Search RPD Archives
[rpd] Updated Proposal - AfriNIC Policy Compliance Dashboard AFPUB-2026-GEN-002-DRAFT02
jordi.palet at theipv6company.com
jordi.palet at theipv6company.com
Fri Oct 2 16:32:10 UTC 2026
Hi Nia,
The way we introduced “possible” is to allow the staff impact assessment to withdraw some of the “cons” against the proposal. The overall goal of the proposal works the same if instead of defining all the details (which are now as examples in non-normative text), we just ensure that there is a notification in “possible” cases and them the staff can take their own steps and decisions.
We don’t have anymore in the normative text the “continued” part, we leave it now to the staff - again, as explained in previous emails, so they can follow their already existing procedures.
The collection of personal data is not needed in our opinion for the monitoring, but we wanted to make it explicit to responde to one of the impact assessment points. Same for “not intruding” the network. Was never expected to be done. If monitoring some aspect needs going “inside” the network, then it can be implemented, and only can be done in case of “audits” which can be done by AFRINIC, as they are done by any other RIRs in case of suspicius signals.
We could use your text for section 3, however, I think is superfluous, because the exact text to send should be determined by the staff. If we include it in the proposal, they are mandated to that text, which over the time could be easily improved, changed, etc.
Regarding the history, it needs to be used as explained already in a previous email.
Note that the dashboard has only visibility for the resource holder, not others. As explained in a previous email, I would agree that once a recovery process is started, it should be made public for some time. This was in the LACNIC proposal that was adopted, but a previous version 3 years ago in AFRINIC, reached consensus and was not ratified by the staff/board, because it was considered encroaching them - strange that 2 RIRs doing the same functions have so much different view but this is what we have!
Regards,
Jordi
@jordipalet
> El 2 oct 2026, a las 15:53, NP Petronella <NPertuniaPetronella at outlook.com> escribió:
>
> Dear PDWG,
>
> My comment is on one provision: the history requirement in the Notifications item of the proposed new CPM section.
>
> What the text says. Item 3 provides that the dashboard "Will automatically send notifications to members and staff as soon as a possible non-compliance is detected, showing previous history if available."
>
> Why that is a defect. The test for including history is availability ("if available"), not relevance. Available history and relevant history are not the same thing. The notification is also triggered by a 'possible' non-compliance — before the staff verification contemplated by item 4 — and the same bullet sends the material to staff, not only to the member. The proposal's own description of its design says staff warnings are for "a continued and repeated lack of compliance, or severe violation"; the operative wording is wider than that.
>
> Why the other safeguards do not answer this. Item 2, third paragraph, says the automation "will be made without the need to capture personal data or intrusion in the members' networks". That limits new collection. It does not say which existing information is to accompany a notification, which is precisely what item 3 requires. Existing data-protection law and AFRINIC's Privacy Policy govern how AFRINIC holds information; they do not determine what this policy puts into a notification. Because item 3 is the provision that specifies the content, the policy is the instrument that must state the test.
>
> It may be said that this belongs in implementation and that existing privacy rules already apply. If the notification's content were only an implementation choice, item 3 would not need to specify it. Because it specifies it, the rule needs a relevance test rather than an availability test. A general assurance cannot substitute for the rule when the rule is what the paragraph contains.
>
> Proposed amendment — replace the first bullet of item 3 with:
>
> "Will automatically send notifications to the member as soon as a possible non-compliance is detected. The notification shall state that no determination has been made. Historical information shall be included only where it is necessary and relevant to understand or correct the possible non-compliance identified, and shall identify its source, date and current disposition. Automated findings that have not been confirmed under item 4 shall not form part of the history shown. Staff notification shall follow a determination under item 4, or the continued and repeated non-compliance described in the proposal's summary of how it addresses the problem."
>
> Questions for the authors and colleagues, for the record. (a) What does "previous history" include? (b) Is relevance or availability the test? (c) Does unconfirmed automated output enter that history? (d) Which published procedure governs its reuse?
>
> I ask that this be recorded as a distinct issue from the earlier dashboard-visibility/privacy exchange and from the scope question about item 4 raised by another commenter. I am not alleging unlawful processing, and I am not claiming that no safeguards exist. I am identifying a test the policy should state, and offering wording that achieves it.
>
> Kind regards,
> Nia
>
> _______________________________________________
> RPD mailing list
> RPD at afrinic.net
> https://lists.afrinic.net/mailman/listinfo/rpd
**********************************************
IPv4 is over
Are you ready for the new Internet ?
http://www.theipv6company.com
The IPv6 Company
This electronic message contains information which may be privileged or confidential. The information is intended to be for the exclusive use of the individual(s) named above and further non-explicilty authorized disclosure, copying, distribution or use of the contents of this information, even if partially, including attached files, is strictly prohibited and will be considered a criminal offense. If you are not the intended recipient be aware that any disclosure, copying, distribution or use of the contents of this information, even if partially, including attached files, is strictly prohibited, will be considered a criminal offense, so you must reply to the original sender to inform about this communication and delete it.
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <https://lists.afrinic.net/pipermail/rpd/attachments/20261002/edd20f5c/attachment-0001.html>
More information about the RPD
mailing list