9 ms·
German court issues first GDPR ruling
- mikekchar 8y agoInteresting that the first case deals with an injunction to comply an EU company to collect information -- not to punish a company from collecting information. I'm actually very surprised that ICANN even tried to do this as it looks like a slam dunk defence. I'll be interested to see the result of the appeal.
- ocdtrekkie 8y agoWhat this article may miss, is that ICANN's lawsuit isn't exactly hostile: https://www.icann.org/news/announcement-2018-05-25-en https://www.icann.org/news/announcement-2018-05-25-en and https://www.epag.de/en/tucows-statement-on-icann-legal-action/ https://www.epag.de/en/tucows-statement-on-icann-legal-actio... The lawsuit was filed in order to get an official legal answer on the books as to how Whois data should be handled for GDPR. The easiest way to get actual precedent on the matter is to sue someone over it.
- hn_throwaway_99 8y agoI don't think I came to the same conclusion you did after reading those 2 articles. While you say the lawsuit "isn't exactly hostile", I think it isn't exactly "friendly" either, and it's not like ICANN is neutral and just looking to the courts for guidance. I don't think ICANN is pleased with this ruling, at all. ICANN clearly wants to preserve the requirement around personal details in Whois data, while Tucows pretty much thinks that requirement goes against the spirit of GDPR. From your second link: > ICANN’s goal, since discussions about the impact of the GDPR on domain registration began, has been to preserve as much of the status quo as possible. This has led ICANN to attempt to achieve GDPR-compliant domain registration via ‘process reduction’, as opposed to Tucows’ approach of starting with the GDPR and rebuilding from the ground up.
- JumpCrisscross 8y ago> ICANN clearly wants to preserve the requirement around personal details in Whois data They may just not want to get sued by the MPAA et al over facilitating copyright infringement. Without WHOIS, pursuing rogue domains gets harder.
- guitarbill 8y agoWe're not talking about no WHOIS, we're talking about reducing the number of WHOIS contacts, and not publishing WHOIS information for everybody to see it. Which yes, would means now you need e.g. a court order first before you'd get that information. So I guess "pursuing rogue domains gets harder" is one way to put it, or more legally correct another. For law enforcement this isn't a problem. For scummy copyright lawyers looking to make a quick buck, maybe it is. Guess which of those funds ICANN? And how exactly would not making WHOIS info public "facilitat[e] copyright infringement"? Nobody is buying it.
- mirimir 8y agoYes. Also: > Tucows will continue to ensure that those with legitimate purposes, including law enforcement, intellectual property, and commercial litigation interests will have access to domain registrant information. On a daily basis, we see plenty of important circumstances wherein we find sharing that information to be legally necessary, and this will not change. We collect a contact for the owner of each domain name sold on our platforms, and have the ability to contact the owner. When necessary, we also share that contact with law enforcement and others with a legitimate interest. So there's no loss of data access for those with legal right to it. It's just that there's no free public access.
- lagadu 8y ago> The easiest way to get actual precedent on the matter is to sue someone over it. Precedent is of little relevance in countries that use civil law (as opposed to common law like the US does) so establishing it sounds somewhat futile.
- davidgould 8y agoThe Register had an item about this recently [0]. If you read the whole thing and follow the links to the earlier articles it's somewhere in the uncanny valley between fascinating and horrifying. ICANN is a deeply conflicted organization. Basically they have been on notice about this since 2003 and have done nothing. As of now, they don't have a plan to resolve this. ICANN and any registrar with EU customers providing the whois service are non-compliant with the GDPR. So the EU based registrars have stopped and ICANN is sueing to force them to continue. eta: One of the big reasons ICANN can't do the sensible thing and just discontinue whois is that it is heavily influenced by the big copyright corporations who presently can start enforcement against a domain by lookup in whois. Once whois is gone they will have to use legal process to compel registrars to reveal the identity of domain owners. [0] https://www.theregister.co.uk/2018/07/06/europe_no_to_icann_whois/ https://www.theregister.co.uk/2018/07/06/europe_no_to_icann_...
- guitarbill 8y agoIt does seem like ICANN are delusional idiots. Even their own Non-Commercial Stakeholders Group disowned them when they asked for a moratorium on GDPR: [0] > We do not believe a moratorium on enforcement of the law should be granted to ICANN. [0] https://www.icann.org/en/system/files/files/gdpr-comments-ncsg-article-29-wp-whois-23apr18-en.pdf https://www.icann.org/en/system/files/files/gdpr-comments-nc...
- davidgould 8y ago> It does seem like ICANN are delusional idiots. Oh yes. I followed the link I gave and read all the linked articles and some of their links and some of the comments on it all. It's quite extraordinary and hilarious.
- maze-le 8y ago>> Once whois is gone they will have to use legal process to compel registrars to reveal the identity of domain owners. Well, sounds like the way it is supposed to work... Besides, the ones they are trying to get with it have TLDs without whois requirement, are at cloudflare or use onion services alltogether.
- kilburn 8y agoRelated, with some insights (3 months ago): https://news.ycombinator.com/item?id=16856090 https://news.ycombinator.com/item?id=16856090
- Joky 8y agoI'm curious (and ignorant): how can Europe fine an organization like ICANN? I can imagine that they can forbid them to do any business in Europe if they don't pay their fine, anything else? If it come to this, what does it mean for registrar in Europe?
- dsymonds 8y agoThey likely can't, but they can fine EPAG, which is a German domain registrar. The matter at hand is that ICANN was trying to allegedly force EPAG to violate GDPR.
- samdoidge 8y agoIt's arrogance; see the Brexit negotiations for more examples of this.
- oblio 8y agoDo you have any examples?
- samdoidge 8y ago[1] https://www.scmp.com/news/world/europe/article/2109958/brexit-was-stupid-decision-it-would-be-arrogant-intervene-eu https://www.scmp.com/news/world/europe/article/2109958/brexi... [2] There has been little if any compromise in the negotiations from the EU side, and much from the UK.
- belorn 8y agoSince the core issue is about registered domains for natural persons it becomes a bit unclear what administrative and technical contact would mean in the context of this lawsuit. Most registries that I have to work with do not use those fields or have hijacked those for their own local purpose (such as local presence). ICANN however only accredit registrars for a few of the generic TLDs so there doesn't seem to be any meaningful reason to have administrative and technical contact for natural persons. Those that do fill in those fields anyway usually just copy the data from the registrant fields, or put the registrar data in as administrative and/or technical contact. Neither adds anything meaningful to whois. When the registrant is a company it make sense to have admin and technical contact but then good practice for the last decade is to not have natural persons in those fields. If John Doe leaves the company then its a major pain to change contact information for 100+ domains, so from a pure practical reason it is better to have a company, role and the company address in the fields (except when local policy for each of the country code top-level domain demand something else). That information is naturally not protected by GDPR.
- ape4 8y agoLike most Hacker News users, I have a bunch of domains. I'd be happy if my personal info wasn't in whois.
- majewsky 8y agoAs a German who owns domains, I don't really know if who is changes anything. The German Telecommunications Media Act (Telemediengesetz) requires website operators to publish an imprint including snail-mail contact info. I'm not gonna link it here to not push it up in SERPs, but my blog is linked in my profile and the imprint is linked there.
- Tomte 8y agoThere is a need for a proxy service, and indeed, they do exist. Just not usable for most people. Such a service enters a contract with the domain owner to forward (or scan and mail, or shred, or whatever) everything (or only non-spam) that is sent there. The law is happy, because that is your address now, and failure to forward is something between you and the service you used; you bear all responsibility wrt the sender. The author of a popular novel writing application offers that for his customers, as many write under a pen name and don‘t want their name to be publically known. Other than that... nothing. You could employ a lawyer, but that would be expensive. You could get one of those „hire a post box“ services, but again, too expensive if not really used for business. Some registrars offer that, but not for .de domains.
- 394549 8y ago> You could get one of those „hire a post box“ services, but again, too expensive if not really used for business. They're not too expensive, at least in the US. I an extra-small size PO box, and it costs the equivalent of $7 a month if rented yearly. Besides domain registrations, I've also used it as my mail forwarding address when moving, to help shake off junk-mail senders.
- raverbashing 8y agoCommercial website operators, no? One thing that "would be funny" would be having the contact information show up only for IPs from Germany
- bkor 8y agoFor .nl, the whois information for individuals is hidden except for a) interested parties (manually approved) b) investigative/enforcement authorities c) CAs (need to validate ownership). It's all explained in English at https://www.sidn.nl/a/nl-domain-name/sidn-and-privacy?language_id=2 https://www.sidn.nl/a/nl-domain-name/sidn-and-privacy?langua... The organization handling .nl, SIDN, has worked like this for a pretty long time. It's pretty much a solved problem. The data is available, just not to a lot of people.
- phobosdeimos 8y agoPoor internet. Designed to survive atomic wars. But can it withstand lawyers?
- alexmorse 8y agoThis seems like the worst first take possible for a policy that otherwise seems to have good intentions. Basically this is pedantry around something that completely does not matter. Every major registrar already provides mechanisms for hiding this info from the general public should you choose to do so. Seems like lawyering for lawyering's sake. When can we get rid of that?
- zamadatix 8y agoOTOH maybe you shouldn't have to pay extra to keep your privacy?
- vertex-four 8y agoThe point of GDPR is to implement privacy by default, not privacy for those who know how to pick the right companies and the right options. ICANN have been trying to get an exemption for this, unsuccessfully, for a while. Hence this lawsuit.
- oblio 8y agoTalk to ICANN. It wanted to cut out registrars trying to comply with the law.
- philipodonnell 8y ago> Every major registrar already provides mechanisms for hiding this info from the general public should you choose to do so. I think you missed a "by charging a fee to not do something they have no reason to otherwise do except to force you to pay a fee" in there. Seems like charging fees for charging fees sake, when can we get rid of that?
- roderickm 8y agoAs much as I appreciate the privacy-first aims of the GDPR, I think that at some point it collides head-on with property records. Privacy and property rights are interconnected: after all, what is privacy but the right to do with yourself and your property as you see fit without outside observation/interference? These rights are sometimes at odds with each other: can you really own property if your ownership is not publicly recorded/recognized?
- brainwad 8y agoThe judgement seems to rest on whether collecting data is necessary for the business. But what place is the judge in to decide that? Isn't the fact that ICANN demands the data from registrars good proof that it is necessary to EPAG's business?
- sobani 8y agoThen go one level deeper: why is this data necessary for ICANN? If you there is no good reason, then there's also no good reason for EPAG to collect this information.