Site navigation

GDPR and ICANN: WHOIS Going to Win?

Brian Baglow

,

ICANN WHOIS GDPR

Will Europe’s forthcoming ‘privacy by default’ data protection regulations put an end to one of the internet’s longest-running arguments?

If you’ve ever registered an internet domain, you’ll have come across WHOIS. Everyone who buys a domain must supply personal details and information such as name, address, email, phone number and admin/tech contacts.

The problem is that ICANN, the organisation which coordinates the domain name systems (DNS) for the internet demands that this information is made publicly available, whether the user wishes it or not.

That’s not going to fly under the new GDPR laws, where the default is for privacy instead of letting users opt out of sharing information.

Arguments about the whole WHOIS system have been dragging on for years. The US-based ICANN has tried, and failed to update the Whois system many times. However, two powerful groups: intellectual property lawyers (who really like having personal details of domain owners given the popularity of copyright infringement online) and the domain registration companies (who’d really rather not have to verify the given contact details), both have vested interests in keeping the current system.

In the past ICANN created a bit of a workaround in which European registrars could ask for an exemption.

GDPR won’t allow that, so something new is going to have to take its place. A new system known as Registration Data Access Protocol or RDAP is currently being piloted by a couple of companies, including Verisign. This allows specific data fields to be restricted, or revealed only to a given user (i.e. law enforcement).

While this system is gaining some traction, the fight is far from over. ICANN recently released the legal guidance is had received with regard to GDPR, according to The Register:

Despite sugar-coating the memo with phrases like “potentially challenging areas with existing requirements,” ICANN noted that the “publicly available Whois services cannot remain unchanged” and GDPR “could impact our ability to maintain a single global WHOIS system.” In other words, the current Whois system is dead in the water and the internet community has seven months to replace it.

The response from the internet community has been predictably bad: various stakeholder groups are jockeying for position on a new “compliance task force” rather than focusing on the problem itself.

With European registries now starting to disobey ICANN rules on disclosing WHOIS information and internal struggles causing delays and uncertainty over an eventual solution, the countdown to GDPR implementation provides a very tangible deadline for the organisation.

A fine of four percent of global turnover, or €20 million (whichever is greater) for companies breaking the new regulation promises to be a wonderful incentive for ICANN to sort things out at some point soon.

The ICANN annual general meeting is taking place in Abu Dhabi from 28 October – 3 November. Right now in fact. Fingers crossed there’s good news to report…

Movers and shakers

Brian Baglow

Editor

Latest News

AI

Nvidia Launches Open Secure AI Alliance for AI Safety and Security

AI Business Recruitment

Nearly a Quarter of Orgs Reducing Entry-level Hiring Due to AI Automation

Business

Scottish Businesses Turn to Self-funding as Growth Confidence Dips in H2

Data Finance

Payment Leaders are Struggling to Get Real-time Data