registration data

The information kept about a domain registration Obtaining the right to use a domain name for a set period. Full definition of registration: the domain name A readable internet name made of labels separated by dots. Full definition of domain name, dates, registrar A company that registers domain names for customers with the registry. Full definition of registrar, name server A server that holds a domain's DNS records and answers lookups. Full definition of name server, status and the owner's contact details. Some of it is public through RDAP Registration Data Access Protocol The modern protocol for looking up domain registration data, replacing WHOIS. Full definition of RDAP or WHOIS The legacy lookup service for domain registration data, now replaced by RDAP for gTLDs. Full definition of WHOIS, but personal data is usually hidden. Rules differ between gTLD generic top-level domain A top-level domain not tied to a country, run under ICANN contracts. Full definition of gTLD and ccTLD country code top-level domain A top-level domain for a country or territory, usually two letters long. Full definition of ccTLD.

category
Registration data and privacy

Updated on 4 min read

Registration data is the record kept about each domain name: who holds it, how to reach them, which registrar manages it, its name servers and its key dates. Part of it is public, while personal details are often hidden.

What registration data is

For gTLDs, ICANN Internet Corporation for Assigned Names and Numbers The nonprofit that coordinates the global DNS and gTLD policy. Full definition of ICANN’s Registration Data Policy ICANN's policy on collecting, publishing and disclosing gTLD registration data. Full definition of Registration Data Policy defines it as values “collected from a natural or legal person or generated by” the registrar or registry operator The organization that holds the contract or mandate for a TLD and sets its rules. Full definition of registry operator. As of October 2026, the policy has been in force since 21 August 2025 and was last revised on 12 May 2026.

The holder supplies a name, postal address, phone number and email address, and may add an organization, name servers and DNSSEC Domain Name System Security Extensions Digital signatures that prove DNS answers are genuine and unchanged. Full definition of DNSSEC details. The registrar adds its own name, IANA registrar ID The unique number that identifies an ICANN-accredited registrar. Full definition of IANA registrar ID and abuse contact The published contact where registrars and registries receive abuse reports. Full definition of abuse contact, the domain statuses and the expiry date.

Country code domains (ccTLDs) follow national rules; for .es, Orden ITC/1542/2005 and the rules of Red.es The Spanish public body that manages the .es domain through its unit Dominios.es. Full definition of Red.es. In the European Union, the NIS2 Directive on measures for a high common level of cybersecurity across the Union A European Union cybersecurity directive with rules on accurate domain registration data. Full definition of NIS2 Directive requires member states to make registry The central database and system of a top-level domain, or loosely the organization that runs it. Full definition of registry and registrars keep “accurate and complete” data, including the holder’s name, email address and phone number.

Who collects it and who stores it: registry versus registrar

The registrar collects everything. It always sends the registry the domain-level data: the domain name, the registrar, the abuse contacts and the statuses. It sends the holder’s contact details only “provided an appropriate legal basis exists and data processing agreement The GDPR contract between an organization and a company processing data for it. Full definition of data processing agreement is in place”. The registrar and the registry decide whether that basis exists, not ICANN.

This is the old split between thin and thick registry A registry that holds full owner data, not only technical data. Full definition of thick registry. A thin registry A registry that holds only technical data while registrars keep owner data. Full definition of thin registry holds only domain-level data, and the registrar keeps the contacts; a thick registry holds both. When ICANN’s Thick WHOIS policy was implemented, only .com, .net and .jobs were thin. A 2014 policy was meant to make them thick, but enforcement was deferred on 7 November 2019. As of October 2026, its requirements are set out in the Registration Data Policy.

The holder has duties too. As of October 2026, under the RAA Registrar Accreditation Agreement The contract between ICANN and each accredited registrar. Full definition of RAA (RAA), the details must be accurate and updated within 7 days of any change. Deliberately false details, or not answering the registrar’s accuracy questions for over 15 days, can lead to suspension or cancellation.

Contact types: registrant, admin, tech and billing

The 2013 RAA listed the registrant The person or organization that holds a domain name registration. Full definition of registrant, an administrative contact and a technical contact in the public directory. Registrars also kept a billing contact, which they were never required to publish.

For gTLDs today:

  • Registrant: required.
  • Technical contact: optional, offered at the registrar’s choice. The registrar must explain that the holder can name itself instead of giving another person’s details.
  • Administrative and billing contacts: removed from all collection, transfer, publication and escrow A neutral service holding payment until a domain is transferred. Full definition of escrow requirements.

The registrar must also offer the Registrant Organization field The optional field naming the organization that holds a domain, published when the registrant agrees. Full definition of Registrant Organization field. If it is filled in, the organization is the holder, and the person named is only its point of contact. Registries may require extra fields, and ccTLDs keep their own contact sets.

What is published and what is hidden

A gTLD lookup always shows the domain name, the registrar and its IANA ID, its abuse contacts, the creation and expiry dates, the statuses and the holder’s country. Name servers and DNSSEC details appear when present.

Personal data must be redacted where the law requires it, and may be redacted for a commercially reasonable purpose; it is not a blanket rule. This covers the holder’s name, street, postal code and phone, and the technical contact’s name and phone. Instead of the email address, the registrar publishes an address or web form that reaches the contact without identifying it.

The holder can consent to publication, and the registrar must then publish. The organization is published if the holder agrees; if not, the registrar may hide it. With a privacy or proxy service, the service’s details are shown.

Hidden data can be requested through a disclosure request A request for hidden domain registration data, with reasons given. Full definition of disclosure request. As of October 2026, the deadlines are acknowledgement within 2 business days and an answer within 30 calendar days. Deadlines for urgent request An emergency request for hidden registration data, with a 24-hour answer deadline not yet in force. Full definition of urgent request (2 hours to acknowledge, 24 hours to answer) are adopted but, as of October 2026, not in force until ICANN implements a policy for authenticating requestors. NIS2 requires EU member states to set a 72-hour limit for access requests.

Under its 2010 rules, Red.es publishes only the personal data that is strictly necessary for .es names.

How long data is kept, and backups

As of October 2026, a gTLD registrar must keep the data needed for the TDRP Transfer Dispute Resolution Policy ICANN's process for registrars to dispute a transfer that may have broken the rules. Full definition of TDRP for at least 15 months after it stops managing the domain or after a change of registrant A change of a domain's owner details, with confirmation steps. Full definition of change of registrant. Other RAA rules remain, such as 180 days for log files. The GDPR General Data Protection Regulation The European Union data protection law that led to hiding personal data in WHOIS. Full definition of GDPR says personal data should be kept no longer than necessary.

data escrow Backup copies of registration data held by an independent agent in case a registry or registrar fails. Full definition of data escrow is a safety copy, not a public archive. As of October 2026, registries deposit a full copy every Sunday and a full or differential copy on the other six days. Registrars use an ICANN-designated agent at no charge, or an approved one at their own expense. If a registry or registrar contract ends, the copy is released so another operator can take over. It is not the escrow used in domain sales.

Your data rights as a registrant

The registrar must tell each new or renewing holder why personal data is collected, who receives it (including the registry), which fields are required and how to access and correct them.

Where the GDPR applies, data protection law may give the right to access and correct data, to erasure on limited grounds, to object, and to complain to a supervisory authority. Answers are due within one month, extendable by two months where necessary. Registrars also have retention duties that can limit erasure.

Sources