Bloomberg Law: Privacy & Data Security brings you single-source access to the expertise of Bloomberg Law’s privacy and data security editorial team, contributing practitioners,...
By George Lynch
Providing unlimited public access to the personal data of Dutch internet domain name registrants violates privacy law, the Netherlands’ privacy office said in a recent letter to the organization that maintains the Dutch directory.
The Dutch Data Protection Authority’s letter to the Dutch administrator of .amsterdam and .frl internet domain suffixes concludes that the data of website registrants published by the Internet Corporation for Assigned Names and Numbers (ICANN), the worldwide administrator of domain names, lacks a legitimate legal basis, the regulator said in an Oct. 30 statement. The personal data is normally published in ICANN’s Whois database, a publicly searchable database that contains information such as the names, addresses, email addresses, and telephone numbers of domain name registrants.
In addition to violating Dutch privacy law, the ICANN rules also violate the forthcoming European Union privacy regime, the General Data Protection Regulation, which takes effect in May 2018, the regulator said.
The case illustrates “how that Dutch/European view clashes with that of a non-European entity like ICANN,” Quinten Kroes, a telecommunications, media, and technology attorney at Brinkhof N.V. in Amsterdam, told Bloomberg Law Nov. 2.
ICANN sets the general rules for internet domains and oversees the process by which individual domain registers such as GoDaddy.com in the U.S. operate to log owners of specific internet addresses used to identify websites.
Access to such data should be limited to that “necessary for technical reasons, or for law enforcement when it is legally entitled to such access,” the privacy office letter said.
The practical consequences for Dutch companies will be limited, however, because only a relatively limited number of website addresses have been registered that use the .frl and .amsterdam domain name extensions, Thomas de Weerd, information technology and privacy partner at the Houthoff law firm in Amsterdam, told Bloomberg Law Nov. 2.
The letter was drafted in response to a request by an unnamed Dutch domain name registrar that, under ICANN rules, would have been required to publish all Whois data on the internet with unlimited access. The registrar asked if it would be in violation of privacy law if it complied with the ICANN rules.
It is unusual for the privacy office to make public an opinion at the request of an interested party when the office isn’t doing so in the context of an enforcement action, Kroes said. But the regulator made an exception since the publication of Whois data affects so many individuals, he said.
Publication of the data is a form of processing that requires a legal justification, the privacy office said. ICANN cannot rely on performance of a contract, legitimate interest, or consent for the publication of the data, it said.
Wanne Pemmelaar, senior associate at Allen & Overy LLP in Amsterdam, told Bloomberg Law Nov. 2 that the privacy office is “correcting a flaw in the system that has existed ever since people started registering domain names.”
The Article 29 Working Party, which is made up of privacy regulators from each of the EU member countries, has expressed concerns about the unlimited publication of internet domain holder personal data as far back as 2003.
To contact the reporter on this story: George Lynch in Washington at gLynch@bna.com
To contact the editor responsible for this story: Donald Aplin at firstname.lastname@example.org
Copyright © 2017 The Bureau of National Affairs, Inc. All Rights Reserved.
All Bloomberg BNA treatises are available on standing order, which ensures you will always receive the most current edition of the book or supplement of the title you have ordered from Bloomberg BNA’s book division. As soon as a new supplement or edition is published (usually annually) for a title you’ve previously purchased and requested to be placed on standing order, we’ll ship it to you to review for 30 days without any obligation. During this period, you can either (a) honor the invoice and receive a 5% discount (in addition to any other discounts you may qualify for) off the then-current price of the update, plus shipping and handling or (b) return the book(s), in which case, your invoice will be cancelled upon receipt of the book(s). Call us for a prepaid UPS label for your return. It’s as simple and easy as that. Most importantly, standing orders mean you will never have to worry about the timeliness of the information you’re relying on. And, you may discontinue standing orders at any time by contacting us at 1.800.960.1220 or by sending an email to email@example.com.
Put me on standing order at a 5% discount off list price of all future updates, in addition to any other discounts I may quality for. (Returnable within 30 days.)
Notify me when updates are available (No standing order will be created).
This Bloomberg BNA report is available on standing order, which ensures you will all receive the latest edition. This report is updated annually and we will send you the latest edition once it has been published. By signing up for standing order you will never have to worry about the timeliness of the information you need. And, you may discontinue standing orders at any time by contacting us at 1.800.372.1033, option 5, or by sending us an email to firstname.lastname@example.org.
Put me on standing order
Notify me when new releases are available (no standing order will be created)