---
id: "registration-data"
kind: "glossary-term"
title: "registration data"
language: "en"
category: "Registration data and privacy"
updated: "2026-10-10T10:28:55Z"
canonical: "https://tldlog.com/glossary/registration-data/"
translations:
  es: "https://tldlog.com/es/glosario/datos-registro/"
  de: "https://tldlog.com/de/glossar/registrierungsdaten/"
  fr: "https://tldlog.com/fr/glossaire/donnees-enregistrement/"
  it: "https://tldlog.com/it/glossario/dati-registrazione/"
  pt-BR: "https://tldlog.com/pt/glossario/dados-registro/"
  ru: "https://tldlog.com/ru/glossariy/registratsionnye-dannye/"
  zh-Hans: "https://tldlog.com/zh/cihui/zhuce-shuju/"
---

# registration data

The information kept about a domain registration: the domain name, dates, registrar, name servers, status and the owner's contact details. Some of it is public through RDAP or WHOIS, but personal data is usually hidden. Rules differ between gTLDs and ccTLDs.

Registration data is the record kept about each domain name: who holds it, how to reach them, which registrar manages it, its name servers and its key dates. Part of it is public, while personal details are often hidden.

## What registration data is

For gTLDs, ICANN's Registration Data Policy defines it as values "collected from a natural or legal person or generated by" the registrar or registry operator. As of October 2026, the policy has been in force since 21 August 2025 and was last revised on 12 May 2026.

The holder supplies a name, postal address, phone number and email address, and may add an organization, name servers and DNSSEC details. The registrar adds its own name, IANA ID and abuse contacts, the domain statuses and the expiry date.

Country code domains (ccTLDs) follow national rules; for .es, Orden ITC/1542/2005 and the rules of Red.es. In the European Union, the NIS2 Directive requires member states to make registries and registrars keep "accurate and complete" data, including the holder's name, email address and phone number.

## Who collects it and who stores it: registry versus registrar

The registrar collects everything. It always sends the registry the domain-level data: the domain name, the registrar, the abuse contacts and the statuses. It sends the holder's contact details only "provided an appropriate legal basis exists and data processing agreement is in place". The registrar and the registry decide whether that basis exists, not ICANN.

This is the old split between thin and thick registries. A thin registry holds only domain-level data, and the registrar keeps the contacts; a thick registry holds both. When ICANN's Thick WHOIS policy was implemented, only .com, .net and .jobs were thin. A 2014 policy was meant to make them thick, but enforcement was deferred on 7 November 2019. As of October 2026, its requirements are set out in the Registration Data Policy.

The holder has duties too. As of October 2026, under the Registrar Accreditation Agreement (RAA), the details must be accurate and updated within 7 days of any change. Deliberately false details, or not answering the registrar's accuracy questions for over 15 days, can lead to suspension or cancellation.

## Contact types: registrant, admin, tech and billing

The 2013 RAA listed the registrant, an administrative contact and a technical contact in the public directory. Registrars also kept a billing contact, which they were never required to publish.

For gTLDs today:

- Registrant: required.
- Technical contact: optional, offered at the registrar's choice. The registrar must explain that the holder can name itself instead of giving another person's details.
- Administrative and billing contacts: removed from all collection, transfer, publication and escrow requirements.

The registrar must also offer the Registrant Organization field. If it is filled in, the organization is the holder, and the person named is only its point of contact. Registries may require extra fields, and ccTLDs keep their own contact sets.

## What is published and what is hidden

A gTLD lookup always shows the domain name, the registrar and its IANA ID, its abuse contacts, the creation and expiry dates, the statuses and the holder's country. Name servers and DNSSEC details appear when present.

Personal data must be redacted where the law requires it, and may be redacted for a commercially reasonable purpose; it is not a blanket rule. This covers the holder's name, street, postal code and phone, and the technical contact's name and phone. Instead of the email address, the registrar publishes an address or web form that reaches the contact without identifying it.

The holder can consent to publication, and the registrar must then publish. The organization is published if the holder agrees; if not, the registrar may hide it. With a privacy or proxy service, the service's details are shown.

Hidden data can be requested through a disclosure request. As of October 2026, the deadlines are acknowledgement within 2 business days and an answer within 30 calendar days. Deadlines for urgent requests (2 hours to acknowledge, 24 hours to answer) are adopted but, as of October 2026, not in force until ICANN implements a policy for authenticating requestors. NIS2 requires EU member states to set a 72-hour limit for access requests.

Under its 2010 rules, Red.es publishes only the personal data that is strictly necessary for .es names.

## How long data is kept, and backups

As of October 2026, a gTLD registrar must keep the data needed for the TDRP for at least 15 months after it stops managing the domain or after a change of registrant. Other RAA rules remain, such as 180 days for log files. The GDPR says personal data should be kept no longer than necessary.

Data escrow is a safety copy, not a public archive. As of October 2026, registries deposit a full copy every Sunday and a full or differential copy on the other six days. Registrars use an ICANN-designated agent at no charge, or an approved one at their own expense. If a registry or registrar contract ends, the copy is released so another operator can take over. It is not the escrow used in domain sales.

## Your data rights as a registrant

The registrar must tell each new or renewing holder why personal data is collected, who receives it (including the registry), which fields are required and how to access and correct them.

Where the GDPR applies, data protection law may give the right to access and correct data, to erasure on limited grounds, to object, and to complain to a supervisory authority. Answers are due within one month, extendable by two months where necessary. Registrars also have retention duties that can limit erasure.

## Sources

- [Registration Data Policy](https://www.icann.org/en/contracted-parties/consensus-policies/registration-data-policy)
- [Registration Data Policy Frequently Asked Questions](https://www.icann.org/en/system/files/files/registration-data-policy-faqs-21aug25-en.pdf)
- [Thick WHOIS Transition Policy for .COM, .NET, and .JOBS](https://www.icann.org/en/contracted-parties/consensus-policies/thick-registry-registration-data-directory-services-transition-policy/thick-whois-transition-policy-for-com-net-and-jobs-01-02-2017-en)
- [Registrar Data Escrow Program](https://www.icann.org/en/contracted-parties/accredited-registrars/services/registrar-data-escrow-program)

## related terms

- [RDAP](https://tldlog.com/glossary/rdap/)
- [WHOIS](https://tldlog.com/glossary/whois/)
- [redaction](https://tldlog.com/glossary/redaction/)
- [Registration Data Policy](https://tldlog.com/glossary/registration-data-policy/)
