<html xmlns:o="urn:schemas-microsoft-com:office:office" xmlns:w="urn:schemas-microsoft-com:office:word" xmlns:m="http://schemas.microsoft.com/office/2004/12/omml" xmlns="http://www.w3.org/TR/REC-html40"><head><meta http-equiv=Content-Type content="text/html; charset=utf-8"><meta name=Generator content="Microsoft Word 15 (filtered medium)"><style><!--
/* Font Definitions */
@font-face
        {font-family:Wingdings;
        panose-1:5 0 0 0 0 0 0 0 0 0;}
@font-face
        {font-family:"Cambria Math";
        panose-1:2 4 5 3 5 4 6 3 2 4;}
@font-face
        {font-family:Calibri;
        panose-1:2 15 5 2 2 2 4 3 2 4;}
/* Style Definitions */
p.MsoNormal, li.MsoNormal, div.MsoNormal
        {margin:0in;
        margin-bottom:.0001pt;
        font-size:12.0pt;
        font-family:"Calibri",sans-serif;}
a:link, span.MsoHyperlink
        {mso-style-priority:99;
        color:#0563C1;
        text-decoration:underline;}
a:visited, span.MsoHyperlinkFollowed
        {mso-style-priority:99;
        color:#954F72;
        text-decoration:underline;}
p.MsoListParagraph, li.MsoListParagraph, div.MsoListParagraph
        {mso-style-priority:34;
        margin-top:0in;
        margin-right:0in;
        margin-bottom:0in;
        margin-left:.5in;
        margin-bottom:.0001pt;
        mso-add-space:auto;
        font-size:12.0pt;
        font-family:"Calibri",sans-serif;}
p.MsoListParagraphCxSpFirst, li.MsoListParagraphCxSpFirst, div.MsoListParagraphCxSpFirst
        {mso-style-priority:34;
        mso-style-type:export-only;
        margin-top:0in;
        margin-right:0in;
        margin-bottom:0in;
        margin-left:.5in;
        margin-bottom:.0001pt;
        mso-add-space:auto;
        font-size:12.0pt;
        font-family:"Calibri",sans-serif;}
p.MsoListParagraphCxSpMiddle, li.MsoListParagraphCxSpMiddle, div.MsoListParagraphCxSpMiddle
        {mso-style-priority:34;
        mso-style-type:export-only;
        margin-top:0in;
        margin-right:0in;
        margin-bottom:0in;
        margin-left:.5in;
        margin-bottom:.0001pt;
        mso-add-space:auto;
        font-size:12.0pt;
        font-family:"Calibri",sans-serif;}
p.MsoListParagraphCxSpLast, li.MsoListParagraphCxSpLast, div.MsoListParagraphCxSpLast
        {mso-style-priority:34;
        mso-style-type:export-only;
        margin-top:0in;
        margin-right:0in;
        margin-bottom:0in;
        margin-left:.5in;
        margin-bottom:.0001pt;
        mso-add-space:auto;
        font-size:12.0pt;
        font-family:"Calibri",sans-serif;}
span.EmailStyle17
        {mso-style-type:personal-compose;
        font-family:"Calibri",sans-serif;
        color:windowtext;}
p.paragraph, li.paragraph, div.paragraph
        {mso-style-name:paragraph;
        mso-margin-top-alt:auto;
        margin-right:0in;
        mso-margin-bottom-alt:auto;
        margin-left:0in;
        font-size:12.0pt;
        font-family:"Times New Roman",serif;}
span.apple-converted-space
        {mso-style-name:apple-converted-space;}
.MsoChpDefault
        {mso-style-type:export-only;
        font-family:"Calibri",sans-serif;}
@page WordSection1
        {size:8.5in 11.0in;
        margin:1.0in 1.0in 1.0in 1.0in;}
div.WordSection1
        {page:WordSection1;}
/* List Definitions */
@list l0
        {mso-list-id:295643949;
        mso-list-type:hybrid;
        mso-list-template-ids:-425556840 67698689 1876443518 67698693 67698689 67698691 67698693 67698689 67698691 67698693;}
@list l0:level1
        {mso-level-number-format:bullet;
        mso-level-text:;
        mso-level-tab-stop:none;
        mso-level-number-position:left;
        margin-left:71.25pt;
        text-indent:-.25in;
        font-family:Symbol;}
@list l0:level2
        {mso-level-start-at:0;
        mso-level-number-format:bullet;
        mso-level-text:·;
        mso-level-tab-stop:none;
        mso-level-number-position:left;
        margin-left:152.25pt;
        text-indent:-63.0pt;
        font-family:"Calibri",sans-serif;
        mso-fareast-font-family:"Times New Roman";}
@list l0:level3
        {mso-level-number-format:bullet;
        mso-level-text:;
        mso-level-tab-stop:none;
        mso-level-number-position:left;
        margin-left:143.25pt;
        text-indent:-.25in;
        font-family:Wingdings;}
@list l0:level4
        {mso-level-number-format:bullet;
        mso-level-text:;
        mso-level-tab-stop:none;
        mso-level-number-position:left;
        margin-left:179.25pt;
        text-indent:-.25in;
        font-family:Symbol;}
@list l0:level5
        {mso-level-number-format:bullet;
        mso-level-text:o;
        mso-level-tab-stop:none;
        mso-level-number-position:left;
        margin-left:215.25pt;
        text-indent:-.25in;
        font-family:"Courier New";}
@list l0:level6
        {mso-level-number-format:bullet;
        mso-level-text:;
        mso-level-tab-stop:none;
        mso-level-number-position:left;
        margin-left:251.25pt;
        text-indent:-.25in;
        font-family:Wingdings;}
@list l0:level7
        {mso-level-number-format:bullet;
        mso-level-text:;
        mso-level-tab-stop:none;
        mso-level-number-position:left;
        margin-left:287.25pt;
        text-indent:-.25in;
        font-family:Symbol;}
@list l0:level8
        {mso-level-number-format:bullet;
        mso-level-text:o;
        mso-level-tab-stop:none;
        mso-level-number-position:left;
        margin-left:323.25pt;
        text-indent:-.25in;
        font-family:"Courier New";}
@list l0:level9
        {mso-level-number-format:bullet;
        mso-level-text:;
        mso-level-tab-stop:none;
        mso-level-number-position:left;
        margin-left:359.25pt;
        text-indent:-.25in;
        font-family:Wingdings;}
@list l1
        {mso-list-id:367489199;
        mso-list-type:hybrid;
        mso-list-template-ids:-398038460 67698703 67698713 67698715 67698703 67698713 67698715 67698703 67698713 67698715;}
@list l1:level1
        {mso-level-start-at:4;
        mso-level-tab-stop:none;
        mso-level-number-position:left;
        text-indent:-.25in;}
@list l1:level2
        {mso-level-number-format:alpha-lower;
        mso-level-tab-stop:none;
        mso-level-number-position:left;
        text-indent:-.25in;}
@list l1:level3
        {mso-level-number-format:roman-lower;
        mso-level-tab-stop:none;
        mso-level-number-position:right;
        text-indent:-9.0pt;}
@list l1:level4
        {mso-level-tab-stop:none;
        mso-level-number-position:left;
        text-indent:-.25in;}
@list l1:level5
        {mso-level-number-format:alpha-lower;
        mso-level-tab-stop:none;
        mso-level-number-position:left;
        text-indent:-.25in;}
@list l1:level6
        {mso-level-number-format:roman-lower;
        mso-level-tab-stop:none;
        mso-level-number-position:right;
        text-indent:-9.0pt;}
@list l1:level7
        {mso-level-tab-stop:none;
        mso-level-number-position:left;
        text-indent:-.25in;}
@list l1:level8
        {mso-level-number-format:alpha-lower;
        mso-level-tab-stop:none;
        mso-level-number-position:left;
        text-indent:-.25in;}
@list l1:level9
        {mso-level-number-format:roman-lower;
        mso-level-tab-stop:none;
        mso-level-number-position:right;
        text-indent:-9.0pt;}
@list l2
        {mso-list-id:455222650;
        mso-list-template-ids:88363088;}
@list l2:level1
        {mso-level-number-format:bullet;
        mso-level-text:;
        mso-level-tab-stop:.5in;
        mso-level-number-position:left;
        text-indent:-.25in;
        mso-ansi-font-size:10.0pt;
        font-family:Symbol;}
@list l2:level2
        {mso-level-number-format:bullet;
        mso-level-text:;
        mso-level-tab-stop:1.0in;
        mso-level-number-position:left;
        text-indent:-.25in;
        mso-ansi-font-size:10.0pt;
        font-family:Symbol;}
@list l2:level3
        {mso-level-number-format:bullet;
        mso-level-text:;
        mso-level-tab-stop:1.5in;
        mso-level-number-position:left;
        text-indent:-.25in;
        mso-ansi-font-size:10.0pt;
        font-family:Symbol;}
@list l2:level4
        {mso-level-number-format:bullet;
        mso-level-text:;
        mso-level-tab-stop:2.0in;
        mso-level-number-position:left;
        text-indent:-.25in;
        mso-ansi-font-size:10.0pt;
        font-family:Symbol;}
@list l2:level5
        {mso-level-number-format:bullet;
        mso-level-text:;
        mso-level-tab-stop:2.5in;
        mso-level-number-position:left;
        text-indent:-.25in;
        mso-ansi-font-size:10.0pt;
        font-family:Symbol;}
@list l2:level6
        {mso-level-number-format:bullet;
        mso-level-text:;
        mso-level-tab-stop:3.0in;
        mso-level-number-position:left;
        text-indent:-.25in;
        mso-ansi-font-size:10.0pt;
        font-family:Symbol;}
@list l2:level7
        {mso-level-number-format:bullet;
        mso-level-text:;
        mso-level-tab-stop:3.5in;
        mso-level-number-position:left;
        text-indent:-.25in;
        mso-ansi-font-size:10.0pt;
        font-family:Symbol;}
@list l2:level8
        {mso-level-number-format:bullet;
        mso-level-text:;
        mso-level-tab-stop:4.0in;
        mso-level-number-position:left;
        text-indent:-.25in;
        mso-ansi-font-size:10.0pt;
        font-family:Symbol;}
@list l2:level9
        {mso-level-number-format:bullet;
        mso-level-text:;
        mso-level-tab-stop:4.5in;
        mso-level-number-position:left;
        text-indent:-.25in;
        mso-ansi-font-size:10.0pt;
        font-family:Symbol;}
@list l3
        {mso-list-id:1351030807;
        mso-list-template-ids:1318377618;}
@list l3:level1
        {mso-level-number-format:bullet;
        mso-level-text:;
        mso-level-tab-stop:.5in;
        mso-level-number-position:left;
        text-indent:-.25in;
        mso-ansi-font-size:10.0pt;
        font-family:Symbol;}
@list l3:level2
        {mso-level-number-format:bullet;
        mso-level-text:o;
        mso-level-tab-stop:1.0in;
        mso-level-number-position:left;
        text-indent:-.25in;
        mso-ansi-font-size:10.0pt;
        font-family:"Courier New";
        mso-bidi-font-family:"Times New Roman";}
@list l3:level3
        {mso-level-tab-stop:none;
        mso-level-number-position:left;
        text-indent:-.25in;}
@list l3:level4
        {mso-level-number-format:bullet;
        mso-level-text:;
        mso-level-tab-stop:2.0in;
        mso-level-number-position:left;
        text-indent:-.25in;
        mso-ansi-font-size:10.0pt;
        font-family:Symbol;}
@list l3:level5
        {mso-level-number-format:bullet;
        mso-level-text:;
        mso-level-tab-stop:2.5in;
        mso-level-number-position:left;
        text-indent:-.25in;
        mso-ansi-font-size:10.0pt;
        font-family:Symbol;}
@list l3:level6
        {mso-level-number-format:bullet;
        mso-level-text:;
        mso-level-tab-stop:3.0in;
        mso-level-number-position:left;
        text-indent:-.25in;
        mso-ansi-font-size:10.0pt;
        font-family:Symbol;}
@list l3:level7
        {mso-level-number-format:bullet;
        mso-level-text:;
        mso-level-tab-stop:3.5in;
        mso-level-number-position:left;
        text-indent:-.25in;
        mso-ansi-font-size:10.0pt;
        font-family:Symbol;}
@list l3:level8
        {mso-level-number-format:bullet;
        mso-level-text:;
        mso-level-tab-stop:4.0in;
        mso-level-number-position:left;
        text-indent:-.25in;
        mso-ansi-font-size:10.0pt;
        font-family:Symbol;}
@list l3:level9
        {mso-level-number-format:bullet;
        mso-level-text:;
        mso-level-tab-stop:4.5in;
        mso-level-number-position:left;
        text-indent:-.25in;
        mso-ansi-font-size:10.0pt;
        font-family:Symbol;}
@list l4
        {mso-list-id:1420060449;
        mso-list-type:hybrid;
        mso-list-template-ids:1811826628 67698689 67698691 67698693 67698689 67698691 67698693 67698689 67698691 67698693;}
@list l4:level1
        {mso-level-number-format:bullet;
        mso-level-text:;
        mso-level-tab-stop:none;
        mso-level-number-position:left;
        text-indent:-.25in;
        font-family:Symbol;}
@list l4:level2
        {mso-level-number-format:bullet;
        mso-level-text:o;
        mso-level-tab-stop:none;
        mso-level-number-position:left;
        text-indent:-.25in;
        font-family:"Courier New";}
@list l4:level3
        {mso-level-number-format:bullet;
        mso-level-text:;
        mso-level-tab-stop:none;
        mso-level-number-position:left;
        text-indent:-.25in;
        font-family:Wingdings;}
@list l4:level4
        {mso-level-number-format:bullet;
        mso-level-text:;
        mso-level-tab-stop:none;
        mso-level-number-position:left;
        text-indent:-.25in;
        font-family:Symbol;}
@list l4:level5
        {mso-level-number-format:bullet;
        mso-level-text:o;
        mso-level-tab-stop:none;
        mso-level-number-position:left;
        text-indent:-.25in;
        font-family:"Courier New";}
@list l4:level6
        {mso-level-number-format:bullet;
        mso-level-text:;
        mso-level-tab-stop:none;
        mso-level-number-position:left;
        text-indent:-.25in;
        font-family:Wingdings;}
@list l4:level7
        {mso-level-number-format:bullet;
        mso-level-text:;
        mso-level-tab-stop:none;
        mso-level-number-position:left;
        text-indent:-.25in;
        font-family:Symbol;}
@list l4:level8
        {mso-level-number-format:bullet;
        mso-level-text:o;
        mso-level-tab-stop:none;
        mso-level-number-position:left;
        text-indent:-.25in;
        font-family:"Courier New";}
@list l4:level9
        {mso-level-number-format:bullet;
        mso-level-text:;
        mso-level-tab-stop:none;
        mso-level-number-position:left;
        text-indent:-.25in;
        font-family:Wingdings;}
@list l5
        {mso-list-id:1812359171;
        mso-list-type:hybrid;
        mso-list-template-ids:-2103014626 67698703 67698713 67698715 67698703 67698713 67698715 67698703 67698713 67698715;}
@list l5:level1
        {mso-level-tab-stop:none;
        mso-level-number-position:left;
        text-indent:-.25in;
        color:windowtext;}
@list l5:level2
        {mso-level-number-format:alpha-lower;
        mso-level-tab-stop:none;
        mso-level-number-position:left;
        text-indent:-.25in;}
@list l5:level3
        {mso-level-number-format:roman-lower;
        mso-level-tab-stop:none;
        mso-level-number-position:right;
        text-indent:-9.0pt;}
@list l5:level4
        {mso-level-tab-stop:none;
        mso-level-number-position:left;
        text-indent:-.25in;}
@list l5:level5
        {mso-level-number-format:alpha-lower;
        mso-level-tab-stop:none;
        mso-level-number-position:left;
        text-indent:-.25in;}
@list l5:level6
        {mso-level-number-format:roman-lower;
        mso-level-tab-stop:none;
        mso-level-number-position:right;
        text-indent:-9.0pt;}
@list l5:level7
        {mso-level-tab-stop:none;
        mso-level-number-position:left;
        text-indent:-.25in;}
@list l5:level8
        {mso-level-number-format:alpha-lower;
        mso-level-tab-stop:none;
        mso-level-number-position:left;
        text-indent:-.25in;}
@list l5:level9
        {mso-level-number-format:roman-lower;
        mso-level-tab-stop:none;
        mso-level-number-position:right;
        text-indent:-9.0pt;}
ol
        {margin-bottom:0in;}
ul
        {margin-bottom:0in;}
--></style></head><body lang=EN-US link="#0563C1" vlink="#954F72"><div class=WordSection1><p class=MsoNormal><span style='font-size:11.0pt;color:black'>Dear EPDP Team:<o:p></o:p></span></p><p class=MsoNormal><span style='font-size:11.0pt;color:black'><o:p> </o:p></span></p><p class=MsoNormal><span style='font-size:11.0pt;color:black'>Attached, please find two legal memos from Bird & Bird in response to the following questions:<o:p></o:p></span></p><p class=MsoNormal><span style='font-size:11.0pt;color:black'><o:p> </o:p></span></p><ol style='margin-top:0in' start=1 type=1><li class=paragraph style='color:black;margin-top:0in;margin-bottom:0in;margin-bottom:.0001pt;mso-list:l5 level1 lfo1;vertical-align:baseline'><span style='font-size:11.0pt;font-family:"Calibri",sans-serif'>Consider a System for Standardized Access/Disclosure where:  <o:p></o:p></span></li></ol><ul style='margin-top:0in' type=disc><ul style='margin-top:0in' type=circle><li class=paragraph style='color:black;margin-bottom:0in;margin-bottom:.0001pt;mso-list:l4 level2 lfo2;vertical-align:baseline'><span style='font-size:11.0pt;font-family:"Calibri",sans-serif'>contracted parties “CPs” are contractually required by ICANN to disclose registration data including personal data, <o:p></o:p></span></li><li class=paragraph style='color:black;margin-bottom:0in;margin-bottom:.0001pt;mso-list:l4 level2 lfo2;vertical-align:baseline'><span style='font-size:11.0pt;font-family:"Calibri",sans-serif'>data must be disclosed over RDAP to requestors either directly or through an intermediary request accreditation/authorization body, <o:p></o:p></span></li><li class=paragraph style='color:black;margin-bottom:0in;margin-bottom:.0001pt;mso-list:l4 level2 lfo2;vertical-align:baseline'><span style='font-size:11.0pt;font-family:"Calibri",sans-serif'>the accreditation is carried out by third party commissioned by ICANN without CP involvement, <o:p></o:p></span></li><li class=paragraph style='color:black;margin-bottom:0in;margin-bottom:.0001pt;mso-list:l4 level2 lfo2;vertical-align:baseline'><span style='font-size:11.0pt;font-family:"Calibri",sans-serif'>disclosure takes place in an automated fashion without any manual intervention, <o:p></o:p></span></li><li class=paragraph style='color:black;margin-bottom:0in;margin-bottom:.0001pt;mso-list:l4 level2 lfo2;vertical-align:baseline'><span style='font-size:11.0pt;font-family:"Calibri",sans-serif'>data subjects are being duly informed according to ICANN’s contractual requirements of the purposes for which, and types of entities by which, personal data may be processed. CP’s contract with ICANN also requires CP to notify data subject about this potential disclosure and third-party processing before the data subject enters into the registration agreement with the CP, and again annually via the ICANN-required registration data accuracy reminder. CP has done so. <o:p></o:p></span></li></ul></ul><p class=paragraph style='mso-margin-top-alt:5.0pt;margin-right:0in;margin-bottom:0in;margin-left:17.25pt;margin-bottom:.0001pt;text-indent:.5in;vertical-align:baseline'><span style='font-size:11.0pt;font-family:"Calibri",sans-serif;color:black'>Further, assume the following safeguards are in place <o:p></o:p></span></p><ul style='margin-top:0in' type=disc><li class=paragraph style='color:black;margin-bottom:0in;margin-left:35.25pt;margin-bottom:.0001pt;mso-list:l0 level1 lfo3;vertical-align:baseline'><span style='font-size:11.0pt;font-family:"Calibri",sans-serif'>ICANN or its designee has validated/verified the requestor’s identity, and required in each instance that the requestor: <o:p></o:p></span></li></ul><p class=paragraph style='mso-margin-top-alt:5.0pt;margin-right:0in;margin-bottom:0in;margin-left:152.25pt;margin-bottom:.0001pt;text-indent:-63.0pt;mso-list:l0 level2 lfo3;vertical-align:baseline'><![if !supportLists]><span style='font-size:11.0pt;font-family:"Calibri",sans-serif;color:black'><span style='mso-list:Ignore'>·<span style='font:7.0pt "Times New Roman"'>                                        </span></span></span><![endif]><span style='font-size:11.0pt;font-family:"Calibri",sans-serif;color:black'>represents that it has a lawful basis for requesting and processing the data,  <o:p></o:p></span></p><p class=paragraph style='mso-margin-top-alt:5.0pt;margin-right:0in;margin-bottom:0in;margin-left:152.25pt;margin-bottom:.0001pt;text-indent:-63.0pt;mso-list:l0 level2 lfo3;vertical-align:baseline'><![if !supportLists]><span style='font-size:11.0pt;font-family:"Calibri",sans-serif;color:black'><span style='mso-list:Ignore'>·<span style='font:7.0pt "Times New Roman"'>                                        </span></span></span><![endif]><span style='font-size:11.0pt;font-family:"Calibri",sans-serif;color:black'>provides its lawful basis, <o:p></o:p></span></p><p class=paragraph style='mso-margin-top-alt:5.0pt;margin-right:0in;margin-bottom:0in;margin-left:152.25pt;margin-bottom:.0001pt;text-indent:-63.0pt;mso-list:l0 level2 lfo3;vertical-align:baseline'><![if !supportLists]><span style='font-size:11.0pt;font-family:"Calibri",sans-serif;color:black'><span style='mso-list:Ignore'>·<span style='font:7.0pt "Times New Roman"'>                                        </span></span></span><![endif]><span style='font-size:11.0pt;font-family:"Calibri",sans-serif;color:black'>represents that it is requesting only the data necessary for its purpose,  <o:p></o:p></span></p><p class=paragraph style='mso-margin-top-alt:5.0pt;margin-right:0in;margin-bottom:0in;margin-left:152.25pt;margin-bottom:.0001pt;text-indent:-63.0pt;mso-list:l0 level2 lfo3;vertical-align:baseline'><![if !supportLists]><span style='font-size:11.0pt;font-family:"Calibri",sans-serif;color:black'><span style='mso-list:Ignore'>·<span style='font:7.0pt "Times New Roman"'>                                        </span></span></span><![endif]><span style='font-size:11.0pt;font-family:"Calibri",sans-serif;color:black'>agrees to process the data in accordance with GDPR, and  <o:p></o:p></span></p><p class=paragraph style='mso-margin-top-alt:5.0pt;margin-right:0in;margin-bottom:0in;margin-left:152.25pt;margin-bottom:.0001pt;text-indent:-63.0pt;mso-list:l0 level2 lfo3;vertical-align:baseline'><![if !supportLists]><span style='font-size:11.0pt;font-family:"Calibri",sans-serif;color:black'><span style='mso-list:Ignore'>·<span style='font:7.0pt "Times New Roman"'>                                        </span></span></span><![endif]><span style='font-size:11.0pt;font-family:"Calibri",sans-serif;color:black'>agrees to EU standard contractual clauses for the data transfer.  <o:p></o:p></span></p><p class=paragraph style='margin:0in;margin-bottom:.0001pt;vertical-align:baseline'><span style='font-size:11.0pt;font-family:"Calibri",sans-serif;color:black'>  <o:p></o:p></span></p><ul style='margin-top:0in' type=disc><li class=paragraph style='color:black;margin-bottom:0in;margin-left:35.25pt;margin-bottom:.0001pt;mso-list:l0 level1 lfo3;vertical-align:baseline'><span style='font-size:11.0pt;font-family:"Calibri",sans-serif'>ICANN or its designee logs requests for non-public registration data, regularly audits these logs, takes compliance action against suspected abuse, and makes these logs available upon request by the data subject. <o:p></o:p></span></li></ul><p class=paragraph style='mso-margin-top-alt:5.0pt;margin-right:0in;margin-bottom:0in;margin-left:53.25pt;margin-bottom:.0001pt;vertical-align:baseline'><span style='font-size:11.0pt;font-family:"Calibri",sans-serif;color:black'>1.  What risk or liability, if any, would the CP face for the processing activity of disclosure in this context, including the risk of a third party abusing or circumventing the safeguards?<o:p></o:p></span></p><p class=paragraph style='mso-margin-top-alt:5.0pt;margin-right:0in;margin-bottom:0in;margin-left:53.25pt;margin-bottom:.0001pt;vertical-align:baseline'><span style='font-size:11.0pt;font-family:"Calibri",sans-serif;color:black'>2.  Would you deem the criteria and safeguards outlined above sufficient to make disclosure of registration data compliant? If any risk exists, what improved or additional safeguards would eliminate<sup>1</sup> this risk?  <o:p></o:p></span></p><p class=paragraph style='mso-margin-top-alt:5.0pt;margin-right:0in;margin-bottom:0in;margin-left:53.25pt;margin-bottom:.0001pt;vertical-align:baseline'><span style='font-size:11.0pt;font-family:"Calibri",sans-serif;color:black'>3.  In this scenario, would the CP be a controller or a processor<sup>2</sup>, and to what extent, if at all, is the CP’s liability impacted by this controller/processor distinction? <o:p></o:p></span></p><p class=paragraph style='mso-margin-top-alt:5.0pt;margin-right:0in;margin-bottom:0in;margin-left:53.25pt;margin-bottom:.0001pt;vertical-align:baseline'><span style='font-size:11.0pt;font-family:"Calibri",sans-serif;color:black'>4. Only answer if a risk still exists for the CP: If a risk still exists for the CP, what additional safeguards might be required to eliminate CP liability depending on the nature of the disclosure request, i.e. depending on whether data is requested e.g. by private actors pursuing civil claims or law enforcement authorities depending on their jurisdiction or the nature of the crime (misdemeanor or felony) or the associated sanctions (fine, imprisonment or capital punishment)?<o:p></o:p></span></p><p class=MsoNormal style='margin-left:35.25pt'><span style='font-size:11.0pt;color:black'> <o:p></o:p></span></p><p class=MsoNormal><span style='font-size:11.0pt;color:black'>Footnote 1:<span class=apple-converted-space> </span>“<span style='background:#FCFCFC'>Here it is important to highlight the special role that safeguards may play in reducing the undue impact on the data subjects, and thereby changing the balance of rights and interests to the extent that the data controller’s legitimate interests will not be overridden.“ (</span><a href="https://urldefense.proofpoint.com/v2/url?u=https-3A__iapp.org_media_pdf_resource-5Fcenter_wp217-5Flegitimate-2Dinterests-5F04-2D2014.pdf&d=DwMGaQ&c=FmY1u3PJp6wrcrwll3mSVzgfkbPSS6sJms7xcl4I5cM&r=8K75qGdDlOta4kh6k2F0jrT195M3tF3J_Fxcz6EvuG2kYKDeA67ZTEnthHXAPVXH&m=WmQKTNAW4Y5U-c0lyA5XiCXNYR3bBOIeUD3JHAistCY&s=sWyYss17bzERUGYmyRgrLIYOWeEFfEm8TK82oD0K4Yg&e="><span style='color:black;background:#FCFCFC'>https://iapp.org/media/pdf/resource_center/wp217_legitimate-interests_04-2014.pdf</span><span class=apple-converted-space><span style='color:black'> </span></span><span style='color:black'>[iapp.org]</span></a><span style='background:#FCFCFC'>)</span><o:p></o:p></span></p><p class=MsoNormal><span style='font-size:11.0pt;color:black'> <o:p></o:p></span></p><p class=MsoNormal><span style='font-size:11.0pt;color:black'>Footnote 2:<span class=apple-converted-space> </span><a href="https://urldefense.proofpoint.com/v2/url?u=https-3A__ec.europa.eu_info_law_law-2Dtopic_data-2Dprotection_reform_rules-2Dbusiness-2Dand-2Dorganisations_obligations_controller-2Dprocessor_what-2Ddata-2Dcontroller-2Dor-2Ddata-2Dprocessor-5Fen&d=DwMGaQ&c=FmY1u3PJp6wrcrwll3mSVzgfkbPSS6sJms7xcl4I5cM&r=8K75qGdDlOta4kh6k2F0jrT195M3tF3J_Fxcz6EvuG2kYKDeA67ZTEnthHXAPVXH&m=WmQKTNAW4Y5U-c0lyA5XiCXNYR3bBOIeUD3JHAistCY&s=VLfFI2qvdMLP-znynFRMTpavBVBxa6oxjPohOdyWao0&e=" title="https://urldefense.proofpoint.com/v2/url?u=https-3A__ec.europa.eu_info_law_law-2Dtopic_data-2Dprotection_reform_rules-2Dbusiness-2Dand-2Dorganisations_obligations_controller-2Dprocessor_what-2Ddata-2Dcontroller-2Dor-2Ddata-2Dprocessor-5Fen&d=DwMGaQ&c=FmY1"><span style='color:black'>https://ec.europa.eu/info/law/law-topic/data-protection/reform/rules-business-and-organisations/obligations/controller-processor/what-data-controller-or-data-processor_en [ec.europa.eu]</span></a><o:p></o:p></span></p><p class=MsoNormal><span style='font-size:11.0pt;color:black'><o:p> </o:p></span></p><ol style='margin-top:0in' start=2 type=1><li class=MsoListParagraph style='color:black;margin-left:0in;mso-add-space:auto;mso-list:l5 level1 lfo1'><span style='font-size:11.0pt'>To what extent, if any, are contracted parties liable when a third party that accesses non-public WHOIS data under an accreditation scheme where by the accessor is accredited for the stated purpose, commits to certain reasonable safeguards similar to a code of conduct regarding use of the data, but misrepresents their intended purposes for processing such data, and subsequently processes it in a manner inconsistent with the stated purpose.  Under such circumstances, if there is possibility of liability to contracted parties, are there steps that can be taken to mitigate or reduce the risk of liability to the contracted parties?<o:p></o:p></span></li></ol><p class=MsoNormal><span style='font-size:11.0pt;color:black'><o:p> </o:p></span></p><ol style='margin-top:0in' start=4 type=1><li class=MsoListParagraphCxSpFirst style='color:black;margin-left:0in;mso-add-space:auto;mso-list:l1 level1 lfo6'><span style='font-size:11.0pt'>Under the GDPR, a data controller can disclose personal data to law enforcement of competent authority under Art. 6 1 c GDPR provided the law enforcement authority has the legal authority to create a legal obligation under applicable law. Certain commentators have interpreted “legal obligation” to apply only to legal obligations grounded in EU or Member State law.<o:p></o:p></span></li></ol><p class=MsoListParagraphCxSpLast><span style='font-size:11.0pt;color:black'><o:p> </o:p></span></p><p class=MsoNormal style='text-indent:.25in'><span style='font-size:11.0pt;color:black'>As to the data controller:<o:p></o:p></span></p><p class=MsoNormal><span style='font-size:11.0pt;color:black'><o:p> </o:p></span></p><p class=MsoNormal style='margin-left:.25in'><span style='font-size:11.0pt;color:black'>a. Consequently, does it follow that the data controller may not rely on Art. 6 1 c GDPR to disclose personal data to law enforcement authorities outside the data controller’s jurisdiction? Alternatively, are there any circumstances in which data controllers could rely on Art. 6 1 c GDPR to disclose personal data to law enforcement authorities outside the data controller’s jurisdiction?<o:p></o:p></span></p><p class=MsoNormal><span style='font-size:11.0pt;color:black'><o:p> </o:p></span></p><p class=MsoNormal style='margin-left:.25in'><span style='font-size:11.0pt;color:black'>b. May the data controller rely on any other legal bases, besides Art. 6 I f GDPR, to disclose personal data to law enforcement authorities outside the data controller’s jurisdiction?<o:p></o:p></span></p><p class=MsoNormal><span style='font-size:11.0pt;color:black'><o:p> </o:p></span></p><p class=MsoNormal style='text-indent:.25in'><span style='font-size:11.0pt;color:black'>As to the law enforcement authority:<o:p></o:p></span></p><p class=MsoNormal style='margin-left:.25in'><span style='font-size:11.0pt;color:black'><o:p> </o:p></span></p><p class=MsoNormal style='margin-left:.25in'><span style='font-size:11.0pt;color:black'>Given that Art. 6 1 GDPR states that European public authorities cannot use Art. 6 I f GDPR as a legal basis for processing carried out in the performance of their tasks, these public authorities need to have a legal basis so that disclosure can take place based on another legal basis (e.g. Art. 6 I c GDPR).  <o:p></o:p></span></p><p class=MsoNormal style='margin-left:.25in'><span style='font-size:11.0pt;color:black'><o:p> </o:p></span></p><p class=MsoNormal style='margin-left:.25in'><span style='font-size:11.0pt;color:black'>c. In the light of this, is it possible for non-EU-based law enforcement authorities to rely on Art. 6 I f GDPR as a legal basis for their processing? In this context, can the data controller rely on Art. 6 1 f GDPR to disclose the personal data? If non-EU-based law enforcement authorities cannot rely on Art. 6 1 f GDPR as a legal basis for their processing, on what lawful basis can non-EU-based law enforcement rely?<o:p></o:p></span></p><p class=MsoNormal><span style='font-size:11.0pt;color:black'><o:p> </o:p></span></p><p class=MsoNormal><span style='font-size:11.0pt;color:black'>Please note we are still awaiting a response to one question (Q3), which we will distribute when available. <o:p></o:p></span></p><p class=MsoNormal><span style='font-size:11.0pt;color:black'><o:p> </o:p></span></p><p class=MsoNormal><span style='font-size:11.0pt;color:black'>Thank you.<o:p></o:p></span></p><p class=MsoNormal><span style='font-size:11.0pt;color:black'><o:p> </o:p></span></p><p class=MsoNormal><span style='font-size:11.0pt;color:black'>Best regards, <o:p></o:p></span></p><p class=MsoNormal><span style='font-size:11.0pt;color:black'><o:p> </o:p></span></p><p class=MsoNormal><span style='font-size:11.0pt;color:black'>Marika, Berry, and Caitlin<o:p></o:p></span></p><p class=MsoNormal><span style='font-size:11.0pt;color:black'><o:p> </o:p></span></p><p class=MsoNormal><span style='font-size:11.0pt;color:black'><o:p> </o:p></span></p></div></body></html>