← HomeREP27All categories

Domain registries, registrars and DNS services

Digital and connected products

In short
NIS2 representative and an Article 27 GDPR representative, both established in the Union

Who has to appoint one

Registries, registrars and DNS providers outside the Union serving EU users. DNS service providers and TLD name registries are covered by NIS2 regardless of size, which is unusual and frequently missed.

Thresholds and exemptions

Size thresholds do not apply to DNS service providers and TLD registries, which are covered as essential or important entities irrespective of size.

What must appear on the label

Not physical. NIS2 requires accurate and complete domain registration data to be maintained and made accessible to legitimate access seekers, with a policy published.

Marketplace fields

Registrars must implement verification of registration data, and law enforcement and rights holders increasingly demand access, which the NIS2 provisions now regulate explicitly.

Documentation you must hold

NIS2 registration and risk management documentation, incident procedures, the domain registration data policy with verification procedures, response procedures for legitimate access requests, Article 30 records, and the Article 27 designation.

Standards and testing

Not applicable, though authorities may impose security audits on essential entities.

Language requirements

Policies and access procedures in a language accessible to requesters, and incident reports as the CSIRT requires.

When it applies

NIS2 obligations from the national transposition dates. Reporting within 24 hours, 72 hours and one month.

How long records are kept

Registration data for the life of the registration and afterwards per the policy, balancing accuracy duties against minimisation.

What happens if you do not comply

Up to €10 million or 2% of turnover for essential entities, with management accountability. GDPR fines apply to the registrant data processing.

Who enforces it

NIS2 competent authorities and CSIRTs, data protection authorities, and EURid for the .eu domain.

Where the boundary lies

Article 28 of NIS2 resolved much of the post-GDPR WHOIS impasse by requiring accurate data and lawful access, but the balance between publication and privacy remains contested and the implementation differs by member state.

Questions we are asked

Are we in NIS2 as a small registrar?
DNS service providers and TLD registries are covered regardless of size. Registrars are covered in several implementations too, so the national transposition must be checked.
Must registrant data be public?
Not wholly. NIS2 requires accuracy and lawful access for legitimate requesters, not full publication, and the balance is set nationally.
EU representative · from €290 / year

Who signs for you
EU representative Europe Services, SE — Na Čečeličce 425/4, Smíchov, 150 00 Praha 5, Czech Republic
UK representative REP27 LTD — Unit 82a James Carter Road, Mildenhall, Suffolk IP28 7DE, United Kingdom

Talk to usCheck your category