When the European GDPR came into force in May 2018, the public WHOIS system, which listed names, addresses and phone numbers of domain holders, ran into a legal wall. Registrars began redacting personal data, and a new lookup protocol, RDAP, was introduced.
Spam to domain owners dropped, and investigators lost a convenient tool. The episode also made cookie banners and privacy policies part of ordinary website ownership.
If you registered a domain before 2018 and never paid for privacy protection, your home address was probably public for years. This chapter covers how that changed, what replaced it, and what the same law meant for anyone running a website.
What WHOIS was
WHOIS is older than the web. It began as a simple text service on TCP port 43 for finding out who was responsible for a machine or network, and it was carried over to domain names when they became commercial. The rule that registrants must supply accurate contact details, and that those details would be published, was written into the contracts between ICANN and registrars.
That served some real purposes. Engineers used it to contact whoever ran a misbehaving server. Trademark owners used it to find infringers. Journalists and researchers used it to connect a set of suspicious domains to one owner. It also gave anybody who wanted it a free, searchable list of names, postal addresses, email addresses and phone numbers, and spammers and scam mailers duly collected them.
Many registrars had long sold a privacy option that replaced your details with the registrar's own. It was useful, but it was an extra, and plenty of owners did not know it existed.
The legal collision
The General Data Protection Regulation applied from 25 May 2018. It governs personal data about people in the EU, and it requires a lawful reason for publishing it and limits on how much is published. Putting a private individual's home address on a public website for anyone to download did not fit comfortably within those rules. Registrars and registries, many of them with European customers or operations, could not wait for the argument to be settled.
Just before the deadline, ICANN adopted a temporary specification that let contracted parties redact personal data from the public output. In practice most registrars hid the registrant's name, street address, email and phone number for everyone, not just for people in Europe, because separating them was harder than hiding the lot. Anonymised contact methods took the place of the email address: a web form, or a forwarding address that changed regularly.
RDAP arrives
WHOIS had other faults that the privacy debate made impossible to ignore. Its output was free-form text with no standard layout, each registry formatted it differently, it had no real support for authentication, and it could not tell a casual enquirer from a law enforcement officer. The Registration Data Access Protocol, standardised in 2015, was designed to fix this. It runs over HTTPS, returns structured JSON, and can give different answers to different users.
ICANN required gTLD registries and registrars to support RDAP from 2019, and later relaxed the old port 43 requirement. You can try it from any terminal:
whois example.com
curl -s https://rdap.org/domain/example.com
The second command asks a bootstrap service which registry holds the record and redirects you there; add -L to follow it. What comes back is machine-readable, which made automated checks easier. The compromise for access was a request process: people with a legitimate interest, such as a security team investigating a phishing campaign, could ask the registrar for the hidden details, and answers were often slow.
Consequences for site owners
The immediate effect was welcome. Unsolicited sales mail and fake renewal invoices to domain contacts fell for many owners. Domain owners no longer had to buy privacy as a separate item to keep their address out of public view.
The cost fell on investigators. Abuse teams, who once could look up an owner in seconds, now filed requests. Anyone looking for a missing owner of a domain had to go through the registrar.
The law also changed websites. GDPR requires a lawful basis for processing personal data and, where that basis is consent, a consent that is freely given and can be withdrawn. Analytics scripts, embedded video, advertising tags and contact forms all collect something. The result was the consent banner, then a privacy policy on almost every site, then a steady flow of support questions about whether a small shop needed one. The glossary defines the terms; for a specific legal question, ask a lawyer rather than a hosting engineer.