How the GDPR affects the management of international domains
Team Host.it 5 min read
Content
We are certain that this law will have positive implications as it is designed to make the processing of personal data more transparent but above all we will have the possibility of managing consent to data processing such as modification or cancellation.
As we can imagine, the GDPR also affects data published online which also includes the domain registrant's data visible in the whois.
By domain registrant data we mean:
How does GDPR affect international domains? The international domains maintained in host.it are managed through OpenSRS, reseller of the Tucows International Registry. OpenSRS believes that access to registrant data must come from the authorized person in a specific and limited manner. In order to control the disclosure and transmission of sensitive data, OpenSRS has implemented a new whois with a closed system called "gated whois", this system will allow the information (registrant data, administrative and technical contact) to remain obscured, preventing its transmission and public visibility. This data is available only to bodies authorized to consult and accredited third parties, for example: judicial authorities, members of the security community and lawyers working in defense of intellectual property.
Below I bring you 4 explanatory images regarding the publication of data in the whois before and after the GDPR (OpenSrs source)
The registrant's data is visible online (without active privacy) according to ICANN policies
The registrant's data is not visible on the network (privacy active) according to ICANN policies. In this case, the (privacy) service offers third parties the way to contact the registrant via the contact @contactprivacy.com.
Domains with privacy not enabled. Since the email contact is not visible there is no possibility for third parties to contact the owner of the domain as data protection refers to the GDPR.
Domains with active privacy: the information relating to the registrant is not visible but he can be contacted via the email @contactprivacy.com
How does the domain transfer procedure change now that the registrant is no longer visible via Whois? In agreement with ICANN (Internet Corporation for Assigned Names and Numbers) and the Registry delegation, a migration process has been created that guarantees greater simplicity for the user and data protection as well as preventing domain theft.
I summarize below for clarity and completeness of information the transfer steps before May 25, 2018:
the domain owner asked the current registrar to unlock the domain (Transfer Client Prohibited status) and obtained the authcode or Epp code (migration code). This process has not changed since the current provider (registrar) will be able and must verify that the person who unlocked the domain and requested the authcode is legitimized and carry out these operations.
Once the domain was ready for transfer, the registrant contacted the new provider and submitted the request.
The new registrar sent the transfer authorization form (called FOA) via email to the domain's administrative email contact. This form could be sent to the registrant's or admin's email contact, at the registry's discretion, and was valid for 5 days. The registrant approved the transfer and the new provider subsequently forwarded the order to the original Registry.
The registry completed the transfer (within approximately 5 days), this operation generally also included the annual renewal (varies based on the domain extension) and the transfer block for the following 60 days.
What changes from today post GDPR?
The procedure, as previously mentioned, has been streamlined in order to make the user experience positive and protect personal data. As we saw until yesterday, the transfer of the domain began by sending the FOA to the admin contact of the domain but from today providers will no longer have the possibility of identifying the admin or registrant contact of the domain outside of their management.
How can a domain transfer be processed safely and efficiently without data visibility? The solution was to modify the transfer process like this:
OpenSRS now offers the ability to provide authcode during the domain transfer order.
In this case the transfer will be directly forwarded to the Registry of origin without sending the authorization email (FOA) to the domain admin contact.
The contact used to send the authcode and any other communication related to the transfer (inbound and outbound) will be the registrant contact and no longer the admin.
In the event that the authcode is not provided during the transfer, an email will be sent to the contact owner of the domain provided during the order. This email replaces the FOA which in a simplified way will request the authcode from the registrant via a landing page.
Once the transfer is complete, the contact details will be updated with those provided during the order. This was a possibility until yesterday, but is now mandatory given that the Registry will no longer have to rely on the correctness of the contact data provided by Registry (data no longer shared between the Registries).
The register aims to encourage the registrant to comply with some security measures, one above all: to keep their domain blocked or in the "Client Transfer Prohibited" state and to unlock it exclusively in the event of transfer to another provider. This operation called "locking domain by default" is already carried out automatically (unless otherwise requested) upon transfer of the domain to host.it.
Regarding new registrations, OpenSRS will send via email a request for authorization to consent to data processing in order to provide the requested service. The domain owner may at any time modify or revoke the consent provided.
The changes to the migration process perfectly comply with the GDPR principle, guaranteeing data confidentiality, security and prevention of domain theft.
Host S.p.A, as a hosting service provider, has always processed data considered "massive" of people and companies. The treatment has always been performed with the highest safety standards. We will share the documentation with you starting today, May 25, 2018.
Domains
Register or transfer your domain
.it, .com, .eu extensions and managed DNS. Fast activation plus support for pointing and email.
Related articles
From the blog
From the archive