Or when I returned from Copenhagen ICANN 58, you shall have a purpose.
I have been struggling with the upcoming EU GDPR for a year now. Read the GDPR, read a few books and it just didn’t sink in, let alone I could figure out how to attack this thing on ICANN level or at the Registrar I work for.
For more than a year the RDS WG, the group that is working on a replacement for the WHOIS, has been collecting requirements on what is required for this RDS. The number of requirements we gathered is insane, over 1000 requirements.
We heard from about every stakeholder what they need, and in every discussion, privacy would come up, and how that should work, usually such discussion would look more like a trench war, as most folks think privacy does not equal the abuse problems we are facing.
But ICANN 58 a group of EU Data Commissioners assisted us, including the U.N. Special Rapporteur on the right to privacy and Caroline Goemans-Dorny INTERPOL’s data protection officer.
During the RDS session on Wednesday, something happened that provided me with total clarity. We were running out of time, and we did not really get into the question session we prepared. At one point the Chair of the RDS WG fired off like four questions at once, related to a thin WHOIS output that was shown on the slides.
The U.N. Special Rapporteur said:”I will answer all your questions, with one question,” what is the purpose?
This almost Yoda-like response gave me a real sense of clarity.
Why do we put an expiry date in the WHOIS?
Why do put a create date in the WHOIS?
Why do we put an update date in the WHOIS?
My cell phone subscription is not being published in a public directory, nor is it mentioned when I upgraded my cell phone subscription in a public directory. At that point, it was clear to me that this was not about thin or thick WHOIS, we put the cart before the horse.
I expressed my gratitude in public to the U.N. Special Rapporteur.
After the session I was having a smoke and saw the U.N. Special Rapporteur leave the building real quick, rushing to a taxi (busy person) and just when he hailed a taxi he spotted me, walked up to me, shook my hand and said:”Thank you for the support, and I have the feeling you now have a clear vision on what purpose is”.
I have it for sure, and the entire EU GDPR makes sense now. The EU GDPR is Europe setting a very high ambition trying to create logic in how you process or collect data. The EU GDPR text itself does not provide clear answers; it just shows ambition.
All your current processes need to be re-evaluated, and you have to ask what the purpose is? If you have a clear purpose and you can motivate it, then most likely you are on the right track. The EU GDPR can provide more guidance.
If however you encounter a situation and you ask what the purpose is, and the answer is dodgy, shady or not clear, or the answer is, it is nice to have, then you are most likely on the wrong track.
How does this guide me when it comes to the RDS and the WHOIS?
Simple, the WHOIS is a “nice to have,” that completely spiraled out of control and has no place in this day and age.
RDS? Even though we are still in its early stages, it seems we are working on a compromise to keep everyone happy. Keeping everyone happy and yet complying with the law, is not possible, so the current purpose of RDS will turn into a failure.
Later this week I will go more into detail why RDS will never work and what is required and how we should combat abuse, though I did not figure out the abuse part, yet.
Theo Geurts ICANN RDS WG member.
This blog post was created while listening to: