---
id: "gdpr"
kind: "glossary-term"
title: "GDPR"
language: "en"
category: "Registration data and privacy"
updated: "2026-10-10T10:28:55Z"
canonical: "https://tldlog.com/glossary/gdpr/"
translations:
  es: "https://tldlog.com/es/glosario/rgpd/"
  de: "https://tldlog.com/de/glossar/dsgvo/"
  fr: "https://tldlog.com/fr/glossaire/rgpd/"
  it: "https://tldlog.com/it/glossario/gdpr/"
  pt-BR: "https://tldlog.com/pt/glossario/rgpd/"
  ru: "https://tldlog.com/ru/glossariy/gdpr/"
  zh-Hans: "https://tldlog.com/zh/cihui/gdpr/"
---

# GDPR

General Data Protection Regulation

The European Union law on personal data that has applied since May 2018. It led registries and registrars to hide most personal data from public WHOIS. ICANN responded with a Temporary Specification and later the Registration Data Policy.

The General Data Protection Regulation (GDPR) is the European Union law that protects personal data. It is the main reason a domain lookup today rarely shows the owner's name, address or phone number.

## What the GDPR is and why it changed domain data

The GDPR is [Regulation (EU) 2016/679](https://www.boe.es/buscar/doc.php?id=DOUE-L-2016-80807), adopted on 27 April 2016 and applied from 25 May 2018. It protects personal data: any information about an identified or identifiable living person, called the data subject. It applies to processing in the context of an establishment in the Union, wherever the processing happens, and can also reach controllers outside the Union that offer services to people there.

ICANN said that, without changes to its contracts, registries and registrars could not comply with both the law and those contracts. Fines under the GDPR can reach EUR 20 million or 4 % of a company's worldwide annual turnover, whichever is higher.

## What is hidden now and what is still public

As of October 2026, ICANN's Registration Data Policy (in force since 21 August 2025, last revised on 12 May 2026) sets the rules for gTLDs:

- Always public: the domain name, the registrar with its URL, IANA registrar ID and abuse contacts, the creation and expiry dates, the statuses, and the registrant's country (and state or province, if collected).
- Redacted where the law requires it, and allowed where commercially reasonable: the registrant's name, street, postal code, phone and fax, and the technical contact's name and phone. The city may also be redacted.

A redacted field must say so. Instead of the email address, the registrar publishes a relay address or web form that does not identify the person. The registrant can consent to publish redacted fields. Administrative and billing contacts are no longer required, and a domain using an affiliated or accredited privacy or proxy service shows the service's data.

## Companies versus individuals

The GDPR does not cover data about legal persons, such as a company's name and contact details. Data about named staff is still personal data: in a letter received by ICANN on 5 July 2018, the European Data Protection Board said employees' details should not be public by default, while publishing a generic role address would not be unlawful.

ICANN's policy lets registries and registrars treat companies differently, but does not oblige them to. If the Registrant Organization field is filled in, the organization becomes the registered name holder. Its name is published if the holder agrees; otherwise the registrar may redact it.

ccTLDs set their own rules. As of October 2026, the .eu web WHOIS shows only email and language for individuals, and adds company, city, region and country for organizations; the holder chooses the category.

## Controllers, processors and who is responsible

A controller decides the purposes and means of processing personal data; a processor processes it on the controller's behalf. Parties that decide together are joint controllers. A processor works under a contract that sets the subject, duration, nature and purpose of the processing: the data processing agreement.

Which role ICANN, registries and registrars hold was debated for years. Today they must sign data protection agreements with each other where the law requires. A registry or registrar that needs one with ICANN requests the Data Processing Specification, which treats both sides as independent controllers. ICANN says it is not a data processing agreement, and it covers any applicable data protection law, not only the GDPR.

## How ICANN responded: from the Temporary Specification to current policy

- 17 May 2018: the ICANN Board adopts the Temporary Specification, in effect from 25 May 2018.
- 15 May 2019: the Board adopts the Phase 1 recommendations of the EPDP, with some exceptions.
- 20 May 2019: the Interim Registration Data Policy keeps the Temporary Specification's measures in place after it expires on 25 May 2019.
- 10 March 2022: the Board adopts Phase 2A, on legal versus natural persons and anonymized email addresses.
- 21 August 2025: the Registration Data Policy, published on 21 February 2024, applies in full.

Requesters ask for hidden data through the disclosure process that every registrar and registry must link from its homepage. As of October 2026, receipt must be acknowledged within 2 business days and an answer given within 30 calendar days of acknowledgement, barring exceptional circumstances. A refusal must explain how the requester's legitimate interest was weighed against the data subject's rights. Shorter deadlines for urgent requests are written into the policy but not yet in force.

As of October 2026, ICANN's RDRS, piloted from 28 November 2023 to 30 November 2025 and extended for up to two more years, sends requests to participating registrars. It does not guarantee disclosure.

## Rights of registrants under the GDPR

The GDPR provides rights of access, rectification, erasure, restriction of processing, data portability and objection (Articles 15 to 18, 20 and 21). The controller must reply within one month, extendable by two further months where necessary. Each right has conditions: erasure of data a registrar needs to keep a domain registered, for example, cannot be taken for granted.

A data subject can complain to a supervisory authority, in particular in the Member State where they live, work or where the alleged infringement took place. In Spain, the national supervisory authority is the Agencia Española de Protección de Datos (AEPD); regional authorities also exist. For a specific case, the registrar, the registry or a lawyer is the place to ask.

## Sources

- [Registration Data Policy](https://www.icann.org/en/contracted-parties/consensus-policies/registration-data-policy)
- [Temporary Specification for gTLD Registration Data](https://www.icann.org/en/contracted-parties/generic-top-level-domains/temporary-specification-for-gtld-registration-data-01-01-2020-en)
- [Data Processing Specification (DPS) Requests](https://www.icann.org/en/contracted-parties/consensus-policies/registration-data-policy/data-processing-specification-requests)
- [Registration Data Request Service](https://www.icann.org/rdrs-en)

## related terms

- [Temporary Specification](https://tldlog.com/glossary/temporary-specification/)
- [redaction](https://tldlog.com/glossary/redaction/)
- [Registration Data Policy](https://tldlog.com/glossary/registration-data-policy/)
- [WHOIS](https://tldlog.com/glossary/whois/)
