- Directive (EU) 2022/2555 — NIS2, Article 28 on domain registration data
- Regulation (EU) 2016/679 — GDPR, Article 27
- Regulation (EU) 2022/2065 — DSA
- Regulation (EU) 2019/517 for the .eu top level domain
Who has to appoint one
Registries, registrars and DNS providers outside the Union serving EU users. DNS service providers and TLD name registries are covered by NIS2 regardless of size, which is unusual and frequently missed.
Thresholds and exemptions
Size thresholds do not apply to DNS service providers and TLD registries, which are covered as essential or important entities irrespective of size.
What must appear on the label
Not physical. NIS2 requires accurate and complete domain registration data to be maintained and made accessible to legitimate access seekers, with a policy published.
Marketplace fields
Registrars must implement verification of registration data, and law enforcement and rights holders increasingly demand access, which the NIS2 provisions now regulate explicitly.
Documentation you must hold
NIS2 registration and risk management documentation, incident procedures, the domain registration data policy with verification procedures, response procedures for legitimate access requests, Article 30 records, and the Article 27 designation.
Standards and testing
Not applicable, though authorities may impose security audits on essential entities.
Language requirements
Policies and access procedures in a language accessible to requesters, and incident reports as the CSIRT requires.
When it applies
NIS2 obligations from the national transposition dates. Reporting within 24 hours, 72 hours and one month.
How long records are kept
Registration data for the life of the registration and afterwards per the policy, balancing accuracy duties against minimisation.
What happens if you do not comply
Up to €10 million or 2% of turnover for essential entities, with management accountability. GDPR fines apply to the registrant data processing.
Who enforces it
NIS2 competent authorities and CSIRTs, data protection authorities, and EURid for the .eu domain.
Where the boundary lies
Article 28 of NIS2 resolved much of the post-GDPR WHOIS impasse by requiring accurate data and lawful access, but the balance between publication and privacy remains contested and the implementation differs by member state.
Questions we are asked
- Are we in NIS2 as a small registrar?
- DNS service providers and TLD registries are covered regardless of size. Registrars are covered in several implementations too, so the national transposition must be checked.
- Must registrant data be public?
- Not wholly. NIS2 requires accuracy and lawful access for legitimate requesters, not full publication, and the balance is set nationally.
Who signs for you
EU representative Europe Services, SE — Na Čečeličce 425/4, Smíchov, 150 00 Praha 5, Czech Republic
UK representative REP27 LTD — Unit 82a James Carter Road, Mildenhall, Suffolk IP28 7DE, United Kingdom