Re: EU data protection, was: Extensions in regards to NTLDs
Klaus Malorny <[email protected]>
| Newsgroups | gmane.ietf.provreg |
|---|---|
| Message-ID | <[email protected]> |
On 21/12/11 13:14, Hollenbeck, Scott wrote: >> -----Original Message----- From: [email protected] >> [mailto:[email protected]] On Behalf Of Klaus Malorny Sent: >> Wednesday, December 21, 2011 5:42 AM To: Gavin Brown Cc: [email protected] >> Subject: [provreg] EU data protection, was: Extensions in regards to NTLDs >> >> IMHO<contact:disclose> already provides sufficient control (except for >> the design flaw that you cannot grant and deny disclosures at the same >> time). > > I'm going to disagree (again) on the "design flaw" point. As described in > 5733: > > - The server operator publishes a data collection policy. - The client has > the choice of accepting the policy *and* requesting exceptions (that is, > granting and denying disclosures) as part of the same<create> command. > > [...] Hi Scott, come on, we discussed this already quite a lot, if I remember correctly. If you have, say, the address to be disclosed, but the phone number to be undisclosed by default by the registry policy, you can't issue a create or update request that makes the address undisclosed and the phone number disclosed at the same time. If, for example, the "flag" attribute had been placed on the child elements of the <disclose> element, this would have been possible. As the example I gave is IMHO a valid desire, I consider this as a flaw, although not as a serious one. Regards, Klaus _______________________________________________ provreg mailing list [email protected] https://www.ietf.org/mailman/listinfo/provreg