Home / Blogs

European Privacy Authorities Object to ICANN Whois Proposals

Brenden Kuerbis

In response to a letter from ICANN's Noncommercial Users Constituency (NCUC) to data protection authorities concerning overreaching requests of law enforcement agencies in ICANN's ongoing Registrar Accreditation Agreement negotiations, the Article 29 Data Protection Working Party has written the ICANN Board. Their comments focused on two new requirements proposed by LEAs for domain name registrars, namely that they re-verify registrant contact details and that they retain registrant data for a period of two years after a contract for a domain has ended.

Regarding re-verification the Working Party noted that the problem of inaccurate WHOIS data can only be solved by addressing the unlimited public accessibility of private contact details in the WHOIS database. It also disagreed with the notion that the re-verification request originated from LEAs when the purpose of the WHOIS database is to facilitate contact about technical issues:

The fact that WHOIS data can be used for other beneficial purposes does not in itself legitimise the collection and processing of personal data for those other purposes.

The Working Party finds the proposed new requirement ... excessive and therefore unlawful.

Concerning data retention, the Working Party found the proposed specification to have very broad scope, suggesting it may well facilitate the collection of information like credit card data, Skype handles, and communication log files and registration data. They noted that the requirement did not stem from any legal requirement in Europe, but "is explicitly introduced by ICANN to accommodate wishes from law enforcement." As such,

The Working Party strongly objects to the introduction of data retention by means of contract issued by a private corporation in order to facilitate (public) law enforcement..."

You can read the Working Party's entire letter here.

By Brenden Kuerbis, Fellow in Internet Security Governance, Citizen Lab, Univ of Toronto. Kuerbis is also a contributor to the Internet Governance Project blog.

Related topics: Domain Names, ICANN, Internet Governance, Policy & Regulation, Privacy, Whois

WEEKLY WRAP — Get CircleID's Weekly Summary Report by Email:

Comments

Cannot be mandatory Alessandro Vesely  –  Oct 02, 2012 10:26 PM PST

Obtuse as it may seem, WP29's response has the merit to point out that one-size-fits-all solutions are inadequate. We don't need verified data for all domain name holders, but just for those domains that do email, e-commerce, and similar activities that may affect netizens at large. We don't need unlimited access to personal data, just to the abuse-contact. (Actually, we may just be happy to know whether accurate contact data might be obtained for a given domain.)

Sadly, I note that it's not by chance that WP29 replied by paper. It is because of how they consider the Internet.

To post comments, please login or create an account.

Related Blogs

Related News

Topics

Industry Updates – Sponsored Posts

Minds + Machines in 2014 and 2015

DNN Podcast Interview with Antony Van Couvering

TLD Registry and Right of the Dot Establish a Domain Name Industry "Dream Team"

"Chinese Domaining Masterclass" to be Presented at NamesCon Las Vegas in January 2015

Domain Name .Africa Faces Hurdles - Q&A with Sophia Bekele

LogicBoxes Announces Automation Solutions for ccTLD

TLD Registry Wins Best Marketing Award at China New gTLD Roadshow

Update on Minds + Machines' Top-Level Domain Launches

ICANN Los Angeles Recap Webinar

TLD Registry Appoints First China General Manager, Mr Jin Wang

TLD Registry Opens China Headquarters in "China's Silicon Valley"

.nyc Goes Public to Brand the Big Apple

pink.host: Breast Cancer Awareness by Bluehost

Afilias Director Wins ICANN's 2014 Leadership Award

Infographic: Where in the World Do Chinese People Live?

Auctions Update: MMX Wins .law and .vip

New .ORGANIC Top-Level Domain Welcomes Leading Brands As .ORGANIC Pioneers

Dot Chinese Online and Dot Chinese Website Featured in EURid's World Report on IDNs 2014

New .ORGANIC Top-Level Domain Opens to Serve the Organic Community

DotConnectAfrica Contributes at the 9th IGF in Istanbul, Turkey

Sponsored Topics

Verisign

Security

Sponsored by
Verisign
Minds + Machines

Top-Level Domains

Sponsored by
Minds + Machines
Afilias

DNSSEC

Sponsored by
Afilias
dotMobi

Mobile

Sponsored by
dotMobi