---
id: "privacy-proxy-service"
kind: "glossary-term"
title: "privacy/proxy service"
language: "en"
category: "Registration data and privacy"
updated: "2026-10-10T10:28:55Z"
canonical: "https://tldlog.com/glossary/privacy-proxy-service/"
translations:
  es: "https://tldlog.com/es/glosario/servicio-privacidad-representacion/"
  de: "https://tldlog.com/de/glossar/privacy-proxy-dienst/"
  fr: "https://tldlog.com/fr/glossaire/service-confidentialite-proxy/"
  it: "https://tldlog.com/it/glossario/servizio-privacy-proxy/"
  pt-BR: "https://tldlog.com/pt/glossario/servico-privacidade-proxy/"
  ru: "https://tldlog.com/ru/glossariy/sluzhba-konfidentsialnosti-proksi/"
  zh-Hans: "https://tldlog.com/zh/cihui/yinsi-daili-fuwu/"
---

# privacy/proxy service

A service that keeps a registrant's personal contact details out of public registration data. A privacy service lists the real registrant with other contact details. A proxy service registers the name itself and lets the customer use it. Details may still be disclosed, for example after legal requests.

A privacy or proxy service keeps a domain owner's own contact details out of the public registration record and shows the service's details instead. Messages can reach the owner through the service, and in some situations the owner's identity can be revealed. The two kinds differ in who is legally the registrant.

## What a privacy or proxy service is

It is an add-on to a domain name registration, offered by the registrar, a company affiliated with it, a reseller, or an unrelated company. Instead of the customer's name, address, email and phone number, the public registration data (the RDDS: today mainly RDAP, historically WHOIS) show the provider's contact details.

For gTLDs, the rules are in the Specification on Privacy and Proxy Registrations, part of the RAA that every ICANN-accredited registrar signs (current text approved on 21 January 2024). For services offered by the registrar, its affiliates or resellers, the provider must publish its terms and price, a contact for reporting abuse or infringement of trademarks and other rights, and the circumstances in which it relays messages, ends the service and reveals the customer.

The registrar keeps the customer's real contact details and includes them in its data escrow deposits. Registrants are entitled to know which provider is affiliated with their registrar, and must not face deceptive notices or hidden fees.

What counts is how a service works, not its marketing name ("WHOIS privacy", "ID protection", "proxy").

## Privacy versus proxy: who is the legal holder

- **Privacy service:** the customer is the registrant. Only the contact details shown publicly belong to the provider.
- **Proxy service:** the provider is the registrant of record and licenses the use of the name to the customer, whose position depends on its contract with the provider.

As of October 2026, under the RAA, anyone who licenses a name to someone else remains the registrant of record and accepts liability for harm caused by wrongful use of the name, unless it discloses the licensee's identity and contact details within seven days to a party that provides reasonable evidence of actionable harm.

## How messages reach you

Relay means the provider forwards a third party's message to the customer, or tells the customer that someone is trying to make contact. Under the current specification, each provider decides when it relays and publishes those circumstances.

The PPSAI recommendations, adopted but not yet in force, would set common rules: relay every communication required by the RAA and ICANN consensus policies, and either all other electronic requests (with spam filters allowed) or at least those alleging domain name abuse. Requesters would be told about a persistent delivery failure.

A separate mechanism needs no privacy service. When a gTLD registrar redacts personal data under the Registration Data Policy, it must publish an anonymized email address or a web form that does not identify the contact. For a name using an affiliated privacy or proxy service, nothing is redacted: the provider's full data are published, possibly with its pseudonymized email.

## When your details can be revealed

Reveal covers two actions: disclosure, to one requester, and publication, in the public record. Today each provider reveals according to its published terms. The PPSAI recommendations, not yet in force, would add a framework for requests from trademark and copyright owners; a future framework for law enforcement requests would include an exception for the customer's safety.

Another route is the UDRP: when a UDRP complaint names the privacy or proxy service, the registrar or the service may disclose the underlying registrant. WIPO passes those details to the complainant, invites it to amend the complaint, and notifies all contacts, including the underlying registrant.

An example: the registrant of example.com uses its registrar's affiliated privacy service, so the RDAP record shows the service's details. A trademark owner writes to the service's abuse contact, and the message may be forwarded according to its published relay terms. If the trademark owner then files a UDRP complaint against the service, the registrant's details may be disclosed and, if the complaint is filed with WIPO, the registrant is notified.

## The unfinished accreditation

The PPSAI policy work is meant to replace the specification with an accreditation program. The ICANN Board adopted its 21 recommendations on 9 August 2016. Implementation paused in 2019 because of the GDPR work and restarted in June 2024. ICANN published an Implementation Plan in January 2026; as of its May 2026 briefing, no draft consensus policy had been shared. One open question was whether a standalone program is needed at all. As of October 2026, no provider is accredited, and the RAA specification, first set to expire on 1 January 2017, still applies.

## Is it still needed after the GDPR?

Under the Registration Data Policy (in force since 21 August 2025, revised on 12 May 2026), gTLD registrars must redact personal data where the law requires it and may do so in other cases. They may consider whether the registrant is a company and where it is located. Redaction is not guaranteed: the GDPR does not cover data about companies, and a registrant can consent to publication.

In the European Union (EU), the NIS2 Directive requires registries and registrars, through each member state's law, to collect accurate registration data, publish the data that are not personal, and answer access requests within 72 hours (as of October 2026). A privacy service does not change what the registrar must collect.

For an individual in the EU at a gTLD registrar, redaction already hides most personal data. A privacy or proxy service mainly adds a consistent masked contact, coverage where redaction is optional and, with a proxy, a different registrant of record. Country-code domains follow the rules each registry publishes.

## Sources

- [Registrar Accreditation Agreement (RAA) & Related Materials](https://www.icann.org/en/contracted-parties/accredited-registrars/registrar-accreditation-agreement)
- [Registration Data Policy](https://www.icann.org/en/contracted-parties/consensus-policies/registration-data-policy)
- [PRSP Pre-ICANN86 Briefing (May 2026)](https://www.icann.org/en/system/files/files/prsp-pre-icann86-briefing-18may26-en.pdf)

## related terms

- [WHOIS](https://tldlog.com/glossary/whois/)
- [RDAP](https://tldlog.com/glossary/rdap/)
- [redaction](https://tldlog.com/glossary/redaction/)
- [disclosure request](https://tldlog.com/glossary/disclosure-request/)
- [registrant](https://tldlog.com/glossary/registrant/)
