WHOIS Privacy & GDPR: Current state of domain registration privacy

Before vs After GDPR

Previously, WHOIS exposed registrant name, email, address, and phone to anyone. This aided security research but also enabled spam and privacy risks. After GDPR enforcement in 2018, most gTLD registrant data is now hidden by default.

Current WHOIS Lookup Methods

RDAP (Registration Data Access Protocol)

RDAP is the modern WHOIS replacement with structured JSON output.

Registrar-Specific Queries

Some registrars offer authenticated WHOIS lookups for logged-in users.

Privacy Best Practices

For Domain Owners

  1. Confirm WHOIS privacy is enabled (default on most modern registrars)
  2. Use dedicated email per domain for tracking
  3. Keep emergency contact info accurate
  4. Understand your registrar's privacy policy

16IDC Takeaway

WHOIS privacy has evolved from optional add-on to default configuration. This benefits most domain owners by reducing spam and social engineering risks. Domain owners should ensure their contact information is accurate for receiving important notices.