This draft is well written and clearly articulated. As I was reading the document I noticed a number of references to particular privacy and security issues that were not repeated in the security and privacy considerations, but that section contained references to the relevant parts of the document. I think that is an elegant solution. So all things considered, I believe this document is ready from a secdir PoV.