Check a Domain

Guide

WHOIS Privacy and GDPR Redaction

Most generic domain records are already redacted for free, which changes what a privacy service is actually worth.

The default changed, so the question changed

Before May 2018, buying WHOIS privacy was close to mandatory hygiene for anyone who did not want their home address on the open internet. The public record carried the registrant's name, street address, telephone number and email to anyone who asked, indefinitely.

That is no longer the baseline. ICANN's Temporary Specification for gTLD Registration Data took effect on 25 May 2018, the day GDPR became applicable, and its successor — the Registration Data Policy, effective 21 August 2025 — now governs. Registrant name, street address, telephone and fax data are redacted; registries must redact registrant email and technical contact email; and registrars must publish either an anonymized email address or a link to a web form that reaches the contact without identifying them.

So the question is no longer whether your registrar will keep your details off the public record. For generic extensions it already does, free, by policy. The useful questions are what a paid service adds on top, where it still matters, and what it costs you in places you were not looking.

What a privacy or proxy service actually does

A privacy or proxy service substitutes a third party's contact details for yours in the published record. Instead of your name and address, it shows the provider's, usually alongside a forwarding address that relays messages to you.

The distinction buried in that sentence is contractual rather than technical, and it is the one to get straight. Under a privacy service in the narrow sense, you remain the registered name holder — the legal registrant — and only the published contact data is substituted. Under a proxy arrangement, the provider may be listed as the registrant of record, holding the registration on your behalf under a contract that defines your route back to control.

Establish which one you have bought before you need to know. The published record is the fastest available evidence of who holds a domain, and if it names a provider rather than you, your proof of ownership is a contract with that provider plus whatever the registrar holds behind it.

One structural fact matters here. ICANN developed a Privacy and Proxy Services Accreditation Program but never brought it into full force, so these remain registrar-offered commercial services rather than accredited ones. The terms come from the provider's contract, not from consensus policy, and they vary.

Redaction and privacy are not the same product

These get conflated constantly, including by people selling them.

Redaction is the registry or registrar withholding, from the published record, data that it holds and continues to hold. For generic extensions it is mandated, automatic, free, and applies to nearly every registration regardless of what the registrant asked for. The details remain on file at the registrar, escrowed, and disclosable under process.

A privacy or proxy service is a contract with a third party whose details are published in place of yours. It changes what data exists in the published record; redaction changes whether existing data is shown.

Since 2018 the overlap has become very large, which is why a privacy product now buys a narrower increment than the same product bought a decade ago. What it can still cover: fields a registry does publish, such as registrant organization or postal code where those are collected and shown; country-code extensions outside ICANN's Registration Data Policy, several of which publish in full; and reduced harvesting of the registrant email address, which is a genuine security benefit given how many domain takeovers begin with the registrant's mailbox. It does not secure that mailbox. Only two-factor authentication on the mail account does that.

The registries that will not let you use it

Privacy is not universally available, and several registries prohibit it. If you must register in those namespaces, plan for it before you register rather than afterwards.

  • .us prohibits privacy and proxy services outright, a prohibition originating in a 2005 NTIA ruling that .us registrants may not use anonymizing proxies. Registrars may not substitute their own details for the registrant's, and the registry uses an algorithm to detect proxy, anonymous and private registrations. Name, postal address, email and telephone number are published. A 2023 NTIA notice on an authenticated access gateway stated explicitly that the prohibition would remain, and no implemented change has followed.
  • .nl has not allowed third parties to act as nominal registrants since 1 October 2023, which rules out privacy and proxy providers and also registrars and resellers holding names in their own name. Individuals' data has been withheld automatically since 2016. Business registrants are public, and the opt-out requires demonstrating a material interest in anonymity outweighing the public interest in disclosure — typically granted where police are involved, typically refused where the motivation is spam or a grudge.
  • .in prohibits privacy and proxy registration registry-wide. Registrants routinely buy one expecting to add privacy later, then find themselves choosing between a public home address and abandoning the name.
  • .de, .fr, .ch and .es offer no privacy product and largely do not need one for individuals, whose data is withheld or never published. For legal entities the position inverts: publication is by design, and an arrangement that misstates the true holder collides with those registries' accuracy requirements and, in some cases, with an express power to revoke.

The general principle: where a registry publishes registrant data by design, the answer is not a privacy product but a deliberate choice about what you publish. Use a role-based mailbox rather than a personal one, a business address rather than a home address, and a business number — while keeping every field accurate, because inaccurate registration data is itself a breach that can cost you the domain.

What privacy does not protect you from

A privacy service changes what the public sees. It does not change what exists, and it stops nobody who has legal process behind them.

  • Legal process. Subpoenas, court orders and law enforcement requests go to the registrar, which holds your full data and escrows it with a third-party provider. Privacy is not a shield against any of them.
  • Disclosure requests. Under the Registration Data Policy a registrar must acknowledge a disclosure request within two business days and respond substantively within thirty calendar days, with far shorter deadlines for genuine safety emergencies. Requests are refused more often than granted, but the mechanism exists and your privacy provider is not a party to it.
  • UDRP. Filing a dispute complaint against a privacy-shielded domain typically causes the registrar to reveal the underlying registrant to the dispute provider. The shield holds until somebody with a trademark and a plausible case files, and then it comes off.
  • Your registrar's own records. Whatever the public record shows, the registrar knows who you are, and accuracy obligations require that what it knows is correct.

Read against that list, privacy is protection from bulk harvesting, unsolicited contact, casual competitive research and opportunistic social engineering. Those are worth having. It is not protection from anyone with a lawful basis and the patience to use it, and should never be sold as though it were.

Where privacy makes ownership harder to prove

The risk that gets underweighted is what happens when you need the public record working for you rather than against you.

If a proxy provider is listed as the registrant of record, the fastest available evidence of who owns the name points at somebody else. In a dispute, a recovery after a theft, a due diligence review, or an argument with a registrar over an account you can no longer access, you are relying on a contract with the provider and on the registrar's internal records rather than on anything a third party can verify in minutes. That is survivable, and it is slower and more expensive at precisely the moment speed matters.

Privacy services also interfere with transfers. Some must be disabled first, which adds a step at an awkward moment. Worse, disabling privacy can change the registrant email address — and under ICANN's Transfer Policy a material change to the registrant name, organization or email is a Change of Registrant, triggering a mandatory 60-day transfer lock that cannot be lifted retrospectively. Switch privacy off on the day you intend to move a domain and you can find yourself waiting two months.

The related failure is quieter. Since 2018, transfer confirmation messages go to whatever address the record carries: a relay, a proxy mailbox, an address nobody monitors. A transfer that is never confirmed is among the most common modern failures, and it usually traces back to a contact address the registrant forgot was in place.

Included or billed separately, and how to read that

Registrars are required to disclose pricing for privacy and proxy services as they are for registrations, so the information is available. What to do with it has changed.

Because redaction is now free and automatic for generic extensions, a separately billed privacy product sells a narrower benefit than the same product did before 2018. Some registrars bundle it at no extra charge, some bill it per domain per year, and some charge more for it than the gap between their renewal price and a cheaper registrar's. A headline renewal figure with several paid add-ons behind it is not comparable to one without.

The questions worth asking are more useful than the line item:

  • Who is the registrant of record when the service is enabled — you, or the provider?
  • Does it have to be disabled to transfer, and does disabling it change the registrant email and trigger a Change of Registrant lock?
  • What is the published process for disclosure requests, and will you be told when one is made about your domain?
  • Does it apply to the extensions you actually use, given that country-code registries are not bound by ICANN's redaction rules?
  • What happens on non-renewal or account closure — does the underlying registration revert cleanly to you?

When to use it

Use it when you are an individual registering under a home address in a namespace that publishes in full and permits privacy; when you are assembling names ahead of a launch you would rather not have traced; and where the registrant contact would otherwise be a personal mailbox certain to attract harvesting.

Do not bother with it for ordinary generic-extension registrations held by an organization that is already identifiable from its own website. Redaction covers the personal fields already, and many organizations positively benefit from being findable — consent to publication remains available, and large organizations frequently take it.

Do not use it where the registry prohibits it, and do not attempt a workaround. Naming somebody other than the true holder is a compliance breach in several namespaces and, in some, express grounds for revocation.

Whichever way you go, keep the underlying data accurate and the mailbox monitored. The controls that actually prevent losing a domain are a registrar lock, two-factor authentication on both the registrar account and the email account behind it, a monitored role address on an independent domain, and registry lock for names you cannot afford to lose. Privacy reduces noise; those others are not optional.

Common questions

Do I still need WHOIS privacy after GDPR?

For generic extensions, much less than you did. Registrant name, street address, phone and email are redacted by default under ICANN's Registration Data Policy at no charge. Privacy still adds value for country-code extensions that publish in full and for fields a registry does show.

What is the difference between redaction and a privacy service?

Redaction is the registrar or registry withholding data it holds, mandated and free for generic domains. A privacy service is a contract with a third party whose details are published in place of yours. They are different mechanisms that produce a similar-looking result.

Which domain extensions do not allow WHOIS privacy?

.us prohibits privacy and proxy services outright and actively detects them. .in prohibits them registry-wide. .nl has barred third parties from acting as nominal registrants since 1 October 2023. Several European registries such as .de, .fr, .ch and .es offer no privacy product because individuals' data is already withheld.

Does WHOIS privacy stop a UDRP complaint?

No. Filing a UDRP complaint against a privacy-shielded domain typically causes the registrar to reveal the underlying registrant to the dispute provider. Privacy delays identification, it does not prevent it.

Can WHOIS privacy cause problems when transferring a domain?

Yes. Some services must be disabled before a transfer, and disabling one can change the registrant email address. Under ICANN's Transfer Policy that counts as a Change of Registrant and triggers a mandatory 60-day transfer lock that cannot be lifted after the fact.

Who legally owns a domain registered with a privacy service?

It depends on the product. With a privacy service in the narrow sense you remain the registered name holder and only the published contacts are substituted. With a proxy arrangement the provider may be the registrant of record, holding it for you under contract. Check which one you have before you need to prove ownership.

Related extensions

.us

CountryNexus required

The only major extension where you must formally declare your connection to the country and cannot hide your details afterwards.

Registry Services, LLC (GoDaddy Registry)

.nl

Country

The Dutch register domains at a rate few countries match, and SIDN has been an early mover on DNSSEC and registry security.

SIDN

.in

Country

India opened its namespace to the world and has grown one of the largest country-code registries in Asia.

NIXI