Home / Blogs

European Privacy Authorities Object to ICANN Whois Proposals

In response to a letter from ICANN’s Noncommercial Users Constituency (NCUC) to data protection authorities concerning overreaching requests of law enforcement agencies in ICANN’s ongoing Registrar Accreditation Agreement negotiations, the Article 29 Data Protection Working Party has written the ICANN Board. Their comments focused on two new requirements proposed by LEAs for domain name registrars, namely that they re-verify registrant contact details and that they retain registrant data for a period of two years after a contract for a domain has ended.

Regarding re-verification the Working Party noted that the problem of inaccurate WHOIS data can only be solved by addressing the unlimited public accessibility of private contact details in the WHOIS database. It also disagreed with the notion that the re-verification request originated from LEAs when the purpose of the WHOIS database is to facilitate contact about technical issues:

The fact that WHOIS data can be used for other beneficial purposes does not in itself legitimise the collection and processing of personal data for those other purposes.

The Working Party finds the proposed new requirement ... excessive and therefore unlawful.

Concerning data retention, the Working Party found the proposed specification to have very broad scope, suggesting it may well facilitate the collection of information like credit card data, Skype handles, and communication log files and registration data. They noted that the requirement did not stem from any legal requirement in Europe, but “is explicitly introduced by ICANN to accommodate wishes from law enforcement.” As such,

The Working Party strongly objects to the introduction of data retention by means of contract issued by a private corporation in order to facilitate (public) law enforcement…”

You can read the Working Party’s entire letter here.

By Brenden Kuerbis, Internet Governance Researcher & Policy Analyst at Georgia Tech

Filed Under

Comments

Cannot be mandatory Alessandro Vesely  –  Oct 3, 2012 6:26 AM

Obtuse as it may seem, WP29’s response has the merit to point out that one-size-fits-all solutions are inadequate. We don’t need verified data for all domain name holders, but just for those domains that do email, e-commerce, and similar activities that may affect netizens at large. We don’t need unlimited access to personal data, just to the abuse-contact. (Actually, we may just be happy to know whether accurate contact data might be obtained for a given domain.)

Sadly, I note that it’s not by chance that WP29 replied by paper. It is because of how they consider the Internet.

Comment Title:

  Notify me of follow-up comments

We encourage you to post comments and engage in discussions that advance this post through relevant opinion, anecdotes, links and data. If you see a comment that you believe is irrelevant or inappropriate, you can report it using the link at the end of each comment. Views expressed in the comments do not represent those of CircleID. For more information on our comment policy, see Codes of Conduct.

CircleID Newsletter The Weekly Wrap

More and more professionals are choosing to publish critical posts on CircleID from all corners of the Internet industry. If you find it hard to keep up daily, consider subscribing to our weekly digest. We will provide you a convenient summary report once a week sent directly to your inbox. It's a quick and easy read.

I make a point of reading CircleID. There is no getting around the utility of knowing what thoughtful people are thinking and saying about our industry.

VINTON CERF
Co-designer of the TCP/IP Protocols & the Architecture of the Internet

Related

Topics

Domain Names

Sponsored byVerisign

New TLDs

Sponsored byRadix

Cybersecurity

Sponsored byVerisign

Threat Intelligence

Sponsored byWhoisXML API

Brand Protection

Sponsored byCSC

IPv4 Markets

Sponsored byIPv4.Global

DNS

Sponsored byDNIB.com