Hosting Through the Years / 2018: Privacy law reshapes the registry

2018: Privacy law reshapes the registry

HISTORY

4 min read · 834 words

When the European GDPR came into force in May 2018, the public WHOIS system, which listed names, addresses and phone numbers of domain holders, ran into a legal wall. Registrars began redacting personal data, and a new lookup protocol, RDAP, was introduced.

Spam to domain owners dropped, and investigators lost a convenient tool. The episode also made cookie banners and privacy policies part of ordinary website ownership.

If you registered a domain before 2018 and never paid for privacy protection, your home address was probably public for years. This chapter covers how that changed, what replaced it, and what the same law meant for anyone running a website.

What WHOIS was

WHOIS is older than the web. It began as a simple text service on TCP port 43 for finding out who was responsible for a machine or network, and it was carried over to domain names when they became commercial. The rule that registrants must supply accurate contact details, and that those details would be published, was written into the contracts between ICANN and registrars.

That served some real purposes. Engineers used it to contact whoever ran a misbehaving server. Trademark owners used it to find infringers. Journalists and researchers used it to connect a set of suspicious domains to one owner. It also gave anybody who wanted it a free, searchable list of names, postal addresses, email addresses and phone numbers, and spammers and scam mailers duly collected them.

Many registrars had long sold a privacy option that replaced your details with the registrar's own. It was useful, but it was an extra, and plenty of owners did not know it existed.

The General Data Protection Regulation applied from 25 May 2018. It governs personal data about people in the EU, and it requires a lawful reason for publishing it and limits on how much is published. Putting a private individual's home address on a public website for anyone to download did not fit comfortably within those rules. Registrars and registries, many of them with European customers or operations, could not wait for the argument to be settled.

Just before the deadline, ICANN adopted a temporary specification that let contracted parties redact personal data from the public output. In practice most registrars hid the registrant's name, street address, email and phone number for everyone, not just for people in Europe, because separating them was harder than hiding the lot. Anonymised contact methods took the place of the email address: a web form, or a forwarding address that changed regularly.

Before May 2018 (example)After (typical)Domain: example.comName: A. ExampleStreet: 1 High StreetEmail: [email protected]Phone: +00 000 0000Domain: example.comName: REDACTED FOR PRIVACYStreet: REDACTED FOR PRIVACYEmail: contact form onlyRegistrar: still shown
The registrar, dates and name servers stayed public. The person behind the registration mostly did not.

RDAP arrives

WHOIS had other faults that the privacy debate made impossible to ignore. Its output was free-form text with no standard layout, each registry formatted it differently, it had no real support for authentication, and it could not tell a casual enquirer from a law enforcement officer. The Registration Data Access Protocol, standardised in 2015, was designed to fix this. It runs over HTTPS, returns structured JSON, and can give different answers to different users.

ICANN required gTLD registries and registrars to support RDAP from 2019, and later relaxed the old port 43 requirement. You can try it from any terminal:

whois example.com
curl -s https://rdap.org/domain/example.com

The second command asks a bootstrap service which registry holds the record and redirects you there; add -L to follow it. What comes back is machine-readable, which made automated checks easier. The compromise for access was a request process: people with a legitimate interest, such as a security team investigating a phishing campaign, could ask the registrar for the hidden details, and answers were often slow.

WHOISRDAPTransport: TCP port 43Output: free-form textLayout: differs per registryAccess: same answer for allTransport: HTTPSOutput: structured JSONLayout: one standard formatAccess: can differ by user
RDAP keeps the same purpose as WHOIS but fixes its format and gives registries a way to control who sees what.

Consequences for site owners

The immediate effect was welcome. Unsolicited sales mail and fake renewal invoices to domain contacts fell for many owners. Domain owners no longer had to buy privacy as a separate item to keep their address out of public view.

The cost fell on investigators. Abuse teams, who once could look up an owner in seconds, now filed requests. Anyone looking for a missing owner of a domain had to go through the registrar.

Redacted does not mean your contact details are optional. Keep the email on your domain registration valid. Transfers, expiry warnings and verification messages are sent there, and a dead address is how people lose domains.

The law also changed websites. GDPR requires a lawful basis for processing personal data and, where that basis is consent, a consent that is freely given and can be withdrawn. Analytics scripts, embedded video, advertising tags and contact forms all collect something. The result was the consent banner, then a privacy policy on almost every site, then a steady flow of support questions about whether a small shop needed one. The glossary defines the terms; for a specific legal question, ask a lawyer rather than a hosting engineer.

Previous2016: When DNS fell overNext2020 to today: Edge, automation and email grows up

More from Hosting Through the Years

History

2016: When DNS fell over

In October 2016, a huge botnet built from poorly secured cameras and routers directed a flood of traffic at...

History

1994 to 1996: Encryption arrives

As the first online shops appeared, people wanted to send card numbers without them being read in transit....

History

1993 to 1996: The first hosts

The NCSA's Mosaic browser appeared in 1993 and made the web visible to people who were not computer...