMILY: Calibri">Registrars collect and hold personal information about registrants and have obligations to uphold privacy-related principles for the collection, use, storage and disposal of this registration data. It is my belief that ICANN requirements within the contracts with Registrars must uphold and not violate international human rights standards on privacy, in particular collection, access to, and use of such data. Incursions on privacy are permissible, only when restricted to exceptional circumstances, such as access by law enforcement bodies pursuant to a judicial process and in any event subject to rules relating to access to data across national borders.</span></p><p><span style="FONT-SIZE: 11pt; FONT-FAMILY: Calibri">The aggregated database of registrants’ contact information is called the WHOIS database, and is </span><span style="FONT-SIZE: 11pt; FONT-FAMILY: Calibri">currently required to be published to unauthenticated requesters. In my view, information within this database must only be collected for the purpose for which is needed, and sensitive information must be made available only to those with demonstrated need. There is no clearly established need for the collection of, for instance, telephone numbers for the purposes of registering a domain name, although Registrars and others may find this convenient. A blanket requirement to provide telephone numbers would, therefore, seem to be an unreasonable intrusion into the privacy rights of registrants. Similarly, physical addresses and secondary identity verification documents are not required for the operation of the domain name system, and in my view should not be permitted or required in the contracts ICANN has with Registrars.</span></p><p><span style="FONT-SIZE: 11pt; FONT-FAMILY: Calibri">I am sure you will understand that with the creation of a data-rich database, concerns regarding the proper and secure storage and compliant arrangements for the disposal of registration data when it is no longer required become more important and potentially privacy-intrusive. In my view, the current requirements in the new draft contracts with Registrars are likely to infringe national privacy laws and have impact on citizens within your jurisdiction.</span></p><p><span style="FONT-SIZE: 11pt; FONT-FAMILY: Calibri">For example, WHOIS contact details need only be an email address of a technical officer who is empowered by the registrant to fix technical issues with a domain name address or pass on communications. There is no technical need for identity verification, let alone regular or annual verification, beyond the existing requirements. In many jurisdictions where freedom of expression is tenuous, the greater the degree of anonymity or pseudonymity, the greater the freedom of expression. This is even more acute when the database is stored in a foreign country and subject to </span><span class="x_Apple-style-span" style="FONT-SIZE: 15px; FONT-FAMILY: Calibri">different national laws regarding privacy and access by public officials to private databases. It is important, therefore, to ensure that national laws relating to privacy are respected.</span></p> </div> <div class="x_section"> <div class="x_layoutArea"> <div class="x_column"><p><span style="FONT-SIZE: 11pt; FONT-FAMILY: Calibri">The Article 29 Working Party has previously considered WHOIS, and raised concerns as far back as 2003, saying that </span><span style="FONT-SIZE: 11pt; FONT-FAMILY: Calibri">“it is necessary to look for less intrusive methods that would still serve the purpose </span><span style="FONT-SIZE: 11pt; FONT-FAMILY: Calibri">of the Whois directories without having all data directly available on-line </span><span style="FONT-SIZE: 11pt; FONT-FAMILY: Calibri">to everybody.” </span><span style="FONT-SIZE: 11pt; FONT-FAMILY: Calibri"><a href="http://ec.europa.eu/justice/policies/privacy/docs/wpdocs/2003/wp76_en.pdf">http://ec.europa.eu/justice/policies/privacy/docs/wpdocs/2003/wp76_en.pdf</a> </span><span style="FONT-SIZE: 11pt; FONT-FAMILY: Calibri">Unfortunately, ICANN’s </span><span style="FONT-SIZE: 11pt; FONT-FAMILY: Calibri">draft contract goes in the opposite direction, exacerbating the privacy harms.</span></p><p><span style="FONT-SIZE: 11pt; FONT-FAMILY: Calibri">The draft contracts are open for comment </span><span style="FONT-SIZE: 11pt; FONT-FAMILY: Calibri">– </span><span style="FONT-SIZE: 11pt; FONT-FAMILY: Calibri">see </span><span style="FONT-SIZE: 11pt; FONT-FAMILY: Calibri"><a href="http://www.icann.org/en/news/announcements/announcement-7-04jun12-en.htm">http://www.icann.org/en/news/announcements/announcement-7-04jun12-en.htm</a> </span><span style="FONT-SIZE: 11pt; FONT-FAMILY: Calibri">- and I would request your organisation review and consider the privacy impacts of these new contracts </span><span style="FONT-SIZE: 11pt; FONT-FAMILY: Calibri">– </span><span style="FONT-SIZE: 11pt; FONT-FAMILY: Calibri">in particular </span><span style="FONT-SIZE: 11pt; FONT-FAMILY: Calibri">the summary of the negotiating team’s responses to law enforcement submissions</span><span style="FONT-SIZE: 11pt; FONT-FAMILY: Calibri">. On behalf of the Non-Commercial User Constituency, I recommend that your organisation respond to the ICANN consultative process to ensure that privacy considerations and </span><span style="FONT-SIZE: 11pt; FONT-FAMILY: Calibri">respect for national privacy laws remains a strong feature of ICANN’s contractual arrangements. Your </span><span style="FONT-SIZE: 11pt; FONT-FAMILY: Calibri">comments would be very helpful in giving balanced background to the negotiations.</span></p><p><span style="FONT-SIZE: 11pt; FONT-FAMILY: Calibri">I recommend that you send comments directly to Dr. Steve Crocker, Chair of the ICANN Board, and Akram Atallah, interim CEO, via email to the Director of Board Support, <a href="mailto:diane.schroeder@icann.org">diane.schroeder@icann.org</a>. Comments by the end of July would be most helpful, but any information you can add would be welcome.</span></p><p><span style="FONT-SIZE: 11pt; FONT-FAMILY: Calibri">Please feel free to contact me </span><span style="FONT-SIZE: 11pt; FONT-FAMILY: Calibri"><a href="mailto:dave@DIFFERENCE.COM.AU">dave@DIFFERENCE.COM.AU</a> </span><span style="FONT-SIZE: 11pt; FONT-FAMILY: Calibri">if the NCUC can provide further information or background.</span></p><p><span style="FONT-SIZE: 11pt; FONT-FAMILY: Calibri">Very truly yours,</span></p><p><span style="FONT-SIZE: 11pt; FONT-FAMILY: Calibri">David Cake, Chair, Non-Commercial Users Constituency </span></p> <div style="FONT-SIZE: 13px">Robin Gross, Chair, Non-Commercial Stakeholders Group</div> </div> </div> </div> <div><br class="x_webkit-block-placeholder"> </div> <div>More info on ICANN RAA contract negotiations: </div> <div> <a href="https://community.icann.org/display/RAA/Negotiations+Between+ICANN+and+Registrars+to+Amend+the+Registrar+Accreditation+Agreement">https://community.icann.org/display/RAA/Negotiations+Between+ICANN+and+Registrars+to+Amend+the+Registrar+Accreditation+Agreement</a></div> <div style="FONT-SIZE: 13px">_______________________________________________</div> <div style="FONT-SIZE: 13px">Robin D. Gross, IP Justice Executive Director</div> <div style="FONT-SIZE: 13px">Web: <a href="http://www.ipjustice.org/">www.ipjustice.org</a></div> <div style="FONT-SIZE: 13px">Email: <a href="mailto:Robin@ipjustice.org">Robin@ipjustice.org</a></div> <div style="FONT-SIZE: 13px">Phone: +1 415.553.6261</div> <div style="FONT-SIZE: 13px"><br> </div> <div style="FONT-SIZE: 13px"></div> </div> <div style="WORD-WRAP: break-word"> <div style="FONT-SIZE: 13px"><span class="x_Apple-style-span" style="FONT-SIZE: medium"></span></div> </div> <div style="WORD-WRAP: break-word"></div> </blockquote></div></div></body></html>