Transparency report policy
What the joint six-monthly transparency report for GOpenCDR, GOpenCNR and GOpenCSR counts, what it never contains, and where every report is published.
What the report is
GOpenCDR, GOpenCNR and GOpenCSR publish one joint transparency report every six months. It counts what happened in the one case system and with requests from courts and authorities across all three services, so that anybody can see how often we act, on what, at whose request, and how our decisions hold up on appeal.
The transparency log records each action as it happens, with identifiers only. The report adds them up and puts beside them what the log does not hold, such as reports received and requests from authorities. The six-monthly transparency report that GOpenCDR's documents refer to is this joint report.
"We" is Gelhaus Solutions, which operates the three services and holds the Tier 0 role.
Which period each report covers
Each report covers one half-year: January to June, or July to December. It is published after the end of the half-year it covers.
Every figure counts what happened within the half-year. A case opened in one half-year and closed in the next is counted in each for what happened in it.
What it counts
Figures are given for each product, GOpenCDR, GOpenCNR or GOpenCSR, wherever they belong to one.
Reports and cases
- reports received, by product and by category, using the kinds of abuse the acceptable use policies name, such as phishing, malware, scanning or a route leak;
- cases opened;
- cases in which the holder acted first, and cases in which Tier 0 stepped in.
Actions
- actions taken, by kind: for names, holds, locks, suspensions and deletions; for addresses and the network, each step of the sanctions ladder (warning, reduced max-prefix, routes suppressed at the hubs, depeered from all Tier 0 nodes, allocation reclaimed);
- sanctions that covered a holder's names and addresses together;
- closed-prefix leaks cut automatically by a hub;
- emergency actions, and for each whether it lapsed, was reaffirmed or was lifted;
- appeals lodged and decided, with their outcomes.
Requests from courts and authorities
- requests received, by type (requests for data, requests or orders to preserve data, and orders to act on a name, an address or prefix, or an ASN) and by country group: Germany, other member states of the EU, and countries outside the EU;
- how each was answered: complied with, complied with in part, or refused;
- in how many the holder was told, and in how many the law did not yet allow it;
- European Production Orders and European Preservation Orders under Regulation (EU) 2023/1543, counted separately;
- disclosures made without a request, to prevent an imminent danger to life or limb;
- requests from others for GOpenCDR registration data, by kind of requester and by ground, as GOpenCDR's registration data disclosure policy sets out, and the requests TLD operators report to us under their agreements, marked as theirs.
How requests are checked and answered is set out in the authority request policy.
Sanctions screening
- matches against the EU consolidated financial sanctions list, as counts only: how many were cleared and how many were confirmed. Nothing tied to a holder is published, because only the holder and Tier 0 know that a review exists.
What it never contains
- No personal data. No names of people, no email addresses, no IP addresses and no account identifiers.
- Nothing that identifies a reporter, or a holder under investigation. A report gives no case numbers and no resources, and no figure is broken down so far that it points to one case.
- No count small enough to be unsafe. Where a count is so small that it could point to a person or to a case, the report shows a range instead of the number.
What happened to a particular resource is in the transparency log, as the abuse and sanctions policy describes. The report only counts.
Where it is published
On GOpenCSR's public pages at csr.gplatform.org, beside the abuse report form, readable without an account. The figures of each report can be downloaded as a CSV file.
Every report stays published. A new report never replaces an earlier one, so every half-year can be compared with every other.
Changes
This policy changes through the process the general terms of service set out. Every version is kept in the document archive.