GDPR

General Data Protection Regulation

The European Union law on personal data that has applied since May 2018. It led registry The central database and system of a top-level domain, or loosely the organization that runs it. Full definition of registry and registrar A company that registers domain names for customers with the registry. Full definition of registrar to hide most personal data from public WHOIS The legacy lookup service for domain registration data, now replaced by RDAP for gTLDs. Full definition of WHOIS. ICANN Internet Corporation for Assigned Names and Numbers The nonprofit that coordinates the global DNS and gTLD policy. Full definition of ICANN responded with a Temporary Specification ICANN's 2018 emergency rules for WHOIS under the GDPR. Full definition of Temporary Specification and later the Registration Data Policy ICANN's policy on collecting, publishing and disclosing gTLD registration data. Full definition of Registration Data Policy.

category
Registration data and privacy

Updated on 4 min read

The General Data Protection Regulation (GDPR) is the European Union law that protects personal data. It is the main reason a domain lookup today rarely shows the owner’s name, address or phone number.

What the GDPR is and why it changed domain data

The GDPR is Regulation (EU) 2016/679, opens another website in a new tab, adopted on 27 April 2016 and applied from 25 May 2018. It protects personal data: any information about an identified or identifiable living person, called the data subject The person whose personal data is processed, usually the registrant in a domain record. Full definition of data subject. It applies to processing in the context of an establishment in the Union, wherever the processing happens, and can also reach controllers outside the Union that offer services to people there.

ICANN said that, without changes to its contracts, registries and registrars could not comply with both the law and those contracts. Fines under the GDPR can reach EUR 20 million or 4 % of a company’s worldwide annual turnover, whichever is higher.

What is hidden now and what is still public

As of October 2026, ICANN’s Registration Data Policy (in force since 21 August 2025, last revised on 12 May 2026) sets the rules for gTLD generic top-level domain A top-level domain not tied to a country, run under ICANN contracts. Full definition of gTLD:

  • Always public: the domain name A readable internet name made of labels separated by dots. Full definition of domain name, the registrar with its URL, IANA registrar ID The unique number that identifies an ICANN-accredited registrar. Full definition of IANA registrar ID and abuse contact The published contact where registrars and registries receive abuse reports. Full definition of abuse contact, the creation and expiry dates, the statuses, and the registrant The person or organization that holds a domain name registration. Full definition of registrant’s country (and state or province, if collected).
  • Redacted where the law requires it, and allowed where commercially reasonable: the registrant’s name, street, postal code, phone and fax, and the technical contact’s name and phone. The city may also be redacted.

A redacted field must say so. Instead of the email address, the registrar publishes a relay address or web form that does not identify the person. The registrant can consent to publish A registrant's agreement to show contact details that would otherwise be redacted. Full definition of consent to publish redacted fields. Administrative and billing contacts are no longer required, and a domain using an affiliated or accredited privacy or proxy service shows the service’s data.

Companies versus individuals

The GDPR does not cover data about legal persons, such as a company’s name and contact details. Data about named staff is still personal data: in a letter received by ICANN on 5 July 2018, the European Data Protection Board said employees’ details should not be public by default, while publishing a generic role address would not be unlawful.

ICANN’s policy lets registries and registrars treat companies differently, but does not oblige them to. If the Registrant Organization field The optional field naming the organization that holds a domain, published when the registrant agrees. Full definition of Registrant Organization field is filled in, the organization becomes the registered name holder. Its name is published if the holder agrees; otherwise the registrar may redact it.

ccTLD country code top-level domain A top-level domain for a country or territory, usually two letters long. Full definition of ccTLD set their own rules. As of October 2026, the .eu web WHOIS shows only email and language for individuals, and adds company, city, region and country for organizations; the holder chooses the category.

Controllers, processors and who is responsible

A controller decides the purposes and means of processing personal data; a processor processes it on the controller’s behalf. Parties that decide together are joint controllers. A processor works under a contract that sets the subject, duration, nature and purpose of the processing: the data processing agreement The GDPR contract between an organization and a company processing data for it. Full definition of data processing agreement.

Which role ICANN, registries and registrars hold was debated for years. Today they must sign data protection agreements with each other where the law requires. A registry or registrar that needs one with ICANN requests the Data Processing Specification An optional contract add-on on how ICANN and contracted parties handle registration data lawfully. Full definition of Data Processing Specification, which treats both sides as independent controllers. ICANN says it is not a data processing agreement, and it covers any applicable data protection law, not only the GDPR.

How ICANN responded: from the Temporary Specification to current policy

  • 17 May 2018: the ICANN Board ICANN's board of directors, which adopts policies and approves key decisions. Full definition of ICANN Board adopts the Temporary Specification, in effect from 25 May 2018.
  • 15 May 2019: the Board adopts the Phase 1 recommendations of the EPDP Expedited Policy Development Process A faster ICANN policy process, best known for post-GDPR registration data work. Full definition of EPDP, with some exceptions.
  • 20 May 2019: the Interim Registration Data Policy The stopgap policy that kept Temporary Specification rules alive from 2019 until August 2025. Full definition of Interim Registration Data Policy keeps the Temporary Specification’s measures in place after it expires on 25 May 2019.
  • 10 March 2022: the Board adopts Phase 2A, on legal versus natural persons and anonymized email address A forwarding address or web form that reaches a registrant without showing the real email. Full definition of anonymized email address.
  • 21 August 2025: the Registration Data Policy, published on 21 February 2024, applies in full.

Requesters ask for hidden data through the disclosure process that every registrar and registry must link from its homepage. As of October 2026, receipt must be acknowledged within 2 business days and an answer given within 30 calendar days of acknowledgement, barring exceptional circumstances. A refusal must explain how the requester’s legitimate interest A GDPR ground for processing personal data, weighed against the registrant's privacy rights. Full definition of legitimate interest was weighed against the data subject’s rights. Shorter deadlines for urgent request An emergency request for hidden registration data, with a 24-hour answer deadline not yet in force. Full definition of urgent request are written into the policy but not yet in force.

As of October 2026, ICANN’s RDRS Registration Data Request Service ICANN's free service for requesting hidden gTLD registration data from participating registrars. Full definition of RDRS, piloted from 28 November 2023 to 30 November 2025 and extended for up to two more years, sends requests to participating registrars. It does not guarantee disclosure.

Rights of registrants under the GDPR

The GDPR provides rights of access, rectification, erasure, restriction of processing, data portability and objection (Articles 15 to 18, 20 and 21). The controller must reply within one month, extendable by two further months where necessary. Each right has conditions: erasure of data a registrar needs to keep a domain registered, for example, cannot be taken for granted.

A data subject can complain to a supervisory authority, in particular in the Member State where they live, work or where the alleged infringement took place. In Spain, the national supervisory authority is the Agencia Española de Protección de Datos (AEPD); regional authorities also exist. For a specific case, the registrar, the registry or a lawyer is the place to ask.

Sources