
In what we hope is not breaking news for anyone reading the DomainTools blog, GDPR commenced its enforcement period today. We have already seen domain name registrars and registries adjust the data they make available in Whois, with many following the Temporary Specification model that was mandated by the ICANN Board of Directors last week. Recall that ICANN sets policy for the generic TLD space but not for the country code TLD space. Here again are some of the attributes of this interim model:
The Temporary Specification accomplishes some important things. First, it becomes part of the contracts in place between ICANN and Registrars/Registries, meaning that ICANN can enforce compliance to this data model. Second, many useful data fields will remain in the public Whois data set for affected domains, including Registrant Organization, Registrar, Create Date, Expiration Date, Registrant State/Province, Country and Nameservers. Third, higher volume access to the remaining public data fields is still required to be supported. Fourth, it sets a schedule for the ‘gated access model’ to be defined and implemented before year-end.
A lot of people and influential organizations are going to be paying attention to how this new Whois model affects the work of those who feel they have a legitimate interest in accessing the full data. It’s important that practitioners in security, brand and IP enforcement, and consumer protection who currently use Whois data in their workflows, continue to do so and document any increased friction or impairment that comes as a result of reduced access to critical Whois data fields.
DomainTools recently released significant updates to our Iris Investigate platform in order to guide users to useful attribution, context and connections still possible without the Personal Data restricted by GDPR. Still, it remains important to be vocal about the need to access full Whois records and the need to search across Whois data at scale. Constituents in the security, brand protection and related arenas must involve themselves in the creation of the Accreditation Model and demand that their legitimate interests be duly considered. Finally, for more regular updates to GDPR policy, visit our GDPR page.
May 25th is not a finish line, it is a beginning. We hope that our customers and users will continue to communicate with us as to how these changes impact their security posture and join us in fighting for a functional balance between privacy and security, at the intersection of Whois, DNS and the GDPR.