disclosure request

A request to a registrar A company that registers domain names for customers with the registry. Full definition of registrar or registry The central database and system of a top-level domain, or loosely the organization that runs it. Full definition of registry for registration data The information kept about a domain and its owner. Full definition of registration data that is hidden from public view, such as the owner's name or email. The requester, for example police or a trademark lawyer, explains why they need it. The registrar or registry decides whether to disclose.

category
Registration data and privacy

Updated on 5 min read

A disclosure request is how someone asks for the details of a domain owner that are hidden from public view, such as a name or an email address. The request goes to the company that sells or runs the domain and must explain who is asking and why. That company, not ICANN Internet Corporation for Assigned Names and Numbers The nonprofit that coordinates the global DNS and gTLD policy. Full definition of ICANN, decides whether to hand the data over.

What a disclosure request is

Since 2018, under the Temporary Specification ICANN's 2018 emergency rules for WHOIS under the GDPR. Full definition of Temporary Specification, much of the personal data in gTLD generic top-level domain A top-level domain not tied to a country, run under ICANN contracts. Full definition of gTLD registration Obtaining the right to use a domain name for a set period. Full definition of registration records has been hidden (tiered access A model where personal registration data is hidden and released only to justified requestors. Full definition of tiered access). Today the Registration Data Policy ICANN's policy on collecting, publishing and disclosing gTLD registration data. Full definition of Registration Data Policy governs it, in force since 21 August 2025 and revised on 12 May 2026: registrars and registries must redact personal data where the law requires it, and may do so in some other cases.

ICANN’s formal name for it is “Reasonable Requests for Lawful Disclosure”. The request goes to the registrar or the registry operator The organization that holds the contract or mandate for a TLD and sets its rules. Full definition of registry operator, and the one that receives it decides. ICANN neither takes the decision nor re-examines it.

Who can ask and on what grounds

Anyone may ask. As of October 2026, a request must contain at least:

  • the requester’s identity, contact details and type (business or individual), with proof of authority when acting for someone else;
  • the data elements wanted;
  • the requester’s legal rights and the specific reason for the request;
  • a statement of good faith and an agreement to process the data lawfully.

The registrar or registry must consider each properly formed request on its merits. Where the law requires it, it weighs the requester’s legitimate interest A GDPR ground for processing personal data, weighed against the registrant's privacy rights. Full definition of legitimate interest against the registrant The person or organization that holds a domain name registration. Full definition of registrant’s rights, and it may consider other factors, such as jurisdiction.

Over the RDRS Registration Data Request Service ICANN's free service for requesting hidden gTLD registration data from participating registrars. Full definition of RDRS pilot, intellectual property holders sent 1,202 of the 3,721 requests and law enforcement 605.

As of October 2026, in the European Union (EU), Article 28(5) of the NIS2 Directive on measures for a high common level of cybersecurity across the Union A European Union cybersecurity directive with rules on accurate domain registration data. Full definition of NIS2 Directive requires member states to make TLD top-level domain The last part of a domain name, after the final dot. Full definition of TLD registries and registrars give specific registration data to legitimate access seekers on a lawful and duly justified request, in line with EU data protection law, and to answer within 72 hours.

How to send a request, step by step

For a gTLD name, as of October 2026:

  1. Check the public data with ICANN Lookup ICANN's free web tool that looks up public registration data through RDAP. Full definition of ICANN Lookup, to confirm the data is hidden and find the registrar.
  2. Follow the registrar’s process. Every registrar and registry must link from its homepage to a page giving the request format, how answers are sent and the expected timeline.
  3. Or use RDRS, which is free and needs an ICANN account. The requester picks a category, describes what it wants, may attach up to five PDF files of up to 5 MB each, and confirms it will comply with data protection law.
  4. If the registrar does not take part, RDRS lets the requester save the form as a PDF to send directly. In every case, any disclosure happens outside RDRS, by the method the registrar chooses.

As of October 2026, RDRS is voluntary for registrars. At the end of its pilot in November 2025, participating registrars covered 46% of domains under management. The ICANN Board ICANN's board of directors, which adopts policies and approves key decisions. Full definition of ICANN Board extended it for up to two years: to December or November 2027, depending on the ICANN document. RDRS does not cover ccTLD country code top-level domain A top-level domain for a country or territory, usually two letters long. Full definition of ccTLD and is not a way to file a UDRP Uniform Domain-Name Dispute-Resolution Policy ICANN's out-of-court process for trademark disputes over domain names. Full definition of UDRP complaint.

ccTLDs apply their own rules and law, so the requester contacts the registry; EURid The nonprofit registry that runs .eu under contract with the European Commission. Full definition of EURid, for example, offers a form for .eu data. The .es registry is not bound by ICANN’s policy or by RDRS, so for a .es name check with Red.es The Spanish public body that manages the .es domain through its unit Dominios.es. Full definition of Red.es or a lawyer.

Response times and urgent requests

As of October 2026, a registrar or registry must acknowledge a properly formatted request within 2 business days and answer within 30 calendar days of acknowledgement, barring exceptional circumstances. During the RDRS pilot, approvals took 7 days on average and denials 17. The RDRS “Expedited” option does not oblige the registrar to hurry: in the pilot, 169 of 220 such requests were changed to standard, and in an emergency ICANN tells requesters not to rely on it and to contact the registrar directly.

urgent request An emergency request for hidden registration data, with a 24-hour answer deadline not yet in force. Full definition of urgent request were added to the policy on 12 May 2026. They come only from an authenticated law enforcement or other trusted authority, for an imminent threat to life, of serious bodily injury, to critical infrastructure or of child exploitation. The answer would be due within 24 hours, extendable with reasons to at most 72 hours from receipt. As of October 2026 this rule is not in force: it applies only once ICANN implements a policy for authenticating requesters. ICANN is preparing a test with law enforcement, including INTERPOL and the US Federal Bureau of Investigation (FBI).

As of October 2026, the RAA Registrar Accreditation Agreement The contract between ICANN and each accredited registrar. Full definition of RAA requires every gTLD registrar to keep an abuse contact The published contact where registrars and registries receive abuse reports. Full definition of abuse contact monitored around the clock for authorities of its own jurisdiction and to review their well-founded reports within 24 hours: reports, not disclosure.

What happens when a request is refused

A refusal must give specific reasons and, where that balancing applies, explain how the registrant’s rights were weighed against the requester’s interest.

Refusals are frequent. From launch to 30 June 2026, RDRS recorded 4,275 requests: 1,072 approved and 2,540 denied. The most common reasons in the pilot were that the law prevented disclosure and that the request was incomplete.

The requester can then send a new request with more information, or complain to ICANN Contractual Compliance The ICANN team that enforces registry and registrar contracts. Full definition of ICANN Contractual Compliance if the registrar did not answer or did not follow the rules; ICANN will not reconsider the decision itself.

On 12 March 2026 the ICANN Board decided not to adopt the 18 SSAD System for Standardized Access/Disclosure A proposed central system for requesting hidden registration data, which ICANN's Board declined to adopt. Full definition of SSAD recommendations and urged the GNSO Generic Names Supporting Organization The ICANN body that develops policy for generic top-level domains. Full definition of GNSO Council to finish new work within the RDRS extension, which ends in November 2027. Mandatory registrar participation, response service levels and law enforcement authentication are under discussion; as of October 2026, none is decided.

Sources