Page History
...
Tip | ||
---|---|---|
| ||
Apologies: none Alternates: none |
Note |
---|
Notes/ Action Items Action Items
Notes These high-level notes are designed to help the EPDP Team navigate through the content of the call and are not meant as a substitute for the transcript and/or recording.
2. Continued Substantive Review of Priority 1 (SSAD) Legal Questions Submitted to Date a) Substantive review of SSAD questions (beginning where LC left off during last LC meeting) Updated Question 11
Action item: Brian, Margie, Thomas, and Volker to work together on reformulating the question based on today’s discussion. In redrafting the question, small group to consider the previous Bird & Bird advice re: safeguards. Updated Question 12 and 13 Notes:
3. Questions previously put on hold pending further legal advice and/or EPDP Team discussion
a) Additional topics noted in plenary sessions, where an EPDP Member requested the topic be considered by the Legal Committee
Status: Thomas, Volker, Brian and Margie to consider these items in their review of Q11.
Notes:
Assume that registrars notify their registrants up-front of the purposes of data collection, under what circumstances the data may be released, the right to object, etc. a. When a data controller receives a legitimate third-party data request, under what circumstances is the controller required under GDPR to explicitly notify the data subject that a request has occurred, and/or that it has provided data to a third party? b. Under what circumstances do data subjects have the right to object under GDPR to the release of their data to third parties? Per Bird & Bird's Question 3 memo, ICANN's use cases do not involve profiling or highly sensitive data categories (race, political affiliation, etc.), and "a decision to release information via the SSAD is would not in itself have legal effect on the data subject." c. Are data controllers ever required to notify the data subject of the identity of a third-party requestor? d. Please confirm: when a data subject objects to processing, the decision to release the data resides with the data controller? e. If a registrant must be notified of a request and then be given the opportunity to object, please explain how this process can be reconciled with or integrated into a SSAD that is designed to provide timely data exchange when possible and does not involve "a decision based solely on automated processing". (See Bird & Bird's Question 3 memo, paragraph 1.12.) Notes:
Notes:
b) Agree on next steps 4. Presentation of high-level summaries of legal memos
Notes:
5. Wrap and confirm next meeting to be scheduled a) Confirm action items b) The next Legal Committee meeting is scheduled for Tuesday, 19 November at 14:00 UTC. |