Article 13 flashbacks all over again — unaccountable intermediaries providing false information with no liability. I queried three major APIs last Tuesday for a project domain. All returned "available." I proceed to branding mockups, client presentation, the full GDPR-compliant data processing workflow. Purchase attempt: premium tier, $4,200/year.
This is not availability. This is a database sync failure treated as authoritative truth.
- API A checks registry drop list only, not premium tiers
- API B caches WHOIS for 72 hours minimum
- API C queries correctly but returns "available" for any non-NXDOMAIN due to parsing bug
Under GDPR Article 5(1)(d), data must be accurate. These APIs process personal data (registrant queries) while delivering systematically inaccurate results. I have filed complaints with my DPA. Earnestly, this market needs regulation.