WHOIS Privacy & GDPR: Current state of domain registration privacy
Before vs After GDPR
Previously, WHOIS exposed registrant name, email, address, and phone to anyone. This aided security research but also enabled spam and privacy risks. After GDPR enforcement in 2018, most gTLD registrant data is now hidden by default.
Current WHOIS Lookup Methods
RDAP (Registration Data Access Protocol)
RDAP is the modern WHOIS replacement with structured JSON output.
Registrar-Specific Queries
Some registrars offer authenticated WHOIS lookups for logged-in users.
Privacy Best Practices
For Domain Owners
- Confirm WHOIS privacy is enabled (default on most modern registrars)
- Use dedicated email per domain for tracking
- Keep emergency contact info accurate
- Understand your registrar's privacy policy
16IDC Takeaway
WHOIS privacy has evolved from optional add-on to default configuration. This benefits most domain owners by reducing spam and social engineering risks. Domain owners should ensure their contact information is accurate for receiving important notices.