GOpenCDR registration data disclosure policy
Who may see the registration data RDAP redacts, on what grounds, how a request is decided, and how quickly.
What this policy decides
Who may see the parts of GOpenCDR's registration data that concern a person, on what grounds, and how a request is handled. It applies to every TLD Gelhaus Solutions hosts. A self-hosted TLD publishes its own policy, which may not disclose more than this one allows.
What there is to disclose
GOpenCDR's floor is an account with a verified email address. For a name in a hosted TLD, the registration data about the person behind it is therefore the email address of the account that holds it, unless the TLD's published policy collects more. Everything else about a name, its nameservers, its DS records, its status and its dates, is public anyway.
What RDAP shows
RDAP answers for any name in a GOpenCDR TLD with its status, its dates, its nameservers, its DNSSEC data and the registry responsible for it. Everything about the registrant is redacted and marked as redacted, following RFC 9537, so that the answer says which fields exist and that they were withheld on purpose. There is no bulk access, no search by registrant and no reverse lookup.
Reaching a registrant without learning who they are
Most people who ask who is behind a name want to reach them. For that there is a relay: the contact form in the portal, or a message to the address below, forwards your message to the registrant without disclosing their address to you. The registrant decides whether to answer. Messages through the relay are kept for 12 months and are not used for anything else.
Who may receive redacted data
Redacted data is disclosed only to a requester who has been identified, who states a purpose, and whose request is granted by a person after weighing it. Every request is logged with its purpose and its outcome.
Courts and authorities receive it where they present valid legal process from a competent authority. Authorities outside the EU route their request through mutual legal assistance or an equivalent channel that is binding under German law.
Others receive it only where they show a legitimate interest that outweighs the registrant's interest in privacy (Art. 6(1)(f) GDPR). In practice that is:
- a rights holder who substantiates, with evidence, that the name or its use infringes their right, and who needs the data to pursue the claim;
- a security team or CERT investigating DNS abuse under the name, where contacting the TLD and the registrant through the relay has not been enough.
Curiosity, marketing, research without a legal basis and the wish to buy a name are not a legitimate interest for this purpose.
What is disclosed
The least that serves the purpose, which for most hosted TLDs means the account's email address. Disclosure is made to the requester alone, in text, with a note that the data may be used only for the purpose stated and must be deleted when that purpose is met.
Telling the registrant
The registrant is told who asked, why and what was disclosed, unless the law forbids it or telling them would defeat the purpose of a lawful request, in which case they are told once that no longer applies.
How to ask, and how quickly we answer
Write to egelhaus@ennogelhaus.de with "Registration data" in the subject line. Say who you are, which name the request concerns, what you need, why, and on what legal ground, and attach the legal process or the evidence for your interest.
We acknowledge a request within 24 hours and decide it without undue delay, in any event within 72 hours of receiving a complete request. Where there is a risk to life or limb, we act as fast as it takes. A refused request is answered with reasons.
Counting
Every request and its outcome, by kind of requester and ground, is counted in the transparency report published every six months.
Where the law requires more
GOpenCDR collects an email address and nothing more unless a TLD's policy says otherwise. Where the law requires fuller registration data from a registry of this kind, including under Article 28 of the NIS2 Directive as transposed into German law, we collect what it requires, from the date it requires it, and tell registrants before we start.
Roles
For hosted TLDs, Gelhaus Solutions and the TLD operator are joint controllers for registration data; see the joint controller arrangement. Requests come to us either way. The rest of what we process is in the privacy notice.