The Struggle for WHOIS Privacy: Understanding the Standoff Between ICANN and the World’S Data Protection Authorities
Total Page:16
File Type:pdf, Size:1020Kb
The Struggle for WHOIS Privacy: Understanding the Standoff Between ICANN and the World’s Data Protection Authorities by Stephanie E. Perrin A thesis submitted in conformity with the requirements for the degree of degree of Doctor of Philosophy Faculty of Information University of Toronto © Copyright by Stephanie E. Perrin 2018 The Struggle for WHOIS Privacy: Understanding the Standoff Between ICANN and the World’s Data Protection Authorities Stephanie E. Perrin Doctor of Philosophy Faculty of Information University of Toronto 2018 Abstract This dissertation examines the struggle over privacy rights in WHOIS, the public directory of registrants of Internet domain names. ICANN, the Internet Corporation for Assigned Names and Numbers, is the non-profit corporation established by the U.S. government to run the Domain Name System and the Internet Assigned Numbers Authority, functions essential for Internet operations. Through contractual obligation, ICANN requires registrars to collect and publish personal data in the WHOIS directory, contravening many national data protection laws. My research first asked how ICANN managed to avoid the demands of authorities mandated to enforce data protection laws. Analyzing extensive documentary records maintained by ICANN, I demonstrate that the organization refused to effectively accommodate privacy concerns in their policies. I found that, since its inception, ICANN rebuffed repeated complaints by data protection authorities that WHOIS requirements violate national laws and continue to avoid privacy compliance. I provide evidence of a clash of values in the emerging commercial Internet. Business enterprises with strong intellectual property interests, supported by the U.S. ii government, initiated the focus on an open WHOIS policy to ensure they could identify suspected copyright and trademark violators. Law enforcement agencies represented at ICANN’s Governmental Advisory Committee also demanded open access to registrant data. A growing information services industry depended on the sale of this data to domain businesses and cybercrime fighters in both the public and private sectors. In combination, these stakeholders have prevented privacy advocates from gaining a foothold. Data Protection Authorities have also declined to exercise their powers, and they have remained outsiders and unsuccessful interveners in ICANN’s multi-stakeholder process. The dissertation then explores the implications of this failure of privacy law from the perspectives of Internet privacy scholarship and accountability issues in multi-stakeholder governance. Establishing WHOIS as a wide-open information resource not only erodes legitimate expectations of privacy in telecommunications directories, it undermines our ability to negotiate personal space and speech on the Internet. This research contributes to understanding challenges to Internet privacy, law enforcement access to personal data, and the prospects for developing international Internet governance regimes that promote the public interest while protecting the rights of individuals. iii Acknowledgements I could not have completed this project without the enthusiastic support of my advisors, Andrew Clement and David Phillips. Leslie Shade, besides being the graduate coordinator during a critical period of this research, has also been a terrific committee member and supporter of my work. Straddling the rift between privacy advocate, government employee, and doctoral student has been challenging and I thank these three for helping me to navigate this transition effectively. Thanks also to Professor Colin Bennett, whose encouragement was greatly appreciated, and to the many other professors and colleagues who supported me and provided advice. Had I listened to Professor Lee Bygrave’s excellent advice to quit volunteering at ICANN for six months to finish writing, the dissertation would have been done earlier. In terms of my research and writing, I must thank my sons Matthew Purcell, Jesse Purcell, Joe Rochon, and Marco Rochon for their unflagging support. Special thanks to my friends Heather Black for her insight into privacy compliance issues, and Bob Gellman in Washington for reading versions of the document and providing valuable feedback. Thanks also to Theo Geurts of Realtime Register for reading the draft and providing valuable feedback from a technical and business perspective. To all my other friends and relatives who have put up with me, listened to me discuss ICANN, and encouraged me to finish, my thanks to you all. My cohort at the Faculty of Information, Glen Farrelly, Michael Jones, Rebecca Sheffield, and Rhon Teruelle have been great supporters and colleagues. And finally to my many colleagues at ICANN, particularly in the Noncommercial Users Constituency and the Noncommercial Stakeholders Group, my thanks for all their support, information, and collaboration. This is a small contribution to the literature on how privacy protection fails in one specific application. I hope to contribute solutions to the problems and to raising the support required to achieve that end. iv Table of Contents Acknowledgements ........................................................................................................................ iv Table of Contents ............................................................................................................................ v List of Tables ................................................................................................................................ xii List of Figures .............................................................................................................................. xiii List of Appendices ....................................................................................................................... xiv Chapter 1 The Failure of WHOIS Privacy at ICANN: What is at Stake? ...................................... 1 1.1 Development of the WHOIS Directory of Domain Registrants ......................................... 2 1.1.1 Establishment of ICANN ........................................................................................ 3 1.1.2 The Domain Name System is fundamental to Internet operations ......................... 6 1.2 Who Wants WHOIS Data and Why? .................................................................................. 7 1.2.1 Three leading stakeholders: intellectual property owners, law enforcement, and the value-added services providers .................................................................. 8 1.3 What Does Privacy Mean in this Context? ......................................................................... 9 1.3.1 Risks of releasing personal information and privacy rights .................................. 11 1.4 Who Cares About WHOIS Privacy and Why? ................................................................. 12 1.4.1 Civil society and their allies .................................................................................. 12 1.5 Data Protection Authorities ............................................................................................... 14 1.5.1 My involvement with ICANN and choice of this case study as a research focus ...................................................................................................................... 14 1.6 ICANN Stymies WHOIS Data Privacy Since 1998 ......................................................... 16 1.6.1 ICANN’s failure to respond .................................................................................. 17 1.7 WHOIS Conflicts with Law Policy—ICANN’s Only Concession to Privacy Demands . 18 1.8 Research Questions ........................................................................................................... 19 v 1.9 The Importance of These Questions and Prospective Research Contributions to Privacy Scholarship (and Advocacy) ................................................................................ 20 1.9.1 Implications for Internet governance .................................................................... 27 1.9.2 Implications for the Domain Name System industry ............................................ 28 1.10 Thesis Outline ................................................................................................................... 29 Chapter 2 Personal Background and Methodological Approach .................................................. 32 2.1 Researcher, Privacy Expert and Advocate ........................................................................ 32 2.2 Why I Worked with ICANN Documents .......................................................................... 34 2.3 Selecting Documents ........................................................................................................ 37 2.3.1 Selecting documents relevant to a process and decision....................................... 40 2.4 Possible Explanations for ICANN’s Lack of Response to Privacy Claims ...................... 43 2.4.1 Political and governmental issues ......................................................................... 43 2.4.2 Legal and practical issues affecting data commissioners ..................................... 44 2.4.3 Economic issues facing stakeholders .................................................................... 46 2.4.4 Internal ICANN issues management .................................................................... 47 Chapter 3 Privacy Scholarship Relevant to WHOIS Privacy