Domain Yoga

GDPR, WHOIS privacy, and your domain: what EU founders should know

By Domain Yoga · Last updated July 28, 2026

GDPR means that when you register a domain as an individual, your name, address, email, and phone number are no longer published in the public WHOIS record by default. Since 2018 — when GDPR took effect and ICANN issued a matching policy for generic TLDs — public lookups typically show REDACTED FOR PRIVACY where personal contact details used to sit in plain view. But that emphasis on individual now carries real weight: the EU’s NIS-2 Directive is putting company registration data back into public view, registry by registry, as member states transpose it. If you register as a business, the 2018 default is being undone for you. Here’s what changed, what it means for those paid “WHOIS privacy” add-ons, and how anyone still reaches you.

What are WHOIS and RDAP, and what did GDPR change?

WHOIS is the decades-old public directory of domain registrations: a plaintext lookup protocol that answered “who registered this domain, when, through which registrar, and how do I contact them?” For most of its history, that answer included the registrant’s real name, postal address, email, and phone number — published openly for anyone, including spammers and scrapers, to read.

GDPR ended that. The regulation took effect on 25 May 2018, and days earlier — on 17 May 2018 — ICANN adopted a Temporary Specification for gTLD Registration Data directing registries and registrars to redact personal contact data from public WHOIS for registrants covered by GDPR. In practice, most registrars didn’t build separate pipelines for EU and non-EU customers: they apply one policy everywhere, so personal data for individual registrants is now redacted by default across most generic TLDs regardless of where the registrant lives. Organisation and business names, by contrast, are often still displayed.

The protocol itself has moved on too. RDAP (Registration Data Access Protocol) is WHOIS’s modern successor — structured, HTTPS-based, returning JSON instead of free-form text, and designed with tiered access in mind. As of 28 January 2025, RDAP became the definitive source for generic-TLD registration data in place of sunsetted WHOIS services. Since then, gTLD registries and registrars are generally no longer required to operate WHOIS at all — the legacy exceptions still requiring it are narrow, .com, .name and .post — though many run it alongside RDAP.

One caveat for European founders: country-code TLDs like .de, .fr, .nl, and .eu are not ICANN-contracted. GDPR applies to those EU-based registries directly, but both their publication policies and their RDAP adoption are their own decisions — so don’t assume the gTLD pattern carries over one-to-one. Check the specific registry’s policy for the ccTLD you’re using. As the next section shows, that divergence has become much more consequential than it was.

Is NIS-2 putting company data back in public?

Yes — if you register as a company. This is the most important change since 2018, and it runs in the opposite direction to everything above.

The EU’s NIS-2 Directive (2022/2555) includes an article on domain registration data requiring TLD registries and “entities providing domain name registration services” to keep accurate, complete registration data, publish verification procedures, make non-personal registration data publicly available without undue delay, and disclose specific data to legitimate access seekers on lawful, substantiated requests within 72 hours.

The mechanism that decides who is affected is worth understanding, because it’s clean: NIS-2 requires publication of registration data other than personal data. Under GDPR, “personal data” protects natural persons only. So a legal entity’s registration details fall outside that protection and get published, while an individual’s stay redacted. Companies lose the shield; people keep it.

Two consequences catch people out:

  • A privacy service cannot save you. Privacy and proxy providers are themselves within scope as entities providing registration services, so buying an add-on does not exempt a company from publication in a jurisdiction where this applies.
  • Sole traders can be caught by accident. If you fill in a “Company” field during registration, some registrars will classify you as an organisation and stop redacting — even though as a natural person you’d otherwise be protected. If you’re a freelancer or sole trader, leaving that field empty is the difference.

There is no single EU-wide switch-on date, and this is where most write-ups oversimplify. NIS-2 is a directive, so it binds only as each member state transposes it. The deadline was 17 October 2024; roughly 20 of 27 states had completed transposition by mid-2026, and in July 2026 the European Commission referred Ireland, Spain, France and the Netherlands to the Court of Justice over incomplete transposition. What that means in practice varies enormously by registry:

RegistryStatusWhat’s published for legal entities
DENIC (.de)Live since 6 December 2025; a second phase adding automated risk assessment followed in April 2026Name, full postal address, email, phone, registration date, sponsoring registrar
EURid (.eu)Live since around October 2024, following Belgium’s early transpositionOrganisation name, city and country, email — no street address, no phone
AFNIC (.fr)Publishes organisation data, but under long-standing French domestic law — France had not transposed NIS-2 at the time of writingOrganisation name and address
SIDN (.nl)Not yet — the Dutch implementing law was due to enter force in August 2026Not yet applicable
Nominet (.uk)Out of scope — the UK is not an EU memberUnchanged; registrant details redacted absent consent

Note how differently DENIC and EURid interpret the same obligation: one publishes a full postal address and phone number, the other deliberately doesn’t. “NIS-2 applies” tells you very little on its own.

And this reaches .com, which surprises people. The obligation attaches to the registrar, not the TLD — so a company registering a .com through an EU-established registrar can have its details published under that registrar’s home-state law, even though .com itself carries no NIS-2 obligation. IONOS, for instance, announced it would publish legal-entity contact details across all the TLDs it sells and permanently removed the privacy toggle for company registrations. That’s one registrar’s policy rather than a universal rule, but the legal logic behind it applies broadly, so check your own registrar rather than assuming your .com is unaffected.

Do you still need paid WHOIS privacy as an EU registrant?

For most individual registrants: probably not, because the thing paid privacy services originally sold — keeping your home address and personal email out of a public database — is now the default for personal data on most gTLDs. What used to be a paid upsell became baseline behaviour in 2018, and less data is even collected now: ICANN’s Registration Data Policy, in force since 21 August 2025, defines a “Minimum Data Set” in which only the registrant contact is mandatory, with admin, billing and technical contacts no longer required by default.

But “probably not” deserves its footnotes:

  • Registering as a company? Paid privacy no longer works for you at all in jurisdictions where NIS-2 applies. This is a change from the older advice that a company name is “often still shown” — where the directive is transposed, publication of your legal entity’s data is a legal requirement, and the proxy service you’d have bought to avoid it is itself covered by the same rule. Budget for being visible rather than for hiding.
  • Registrar policies differ at the edges. Redaction is the norm, not a law of physics. Before relying on it, run a lookup on a domain you already own and see exactly what your registrar publishes.
  • ccTLDs play by their own rules. Each European registry sets its own policy on what appears in public lookups, so verify per TLD rather than assuming — and see the table above for how far apart those policies now sit.

Equally important is what redaction is not: anonymity. Your registrar still collects and holds your full, accurate contact details — you’re contractually required to provide them — and those details remain reachable through disputes and legal process. GDPR changed who can casually read your data, not whether it exists or whether you’re accountable for the domain.

How can someone reach or dispute a redacted domain owner?

Redaction raised an obvious worry: if the registrant is hidden, how does anyone report abuse, make a purchase offer, or enforce a trademark? Three channels survived the change intact.

Registrar relay. Registrars are required to provide some way to contact a redacted registrant — typically a web contact form or an anonymised forwarding email published in the record. Messages reach the owner without exposing their real address. This is also why keeping your registrant email current matters: a genuine offer or a legal notice may arrive through that relay.

UDRP. The Uniform Domain-Name Dispute-Resolution Policy — administered by providers such as WIPO — works fine against a REDACTED FOR PRIVACY listing. A complainant files against the domain as listed; once the complaint passes the compliance check, the provider asks the registrar to confirm the underlying registrant’s identity and lock the domain, typically within about two business days, and the confirmed identity is used for the proceeding. In other words, redaction is no shield for bad-faith registrations against someone else’s mark — which is exactly why the searches in our guide to trademark basics before you register belong before checkout, not after a dispute notice arrives.

Courts. For disputes that don’t fit the UDRP’s narrow scope, ordinary legal process still applies: a court order or subpoena can compel a registrar to disclose the registrant behind a redacted record.

Two newer routes have since been added, and both are faster than going to court. On generic TLDs, ICANN’s Registration Data Policy sets out a disclosure request process: a contracted party must acknowledge a request within two business days and respond within 30 calendar days, with urgent cases — an imminent threat to life, to critical infrastructure, or child exploitation — carrying a 24-hour response requirement added in 2026. ICANN also runs a Registration Data Request Service, a central portal through which legitimate access seekers such as law-enforcement, IP and cybersecurity professionals can submit standardised requests to participating registrars instead of approaching each one separately; it began as a pilot and has been extended while ICANN evaluates it. And in NIS-2 jurisdictions the ccTLD timeline is stricter still, because it’s statutory rather than contractual: disclosure to legitimate access seekers within 72 hours, or 24 for urgent cases.

The practical upshot for a registrant hasn’t changed, but it’s worth stating plainly: the paths to your identity are getting faster and more formalised, not slower.

What should you take away before your next registration?

Four things now. First, registering as an individual on a gTLD, your personal data is redacted by default — the paid privacy add-on mostly duplicates what GDPR already gave you, though it costs nothing to verify what your registrar actually publishes. Second, registering as a company in the EU, expect the opposite: NIS-2 is making your entity’s details public, a privacy service won’t prevent it, and if you’re a sole trader, filling in a company field may cost you protection you’d otherwise have. Third, for ccTLDs, check the registry’s own policy rather than assuming — the gap between what DENIC and EURid publish under the same directive shows how far apart those policies sit. Our guide to European country-code domains goes registry by registry.

Fourth, and unchanged: privacy by default was never immunity. Relay channels, the UDRP, disclosure requests and courts all still reach you — faster now than they did — so the accuracy of your registration data and the legal cleanliness of your name still matter. If a name is worth building on, it’s worth clearing before you buy it, which is what trademark basics and the pre-registration checklist are for.

Best done while you’re still choosing. A Domain Yoga search returns around 250 availability-checked ideas ranked for brandability using our published methodology, at $2–$5 per search — so the time goes on the checks that protect a name rather than on hunting for one.