Registration-data privacy
Domain privacy after the move from WHOIS to RDAP
Reviewed 10 September 2026 · 7-minute read
Domain privacy changes what registration data is published; it does not remove the registrar's underlying records or make a registrant anonymous. Public RDAP results may redact personal fields, publish an anonymized contact or show a privacy/proxy service, depending on ICANN policy, applicable law and the registry/registrar.
Three different privacy mechanisms
| Mechanism | Public result | Underlying relationship |
|---|---|---|
| Redaction | Selected personal fields are removed or marked redacted. | The registrar retains required registration data. |
| Privacy service | Alternate contact data can be published while the customer remains the registrant. | The provider relays contact under its terms. |
| Proxy service | The proxy service's public details appear. | The service is the registrant of record under its agreement with the customer. |
The current ICANN policy boundary
ICANN's Registration Data Policy became effective on 21 August 2025 and was revised in May 2026. It applies to ICANN-accredited registrars and contracted gTLD registry operators. It defines publication, redaction and lawful disclosure requirements. It is not a single worldwide rule for every country-code domain.
What can still be public
Depending on the registry, registrar and access level, public data can include the domain, registrar, status codes, registration events, name servers, DNSSEC details, notices and an anonymized contact method. The absence of a person's name or address does not mean the record is incomplete for the registrar's private compliance purposes.
What privacy does not protect against
- Disclosure required through a valid legal or policy process
- Identification through website content, DNS, certificates, company records or other sources
- Account takeover, weak registrar authentication or domain-transfer fraud
- Trademark or dispute proceedings
- Operational contact through an anonymized address or web form
A practical registrant checklist
- Read the registrar's privacy/proxy terms and renewal price.
- Use accurate underlying registration details and keep them current.
- Use a durable email, multi-factor authentication and recovery method.
- Check the actual public RDAP result after registration.
- Document the correct process for receiving and answering contact or disclosure requests.
Frequently asked questions
Does domain privacy make a registrant anonymous?
No. Public registration output may redact or substitute contact data, but the registrar still collects required information and can disclose non-public data under applicable policy, law and process.
Are all RDAP records redacted in the same way?
No. ICANN's policy governs contracted gTLD parties, while applicable law, registry policy, legal-person data and country-code rules can produce different public fields.
Can a redacted domain owner still be contacted?
Often yes. Public RDAP output can include an anonymized email address or a registrar contact form. Availability and behavior depend on the registrar and registry.