Search RPD Archives
[rpd] Updated Proposal - AfriNIC Policy Compliance Dashboard AFPUB-2026-GEN-002-DRAFT02
NP Petronella
NPertuniaPetronella at outlook.com
Fri Oct 2 13:53:05 UTC 2026
Dear PDWG,
My comment is on one provision: the history requirement in the Notifications item of the proposed new CPM section.
What the text says. Item 3 provides that the dashboard "Will automatically send notifications to members and staff as soon as a possible non-compliance is detected, showing previous history if available."
Why that is a defect. The test for including history is availability ("if available"), not relevance. Available history and relevant history are not the same thing. The notification is also triggered by a 'possible' non-compliance — before the staff verification contemplated by item 4 — and the same bullet sends the material to staff, not only to the member. The proposal's own description of its design says staff warnings are for "a continued and repeated lack of compliance, or severe violation"; the operative wording is wider than that.
Why the other safeguards do not answer this. Item 2, third paragraph, says the automation "will be made without the need to capture personal data or intrusion in the members' networks". That limits new collection. It does not say which existing information is to accompany a notification, which is precisely what item 3 requires. Existing data-protection law and AFRINIC's Privacy Policy govern how AFRINIC holds information; they do not determine what this policy puts into a notification. Because item 3 is the provision that specifies the content, the policy is the instrument that must state the test.
It may be said that this belongs in implementation and that existing privacy rules already apply. If the notification's content were only an implementation choice, item 3 would not need to specify it. Because it specifies it, the rule needs a relevance test rather than an availability test. A general assurance cannot substitute for the rule when the rule is what the paragraph contains.
Proposed amendment — replace the first bullet of item 3 with:
"Will automatically send notifications to the member as soon as a possible non-compliance is detected. The notification shall state that no determination has been made. Historical information shall be included only where it is necessary and relevant to understand or correct the possible non-compliance identified, and shall identify its source, date and current disposition. Automated findings that have not been confirmed under item 4 shall not form part of the history shown. Staff notification shall follow a determination under item 4, or the continued and repeated non-compliance described in the proposal's summary of how it addresses the problem."
Questions for the authors and colleagues, for the record. (a) What does "previous history" include? (b) Is relevance or availability the test? (c) Does unconfirmed automated output enter that history? (d) Which published procedure governs its reuse?
I ask that this be recorded as a distinct issue from the earlier dashboard-visibility/privacy exchange and from the scope question about item 4 raised by another commenter. I am not alleging unlawful processing, and I am not claiming that no safeguards exist. I am identifying a test the policy should state, and offering wording that achieves it.
Kind regards,
Nia
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <https://lists.afrinic.net/pipermail/rpd/attachments/20261002/5183b535/attachment-0001.html>
More information about the RPD
mailing list