Interesų grupė
Šaltinis: Europos Komisijos skelbiami susitikimai, sutapatinti pagal skaidrumo registro numerį. n = 8 susitikimų; x — metai pagal susitikimo datą, y — susitikimų skaičius.
| Data | Priėmė | Tema |
|---|---|---|
| 2021-12-09 | Cabinet of Executive Vice-President Margrethe Vestager | Presentation of the organisation, TTC |
| 2021-12-02 | Cabinet of President Ursula von der Leyen | Maintaining a secure, stable, and interoperable global Internet |
| 2021-12-01 | Cabinet of Commissioner Mariya Gabriel | Domain name system (DNS) |
| 2019-04-09 | Communications Networks, Content and Technology | Cybersecurity certification scheme for DNS/WHOIS |
| 2019-02-26 | Communications Networks, Content and Technology | ICANN WHOIS policy reform & WRC-19 |
| 2019-02-26 | Communications Networks, Content and Technology | ICANN WHOIS policy reform & WRC-19 |
| 2018-05-18 | Migration and Home Affairs | Ongoing dialogues between ICANN and Art.29WP |
| 2016-01-20 | Inspire, Debate, Engage and Accelerate Action | Internet Governance |
ICANN org comments on the two-year review exercise of the GDPR April 2020 The Internet Corporation for Assigned Names and Numbers (ICANN) is a not-for-profit public-benefit corporation that, on behalf of the Internet community, oversees the technical coordination of the top-most level of the Internet’s Domain Name System (DNS), and especially its security, stability, and resiliency. ICANN brings together governments, non- commercial and commercial stakeholder groups, civil society, and individuals. Each group represents a different interest on the Internet. Collectively, they make up the ICANN community, which develops policies for the DNS through a consensus-driven bottom-up process. The requirements of the EU General Data Protection Regulation (GDPR) have had a significant impact on the personal data processing activities of the whole Internet community.
(GDPR) have had a significant impact on the personal data processing activities of the whole Internet community. This includes the processing and availability of registration data in relation to the administration of generic top-level domains (gTLDs). Access to domain name registration data, commonly known as WHOIS data, serves the public interest and contributes to the security and stability of the Internet by providing contact information to support efforts related to consumer protection, cybercrime investigation, DNS abuse mitigation, intellectual property protection, and to address appropriate law enforcement needs. Registration data also enable network administrators and others to identify and correct system problems and to maintain Internet stability.
…enable network administrators and others to identify and correct system problems and to maintain Internet stability. ICANN’s role in providing the technical coordination of the globally distributed WHOIS system is a unique matter, considering the public interest nature of WHOIS, and responsibilities relating to the WHOIS system are encapsulated in ICANN’s Bylaws. Following the adoption of the GDPR, ICANN’s obligations on contracted registries and registrars for robust collection of registration data were maintained. However, instead of registries and registrars publishing that data as they did pre-GDPR, access to registration data that may include personal data is restricted. Now, access to this data is granted at the discretion of the contracted registries and registrars.
…data is restricted. Now, access to this data is granted at the discretion of the contracted registries and registrars. This has fragmented a system that many rely upon for reasons as varied as law enforcement investigations, intellectual property, and security incident response, among others as mentioned above. The ICANN community and the ICANN organization (org) are working to develop and implement a model that will enable access to non-public registration data for legitimate Ref.
…working to develop and implement a model that will enable access to non-public registration data for legitimate Ref. Ares(2020)2298583 - 29/04/2020 | 2 purposes as prompted by the European Data Protection Board,1 the EU Member States,2 and the European Commission.3 Developing and implementing a global system to balance the law’s data protection requirements with the legitimate interests of parties seeking access to non- public gTLD registration data, including the important public interest goals that legitimate access to non-public registration data serves for all parties involved, presents a number of challenges. ICANN org therefore welcomes the opportunity to provide feedback in the course of the European Commission’s GDPR evaluation initiative.
…welcomes the opportunity to provide feedback in the course of the European Commission’s GDPR evaluation initiative. While there are other GDPR provisions of concern for ICANN, we focus this submission on (1) international transfers of personal data to non-EU countries and (2) the cooperation mechanism between national data protection authorities, as the main topics of this review. Both availability of effective transfer mechanisms and efficient and consistent decision-making by supervisory authorities in matters of general application are particularly important when it comes to global operations such as the coordination of the Internet’s unique identifiers that ICANN performs. We additionally raise the topic of joint controllership, as currently great uncertainty exists as to the scope of joint controllership and the content of arrangements required between joint controllers.
…exists as to the scope of joint controllership and the content of arrangements required between joint controllers. This is a matter that significantly affects the development and implementation of a WHOIS system, which includes multiple actors across the world, which can meaningfully meet the public interest functionality the system is expected to serve at a global scale. 1. Applicability of Chapter V of the GDPR to non-EEA controllers or processors Art. 3 GDPR identifies the conditions under which the GDPR applies to the processing of personal data by controllers or processors established outside of the European Economic Area (EEA). What remains unclear, however, is whether data transfers to such controllers or processors are subject to the provisions of Chapter V of the GDPR.
…is whether data transfers to such controllers or processors are subject to the provisions of Chapter V of the GDPR. We understand that the European Data Protection Board (EDPB) is well aware of this issue, as it has stated in the Guidelines 3/2018 on the territorial scope of the GDPR (Article 3) (Version 2.0) that it will “further assess the interplay between the application of the territorial scope of the GDPR as per Article 3 and the provisions on international data transfers as per Chapter V” and may issue further guidance in this regard. However, a clarification in the GDPR itself that the provisions of Chapter V do not apply with respect to transfers to controllers or processors outside of the EEA which are directly subject to GDPR provisions pursuant to Art. 3 GDPR would be helpful.
…processors outside of the EEA which are directly subject to GDPR provisions pursuant to Art. 3 GDPR would be helpful. It 1 See https://edpb.europa.eu/news/news/2018/european-data-protection-board-endorsed-statement-wp29- icannwhois_en. 2 See http://data.consilium.europa.eu/doc/document/ST-13443-2018-INIT/en/pdf. 3 See https://www.icann.org/en/system/files/correspondence/odonohue-to-marby-03may19-en.pdf. | 3 seems superfluous and to a certain extent even contradictory to additionally implement transfer safeguards with such controllers or processors.
…a certain extent even contradictory to additionally implement transfer safeguards with such controllers or processors. 2. Updates required to EU Standard Contractual Clauses The GDPR introduced additional transfer mechanisms such as transferring under an approved code of conduct or an approved certification mechanism. While these mechanisms theoretically offer greater flexibility, they have not yet gained practical relevance. Thus, in many cases EU Standard Contractual Clauses remain the preferred or sometimes exclusively available data transfer mechanism. To provide organizations transferring data internationally with greater certainty when using EU Standard Contractual Clauses, the Clauses should be updated to reflect the requirements of the GDPR, including the requirements of Art. 28 GDPR in the EU Standard Contractual Clauses (Processors) (2010/87/EU). Furthermore, developing a set…
…case a decision of the ECJ adversely impacts the validity of the updated EU Standard Contractual Clauses.
…developed in case a decision of the ECJ adversely impacts the validity of the updated EU Standard Contractual Clauses. 3. Lead supervisory authority The possibility of having a lead supervisory authority (i.e., the introduction of the “one- stop shop mechanism” in the GDPR) is a substantial development for organizations carrying out cross-border processing. The one-stop shop mechanism needs to be correctly applied taking into account the requirements of Art. 56 (1) GDPR, which stipulates that “the supervisory authority of the main establishment or of the single establishment of the controller or processor shall be competent to act as lead supervisory authority for the cross-border processing carried out by that controller or processor …”.
28 → 12