Re: EU data protection, was: Extensions in regards to NTLDs
"Hollenbeck, Scott" <[email protected]>
| Newsgroups | gmane.ietf.provreg |
|---|---|
| Message-ID | <831693C2CDA2E849A7D7A712B24E257F0D570905@BRN1WNEXMBX01.vcorp.ad.vrsn.com> |
> -----Original Message----- > From: [email protected] [mailto:[email protected]] On > Behalf Of Klaus Malorny > Sent: Wednesday, December 21, 2011 5:42 AM > To: Gavin Brown > Cc: [email protected] > Subject: [provreg] EU data protection, was: Extensions in regards to > NTLDs > > IMHO <contact:disclose> already provides sufficient control (except for > the > design flaw that you cannot grant and deny disclosures at the same > time). I'm going to disagree (again) on the "design flaw" point. As described in 5733: - The server operator publishes a data collection policy. - The client has the choice of accepting the policy *and* requesting exceptions (that is, granting and denying disclosures) as part of the same <create> command. The server operator needs to publish a policy that meets the requirements of the local operating environment, such as is defined in the EU. It would be a design flaw to allow the client to grant and/or deny disclosures in conflict with the server operator's data collection policy. Doing so would put the server operator in an untenable state with respect to the client's data. Scott _______________________________________________ provreg mailing list [email protected] https://www.ietf.org/mailman/listinfo/provreg