| (KI) Whois and Privacy Policy | | Print | |
|
1. OBJECTIVES 1.1 The objectives of this Privacy Policy are: (1) To disclose to the Registrant, and in doing so obtain the Registrant's consent, to the fact that the Personal Information (defined below) provided by the Registrant may be dealt with in the following manner by the Telecommunications Authority of Kiribati ("KINIC"): (a) Personal Information shall be collected in the form of a Registrant database, which is used, maintained and corrected from time to time in accordance with this Policy; (b) Personal Information shall be collected by KINIC for the purpose of the storage and maintenance of the Personal Information. KINIC shall not disclose or transfer the Personal Information to any third party other than the .ki ccTLD Escrow Agent unless under the circumstances detailed in the "Use and Disclosure" section of this Policy; (c) All personal information about the Registrant which is supplied to KINIC or an accredited registrar is held by KINIC for the benefit of Kiribati and global internet communities and may be required to be publicly disclosed to third parties and used to maintain a public "Whois" service, provided that such disclosure is consistent with: (i) Privacy principles specified in CoCCA recommended policies; and (2) To outline KINIC's procedures for the appropriate collection, holding, use, correction, disclosure and transfer of a Registrant's Personal Information by KINIC; (3) For KINIC to undertake the requirements of Section 1.1(1) in such a way so as to ensure that KINIC: (a) meets international concerns and obligations relating to privacy; 2.2 "KINIC" means the Communications Authority of Kiribati; 2.3 "Domain" means a .ki Domain name applied for by a Registrant, whose registration application has been processed and accepted by KINIC; 2.4 "Escrow Agent" means a third party contracted to perform data escrow services for KINIC. The data escrow arrangement with the Escrow Agent will ensure the transfer of all relevant DNS data and Registrant information, including Personal Information to a nominated replacement/back-up system, and will ensure the safety and integrity of the .ki country code Top Level Domain ("ccTLD") database. The Escrow Agent is prohibited from use or disclosure of the .ki ccTLD Data unless that use or disclosure is deemed essential to ensure the stability and integrity of the .ki ccTLD; 2.5 "Identifier" for the purposes of Section 10 includes a number assigned by KINIC to an individual to identify uniquely the Registrant for the purposes of KINIC's operations. However, an individual's name is not an identifier; 2.6 "Personal Information" means information or an opinion (including information or an opinion forming part of a database), whether true or not, and whether recorded in a material form or not, about a Registrant whose identity is apparent, or can reasonably be ascertained, from the information or opinion provided by the Registrant including information contained in applications for KINIC domain names; 2.7 "Policy" means the contents of the KINIC Privacy Policy and any amendments or updates to the Policy made by KINIC from time to time and posted on the KINIC website http://www.nic.ki ; 2.8 "Sensitive information" means Personal Information that would be considered to be "sensitive" under the CoCCA recommended policies; 2.9 "Registrant" means the individual, entity or the authorised agent for the individual or entity who applied for or caused to be applied for a Domain and whose registration application has been processed and accepted by KINIC; 2.10 "Whois Service" means the service provided by KINIC to the public, as described in Section 3 of this Policy, which is available at http://www.nic.ki. 3.1 KINIC will maintain a publicly accessible information service known as the .ki ccTLD "Whois" service which will provide limited information in relation to a Domain as follows: (1) technical information on the DNS servers resolving a Domain; 3.2 KINIC shall not release a Registrant's phone numbers, addresses or email contact details without the consent of the Registrant, unless under the circumstances detailed in "Use and Disclosure" section below. 3.3 KINIC or CoCCA Accredited Registrars are required, as a condition of their accreditation, to provide Registrants with the tools to make visible "Extended Whois" information on .ki ccTLD domains registered through them. 3.4 KINIC will provide registrants with an on-line tool at http://www.nic.ki to edit information published in the ccTLD Whois. The registrant will require a registry key and will not be able to disable display of data set in 3.1. 4.1 KINIC shall only collect Personal Information necessary for one or more of its functions or activities: (1) as the trustee for the .ki ccTLD database; 4.2 The "Primary Purpose of Collection" by KINIC shall be for one of the necessary functions or activities of KINIC as described in Section 4.1 above and KINIC will exercise its reasonable endeavours to ensure that: (1) KINIC shall collect Personal Information only by lawful and fair means and not in an unreasonably intrusive way. (a) the identity of KINIC and the Escrow Agent and how the Registrant may contact KINIC; and (3) If it is reasonable and practicable to do so, KINIC shall collect Personal Information about a Registrant only from that individual. (4) If KINIC collects Personal Information about the Registrant from someone else, it shall take reasonable steps to ensure that the Registrant is or has been made aware of the matters listed in the "Objectives" Section 1, except to the extent that making the Registrant aware of the matters would pose a serious threat to the life or health of any individual. 4.3 KINIC's website does not utilise technology to collect user information or track usage. KINIC's website may feature links to other websites. KINIC is not responsible for the content and privacy practices of such other websites. 5.1 KINIC shall NOT use or disclose Personal Information about a Registrant for a purpose (the Secondary purpose) other than the Primary Purpose of Collection unless: (1) the Registrant has consented to the use or disclosure; or (2) KINIC reasonably believes that the use or disclosure is necessary: (a) to lessen or prevent a serious and imminent threat to an individual's life, health or safety; or (i) the prevention, detection, investigation, prosecution or punishment of criminal offences, breaches of a law imposing a penalty or sanction or breaches of a prescribed law; (f) because a third party has filed a complaint relating to the AUP and providing the Personal Information may contribute to resolution of the complaint. 5.2 KINIC shall lawfully co-operate with agencies performing law enforcement functions. 5.3 This "Use and Disclosure" Section 5 does not override any existing legal obligations not to disclose Personal Information. Nothing in this "Use and Disclosure" Section 5 requires KINIC to disclose any Personal Information; KINIC is always entitled not to disclose Personal Information in the absence of a legal obligation to disclose it. 5.4 KINIC is also subject to the requirements set out in the "Transborder Data Flows" Section 12 of this Policy if it transfers Personal Information to a person in a foreign country, situated outside of Kiribati. 5.5 If KINIC uses or discloses Personal Information under this "Use and Disclosure" Section 5, it shall make a written note of the use or disclosure, and except where requested by a law enforcement agency, inform the Registrant by email of the identity of the requesting entity and stated reasons for the release of the information. These reasons must be one of the stated reasons in Section 5.1(2). 6.1 KINIC shall take reasonable steps to make sure that the Personal Information it collects, uses or discloses is accurate, complete and up-to-date. 7.1 KINIC shall take reasonable steps to protect the Personal Information it holds from misuse and loss and from unauthorised access, modification or disclosure. 7.2 KINIC shall take reasonable steps to destroy or permanently de-identify Personal Information if it is no longer needed for any purpose for which the information may be used or disclosed under the "Use and Disclosure" section of this Policy, except where prohibited by law or applicable policy 8.1 This Policy sets out KINIC's policies on its management of Personal Information. KINIC shall make this document available to anyone who asks for it. 8.2 On request by any person, KINIC shall take reasonable steps to let the person know, generally, what sort of Personal Information KINIC holds, for what purposes, and how it collects, holds, uses and discloses that information. 9.1 If KINIC holds Personal Information about a Registrant, it shall provide the Registrant with access to the information on request by the Registrant, except to the extent that: (1) in the case of Personal Information, providing access would pose a serious and imminent threat to the life or health of any individual; or (2) providing access would have an unreasonable impact upon the privacy of other individuals; or (3) the request for access is frivolous or vexatious; or (4) the information relates to existing or anticipated legal proceedings between KINIC and the Registrant and the information would not be accessible by the process of discovery in those proceedings; or (5) providing access would reveal the intentions of KINIC in relation to negotiations with the Registrant in such a way as to prejudice those negotiations; or (6) providing access would be unlawful; or (7) denying access is required or authorised by or under law; or (8) providing access would be likely to prejudice an investigation of possible unlawful activity; or (9) providing access would be likely to prejudice: (a) the prevention, detection, investigation, prosecution or punishment of criminal offences, breaches of a law imposing a penalty or sanction or breaches of a prescribed law; or 9.2 However, where providing access would reveal evaluative information generated within KINIC in connection with a commercially sensitive decision-making process, KINIC may give the Registrant an explanation for the commercially sensitive decision rather than direct access to the information. 9.3 If KINIC charges for providing access to Personal Information, those charges: 9.4 If KINIC holds Personal Information about a Registrant and the Registrant is able to establish that the information is not accurate, complete and up-to-date, KINIC shall take reasonable steps to correct the information so that it is accurate, complete and up-to-date, as requested by the Registrant. 9.5 If the Registrant and KINIC disagree about whether the Personal Information is accurate, complete and up-to-date, and the Registrant asks KINIC to associate with the information a statement claiming that the information is not accurate, complete or up-to-date, KINIC shall take reasonable steps to do so. 9.6 KINIC shall provide written reasons for denial of access or a refusal to correct Personal Information under this Section 9 in relation to "Access and Correction". 10.1 KINIC shall not adopt as its own identifier of a Registrant, an identifier of the Registrant that has been assigned by: (1) an agency; or 10.2 KINIC shall not use or disclose an identifier assigned to an individual by an agency, or by an agent or contracted service provider mentioned in Section 10 in relation to "Identifiers" unless: (1) the use or disclosure is necessary for KINIC to fulfill its obligations to the agency; or 11.1 A Registrant's request not to be identified when entering transactions with KINIC shall be considered by KINIC on a case by case basis, in its sole discretion, although KINIC may to honour such request wherever it is lawful or practicable to do so. 12.1 KINIC may transfer Personal Information to someone (other than KINIC, its affiliates or the Registrant) who is in a foreign country only if: (1) KINIC reasonably believes that the recipient of the information is subject to a law, binding scheme, or contract which effectively upholds principles for fair Resolution of the information that are substantially similar to the privacy principles under CoCCA recommendations; or (2) The Registrant consents to the transfer; or (3) The transfer is necessary for the performance of a contract between the Registrant and KINIC, or for the implementation of pre-contractual measures taken in response to the Registrants request; or (4) The transfer is necessary for the conclusion or performance of a contract concluded in the interest of the Registrant between KINIC, its affiliates or a third party; or (5) All of the following apply: (a) the transfer is for the benefit of the Registrant; (6) KINIC has taken reasonable steps to ensure that the information which it has transferred will not be held, used or disclosed by the recipient of the information inconsistently with the privacy principles in the CoCCA recommendations. 13.1 KINIC shall not collect sensitive information about a Registrant unless: (1) the Registrant has consented; or (2) the collection is required by law; or (3) the collection is necessary to prevent or lessen a serious and imminent threat to the life or health of any individual, where the Registrant whom the information concerns: (a) is physically or legally incapable of giving consent to the collection; or (4) where the information is collected in the course of the activities of a non-profit organisation the following conditions are satisfied: (a) the information relates solely to the members of KINIC or to individuals who have regular contact with it in connection with its activities; (5) the collection is necessary for the establishment, exercise or defence of a legal or equitable claim. 14.1 KINIC reserves the right to review or revise this policy at any time and those people who volunteer their personal details to KINIC are deemed to acknowledge and be bound by this policy and any changes made to it. This in no way affects the privacy protection available under CoCCA recommendations or other relevant laws. |