<html>
  <head>
    <meta http-equiv="Content-Type" content="text/html; charset=UTF-8">
  </head>
  <body text="#000000" bgcolor="#FFFFFF">
    <p><font size="+1"><font face="Lucida Grande">I agree with Sara
          wholeheartedly.  I would like to propose a workshop at the
          Barcelona meeting to discuss accreditation requirements for
          cybersecurity an IP actors who want to retain access to
          personal data in a tiered access solution.  Release of data in
          such a system will require standards, and I (as mentioned in
          Abu, on the public panel on GDPR, and in my own comments on
          the 3 models) I think we should get on with developing those
          standards, preferably ISO standards with possibility for
          independent audit.</font></font></p>
    <p><font size="+1"><font face="Lucida Grande">Stephanie Perrin</font></font><br>
    </p>
    <div class="moz-cite-prefix">On 2018-02-15 11:34, Sara Bockey wrote:<br>
    </div>
    <blockquote type="cite"
      cite="mid:AB42AE93-0F89-4045-853C-C52424256DC9@godaddy.com">
      <meta http-equiv="Content-Type" content="text/html; charset=UTF-8">
      <meta name="Generator" content="Microsoft Word 15 (filtered
        medium)">
      <style><!--
/* Font Definitions */
@font-face
        {font-family:"Cambria Math";
        panose-1:2 4 5 3 5 4 6 3 2 4;}
@font-face
        {font-family:Calibri;
        panose-1:2 15 5 2 2 2 4 3 2 4;}
@font-face
        {font-family:Consolas;
        panose-1:2 11 6 9 2 2 4 3 2 4;}
@font-face
        {font-family:"GD Boing";
        panose-1:2 0 6 3 3 0 0 2 0 4;}
@font-face
        {font-family:-webkit-standard;
        panose-1:2 11 6 4 2 2 2 2 2 4;}
/* Style Definitions */
p.MsoNormal, li.MsoNormal, div.MsoNormal
        {margin:0in;
        margin-bottom:.0001pt;
        font-size:11.0pt;
        font-family:"Calibri",sans-serif;}
a:link, span.MsoHyperlink
        {mso-style-priority:99;
        color:blue;
        text-decoration:underline;}
a:visited, span.MsoHyperlinkFollowed
        {mso-style-priority:99;
        color:purple;
        text-decoration:underline;}
pre
        {mso-style-priority:99;
        mso-style-link:"HTML Preformatted Char";
        margin:0in;
        margin-bottom:.0001pt;
        font-size:10.0pt;
        font-family:"Courier New";}
p.msonormal0, li.msonormal0, div.msonormal0
        {mso-style-name:msonormal;
        mso-margin-top-alt:auto;
        margin-right:0in;
        mso-margin-bottom-alt:auto;
        margin-left:0in;
        font-size:11.0pt;
        font-family:"Calibri",sans-serif;}
span.HTMLPreformattedChar
        {mso-style-name:"HTML Preformatted Char";
        mso-style-priority:99;
        mso-style-link:"HTML Preformatted";
        font-family:Consolas;}
span.EmailStyle21
        {mso-style-type:personal-reply;
        font-family:"Calibri",sans-serif;
        color:windowtext;}
.MsoChpDefault
        {mso-style-type:export-only;
        font-size:10.0pt;}
@page WordSection1
        {size:8.5in 11.0in;
        margin:1.0in 1.0in 1.0in 1.0in;}
div.WordSection1
        {page:WordSection1;}
--></style>
      <div class="WordSection1">
        <p class="MsoNormal"><span
style="font-size:13.5pt;font-family:"-webkit-standard",serif;color:black;background:white">Our
            job is now to cooperate in good faith to build a new
            universal system that still fits most needs but also takes
            data protection as its core principle.</span><o:p></o:p></p>
        <p class="MsoNormal"><o:p> </o:p></p>
        <p class="MsoNormal">EXACTLY! And what’s lacking from most of
          our conversations are SOLUTIONS.  We understand that many of
          you have come to rely on various types of data from WHOIS.  We
          get it.  We’ve heard you.  What we have NOT heard is “we
          understand the changing landscape, and while we are concerned
          about losing X data, perhaps if we do Y, we can improve RDS
          and still have access OR if we do Z, we can _________.” 
          <o:p></o:p></p>
        <p class="MsoNormal"><o:p> </o:p></p>
        <p class="MsoNormal">Given the number of really smart people on
          this list, I am frustrated by the lack of innovative, forward
          thinking.  Change doesn’t have to be scary.  Change can be
          better - an improvement.  We need to stop with the myopia.  We
          need to stop looking backward.  We need to stop demonizing. 
          If you are not saying something NEW, something to move this
          PDP
          <u>forward</u>, you are part of the problem.<o:p></o:p></p>
        <p class="MsoNormal"><o:p> </o:p></p>
        <p class="MsoNormal">Sara  <o:p></o:p></p>
        <p class="MsoNormal"><o:p> </o:p></p>
        <div>
          <p class="MsoNormal" style="margin-bottom:1.0pt"><b><span
                style="font-size:9.0pt;font-family:"GD
                Boing";color:#02C54C">sara bockey</span></b><span
              style="font-size:12.0pt;color:black"><o:p></o:p></span></p>
          <p class="MsoNormal" style="margin-bottom:1.0pt"><b><span
                style="font-size:9.0pt;font-family:"GD
                Boing";color:#111111">sr. policy manager | </span></b><b><span
                style="font-size:9.0pt;font-family:"GD
                Boing";color:#02C54C">Go</span></b><b><span
                style="font-size:9.0pt;font-family:"GD
                Boing";color:black">Daddy<sup>™</sup></span></b><span
              style="font-size:12.0pt;color:black"><o:p></o:p></span></p>
          <p class="MsoNormal" style="margin-bottom:1.0pt"><b><span
                style="font-size:9.0pt;font-family:"GD
                Boing";color:#111111"><a
                  href="mailto:sbockey@godaddy.com"
                  moz-do-not-send="true"><span style="color:#954F72">sbockey@godaddy.com</span></a> 
                480-366-3616</span></b><span
              style="font-size:12.0pt;color:black"><o:p></o:p></span></p>
          <p class="MsoNormal"><b><span
                style="font-size:9.0pt;font-family:"GD
                Boing";color:#111111">skype: sbockey</span></b><span
              style="font-size:12.0pt;color:black"><o:p></o:p></span></p>
          <p class="MsoNormal"><i><span
                style="font-size:10.0pt;color:black;background:white"><o:p> </o:p></span></i></p>
          <p class="MsoNormal"><i><span
                style="font-size:10.0pt;color:black;background:white">This
                email message and any attachments hereto is intended for
                use only by the addressee(s) named herein and may
                contain confidential information. If you have received
                this email in error, please immediately notify
                the sender and permanently delete the original and any
                copy of this message and its attachments.</span></i><span
              style="font-size:12.0pt;color:black"><o:p></o:p></span></p>
          <p class="MsoNormal"> <o:p></o:p></p>
        </div>
        <p class="MsoNormal"><o:p> </o:p></p>
        <div style="border:none;border-top:solid #B5C4DF
          1.0pt;padding:3.0pt 0in 0in 0in">
          <p class="MsoNormal"><b><span
                style="font-size:12.0pt;color:black">From: </span></b><span
              style="font-size:12.0pt;color:black">gnso-rds-pdp-wg
              <a class="moz-txt-link-rfc2396E" href="mailto:gnso-rds-pdp-wg-bounces@icann.org"><gnso-rds-pdp-wg-bounces@icann.org></a> on behalf of
              Volker Greimann <a class="moz-txt-link-rfc2396E" href="mailto:vgreimann@key-systems.net"><vgreimann@key-systems.net></a><br>
              <b>Date: </b>Thursday, February 15, 2018 at 4:30 AM<br>
              <b>To: </b>Greg Shatan <a class="moz-txt-link-rfc2396E" href="mailto:gregshatanipc@gmail.com"><gregshatanipc@gmail.com></a><br>
              <b>Cc: </b><a class="moz-txt-link-rfc2396E" href="mailto:gnso-rds-pdp-wg@icann.org">"gnso-rds-pdp-wg@icann.org"</a>
              <a class="moz-txt-link-rfc2396E" href="mailto:gnso-rds-pdp-wg@icann.org"><gnso-rds-pdp-wg@icann.org></a><br>
              <b>Subject: </b>Re: [gnso-rds-pdp-wg] Equifax hack worse
              than previously thought: Biz kissed goodbye to card expiry
              dates, tax IDs etc<o:p></o:p></span></p>
        </div>
        <div>
          <p class="MsoNormal"><o:p> </o:p></p>
        </div>
        <p><a name="_MailOriginalBody" moz-do-not-send="true">That would
            be problematic, as you should know, since there is no clear
            cut line of what would constitute over-enforcement or
            under-enforcement. Well, the latter will resolve itself due
            to the incoming DPA actions. <o:p></o:p></a></p>
        <p><span style="mso-bookmark:_MailOriginalBody">I also never
            heard of fees to be paid into a fund by those simply trying
            to remain compliant with their applicable laws.
            <o:p></o:p></span></p>
        <p><span style="mso-bookmark:_MailOriginalBody">Contracted
            parties have been stating for years, if not over a decade
            that publication whois details in the current form and shape
            is problematic from a data protection perspective. We have
            repeatedly tried to drive home the point that the current
            system is not sustainable. We were ignored or ridiculed, or
            asked to get sued to prove our point. Now that we are forced
            to take action, everybody is protesting as if this were
            something new. It is not. Now we have to do a short-term
            fix, that will hurt more than it would have needed to if
            everyone had cooperated in good faith to reform whois years
            ago. The status quo will change.<o:p></o:p></span></p>
        <p><span style="mso-bookmark:_MailOriginalBody">Our job is now
            to cooperate in good faith to build a new universal system
            that still fits most needs but also takes data protection as
            its core principle.<o:p></o:p></span></p>
        <p><span style="mso-bookmark:_MailOriginalBody">Volker out!<o:p></o:p></span></p>
        <p><span style="mso-bookmark:_MailOriginalBody"><o:p> </o:p></span></p>
        <p class="MsoNormal"><span
            style="mso-bookmark:_MailOriginalBody"><o:p> </o:p></span></p>
        <div>
          <p class="MsoNormal"><span
              style="mso-bookmark:_MailOriginalBody">Am 15.02.2018 um
              05:14 schrieb Greg Shatan:<o:p></o:p></span></p>
        </div>
        <blockquote style="margin-top:5.0pt;margin-bottom:5.0pt">
          <div>
            <div>
              <p class="MsoNormal"><span
                  style="mso-bookmark:_MailOriginalBody">In a similar
                  vein, ICANN could establish an “Over-enforce the GDPR
                  Fund,” in which everyone who thinks the GDPR’s data
                  blackout should be extended to the data of non-EU and
                  legal persons would pay in, and it would be used to
                  defray the expenses incurred by those who should have
                  access to information and instead must expend
                  additional time, money and effort, and often incur
                  additional harm, due GDPR over-enforcement.<o:p></o:p></span></p>
            </div>
            <p class="MsoNormal"><span
                style="mso-bookmark:_MailOriginalBody"><o:p> </o:p></span></p>
            <div>
              <div>
                <p class="MsoNormal"><span
                    style="mso-bookmark:_MailOriginalBody">On Wed, Feb
                    14, 2018 at 5:03 AM Volker Greimann <</span><a
                    href="mailto:vgreimann@key-systems.net"
                    moz-do-not-send="true"><span
                      style="mso-bookmark:_MailOriginalBody">vgreimann@key-systems.net</span><span
                      style="mso-bookmark:_MailOriginalBody"></span></a><span
                    style="mso-bookmark:_MailOriginalBody">> wrote:<o:p></o:p></span></p>
              </div>
              <blockquote style="border:none;border-left:solid #CCCCCC
                1.0pt;padding:0in 0in 0in
                6.0pt;margin-left:4.8pt;margin-right:0in">
                <div>
                  <p><span style="mso-bookmark:_MailOriginalBody">Maybe
                      you are hitting on something here.
                      <o:p></o:p></span></p>
                  <p><span style="mso-bookmark:_MailOriginalBody">ICANN
                      could just establish a "Leave-Whois-as-it-is"
                      legal defense fund. Everyone who argues that whois
                      should remain as it is has to pay into that fund
                      and everyone who is fined by data protection
                      violations can take the fines and their legal
                      costs out of that fund. Of course, that would
                      necessitate huge investments to set up the fund
                      from mainly volunteer organizations that do not
                      actually have the means to support it.<o:p></o:p></span></p>
                  <p><span style="mso-bookmark:_MailOriginalBody">Best,<o:p></o:p></span></p>
                  <p><span style="mso-bookmark:_MailOriginalBody">Volker<o:p></o:p></span></p>
                </div>
                <div>
                  <p class="MsoNormal"><span
                      style="mso-bookmark:_MailOriginalBody"><o:p> </o:p></span></p>
                  <div>
                    <p class="MsoNormal"><span
                        style="mso-bookmark:_MailOriginalBody">Am
                        14.02.2018 um 02:21 schrieb Rubens Kuhl:<o:p></o:p></span></p>
                  </div>
                  <blockquote
                    style="margin-top:5.0pt;margin-bottom:5.0pt">
                    <p class="MsoNormal"><span
                        style="mso-bookmark:_MailOriginalBody"><o:p> </o:p></span></p>
                    <div>
                      <p class="MsoNormal"><span
                          style="mso-bookmark:_MailOriginalBody"><br>
                          <br>
                          <o:p></o:p></span></p>
                      <blockquote
                        style="margin-top:5.0pt;margin-bottom:5.0pt">
                        <div>
                          <p class="MsoNormal"><span
                              style="mso-bookmark:_MailOriginalBody">On
                              13 Feb 2018, at 20:32, John Horton <</span><a
                              href="mailto:john.horton@legitscript.com"
                              target="_blank" moz-do-not-send="true"><span
                                style="mso-bookmark:_MailOriginalBody">john.horton@legitscript.com</span><span
                                style="mso-bookmark:_MailOriginalBody"></span></a><span
                              style="mso-bookmark:_MailOriginalBody">>
                              wrote:<o:p></o:p></span></p>
                        </div>
                        <p class="MsoNormal"><span
                            style="mso-bookmark:_MailOriginalBody"><o:p> </o:p></span></p>
                        <div>
                          <div>
                            <div>
                              <p class="MsoNormal"><span
                                  style="mso-bookmark:_MailOriginalBody"><span
style="font-family:"Arial",sans-serif;color:#444444">Thanks,
                                    Rubens -- I don't agree with that
                                    interpretation. (I think you mean
                                    the Q&A memo Section 2, right?)
                                    See memo
                                  </span></span><a
href="https://www.icann.org/en/system/files/files/gdpr-memorandum-part2-18dec17-en.pdf"
                                  target="_blank" moz-do-not-send="true"><span
style="mso-bookmark:_MailOriginalBody"><span
                                      style="font-family:"Arial",sans-serif">here</span></span><span
style="mso-bookmark:_MailOriginalBody"></span></a><span
                                  style="mso-bookmark:_MailOriginalBody"><span
style="font-family:"Arial",sans-serif;color:#444444">. Let me
                                    know if you meant the first or a
                                    different one. <o:p></o:p></span></span></p>
                            </div>
                          </div>
                        </div>
                      </blockquote>
                    </div>
                    <p class="MsoNormal"><span
                        style="mso-bookmark:_MailOriginalBody"><o:p> </o:p></span></p>
                    <div>
                      <p class="MsoNormal"><span
                          style="mso-bookmark:_MailOriginalBody"><o:p> </o:p></span></p>
                    </div>
                    <div>
                      <p class="MsoNormal"><span
                          style="mso-bookmark:_MailOriginalBody">It's
                          exactly that memo. <o:p></o:p></span></p>
                    </div>
                    <div>
                      <p class="MsoNormal"><span
                          style="mso-bookmark:_MailOriginalBody">Since
                          you don't agree, does that mean that your
                          organisation is willing to pay every GDPR fine
                          contracted parties get from following your
                          interpretation ? Because if you are unwilling
                          to do that, then your belief in that
                          interpretation is not rock solid.<o:p></o:p></span></p>
                    </div>
                    <div>
                      <p class="MsoNormal"><span
                          style="mso-bookmark:_MailOriginalBody"><o:p> </o:p></span></p>
                    </div>
                    <div>
                      <p class="MsoNormal"><span
                          style="mso-bookmark:_MailOriginalBody">What I
                          can tell you is that this risk has been
                          flagged by that paper, by the eco model and by
                          internal analysis of some registries, all
                          independently of each other; which means you
                          will likely see a good number of contracted
                          parties following exactly the path I outlined
                          in order to mitigate this risk. <o:p></o:p></span></p>
                    </div>
                    <div>
                      <p class="MsoNormal"><span
                          style="mso-bookmark:_MailOriginalBody"><o:p> </o:p></span></p>
                    </div>
                    <div>
                      <p class="MsoNormal"><span
                          style="mso-bookmark:_MailOriginalBody">If you
                          see things differently, get Europeans DPAs to
                          put that in writing, and we are all good to
                          go. <o:p></o:p></span></p>
                    </div>
                    <div>
                      <p class="MsoNormal"><span
                          style="mso-bookmark:_MailOriginalBody"><o:p> </o:p></span></p>
                    </div>
                    <div>
                      <p class="MsoNormal"><span
                          style="mso-bookmark:_MailOriginalBody"><o:p> </o:p></span></p>
                    </div>
                    <div>
                      <p class="MsoNormal"><span
                          style="mso-bookmark:_MailOriginalBody"><o:p> </o:p></span></p>
                    </div>
                    <div>
                      <p class="MsoNormal"><span
                          style="mso-bookmark:_MailOriginalBody">Rubens<o:p></o:p></span></p>
                    </div>
                    <div>
                      <p class="MsoNormal"><span
                          style="mso-bookmark:_MailOriginalBody"><o:p> </o:p></span></p>
                    </div>
                    <div>
                      <p class="MsoNormal"><span
                          style="mso-bookmark:_MailOriginalBody"><o:p> </o:p></span></p>
                    </div>
                    <div>
                      <p class="MsoNormal"><span
                          style="mso-bookmark:_MailOriginalBody"><o:p> </o:p></span></p>
                    </div>
                    <p class="MsoNormal"><span
                        style="mso-bookmark:_MailOriginalBody"><br>
                        <br>
                        <o:p></o:p></span></p>
                    <pre><span style="mso-bookmark:_MailOriginalBody">_______________________________________________<o:p></o:p></span></pre>
                    <pre><span style="mso-bookmark:_MailOriginalBody">gnso-rds-pdp-wg mailing list<o:p></o:p></span></pre>
                    <pre><span style="mso-bookmark:_MailOriginalBody"></span><a href="mailto:gnso-rds-pdp-wg@icann.org" target="_blank" moz-do-not-send="true"><span style="mso-bookmark:_MailOriginalBody">gnso-rds-pdp-wg@icann.org</span><span style="mso-bookmark:_MailOriginalBody"></span></a><span style="mso-bookmark:_MailOriginalBody"><o:p></o:p></span></pre>
                    <pre><span style="mso-bookmark:_MailOriginalBody"></span><a href="https://mm.icann.org/mailman/listinfo/gnso-rds-pdp-wg" target="_blank" moz-do-not-send="true"><span style="mso-bookmark:_MailOriginalBody">https://mm.icann.org/mailman/listinfo/gnso-rds-pdp-wg</span><span style="mso-bookmark:_MailOriginalBody"></span></a><span style="mso-bookmark:_MailOriginalBody"><o:p></o:p></span></pre>
                  </blockquote>
                  <p class="MsoNormal"><span
                      style="mso-bookmark:_MailOriginalBody"><o:p> </o:p></span></p>
                </div>
                <p class="MsoNormal"><span
                    style="mso-bookmark:_MailOriginalBody">_______________________________________________<br>
                    gnso-rds-pdp-wg mailing list<br>
                  </span><a href="mailto:gnso-rds-pdp-wg@icann.org"
                    target="_blank" moz-do-not-send="true"><span
                      style="mso-bookmark:_MailOriginalBody">gnso-rds-pdp-wg@icann.org</span><span
                      style="mso-bookmark:_MailOriginalBody"></span></a><span
                    style="mso-bookmark:_MailOriginalBody"><br>
                  </span><a
                    href="https://mm.icann.org/mailman/listinfo/gnso-rds-pdp-wg"
                    target="_blank" moz-do-not-send="true"><span
                      style="mso-bookmark:_MailOriginalBody">https://mm.icann.org/mailman/listinfo/gnso-rds-pdp-wg</span><span
                      style="mso-bookmark:_MailOriginalBody"></span></a><span
                    style="mso-bookmark:_MailOriginalBody"><o:p></o:p></span></p>
              </blockquote>
            </div>
          </div>
        </blockquote>
        <p class="MsoNormal"><span
            style="mso-bookmark:_MailOriginalBody"><br>
            <br>
          </span><o:p></o:p></p>
      </div>
      <br>
      <fieldset class="mimeAttachmentHeader"></fieldset>
      <pre class="moz-quote-pre" wrap="">_______________________________________________
gnso-rds-pdp-wg mailing list
<a class="moz-txt-link-abbreviated" href="mailto:gnso-rds-pdp-wg@icann.org">gnso-rds-pdp-wg@icann.org</a>
<a class="moz-txt-link-freetext" href="https://mm.icann.org/mailman/listinfo/gnso-rds-pdp-wg">https://mm.icann.org/mailman/listinfo/gnso-rds-pdp-wg</a></pre>
    </blockquote>
  </body>
</html>