<html>
  <head>
    <meta http-equiv="Content-Type" content="text/html; charset=UTF-8">
  </head>
  <body text="#000000" bgcolor="#FFFFFF">
    <p>In fact this raises an interesting question as processing "in
      accordance with applicable law" may not be sufficient, for example
      if the strict rules of a data protection regime the disclosing
      party is subject to for some reason does not apply to the
      requesting party. <br>
    </p>
    <p>The standard that we do want, and which I think is appropriate is
      " in accordance with data protection standards equal/equivalent to
      or greater than the standards applicable to the data subject and
      the disclosing party".</p>
    <p>Thoughts?</p>
    <p><br>
    </p>
    <p>Volker<br>
    </p>
    <div class="moz-cite-prefix">Am 04.10.2019 um 23:14 schrieb
      Anderson, Marc via Gnso-epdp-team:<br>
    </div>
    <blockquote type="cite"
      cite="mid:4417064d79db45ec8bc2687cf7e0602c@verisign.com">
      <meta http-equiv="Content-Type" content="text/html; charset=UTF-8">
      <meta name="Generator" content="Microsoft Word 15 (filtered
        medium)">
      <style><!--
/* Font Definitions */
@font-face
        {font-family:Wingdings;
        panose-1:5 0 0 0 0 0 0 0 0 0;}
@font-face
        {font-family:"Cambria Math";
        panose-1:2 4 5 3 5 4 6 3 2 4;}
@font-face
        {font-family:Calibri;
        panose-1:2 15 5 2 2 2 4 3 2 4;}
/* Style Definitions */
p.MsoNormal, li.MsoNormal, div.MsoNormal
        {margin:0in;
        margin-bottom:.0001pt;
        font-size:12.0pt;
        font-family:"Calibri",sans-serif;}
a:link, span.MsoHyperlink
        {mso-style-priority:99;
        color:#0563C1;
        text-decoration:underline;}
a:visited, span.MsoHyperlinkFollowed
        {mso-style-priority:99;
        color:#954F72;
        text-decoration:underline;}
p.MsoListParagraph, li.MsoListParagraph, div.MsoListParagraph
        {mso-style-priority:34;
        margin-top:0in;
        margin-right:0in;
        margin-bottom:0in;
        margin-left:.5in;
        margin-bottom:.0001pt;
        font-size:12.0pt;
        font-family:"Calibri",sans-serif;}
p.msonormal0, li.msonormal0, div.msonormal0
        {mso-style-name:msonormal;
        mso-margin-top-alt:auto;
        margin-right:0in;
        mso-margin-bottom-alt:auto;
        margin-left:0in;
        font-size:11.0pt;
        font-family:"Calibri",sans-serif;}
span.EmailStyle18
        {mso-style-type:personal;
        font-family:"Calibri",sans-serif;
        color:windowtext;}
span.EmailStyle19
        {mso-style-type:personal;
        font-family:"Calibri",sans-serif;
        color:windowtext;}
span.EmailStyle20
        {mso-style-type:personal-compose;
        font-family:"Calibri",sans-serif;
        color:windowtext;}
.MsoChpDefault
        {mso-style-type:export-only;
        font-size:10.0pt;}
@page WordSection1
        {size:8.5in 11.0in;
        margin:1.0in 1.0in 1.0in 1.0in;}
div.WordSection1
        {page:WordSection1;}
/* List Definitions */
@list l0
        {mso-list-id:2086025650;
        mso-list-type:hybrid;
        mso-list-template-ids:942964526 67698689 67698691 67698693 67698689 67698691 67698693 67698689 67698691 67698693;}
@list l0:level1
        {mso-level-number-format:bullet;
        mso-level-text:;
        mso-level-tab-stop:none;
        mso-level-number-position:left;
        text-indent:-.25in;
        font-family:Symbol;}
@list l0:level2
        {mso-level-number-format:bullet;
        mso-level-text:o;
        mso-level-tab-stop:none;
        mso-level-number-position:left;
        text-indent:-.25in;
        font-family:"Courier New";}
@list l0:level3
        {mso-level-number-format:bullet;
        mso-level-text:;
        mso-level-tab-stop:none;
        mso-level-number-position:left;
        text-indent:-.25in;
        font-family:Wingdings;}
@list l0:level4
        {mso-level-number-format:bullet;
        mso-level-text:;
        mso-level-tab-stop:none;
        mso-level-number-position:left;
        text-indent:-.25in;
        font-family:Symbol;}
@list l0:level5
        {mso-level-number-format:bullet;
        mso-level-text:o;
        mso-level-tab-stop:none;
        mso-level-number-position:left;
        text-indent:-.25in;
        font-family:"Courier New";}
@list l0:level6
        {mso-level-number-format:bullet;
        mso-level-text:;
        mso-level-tab-stop:none;
        mso-level-number-position:left;
        text-indent:-.25in;
        font-family:Wingdings;}
@list l0:level7
        {mso-level-number-format:bullet;
        mso-level-text:;
        mso-level-tab-stop:none;
        mso-level-number-position:left;
        text-indent:-.25in;
        font-family:Symbol;}
@list l0:level8
        {mso-level-number-format:bullet;
        mso-level-text:o;
        mso-level-tab-stop:none;
        mso-level-number-position:left;
        text-indent:-.25in;
        font-family:"Courier New";}
@list l0:level9
        {mso-level-number-format:bullet;
        mso-level-text:;
        mso-level-tab-stop:none;
        mso-level-number-position:left;
        text-indent:-.25in;
        font-family:Wingdings;}
@list l1
        {mso-list-id:2131893132;
        mso-list-template-ids:460776550;}
@list l1:level1
        {mso-level-number-format:bullet;
        mso-level-text:;
        mso-level-tab-stop:.5in;
        mso-level-number-position:left;
        text-indent:-.25in;
        mso-ansi-font-size:10.0pt;
        font-family:Symbol;}
@list l1:level2
        {mso-level-number-format:bullet;
        mso-level-text:o;
        mso-level-tab-stop:1.0in;
        mso-level-number-position:left;
        text-indent:-.25in;
        mso-ansi-font-size:10.0pt;
        font-family:"Courier New";
        mso-bidi-font-family:"Times New Roman";}
@list l1:level3
        {mso-level-number-format:bullet;
        mso-level-text:;
        mso-level-tab-stop:1.5in;
        mso-level-number-position:left;
        text-indent:-.25in;
        mso-ansi-font-size:10.0pt;
        font-family:Wingdings;}
@list l1:level4
        {mso-level-number-format:bullet;
        mso-level-text:;
        mso-level-tab-stop:2.0in;
        mso-level-number-position:left;
        text-indent:-.25in;
        mso-ansi-font-size:10.0pt;
        font-family:Wingdings;}
@list l1:level5
        {mso-level-number-format:bullet;
        mso-level-text:;
        mso-level-tab-stop:2.5in;
        mso-level-number-position:left;
        text-indent:-.25in;
        mso-ansi-font-size:10.0pt;
        font-family:Wingdings;}
@list l1:level6
        {mso-level-number-format:bullet;
        mso-level-text:;
        mso-level-tab-stop:3.0in;
        mso-level-number-position:left;
        text-indent:-.25in;
        mso-ansi-font-size:10.0pt;
        font-family:Wingdings;}
@list l1:level7
        {mso-level-number-format:bullet;
        mso-level-text:;
        mso-level-tab-stop:3.5in;
        mso-level-number-position:left;
        text-indent:-.25in;
        mso-ansi-font-size:10.0pt;
        font-family:Wingdings;}
@list l1:level8
        {mso-level-number-format:bullet;
        mso-level-text:;
        mso-level-tab-stop:4.0in;
        mso-level-number-position:left;
        text-indent:-.25in;
        mso-ansi-font-size:10.0pt;
        font-family:Wingdings;}
@list l1:level9
        {mso-level-number-format:bullet;
        mso-level-text:;
        mso-level-tab-stop:4.5in;
        mso-level-number-position:left;
        text-indent:-.25in;
        mso-ansi-font-size:10.0pt;
        font-family:Wingdings;}
ol
        {margin-bottom:0in;}
ul
        {margin-bottom:0in;}
--></style><!--[if gte mso 9]><xml>
<o:shapedefaults v:ext="edit" spidmax="1026" />
</xml><![endif]--><!--[if gte mso 9]><xml>
<o:shapelayout v:ext="edit">
<o:idmap v:ext="edit" data="1" />
</o:shapelayout></xml><![endif]-->
      <div class="WordSection1">
        <p class="MsoNormal"><span style="font-size:11.0pt">EPDP Team,<o:p></o:p></span></p>
        <p class="MsoNormal"><span style="font-size:11.0pt"><o:p> </o:p></span></p>
        <p class="MsoNormal"><span style="font-size:11.0pt">I’m still
            uncomfortable with the language in Building Block E on
            retention and destruction of data.<o:p></o:p></span></p>
        <p class="MsoNormal"><span style="font-size:11.0pt"><o:p> </o:p></span></p>
        <p class="MsoNormal"><span style="font-size:11.0pt"><o:p> </o:p></span></p>
        <p class="MsoNormal" style="margin-left:.5in"><span
            style="color:black">The EPDP Team recommends that requestors
            must confirm that they will store, protect and dispose of
            the gTLD registration data in accordance with applicable
            law. The requirements for data retention and destruction may
            differ based on the purpose for which the data is retained;
            accordingly, data processing arrangements (for example,
            arrangements between the requestor and its accrediting body
            or arrangements between the requestor and the controller)
            are expected to contain further details with regard to the
            requirements for the retention and destruction of gTLD
            registration data. </span><span style="font-size:11.0pt"><o:p></o:p></span></p>
        <p class="MsoNormal" style="margin-left:.5in"><span
            style="font-size:11.0pt"><o:p> </o:p></span></p>
        <div style="mso-element:para-border-div;border:solid black
          1.0pt;border-bottom:none;padding:1.0pt 4.0pt 0in
          4.0pt;margin-left:.5in;margin-right:0in">
          <p class="MsoNormal" style="border:none;padding:0in"><i><span
                style="color:black">Comments / concerns / questions to
                be considered in relation to building block e): </span></i><span
              style="font-size:11.0pt"><o:p></o:p></span></p>
        </div>
        <div
          style="mso-element:para-border-div;border-top:none;border-left:solid
          black 1.0pt;border-bottom:none;border-right:solid black
          1.0pt;padding:0in 4.0pt 0in
          4.0pt;margin-left:.5in;margin-right:0in">
          <p class="MsoNormal"
            style="margin-left:.25in;text-indent:-.25in;mso-list:l1
            level1 lfo1;vertical-align:baseline;border:none;padding:0in">
            <!--[if !supportLists]--><span
              style="font-size:10.0pt;font-family:Symbol;color:black"><span
                style="mso-list:Ignore">·<span style="font:7.0pt
                  "Times New Roman"">        
                </span></span></span><!--[endif]--><i><span
                style="color:black">How would this be enforced? Could
                accreditation be used to track and enforce?</span></i><i><span
style="font-size:11.0pt;font-family:"Arial",sans-serif;color:black"><o:p></o:p></span></i></p>
        </div>
        <div style="mso-element:para-border-div;border:solid black
          1.0pt;border-top:none;padding:0in 4.0pt 1.0pt
          4.0pt;margin-left:.5in;margin-right:0in">
          <p class="MsoNormal"
            style="margin-left:.25in;text-indent:-.25in;mso-list:l1
            level1 lfo1;vertical-align:baseline;border:none;padding:0in">
            <!--[if !supportLists]--><span
              style="font-size:10.0pt;font-family:Symbol;color:black"><span
                style="mso-list:Ignore">·<span style="font:7.0pt
                  "Times New Roman"">        
                </span></span></span><!--[endif]--><i><span
                style="color:black">Consider changing “such as GDPR” to
                “including the GDPR”. </span></i><i><span
style="font-size:11.0pt;font-family:"Arial",sans-serif;color:black"><o:p></o:p></span></i></p>
        </div>
        <p class="MsoNormal" style="margin-left:.5in"><span
            style="font-size:11.0pt"><o:p> </o:p></span></p>
        <p class="MsoNormal"><span style="font-size:11.0pt"><o:p> </o:p></span></p>
        <p class="MsoNormal"><span style="font-size:11.0pt">I’m ok with
            the first sentence.  The language updated to read “in
            accordance with applicable law” is an improvement and
            addresses the second bullet point from the comments/concerns
            box.  To note, we haven’t addressed the first bullet in the
            comments/concerns box on enforcement yet.<o:p></o:p></span></p>
        <p class="MsoNormal"><span style="font-size:11.0pt"><o:p> </o:p></span></p>
        <p class="MsoNormal"><span style="font-size:11.0pt">One concept
            we have discussed but isn’t captured here is that the gTLD
            registration data should be retained only as long as
            necessary to achieve the purpose stated during the
            disclosure request.  The first sentence may be meant to
            imply that, but I think this building block would benefit
            from having that explicitly stated.<o:p></o:p></span></p>
        <p class="MsoNormal"><span style="font-size:11.0pt"><o:p> </o:p></span></p>
        <p class="MsoNormal"><span style="font-size:11.0pt">The second
            sentence I have a hard time following and a harder time
            figuring out how it would be implemented in practice.  The
            first bit seems to be aimed at stating our agreed
            understanding that we cannot define in policy fixed
            durations around the retention and destruction of the data. 
            Some requests may not require any retention while others may
            need years.  There seems agreement that retention will need
            to be determined on a case by case basis.  This seems like
            more of a foundational concept better suited to a Principle
            than part of a Building Block.  I suggest creating a new
            Principle for this concept and removing it from the Building
            Block.<o:p></o:p></span></p>
        <p class="MsoNormal"><span style="font-size:11.0pt"><o:p> </o:p></span></p>
        <p class="MsoNormal"><span style="font-size:11.0pt">We are
            expected to define the requirements for retention and
            destruction but the second bit seems to avoid that
            altogether saying some yet to be defined data processing
            arrangements will contain the details of the requirements. 
            I have a particularly hard time imagining what an
            implementation team would make of that sentence.<o:p></o:p></span></p>
        <p class="MsoNormal"><span style="font-size:11.0pt"><o:p> </o:p></span></p>
        <p class="MsoNormal"><span style="font-size:11.0pt">In
            parenthesis are two examples, the first being a potential
            arrangement between the requestor and its accrediting body. 
            I don’t recall that we’ve discussed this in terms of a data
            processing arrangement, but we have discussed how in order
            to be accredited, an accrediting body might require
            adherence to a code of conduct.  Such a code of conduct
            might include specifics on data retention and destruction. 
            For example:<o:p></o:p></span></p>
        <p class="MsoNormal"><span style="font-size:11.0pt"><o:p> </o:p></span></p>
        <ul style="margin-top:0in" type="disc">
          <li class="MsoListParagraph"
            style="margin-left:0in;mso-list:l0 level1 lfo2"><span
              style="font-size:11.0pt">Requestors agree that they will
              store, protect and dispose of the gTLD registration data
              in accordance with applicable law<o:p></o:p></span></li>
          <li class="MsoListParagraph"
            style="margin-left:0in;mso-list:l0 level1 lfo2"><span
              style="font-size:11.0pt">Requestors agree that they will
              only retain the gTLD registration data for as long as
              necessary to achieve the purpose stated in the disclosure
              request<o:p></o:p></span></li>
        </ul>
        <p class="MsoNormal"><span style="font-size:11.0pt"><o:p> </o:p></span></p>
        <p class="MsoNormal"><span style="font-size:11.0pt">If that is
            what is meant here, the building block should state that.<o:p></o:p></span></p>
        <p class="MsoNormal"><span style="font-size:11.0pt"><o:p> </o:p></span></p>
        <p class="MsoNormal"><span style="font-size:11.0pt">The second
            example seems to suggest a data processing arrangement
            between the requestor and the controller.  I don’t recall
            this being something we discussed specifically and could
            potentially become unwieldy if it means every requestor
            needs a contract with the controller.  If on the other hand
            this could be accomplished by including something along the
            lines of the above bullet points in a Terms of Use document,
            that might work.  Again if this is what is meant, the
            building block should state as much.<o:p></o:p></span></p>
        <p class="MsoNormal"><span style="font-size:11.0pt"><o:p> </o:p></span></p>
        <p class="MsoNormal"><span style="font-size:11.0pt">Thanks,<o:p></o:p></span></p>
        <p class="MsoNormal"><span style="font-size:11.0pt">Marc<o:p></o:p></span></p>
        <p class="MsoNormal"><span style="font-size:11.0pt"><o:p> </o:p></span></p>
        <p class="MsoNormal"><span style="font-size:11.0pt"><o:p> </o:p></span></p>
        <div>
          <div style="border:none;border-top:solid #E1E1E1
            1.0pt;padding:3.0pt 0in 0in 0in">
            <p class="MsoNormal"><b><span style="font-size:11.0pt">From:</span></b><span
                style="font-size:11.0pt"> Gnso-epdp-team
                <a class="moz-txt-link-rfc2396E" href="mailto:gnso-epdp-team-bounces@icann.org"><gnso-epdp-team-bounces@icann.org></a>
                <b>On Behalf Of </b>Caitlin Tubergen<br>
                <b>Sent:</b> Friday, September 27, 2019 4:28 PM<br>
                <b>To:</b> <a class="moz-txt-link-abbreviated" href="mailto:gnso-epdp-team@icann.org">gnso-epdp-team@icann.org</a><br>
                <b>Subject:</b> [EXTERNAL] [Gnso-epdp-team] Updated
                building block E - retention and destruction of data<o:p></o:p></span></p>
          </div>
        </div>
        <p class="MsoNormal"><o:p> </o:p></p>
        <p class="MsoNormal"><span style="font-size:11.0pt">Dear EPDP
            Team:<o:p></o:p></span></p>
        <p class="MsoNormal"><span style="font-size:11.0pt"><o:p> </o:p></span></p>
        <p class="MsoNormal"><span style="font-size:11.0pt">Further to
            EPDP Support Staff’s action, please find
            <a
href="https://docs.google.com/document/d/1WMhllLz5Zgm42C4Jfjiqinu32Jwiu_lhuBorzeuBKuA/edit"
              moz-do-not-send="true">
              the updated version of Building Block E (retention and
              destruction of data)</a>. The edits intend to capture the
            Team’s discussion from the last meeting.<o:p></o:p></span></p>
        <p class="MsoNormal"><span style="font-size:11.0pt"><o:p> </o:p></span></p>
        <p class="MsoNormal"><span style="font-size:11.0pt">As the
            building block is in the form of a Google Doc, please
            provide suggested edits directly in the document by
            <b>Monday, 7 October</b>. <o:p></o:p></span></p>
        <p class="MsoNormal"><span style="font-size:11.0pt"><o:p> </o:p></span></p>
        <p class="MsoNormal"><span style="font-size:11.0pt">Thank you.<o:p></o:p></span></p>
        <p class="MsoNormal"><span style="font-size:11.0pt"><o:p> </o:p></span></p>
        <p class="MsoNormal"><span style="font-size:11.0pt">Best
            regards,<o:p></o:p></span></p>
        <p class="MsoNormal"><span style="font-size:11.0pt"><o:p> </o:p></span></p>
        <p class="MsoNormal"><span style="font-size:11.0pt">Marika,
            Berry, and Caitlin<o:p></o:p></span></p>
        <p class="MsoNormal"><span
            style="font-size:11.0pt;font-family:"Times New
            Roman",serif;color:black"><o:p> </o:p></span></p>
        <p class="MsoNormal"><o:p> </o:p></p>
      </div>
      <br>
      <fieldset class="mimeAttachmentHeader"></fieldset>
      <pre class="moz-quote-pre" wrap="">_______________________________________________
Gnso-epdp-team mailing list
<a class="moz-txt-link-abbreviated" href="mailto:Gnso-epdp-team@icann.org">Gnso-epdp-team@icann.org</a>
<a class="moz-txt-link-freetext" href="https://mm.icann.org/mailman/listinfo/gnso-epdp-team">https://mm.icann.org/mailman/listinfo/gnso-epdp-team</a>
_______________________________________________
By submitting your personal data, you consent to the processing of your personal data for purposes of subscribing to this mailing list accordance with the ICANN Privacy Policy (<a class="moz-txt-link-freetext" href="https://www.icann.org/privacy/policy">https://www.icann.org/privacy/policy</a>) and the website Terms of Service (<a class="moz-txt-link-freetext" href="https://www.icann.org/privacy/tos">https://www.icann.org/privacy/tos</a>). You can visit the Mailman link above to change your membership status or configuration, including unsubscribing, setting digest-style delivery or disabling delivery altogether (e.g., for a vacation), and so on.</pre>
    </blockquote>
    <div class="moz-signature">-- <br>
      Volker A. Greimann<br>
      General Counsel and Policy Manager<br>
      <strong style="border-bottom: 3px solid #5C46B5">KEY-SYSTEMS GMBH</strong><br>
      <br>
      T: +49 6894 9396901<br>
      M: +49 6894 9396851<br>
      F: +49 6894 9396851<br>
      W: <a class="moz-txt-link-abbreviated" href="http://www.key-systems.net">www.key-systems.net</a><br>
      <br>
      Key-Systems GmbH is a company registered at the local court of
      Saarbruecken, Germany with the registration no. HR B 18835<br>
      CEO: Alexander Siffrin<br>
      <br>
      Part of the CentralNic Group PLC (LON: CNIC) a company registered
      in England and Wales with company number 8576358.</div>
  </body>
</html>