Re: EU data protection, was: Extensions in regards to NTLDs

"Hollenbeck, Scott" <[email protected]>
Newsgroups gmane.ietf.provreg
Message-ID <831693C2CDA2E849A7D7A712B24E257F0D570905@BRN1WNEXMBX01.vcorp.ad.vrsn.com>
> -----Original Message-----
> From: [email protected] [mailto:[email protected]] On
> Behalf Of Klaus Malorny
> Sent: Wednesday, December 21, 2011 5:42 AM
> To: Gavin Brown
> Cc: [email protected]
> Subject: [provreg] EU data protection, was: Extensions in regards to
> NTLDs
> 
> IMHO <contact:disclose> already provides sufficient control (except for
> the
> design flaw that you cannot grant and deny disclosures at the same
> time).

I'm going to disagree (again) on the "design flaw" point. As described in 5733:

- The server operator publishes a data collection policy.
- The client has the choice of accepting the policy *and* requesting exceptions (that is, granting and denying disclosures) as part of the same <create> command.

The server operator needs to publish a policy that meets the requirements of the local operating environment, such as is defined in the EU.  It would be a design flaw to allow the client to grant and/or deny disclosures in conflict with the server operator's data collection policy.  Doing so would put the server operator in an untenable state with respect to the client's data.

Scott
_______________________________________________
provreg mailing list
[email protected]
https://www.ietf.org/mailman/listinfo/provreg
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.