Skip to content
Gelhaus Solutions
Apps Services Security Contact
EN DE
Apps / GOpenCSR / Authority request policy

Authority request policy

How requests and orders from courts and authorities concerning GOpenCDR, GOpenCNR and GOpenCSR are sent, checked and answered, what data exists to disclose, when the holder is told, and how every request is counted.

Last updated 1 October 2026 Auf Deutsch lesen →

On this page

  1. What this policy covers
  2. Who may ask
  3. How to send a request
  4. What we check
  5. Requests under German law
  6. Orders from other EU member states
  7. Requests from anywhere else
  8. What there is to disclose
  9. Preservation
  10. Disclosure without a request
  11. Telling the holder
  12. Our records
  13. Counting
  14. Orders to act on a resource
  15. Changes

What this policy covers

Requests and orders from courts and authorities that concern GOpenCDR, GOpenCNR or GOpenCSR: for data about an account, a holder or a resource, for preserving data, and for action on a name, an address or prefix, or an ASN.

"We" is Gelhaus Solutions, which operates the three services, holds the Tier 0 role and is the controller for the personal data they process. The "holder" is the person or organisation an account or a resource belongs to.

Who may ask

  • courts;
  • public prosecutors;
  • the police;
  • regulators acting within their powers, among them the Federal Network Agency (Bundesnetzagentur, BNetzA), the Federal Office for Information Security (Bundesamt für Sicherheit in der Informationstechnik, BSI) and the data protection supervisory authorities.

Requests from outside Germany are dealt with below. A private party is not an authority: a rights holder or a security team asking for the registration data of a GOpenCDR name follows GOpenCDR's registration data disclosure policy, and a report of abuse goes to the route in the abuse and sanctions policy.

How to send a request

Send it to contact@gplatform.org, in German or English. A formal order may also be served by post at the address in the legal notice. The abuse mailbox is for abuse reports and is not the place for requests from authorities.

A request must contain:

  • the authority, the official handling it, and how to reach them;
  • the legal basis, naming the provision it relies on;
  • the order or decision itself, where the law requires one, for example a court order;
  • exactly what it concerns: the name, the address or prefix, the ASN, the holder's handle or the account identifier, and the period;
  • what it asks for: which data, preservation of which data, or which action;
  • the deadline, and the reason for any urgency;
  • whether the holder must not be told, on what legal basis, and for how long.

contact@gplatform.org is also the single point of contact for authorities under Art. 11 of the Digital Services Act.

What we check

A person checks every request before anything is disclosed or done:

  • Legal basis. A provision allows the authority to ask, and obliges or permits us to answer.
  • Competence. The authority is competent for the matter and for the place.
  • Form. The request has the form the law requires, and where the law requires a court order or another particular decision, it is there.
  • Proportionality. It asks for no more than its purpose needs. A request that is too broad is narrowed with the authority or refused.
  • Identity. The request comes from the authority it names. We verify that through contact details we find ourselves, not through those in the request.

A request that fails a check is refused with reasons, or we ask for what is missing. We disclose the least that answers the request, and we answer within the time the order or the law sets, or without undue delay where neither sets one.

Requests under German law

Requests and orders from German courts and authorities are answered directly once they pass these checks. The powers they rely on are in the laws that grant them, among them the Code of Criminal Procedure (Strafprozessordnung, StPO), the information provisions of the TDDDG and, for GOpenCNR as a telecommunications network, those of the Telecommunications Act (TKG), and the laws that give the BNetzA, the BSI and the data protection supervisory authorities their powers. Telecommunications traffic data of GOpenCNR are passed on only under a law that expressly refers to telecommunications (Section 3(3) TDDDG).

Orders from other EU member states

European Production Orders and European Preservation Orders under Regulation (EU) 2023/1543, which has applied since 18 August 2026, are answered directly, after the same checks and within the time limits the Regulation sets. Domain name registries and IP numbering services are among the providers the Regulation covers. Where the Regulation allows a provider to raise a reason not to comply, we raise it with the authorities it names.

Requests from anywhere else

Every other request from outside Germany, whether from an EU member state outside the Regulation or from a country outside the EU, reaches us only through German authorities, by way of mutual legal assistance. We do not answer it directly, and we tell the requester so.

What there is to disclose

We hold little. The privacy notices list everything we process: the GOpenCSR privacy notice for accounts, holders, organisations, cases and the shared services, the GOpenCNR privacy notice for addresses and the network, and the GOpenCDR privacy notice for names. In short:

  • Accounts: an email address and when it was verified, a password hash, passkey public keys, sessions stored only as hashes, roles, consent records and an optional display name. No postal address and no phone number.
  • Holders: the legal name and country a person gives on first becoming a holder of resources, which only Tier 0 sees and which is used for sanctions screening; for an organisation, its verified name and country and what its verification recorded.
  • Audit records: who did what, when and to what, with a keyed hash of the IP address. The IP address itself is kept for 90 days.
  • Request logs: kept for 14 days.
  • Resources: names, allocations, ASNs, routes and endpoints. Endpoints are stored encrypted and are never public.
  • GOpenCNR traffic: counters per member, not records of traffic: fine-grained counters for 90 days, then only daily totals per member until 12 months. No content of any communication is stored anywhere. Traffic between members' own agent routers is encrypted end to end, and each agent's key is made on its host and never leaves it, so we hold no key to it. A hosted router runs on a hub and is labelled for what it is: encrypted to the hub operator, end to end from there. Sampled flows exist only inside an open abuse case, for at most 7 days, and never contain content.
  • Cases: reports, evidence and findings, kept for 12 months after a case closes.
  • The transparency log is public anyway, and holds identifiers and hashes only.

We do not create records in order to answer a request, and we do not start collecting data we otherwise do not collect, unless the law obliges us to.

Preservation

A request or order to preserve data, including a European Preservation Order, makes us keep the data it names as it stands at that moment, beyond its usual deletion date, for the period the order sets, so that an order to produce it can follow. Preservation is not disclosure: nothing is handed over until an order to produce it has passed our checks. The preserved copy is used for nothing else. It is deleted when the period ends without such an order, or when the authority tells us it is no longer needed.

Disclosure without a request

We disclose data without a request or an order in one case only: to prevent an imminent danger to life or limb, to the authority that can avert it, and only what that needs (Art. 6(1)(d) GDPR). Every such disclosure is recorded with its reasons and counted in the transparency report, and the holder is told as described below. This never covers telecommunications traffic data: those are passed on only under a law that expressly refers to telecommunications (Section 3(3) TDDDG). There is no other voluntary disclosure.

Telling the holder

The holder is always told what was requested, by which authority, on what basis, and what we disclosed or did, unless the law forbids it. Where the law forbids it, we tell the holder as soon as it no longer does.

Our records

Every request is recorded: who sent it and when, its legal basis, what it asked for, how we checked it, what we disclosed or did, and whether and when the holder was told (Art. 6(1)(c) GDPR). The record is kept for 5 years after the request is closed. The GOpenCSR privacy notice describes it.

Counting

Every request and its outcome is counted in the joint transparency report for GOpenCDR, GOpenCNR and GOpenCSR, published every six months: by type, by country group, by how it was answered, and by whether the holder was told. The transparency report policy sets out what is counted and how.

Orders to act on a resource

An order to remove, suspend or block a name, an address or prefix, or an ASN is checked as above and then carried out through the case system, under the abuse and sanctions policy and the terms of the product concerned: the holder receives a statement of reasons unless the law forbids it, the action is recorded in the transparency log, and the holder may appeal how the order was carried out. The order itself is challenged before the court or the authority that made it.

Changes

This policy changes through the process the general terms of service set out. Every version is kept in the document archive.

Gelhaus Solutions

Self-hosted applications, and the platform that hosts them for the people who would rather not.

Site

  • Apps
  • Security
  • Writing
  • Contact
  • Sitemap

GHub

  • GAdvisory
  • GControl
  • GPlatform Control
  • GPlatform SSO
  • GPlatform Billing

Legal

  • Impressum
  • Privacy
  • Terms
  • Data processing
  • Withdrawal
  • Report content

Elsewhere

  • egelhaus@ennogelhaus.de
  • @egelhaus
  • @egelhaus
© 2026 Enno Gelhaus Built and shipped in Germany