I have registered a .com at Contabo since 2 years, and I am wondering if WHOIS privacy is still necessary. As far as I know, GDPR forced the registries to redact personal data anyway. My name and address do not appear in the public WHOIS anymore, only the registrar and a generic email. So why do we still pay 3-5 EUR per year for privacy protection? Is this just a leftover business practice, or am I missing something from a legal perspective? I would be interested in your experiences, especially with non-EU TLDs.
Domain privacy — still needed in the GDPR era?
Hey guys good question fritz
From a business side I always bundle privacy into my reseller packages at Hetzner, customers expect it even if they dont need it lol. Margins are thin tho, the registry charges us almost nothing for it but we markup
Quick question: does the.US still force you to show real info? I heard thier policy is different, no GDPR coverage. Any leads on cheap.US privacy add-ons? 🙏
GDPR redaction is NOT enough!
Here is what could go wrong:
- The registry still has your REAL data, breach happens, now its leaked
- Law enforcement requests, your data gets handed over anyway
- GDPR only covers EU, your.com is under US jurisdiction, different rules apply
- Stalkers use historical WHOIS archives, privacy now doesnt erase the past
I had a client who skipped privacy on a.org in 2019, got stalker emails for YEARS. Privacy is cheap insurance. Run fail2ban on your mail server too while youre at it, the bots will find you
👀
Olespete has a point about historical data, IMO. YMMV depending on your threat model.
To add some balance: for most small sites, GDPR redaction is probably fine. The registrar still sees your data either way, and if someone really wants to find you, domain privacy is a thin layer. Take it with a grain of salt, but I let mine lapse on a .de last year and nothing happened. .de has strong rules anyway.
That said, if you ever posted your real info before GDPR, its archived somewhere. Privacy service wont fix that.