<html>
  <head>
    <meta content="text/html; charset=utf-8" http-equiv="Content-Type">
  </head>
  <body bgcolor="#FFFFFF" text="#000000">
    <p>You are welcome Steve, <br>
      <br>
      I guess we will wait for further responses as my brain is fried at
      the moment, a 16-hour work day will do that you. Though in my
      little world, it makes sense they are not certified for that
      aspect. I mean we only send them domain name and name servers,
      nothing else (in a nutshell).<br>
      <br>
      Slightly off topic, but can you mention those registries, not on
      the list?  Or perhaps we should do this offlist? Not that I am
      asking you to do my leg work, but it sounds you hit the same
      problem as me. A lot of Registries rely on a backend operator.
      That is where the actual data goes to. <br>
      <br>
      So in some cases, you have to dig deeper and in some cases like
      very obvious registries you find out  they use a backend in Europe
      :)<br>
      <br>
      Have a good one, <br>
      <br>
      Theo <br>
    </p>
    <br>
    <div class="moz-cite-prefix">On 31-8-2016 21:05, Metalitz, Steven
      wrote:<br>
    </div>
    <blockquote
      cite="mid:E5B4A2ED43DFAE4F9E710FA54FEF8F62601D85CA@LAEX02.MSK.local"
      type="cite">
      <meta http-equiv="Content-Type" content="text/html; charset=utf-8">
      <meta name="generator" content="HTML Tidy for Windows (vers 25
        March 2009), see www.w3.org">
      <meta name="Generator" content="Microsoft Word 14 (filtered
        medium)">
      <style type="text/css">
<!--
/* Font Definitions */
@font-face
        {font-family:Helvetica;
        panose-1:2 11 6 4 2 2 2 2 2 4;}
@font-face
        {font-family:SimSun;
        panose-1:2 1 6 0 3 1 1 1 1 1;}
@font-face
        {font-family:SimSun;
        panose-1:2 1 6 0 3 1 1 1 1 1;}
@font-face
        {font-family:Calibri;
        panose-1:2 15 5 2 2 2 4 3 2 4;}
@font-face
        {font-family:Tahoma;
        panose-1:2 11 6 4 3 5 4 4 2 4;}
@font-face
        {font-family:"\@SimSun";
        panose-1:2 1 6 0 3 1 1 1 1 1;}
/* Style Definitions */
p.MsoNormal, li.MsoNormal, div.MsoNormal
        {margin:0in;
        margin-bottom:.0001pt;
        font-size:11.0pt;
        font-family:"Calibri","sans-serif";}
a:link, span.MsoHyperlink
        {mso-style-priority:99;
        color:blue;
        text-decoration:underline;}
a:visited, span.MsoHyperlinkFollowed
        {mso-style-priority:99;
        color:purple;
        text-decoration:underline;}
p.MsoAcetate, li.MsoAcetate, div.MsoAcetate
        {mso-style-priority:99;
        mso-style-link:"Balloon Text Char";
        margin:0in;
        margin-bottom:.0001pt;
        font-size:8.0pt;
        font-family:"Tahoma","sans-serif";}
p.MsoListParagraph, li.MsoListParagraph, div.MsoListParagraph
        {mso-style-priority:34;
        margin-top:0in;
        margin-right:0in;
        margin-bottom:0in;
        margin-left:.5in;
        margin-bottom:.0001pt;
        font-size:11.0pt;
        font-family:"Calibri","sans-serif";}
span.BalloonTextChar
        {mso-style-name:"Balloon Text Char";
        mso-style-priority:99;
        mso-style-link:"Balloon Text";
        font-family:"Tahoma","sans-serif";}
span.EmailStyle19
        {mso-style-type:personal;
        font-family:"Calibri","sans-serif";
        color:windowtext;}
span.EmailStyle20
        {mso-style-type:personal;
        font-family:"Calibri","sans-serif";
        color:#1F497D;}
span.EmailStyle21
        {mso-style-type:personal-reply;
        font-family:"Calibri","sans-serif";
        color:#1F497D;}
.MsoChpDefault
        {mso-style-type:export-only;
        font-size:10.0pt;}
@page WordSection1
        {size:8.5in 11.0in;
        margin:1.0in 1.0in 1.0in 1.0in;}
div.WordSection1
        {page:WordSection1;}
/* List Definitions */
@list l0
        {mso-list-id:2032411276;
        mso-list-type:hybrid;
        mso-list-template-ids:474499138 -1735999970 67698713 67698715 67698703 67698713 67698715 67698703 67698713 67698715;}
@list l0:level1
        {mso-level-text:"\(%1\)";
        mso-level-tab-stop:none;
        mso-level-number-position:left;
        text-indent:-.25in;}
@list l0:level2
        {mso-level-number-format:alpha-lower;
        mso-level-tab-stop:none;
        mso-level-number-position:left;
        text-indent:-.25in;}
@list l0:level3
        {mso-level-number-format:roman-lower;
        mso-level-tab-stop:none;
        mso-level-number-position:right;
        text-indent:-9.0pt;}
@list l0:level4
        {mso-level-tab-stop:none;
        mso-level-number-position:left;
        text-indent:-.25in;}
@list l0:level5
        {mso-level-number-format:alpha-lower;
        mso-level-tab-stop:none;
        mso-level-number-position:left;
        text-indent:-.25in;}
@list l0:level6
        {mso-level-number-format:roman-lower;
        mso-level-tab-stop:none;
        mso-level-number-position:right;
        text-indent:-9.0pt;}
@list l0:level7
        {mso-level-tab-stop:none;
        mso-level-number-position:left;
        text-indent:-.25in;}
@list l0:level8
        {mso-level-number-format:alpha-lower;
        mso-level-tab-stop:none;
        mso-level-number-position:left;
        text-indent:-.25in;}
@list l0:level9
        {mso-level-number-format:roman-lower;
        mso-level-tab-stop:none;
        mso-level-number-position:right;
        text-indent:-9.0pt;}
ol
        {margin-bottom:0in;}
ul
        {margin-bottom:0in;}
-->
</style>
      <title></title>
      Thanks Theo. I did check the Safe Harbor list and found some major
      registries not on it or not referencing Whois data in their
      self-certification. Verisign was in the latter category. But
      awaiting further responses.<br>
      <br>
      Steve<br>
      <br>
      <br>
      <br>
      Sent with Good (<a class="moz-txt-link-abbreviated" href="http://www.good.com">www.good.com</a>)<br>
      <br>
      <br>
      -----Original Message-----<br>
      <b>From: </b>theo geurts [<a moz-do-not-send="true"
        href="mailto:gtheo@xs4all.nl">gtheo@xs4all.nl</a>]<br>
      <b>Sent: </b>Wednesday, August 31, 2016 11:49 AM Pacific Standard
      Time<br>
      <b>To: </b>Metalitz, Steven; 'Anderson, Marc';
      <a class="moz-txt-link-abbreviated" href="mailto:gnso-impl-thickwhois-rt@icann.org">gnso-impl-thickwhois-rt@icann.org</a><br>
      <b>Subject: </b>Re: [Gnso-impl-thickwhois-rt] Draft Thick Whois
      memo to the GNSO<br>
      <br>
      Hi Steve,<br>
      <br>
      Good questions, I'll let Marc come up with his own answers.<br>
      <br>
      Just to point out on 1 though, USA back end Registries did rely on
      Safe Harbor. You can still look them up here:
      <a moz-do-not-send="true"
        href="https://safeharbor.export.gov/list.aspx"
        class="moz-txt-link-freetext">
        https://safeharbor.export.gov/list.aspx</a><br>
      <br>
      I already reached out to several of them, and they informed me
      they are in the process of getting certified for Privacy Shield. I
      as an EU based Registrar have a duty to make sure that when I send
      data to USA based companies they are Privacy Shield certified. If
      they are not certified then I am breaking the law.<br>
      <br>
      Keep in mind though that Privacy Shield itself is just a formality
      to send data to the USA. Privacy Shield itself is not enough. So
      as an EU Registrar I cannot put my feet on the table and relax
      that dealing with a Privacy Shield certified company is enough.<br>
      <br>
      Privacy Shield is a framework, nothing more,  a Privacy Shield
      certified company can still be in violation of the EU directive.
      As such an EU Registrar has to make sure that the USA based
      privacy shield Registry back end provider is not in violation of
      the directive.<br>
      This puts a huge burden on the Registry but also on the Registrar.
      Within the thin WHOIS model, this no burden does not apply.<br>
      <br>
      The Dutch Government introduced an additional requirement in 2014
      that certain IT companies actually have to audit the American
      companies they do business with.<br>
      Currently, this does not apply for Dutch Registrars. But these
      things, as we know can change (laws change all the time). Though I
      think I wouldn't mind a few trips to the USA to audit some
      Registries :)<br>
      <br>
      Best regards,<br>
      <br>
      Theo<br>
      <br>
      <div class="moz-cite-prefix">On 31-8-2016 17:37, Metalitz, Steven
        wrote:<br>
      </div>
      <blockquote
        cite="mid:E5B4A2ED43DFAE4F9E710FA54FEF8F62601D83D0@LAEX02.MSK.local"
        type="cite">
        <!--[if !mso]><style>v\:* {behavior:url(#default#VML);}
o\:* {behavior:url(#default#VML);}
w\:* {behavior:url(#default#VML);}
.shape {behavior:url(#default#VML);}
</style><![endif]--><!--[if gte mso 9]><xml>
<o:shapedefaults v:ext="edit" spidmax="1027" />
</xml><![endif]--><!--[if gte mso 9]><xml>
<o:shapelayout v:ext="edit">
<o:idmap v:ext="edit" data="1" />
</o:shapelayout></xml><![endif]-->
        <div class="WordSection1">
          <p class="MsoNormal"><span style="color:#1F497D">Thanks for
              providing this draft, Marc.  A couple of questions about
              it on a quick read:</span></p>
          <p class="MsoNormal"><span style="color:#1F497D"> </span></p>
          <p class="MsoListParagraph"
            style="text-indent:-.25in;mso-list:l0 level1 lfo1"><!--[if !supportLists]--><span
              style="color:#1F497D"><span style="mso-list:Ignore">(1)<span
                  style="font:7.0pt &quot;Times New Roman&quot;">   </span></span></span><!--[endif]-->
            <span style="color:#1F497D"> The first two developments to
              which you cite are the invalidation of the US-EU Safe
              Harbor Program and the adoption of the EU-US Privacy
              Shield framework to replace it.  My impression is that US
              registries generally did not rely upon the Safe Harbor in
              processing thick Whois data (e.g., receiving Whois data
              containing personally identifiable information from
              European registrars and making it available through
              registry Whois), and so would not have been directly
              impacted by its invalidation.   Is my impression wrong? 
              If I am correct then what is the relevance of either the
              Safe Harbor or the Privacy Shield in this context? </span></p>
          <p class="MsoListParagraph"
            style="text-indent:-.25in;mso-list:l0 level1 lfo1"><!--[if !supportLists]--><span
              style="color:#1F497D"><span style="mso-list:Ignore">(2)<span
                  style="font:7.0pt &quot;Times New Roman&quot;">   </span></span></span><!--[endif]-->
            <span style="color:#1F497D">The last paragraph refers to
              data localization laws apart from EU privacy/data
              protection laws.  Can you be more specific?  I note that
              the Russian law was referenced in footnotes 2 and 10 of
              the legal review provided to the IRT in June 2015, are
              there other issues not covered by that analysis?</span></p>
          <p class="MsoListParagraph"
            style="text-indent:-.25in;mso-list:l0 level1 lfo1"><!--[if !supportLists]--><span
              style="color:#1F497D"><span style="mso-list:Ignore">(3)<span
                  style="font:7.0pt &quot;Times New Roman&quot;">   </span></span></span><!--[endif]-->
            <span style="color:#1F497D">If the IRT were to send this
              letter,  the GNSO council  might well ask what (if
              anything) we are asking them to do. How would you
              respond?    </span></p>
          <p class="MsoListParagraph"><span style="color:#1F497D"> </span></p>
          <p class="MsoListParagraph"><span style="color:#1F497D">Steve
              Metalitz</span></p>
          <p class="MsoListParagraph"><span style="color:#1F497D"> </span></p>
          <div>
            <p class="MsoNormal"><b><span style="color:#88162E"><img
                    id="_x0000_i1026"
                    src="cid:part3.C061AE2F.4906F990@xs4all.nl"
                    alt="image001" height="41" width="124"></span></b></p>
            <p class="MsoNormal"><b><span style="color:#88162E">Steven
                  J. Metalitz</span></b>
              <span style="color:black">| </span><b><span
                  style="color:#88162E">Partner, through his
                  professional corporation</span></b></p>
            <p class="MsoNormal"><span
                style="font-size:10.0pt;color:black">T: 202.355.7902</span>
              <span style="font-size:10.0pt;color:black">|</span> <span
                style="font-size:10.0pt;color:black">
                <a moz-do-not-send="true" href="mailto:met@msk.com"><span
                    style="color:black">met@msk.com</span></a></span></p>
            <p class="MsoNormal"><b><span
                  style="font-size:10.0pt;color:#88162E">Mitchell
                  Silberberg &amp; Knupp</span></b>
              <b><span style="font-size:8.0pt;color:#88162E">LLP</span></b>
              <span style="font-size:10.0pt;color:black">
                |</span> <span style="font-size:10.0pt;color:#84162E"><b><a
                    moz-do-not-send="true" href="http://www.msk.com/"><span
                      style="color:#84162E">www.msk.com</span></a></b></span></p>
            <p class="MsoNormal"><span
                style="font-size:10.0pt;color:black">1818 N Street NW,
                8th Floor, Washington, DC 20036</span></p>
            <p class="MsoNormal"><span
                style="font-size:10.0pt;color:black"> </span></p>
            <p class="MsoNormal" style="text-autospace:none"><b><u><span
                    style="font-size:8.0pt;color:gray">THE INFORMATION
                    CONTAINED IN THIS E-MAIL MESSAGE IS INTENDED ONLY
                    FOR THE PERSONAL AND CONFIDENTIAL USE OF THE
                    DESIGNATED RECIPIENTS.</span></u></b>
              <b><span style="font-size:8.0pt;color:gray">THIS MESSAGE
                  MAY BE AN ATTORNEY-CLIENT COMMUNICATION, AND AS SUCH
                  IS PRIVILEGED AND CONFIDENTIAL. IF THE READER OF THIS
                  MESSAGE IS NOT AN INTENDED RECIPIENT, YOU ARE HEREBY
                  NOTIFIED THAT ANY REVIEW, USE, DISSEMINATION,
                  FORWARDING OR COPYING OF THIS MESSAGE IS STRICTLY
                  PROHIBITED. PLEASE NOTIFY US IMMEDIATELY BY REPLY
                  E-MAIL OR TELEPHONE, AND DELETE THE ORIGINAL MESSAGE
                  AND ALL ATTACHMENTS FROM YOUR SYSTEM. THANK YOU.</span></b></p>
          </div>
          <p class="MsoNormal"><span style="color:#1F497D"> </span></p>
          <div>
            <div style="border:none;border-top:solid #B5C4DF
              1.0pt;padding:3.0pt 0in 0in 0in">
              <p class="MsoNormal"><b><span
style="font-size:10.0pt;font-family:&quot;Tahoma&quot;,&quot;sans-serif&quot;">From:</span></b>
                <span
style="font-size:10.0pt;font-family:&quot;Tahoma&quot;,&quot;sans-serif&quot;"><a
                    moz-do-not-send="true"
                    class="moz-txt-link-abbreviated"
                    href="mailto:gnso-impl-thickwhois-rt-bounces@icann.org">gnso-impl-thickwhois-rt-bounces@icann.org</a>
                  [<a moz-do-not-send="true"
                    class="moz-txt-link-freetext"
                    href="mailto:gnso-impl-thickwhois-rt-bounces@icann.org">mailto:gnso-impl-thickwhois-rt-bounces@icann.org</a>]
                  <b>On Behalf Of</b> Anderson, Marc<br>
                  <b>Sent:</b> Friday, August 26, 2016 3:21 PM<br>
                  <b>To:</b> <a moz-do-not-send="true"
                    class="moz-txt-link-abbreviated"
                    href="mailto:gnso-impl-thickwhois-rt@icann.org">
                    gnso-impl-thickwhois-rt@icann.org</a><br>
                  <b>Subject:</b> [Gnso-impl-thickwhois-rt] Draft Thick
                  Whois memo to the GNSO</span></p>
            </div>
          </div>
          <p class="MsoNormal"> </p>
          <p class="MsoNormal">Dear Colleagues,</p>
          <p class="MsoNormal"> </p>
          <p class="MsoNormal">During the IRT meetings held at ICANN 56
            Helsinki, Joe Waldron raised concerns with the changing
            landscape of Privacy Laws, in particular with regard to the
            EU.  He pointed out that recommendation #3 of the Thick
            Whois policy directs the IRT to notify the GNSO should
            privacy issues emerge that were not anticipated by the
            working group.  The IRT agreed that we have an obligation to
            notify the GNSO and asked Verisign to draft a proposed memo
            from the IRT to the GNSO.</p>
          <p class="MsoNormal"> </p>
          <p class="MsoNormal">Please find attached that draft memo
            outlining the obligation and the reasons why we think it is
            necessary to provide that notification at this time.</p>
          <p class="MsoNormal"> </p>
          <p class="MsoNormal">Thank you,</p>
          <p class="MsoNormal">Marc</p>
          <p class="MsoNormal"> </p>
          <p class="MsoNormal"> </p>
          <table class="MsoNormalTable" style="width:278.25pt"
            border="0" cellpadding="0" cellspacing="0" width="371">
            <tbody>
              <tr>
                <td colspan="2" style="padding:0in 0in 0in 0in">
                  <p class="MsoNormal"><img id="Picture_x0020_1"
                      src="cid:part9.73379C0F.21519173@xs4all.nl"
                      alt="Verisign" height="2" border="0" width="371"></p>
                </td>
              </tr>
              <tr>
                <td style="padding:11.25pt 0in 15.0pt 0in">
                  <p class="MsoNormal" style="line-height:10.5pt"><b><span
style="font-size:9.0pt;font-family:&quot;Helvetica&quot;,&quot;sans-serif&quot;;color:#006AAA">Marc
                        Anderson</span></b><span
style="font-size:8.5pt;font-family:&quot;Helvetica&quot;,&quot;sans-serif&quot;;color:#6B6D71"><br>
                      <a moz-do-not-send="true"
                        href="mailto:mcanderson@verisign.com">mcanderson@verisign.com</a><br>
                      <br>
                      m: 571.521.9943 t: 703.948.3404<br>
                      12061 Bluemont Way, Reston, VA 20190<br>
                      <br>
                      <a moz-do-not-send="true"
                        href="http://www.verisigninc.com/"><span
                          style="font-size:9.0pt;color:#006AAA">VerisignInc.com</span></a></span></p>
                </td>
                <td style="padding:11.25pt 0in 0in 0in" valign="top">
                  <p class="MsoNormal"><!--[if gte vml 1]><v:shapetype id="_x0000_t75" coordsize="21600,21600" o:spt="75" o:preferrelative="t" path="m@4@5l@4@11@9@11@9@5xe" filled="f" stroked="f">
<v:stroke joinstyle="miter" />
<v:formulas>
<v:f eqn="if lineDrawn pixelLineWidth 0" />
<v:f eqn="sum @0 1 0" />
<v:f eqn="sum 0 0 @1" />
<v:f eqn="prod @2 1 2" />
<v:f eqn="prod @3 21600 pixelWidth" />
<v:f eqn="prod @3 21600 pixelHeight" />
<v:f eqn="sum @0 0 1" />
<v:f eqn="prod @6 1 2" />
<v:f eqn="prod @7 21600 pixelWidth" />
<v:f eqn="sum @8 21600 0" />
<v:f eqn="prod @7 21600 pixelHeight" />
<v:f eqn="sum @10 21600 0" />
</v:formulas>
<v:path o:extrusionok="f" gradientshapeok="t" o:connecttype="rect" />
<o:lock v:ext="edit" aspectratio="t" />
</v:shapetype><v:shape id="Picture_x0020_2" o:spid="_x0000_s1026" type="#_x0000_t75" alt="Verisign&#8482;" style='position:absolute;margin-left:10.65pt;margin-top:0;width:54.75pt;height:48pt;z-index:251659264;visibility:visible;mso-wrap-style:square;mso-width-percent:0;mso-height-percent:0;mso-wrap-distance-left:0;mso-wrap-distance-top:0;mso-wrap-distance-right:0;mso-wrap-distance-bottom:0;mso-position-horizontal:right;mso-position-horizontal-relative:text;mso-position-vertical:absolute;mso-position-vertical-relative:line;mso-width-percent:0;mso-height-percent:0;mso-width-relative:page;mso-height-relative:page' o:allowoverlap="f">
<v:imagedata src="imap://gtheo@imap.xs4all.nl:143/fetch%3EUID%3E/INBOX%3E10515?header=quotebody&part=1.1.4&filename=image005.gif" o:title="Verisign&#8482;" />
<w:wrap type="square"/>
</v:shape><![endif]--><!--[if !vml]--><img
                      src="cid:part12.011E92C8.493C590C@xs4all.nl"
                      alt="Verisign™" v:shapes="Picture_x0020_2"
                      height="64" align="right" width="73"><!--[endif]--></p>
                </td>
              </tr>
            </tbody>
          </table>
          <p class="MsoNormal"> </p>
          <p class="MsoNormal"> </p>
        </div>
        <br>
        <fieldset class="mimeAttachmentHeader"></fieldset>
        <br>
        <pre wrap="">_______________________________________________
Gnso-impl-thickwhois-rt mailing list
<a moz-do-not-send="true" class="moz-txt-link-abbreviated" href="mailto:Gnso-impl-thickwhois-rt@icann.org">Gnso-impl-thickwhois-rt@icann.org</a>
<a moz-do-not-send="true" href="https://mm.icann.org/mailman/listinfo/gnso-impl-thickwhois-rt" class="moz-txt-link-freetext">https://mm.icann.org/mailman/listinfo/gnso-impl-thickwhois-rt</a>
</pre>
      </blockquote>
      <br>
    </blockquote>
    <br>
  </body>
</html>