<html>
<head>
<meta http-equiv="Content-Type" content="text/html; charset=utf-8">
<meta name="generator" content="HTML Tidy for Windows (vers 25 March 2009), see www.w3.org">
<meta name="Generator" content="Microsoft Word 14 (filtered medium)">
<style type="text/css">
<!--
/* Font Definitions */
@font-face
        {font-family:Helvetica;
        panose-1:2 11 6 4 2 2 2 2 2 4;}
@font-face
        {font-family:SimSun;
        panose-1:2 1 6 0 3 1 1 1 1 1;}
@font-face
        {font-family:SimSun;
        panose-1:2 1 6 0 3 1 1 1 1 1;}
@font-face
        {font-family:Calibri;
        panose-1:2 15 5 2 2 2 4 3 2 4;}
@font-face
        {font-family:Tahoma;
        panose-1:2 11 6 4 3 5 4 4 2 4;}
@font-face
        {font-family:"\@SimSun";
        panose-1:2 1 6 0 3 1 1 1 1 1;}
/* Style Definitions */
p.MsoNormal, li.MsoNormal, div.MsoNormal
        {margin:0in;
        margin-bottom:.0001pt;
        font-size:11.0pt;
        font-family:"Calibri","sans-serif";}
a:link, span.MsoHyperlink
        {mso-style-priority:99;
        color:blue;
        text-decoration:underline;}
a:visited, span.MsoHyperlinkFollowed
        {mso-style-priority:99;
        color:purple;
        text-decoration:underline;}
p.MsoAcetate, li.MsoAcetate, div.MsoAcetate
        {mso-style-priority:99;
        mso-style-link:"Balloon Text Char";
        margin:0in;
        margin-bottom:.0001pt;
        font-size:8.0pt;
        font-family:"Tahoma","sans-serif";}
p.MsoListParagraph, li.MsoListParagraph, div.MsoListParagraph
        {mso-style-priority:34;
        margin-top:0in;
        margin-right:0in;
        margin-bottom:0in;
        margin-left:.5in;
        margin-bottom:.0001pt;
        font-size:11.0pt;
        font-family:"Calibri","sans-serif";}
span.BalloonTextChar
        {mso-style-name:"Balloon Text Char";
        mso-style-priority:99;
        mso-style-link:"Balloon Text";
        font-family:"Tahoma","sans-serif";}
span.EmailStyle19
        {mso-style-type:personal;
        font-family:"Calibri","sans-serif";
        color:windowtext;}
span.EmailStyle20
        {mso-style-type:personal;
        font-family:"Calibri","sans-serif";
        color:#1F497D;}
span.EmailStyle21
        {mso-style-type:personal-reply;
        font-family:"Calibri","sans-serif";
        color:#1F497D;}
.MsoChpDefault
        {mso-style-type:export-only;
        font-size:10.0pt;}
@page WordSection1
        {size:8.5in 11.0in;
        margin:1.0in 1.0in 1.0in 1.0in;}
div.WordSection1
        {page:WordSection1;}
/* List Definitions */
@list l0
        {mso-list-id:2032411276;
        mso-list-type:hybrid;
        mso-list-template-ids:474499138 -1735999970 67698713 67698715 67698703 67698713 67698715 67698703 67698713 67698715;}
@list l0:level1
        {mso-level-text:"\(%1\)";
        mso-level-tab-stop:none;
        mso-level-number-position:left;
        text-indent:-.25in;}
@list l0:level2
        {mso-level-number-format:alpha-lower;
        mso-level-tab-stop:none;
        mso-level-number-position:left;
        text-indent:-.25in;}
@list l0:level3
        {mso-level-number-format:roman-lower;
        mso-level-tab-stop:none;
        mso-level-number-position:right;
        text-indent:-9.0pt;}
@list l0:level4
        {mso-level-tab-stop:none;
        mso-level-number-position:left;
        text-indent:-.25in;}
@list l0:level5
        {mso-level-number-format:alpha-lower;
        mso-level-tab-stop:none;
        mso-level-number-position:left;
        text-indent:-.25in;}
@list l0:level6
        {mso-level-number-format:roman-lower;
        mso-level-tab-stop:none;
        mso-level-number-position:right;
        text-indent:-9.0pt;}
@list l0:level7
        {mso-level-tab-stop:none;
        mso-level-number-position:left;
        text-indent:-.25in;}
@list l0:level8
        {mso-level-number-format:alpha-lower;
        mso-level-tab-stop:none;
        mso-level-number-position:left;
        text-indent:-.25in;}
@list l0:level9
        {mso-level-number-format:roman-lower;
        mso-level-tab-stop:none;
        mso-level-number-position:right;
        text-indent:-9.0pt;}
ol
        {margin-bottom:0in;}
ul
        {margin-bottom:0in;}
-->
</style>
<title></title>
</head>
<body>
Thanks Theo. I did check the Safe Harbor list and found some major registries not on it or not referencing Whois data in their self-certification. Verisign was in the latter category. But awaiting further responses.<br>
<br>
Steve<br>
<br>
<br>
<br>
Sent with Good (www.good.com)<br>
<br>
<br>
-----Original Message-----<br>
<b>From:&nbsp;</b>theo geurts [<a href="mailto:gtheo@xs4all.nl">gtheo@xs4all.nl</a>]<br>
<b>Sent:&nbsp;</b>Wednesday, August 31, 2016 11:49 AM Pacific Standard Time<br>
<b>To:&nbsp;</b>Metalitz, Steven; 'Anderson, Marc'; gnso-impl-thickwhois-rt@icann.org<br>
<b>Subject:&nbsp;</b>Re: [Gnso-impl-thickwhois-rt] Draft Thick Whois memo to the GNSO<br>
<br>
Hi Steve,<br>
<br>
Good questions, I'll let Marc come up with his own answers.<br>
<br>
Just to point out on 1 though, USA back end Registries did rely on Safe Harbor. You can still look them up here:
<a href="https://safeharbor.export.gov/list.aspx" class="moz-txt-link-freetext">
https://safeharbor.export.gov/list.aspx</a><br>
<br>
I already reached out to several of them, and they informed me they are in the process of getting certified for Privacy Shield. I as an EU based Registrar have a duty to make sure that when I send data to USA based companies they are Privacy Shield certified.
 If they are not certified then I am breaking the law.<br>
<br>
Keep in mind though that Privacy Shield itself is just a formality to send data to the USA. Privacy Shield itself is not enough. So as an EU Registrar I cannot put my feet on the table and relax that dealing with a Privacy Shield certified company is enough.<br>
<br>
Privacy Shield is a framework, nothing more,&nbsp; a Privacy Shield certified company can still be in violation of the EU directive. As such an EU Registrar has to make sure that the USA based privacy shield Registry back end provider is not in violation of the
 directive.<br>
This puts a huge burden on the Registry but also on the Registrar. Within the thin WHOIS model, this no burden does not apply.<br>
<br>
The Dutch Government introduced an additional requirement in 2014 that certain IT companies actually have to audit the American companies they do business with.<br>
Currently, this does not apply for Dutch Registrars. But these things, as we know can change (laws change all the time). Though I think I wouldn't mind a few trips to the USA to audit some Registries :)<br>
<br>
Best regards,<br>
<br>
Theo<br>
<br>
<div class="moz-cite-prefix">On 31-8-2016 17:37, Metalitz, Steven wrote:<br>
</div>
<blockquote cite="mid:E5B4A2ED43DFAE4F9E710FA54FEF8F62601D83D0@LAEX02.MSK.local" type="cite">
<!--[if !mso]><style>v\:* {behavior:url(#default#VML);}
o\:* {behavior:url(#default#VML);}
w\:* {behavior:url(#default#VML);}
.shape {behavior:url(#default#VML);}
</style><![endif]--><!--[if gte mso 9]><xml>
<o:shapedefaults v:ext="edit" spidmax="1027" />
</xml><![endif]--><!--[if gte mso 9]><xml>
<o:shapelayout v:ext="edit">
<o:idmap v:ext="edit" data="1" />
</o:shapelayout></xml><![endif]-->
<div class="WordSection1">
<p class="MsoNormal"><span style="color:#1F497D">Thanks for providing this draft, Marc.&nbsp; A couple of questions about it on a quick read:</span></p>
<p class="MsoNormal"><span style="color:#1F497D">&nbsp;</span></p>
<p class="MsoListParagraph" style="text-indent:-.25in;mso-list:l0 level1 lfo1"><!--[if !supportLists]--><span style="color:#1F497D"><span style="mso-list:Ignore">(1)<span style="font:7.0pt &quot;Times New Roman&quot;">&nbsp;&nbsp;&nbsp;</span></span></span><!--[endif]-->
<span style="color:#1F497D">&nbsp;The first two developments to which you cite are the invalidation of the US-EU Safe Harbor Program and the adoption of the EU-US Privacy Shield framework to replace it.&nbsp; My impression is that US registries generally did not rely
 upon the Safe Harbor in processing thick Whois data (e.g., receiving Whois data containing personally identifiable information from European registrars and making it available through registry Whois), and so would not have been directly impacted by its invalidation.
 &nbsp;&nbsp;Is my impression wrong?&nbsp; If I am correct then what is the relevance of either the Safe Harbor or the Privacy Shield in this context?&nbsp;</span></p>
<p class="MsoListParagraph" style="text-indent:-.25in;mso-list:l0 level1 lfo1"><!--[if !supportLists]--><span style="color:#1F497D"><span style="mso-list:Ignore">(2)<span style="font:7.0pt &quot;Times New Roman&quot;">&nbsp;&nbsp;&nbsp;</span></span></span><!--[endif]-->
<span style="color:#1F497D">The last paragraph refers to data localization laws apart from EU privacy/data protection laws.&nbsp; Can you be more specific?&nbsp; I note that the Russian law was referenced in footnotes 2 and 10 of the legal review provided to the IRT
 in June 2015, are there other issues not covered by that analysis?</span></p>
<p class="MsoListParagraph" style="text-indent:-.25in;mso-list:l0 level1 lfo1"><!--[if !supportLists]--><span style="color:#1F497D"><span style="mso-list:Ignore">(3)<span style="font:7.0pt &quot;Times New Roman&quot;">&nbsp;&nbsp;&nbsp;</span></span></span><!--[endif]-->
<span style="color:#1F497D">If the IRT were to send this letter, &nbsp;the GNSO council &nbsp;might well ask what (if anything) we are asking them to do. How would you respond?&nbsp; &nbsp;&nbsp;</span></p>
<p class="MsoListParagraph"><span style="color:#1F497D">&nbsp;</span></p>
<p class="MsoListParagraph"><span style="color:#1F497D">Steve Metalitz</span></p>
<p class="MsoListParagraph"><span style="color:#1F497D">&nbsp;</span></p>
<div>
<p class="MsoNormal"><b><span style="color:#88162E"><img id="_x0000_i1026" src="cid:part1.34FDE91A.0CBDD843@xs4all.nl" alt="image001" height="41" width="124"></span></b></p>
<p class="MsoNormal"><b><span style="color:#88162E">Steven J. Metalitz</span></b>
<span style="color:black">| </span><b><span style="color:#88162E">Partner, through his professional corporation</span></b></p>
<p class="MsoNormal"><span style="font-size:10.0pt;color:black">T: 202.355.7902</span>
<span style="font-size:10.0pt;color:black">|</span> <span style="font-size:10.0pt;color:black">
<a moz-do-not-send="true" href="mailto:met@msk.com"><span style="color:black">met@msk.com</span></a></span></p>
<p class="MsoNormal"><b><span style="font-size:10.0pt;color:#88162E">Mitchell Silberberg &amp; Knupp</span></b>
<b><span style="font-size:8.0pt;color:#88162E">LLP</span></b> <span style="font-size:10.0pt;color:black">
|</span> <span style="font-size:10.0pt;color:#84162E"><b><a moz-do-not-send="true" href="http://www.msk.com/"><span style="color:#84162E">www.msk.com</span></a></b></span></p>
<p class="MsoNormal"><span style="font-size:10.0pt;color:black">1818 N Street NW, 8th Floor, Washington, DC 20036</span></p>
<p class="MsoNormal"><span style="font-size:10.0pt;color:black">&nbsp;</span></p>
<p class="MsoNormal" style="text-autospace:none"><b><u><span style="font-size:8.0pt;color:gray">THE INFORMATION CONTAINED IN THIS E-MAIL MESSAGE IS INTENDED ONLY FOR THE PERSONAL AND CONFIDENTIAL USE OF THE DESIGNATED RECIPIENTS.</span></u></b>
<b><span style="font-size:8.0pt;color:gray">THIS MESSAGE MAY BE AN ATTORNEY-CLIENT COMMUNICATION, AND AS SUCH IS PRIVILEGED AND CONFIDENTIAL. IF THE READER OF THIS MESSAGE IS NOT AN INTENDED RECIPIENT, YOU ARE HEREBY NOTIFIED THAT ANY REVIEW, USE, DISSEMINATION,
 FORWARDING OR COPYING OF THIS MESSAGE IS STRICTLY PROHIBITED. PLEASE NOTIFY US IMMEDIATELY BY REPLY E-MAIL OR TELEPHONE, AND DELETE THE ORIGINAL MESSAGE AND ALL ATTACHMENTS FROM YOUR SYSTEM. THANK YOU.</span></b></p>
</div>
<p class="MsoNormal"><span style="color:#1F497D">&nbsp;</span></p>
<div>
<div style="border:none;border-top:solid #B5C4DF 1.0pt;padding:3.0pt 0in 0in 0in">
<p class="MsoNormal"><b><span style="font-size:10.0pt;font-family:&quot;Tahoma&quot;,&quot;sans-serif&quot;">From:</span></b>
<span style="font-size:10.0pt;font-family:&quot;Tahoma&quot;,&quot;sans-serif&quot;"><a class="moz-txt-link-abbreviated" href="mailto:gnso-impl-thickwhois-rt-bounces@icann.org">gnso-impl-thickwhois-rt-bounces@icann.org</a> [<a class="moz-txt-link-freetext" href="mailto:gnso-impl-thickwhois-rt-bounces@icann.org">mailto:gnso-impl-thickwhois-rt-bounces@icann.org</a>]
<b>On Behalf Of</b> Anderson, Marc<br>
<b>Sent:</b> Friday, August 26, 2016 3:21 PM<br>
<b>To:</b> <a class="moz-txt-link-abbreviated" href="mailto:gnso-impl-thickwhois-rt@icann.org">
gnso-impl-thickwhois-rt@icann.org</a><br>
<b>Subject:</b> [Gnso-impl-thickwhois-rt] Draft Thick Whois memo to the GNSO</span></p>
</div>
</div>
<p class="MsoNormal">&nbsp;</p>
<p class="MsoNormal">Dear Colleagues,</p>
<p class="MsoNormal">&nbsp;</p>
<p class="MsoNormal">During the IRT meetings held at ICANN 56 Helsinki, Joe Waldron raised concerns with the changing landscape of Privacy Laws, in particular with regard to the EU.&nbsp; He pointed out that recommendation #3 of the Thick Whois policy directs the
 IRT to notify the GNSO should privacy issues emerge that were not anticipated by the working group.&nbsp; The IRT agreed that we have an obligation to notify the GNSO and asked Verisign to draft a proposed memo from the IRT to the GNSO.</p>
<p class="MsoNormal">&nbsp;</p>
<p class="MsoNormal">Please find attached that draft memo outlining the obligation and the reasons why we think it is necessary to provide that notification at this time.</p>
<p class="MsoNormal">&nbsp;</p>
<p class="MsoNormal">Thank you,</p>
<p class="MsoNormal">Marc</p>
<p class="MsoNormal">&nbsp;</p>
<p class="MsoNormal">&nbsp;</p>
<table class="MsoNormalTable" style="width:278.25pt" border="0" cellpadding="0" cellspacing="0" width="371">
<tbody>
<tr>
<td colspan="2" style="padding:0in 0in 0in 0in">
<p class="MsoNormal"><img id="Picture_x0020_1" src="cid:part4.01F2A8B4.DD20F220@xs4all.nl" alt="Verisign" height="2" border="0" width="371"></p>
</td>
</tr>
<tr>
<td style="padding:11.25pt 0in 15.0pt 0in">
<p class="MsoNormal" style="line-height:10.5pt"><b><span style="font-size:9.0pt;font-family:&quot;Helvetica&quot;,&quot;sans-serif&quot;;color:#006AAA">Marc Anderson</span></b><span style="font-size:8.5pt;font-family:&quot;Helvetica&quot;,&quot;sans-serif&quot;;color:#6B6D71"><br>
<a moz-do-not-send="true" href="mailto:mcanderson@verisign.com">mcanderson@verisign.com</a><br>
<br>
m: 571.521.9943 t: 703.948.3404<br>
12061 Bluemont Way, Reston, VA 20190<br>
<br>
<a moz-do-not-send="true" href="http://www.verisigninc.com/"><span style="font-size:9.0pt;color:#006AAA">VerisignInc.com</span></a></span></p>
</td>
<td style="padding:11.25pt 0in 0in 0in" valign="top">
<p class="MsoNormal"><!--[if gte vml 1]><v:shapetype id="_x0000_t75" coordsize="21600,21600" o:spt="75" o:preferrelative="t" path="m@4@5l@4@11@9@11@9@5xe" filled="f" stroked="f">
<v:stroke joinstyle="miter" />
<v:formulas>
<v:f eqn="if lineDrawn pixelLineWidth 0" />
<v:f eqn="sum @0 1 0" />
<v:f eqn="sum 0 0 @1" />
<v:f eqn="prod @2 1 2" />
<v:f eqn="prod @3 21600 pixelWidth" />
<v:f eqn="prod @3 21600 pixelHeight" />
<v:f eqn="sum @0 0 1" />
<v:f eqn="prod @6 1 2" />
<v:f eqn="prod @7 21600 pixelWidth" />
<v:f eqn="sum @8 21600 0" />
<v:f eqn="prod @7 21600 pixelHeight" />
<v:f eqn="sum @10 21600 0" />
</v:formulas>
<v:path o:extrusionok="f" gradientshapeok="t" o:connecttype="rect" />
<o:lock v:ext="edit" aspectratio="t" />
</v:shapetype><v:shape id="Picture_x0020_2" o:spid="_x0000_s1026" type="#_x0000_t75" alt="Verisign&#8482;" style='position:absolute;margin-left:10.65pt;margin-top:0;width:54.75pt;height:48pt;z-index:251659264;visibility:visible;mso-wrap-style:square;mso-width-percent:0;mso-height-percent:0;mso-wrap-distance-left:0;mso-wrap-distance-top:0;mso-wrap-distance-right:0;mso-wrap-distance-bottom:0;mso-position-horizontal:right;mso-position-horizontal-relative:text;mso-position-vertical:absolute;mso-position-vertical-relative:line;mso-width-percent:0;mso-height-percent:0;mso-width-relative:page;mso-height-relative:page' o:allowoverlap="f">
<v:imagedata src="imap://gtheo@imap.xs4all.nl:143/fetch%3EUID%3E/INBOX%3E10515?header=quotebody&part=1.1.4&filename=image005.gif" o:title="Verisign&#8482;" />
<w:wrap type="square"/>
</v:shape><![endif]--><!--[if !vml]--><img src="cid:part7.2C7ECDF6.280CA372@xs4all.nl" alt="Verisign™" v:shapes="Picture_x0020_2" height="64" align="right" width="73"><!--[endif]--></p>
</td>
</tr>
</tbody>
</table>
<p class="MsoNormal">&nbsp;</p>
<p class="MsoNormal">&nbsp;</p>
</div>
<br>
<fieldset class="mimeAttachmentHeader"></fieldset> <br>
<pre wrap="">
_______________________________________________
Gnso-impl-thickwhois-rt mailing list
<a class="moz-txt-link-abbreviated" href="mailto:Gnso-impl-thickwhois-rt@icann.org">Gnso-impl-thickwhois-rt@icann.org</a>
<a href="https://mm.icann.org/mailman/listinfo/gnso-impl-thickwhois-rt" class="moz-txt-link-freetext">https://mm.icann.org/mailman/listinfo/gnso-impl-thickwhois-rt</a>
</pre>
</blockquote>
<br>
</body>
</html>