Skip to content

Domain privacy — still needed in the GDPR era?

Domain Names by Fritz48 3 replies 226 views
#1

I have registered a .com at Contabo since 2 years, and I am wondering if WHOIS privacy is still necessary. As far as I know, GDPR forced the registries to redact personal data anyway. My name and address do not appear in the public WHOIS anymore, only the registrar and a generic email. So why do we still pay 3-5 EUR per year for privacy protection? Is this just a leftover business practice, or am I missing something from a legal perspective? I would be interested in your experiences, especially with non-EU TLDs.

Neuland. Aber schnell.
#2
Fritz48 said:
So why do we still pay 3-5 EUR per year for privacy protection?

Hey guys good question fritz

From a business side I always bundle privacy into my reseller packages at Hetzner, customers expect it even if they dont need it lol. Margins are thin tho, the registry charges us almost nothing for it but we markup

Quick question: does the.US still force you to show real info? I heard thier policy is different, no GDPR coverage. Any leads on cheap.US privacy add-ons? 🙏

your margin is my opportunity
11 #3

GDPR redaction is NOT enough!

Here is what could go wrong:

  • The registry still has your REAL data, breach happens, now its leaked
  • Law enforcement requests, your data gets handed over anyway
  • GDPR only covers EU, your.com is under US jurisdiction, different rules apply
  • Stalkers use historical WHOIS archives, privacy now doesnt erase the past

I had a client who skipped privacy on a.org in 2019, got stalker emails for YEARS. Privacy is cheap insurance. Run fail2ban on your mail server too while youre at it, the bots will find you

👀

airgapped, encrypted, faraday'd, still worried
#4

Olespete has a point about historical data, IMO. YMMV depending on your threat model.

To add some balance: for most small sites, GDPR redaction is probably fine. The registrar still sees your data either way, and if someone really wants to find you, domain privacy is a thin layer. Take it with a grain of salt, but I let mine lapse on a .de last year and nothing happened. .de has strong rules anyway.

That said, if you ever posted your real info before GDPR, its archived somewhere. Privacy service wont fix that.

...

Post a reply

You need an account to reply. Log in or register to join the conversation.

Post reply Preview Save draft