EPDP on gTLD Registration Data What You Need to Know

The Expedited Policy Development Process, or EPDP, on gTLD Registration Data is one of the most consequential and complex policy initiatives undertaken within the ICANN multi-stakeholder model. Emerging in response to sweeping changes in global data protection regulations, particularly the European Union’s General Data Protection Regulation (GDPR), the EPDP represents a comprehensive effort to modernize and realign ICANN’s policies governing the collection, processing, and disclosure of domain name registration data, commonly known as WHOIS data. This process has profound implications for privacy, security, law enforcement, intellectual property rights, and the functioning of the global DNS ecosystem.

Historically, WHOIS services offered open, publicly accessible databases of domain name registration information, including the names, physical addresses, phone numbers, and email addresses of domain name registrants. This system was designed to promote transparency, support intellectual property enforcement, enable cybersecurity investigations, and assist in the resolution of technical issues. However, as concerns over privacy and data protection mounted, the publication of personally identifiable information in WHOIS became increasingly controversial. The adoption of GDPR in 2018, with its strict requirements for processing personal data of EU residents, created an urgent legal conflict. ICANN’s existing WHOIS policies risked violating GDPR provisions, exposing contracted parties and ICANN itself to potential legal liability.

To address this regulatory conflict, ICANN implemented a Temporary Specification for gTLD Registration Data in May 2018. This emergency policy served as a stopgap measure, modifying contractual obligations to minimize the exposure of personal data while ensuring that essential registration functions could continue. The Temporary Specification significantly redacted publicly available WHOIS information, limiting access to registrant data except for certain non-personal data elements and restricting the full data set to parties with legitimate purposes under narrowly defined circumstances.

Recognizing the need for a permanent solution, ICANN’s Generic Names Supporting Organization (GNSO) initiated the EPDP on the Temporary Specification for gTLD Registration Data. The EPDP was designed as an accelerated policy development process, departing from ICANN’s typically lengthy timeline in order to meet urgent legal and operational requirements. The EPDP Working Group was tasked with reviewing the Temporary Specification, determining which elements should be retained, modified, or discarded, and developing new consensus policies that would bring ICANN’s registration data policies into full compliance with applicable data protection laws.

The EPDP Working Group brought together representatives from across ICANN’s stakeholder spectrum, including registrars, registries, intellectual property interests, law enforcement, civil society, technical experts, privacy advocates, and governments. This broad composition ensured that a diverse range of interests and legal perspectives were incorporated into the policy discussions, but it also made achieving consensus a challenging and at times contentious process. Fundamental disagreements emerged over issues such as the scope of data collection, the definition of legitimate interests, the role of consent, data retention periods, and access to non-public registration data for third parties.

In its Phase 1 Final Report, delivered in March 2019, the EPDP Working Group established a new baseline policy framework for gTLD registration data. The policy reaffirmed the collection of certain registrant data elements by registrars but required most personally identifiable information to be redacted from public WHOIS output. The report also introduced the concept of “legal vs. natural” differentiation, recommending further exploration of whether legal entity data, which may not be subject to the same privacy protections as personal data, could be publicly disclosed. However, no binding consensus was reached on mandatory differentiation practices, leaving implementation largely at the discretion of individual contracted parties.

Phase 2 of the EPDP focused on developing a standardized system for providing access and disclosure to non-public registration data, known as the System for Standardized Access/Disclosure (SSAD). The SSAD was envisioned as a global mechanism through which accredited users, such as law enforcement, intellectual property holders, and cybersecurity professionals, could request access to redacted data based on defined legal grounds. The system aimed to balance the need for legitimate access with the protection of registrant privacy and compliance with data protection laws.

The development of the SSAD revealed substantial operational, legal, and financial complexities. Key debates centered on whether ICANN itself should act as a centralized decision-maker for disclosure requests or merely serve as a routing system forwarding requests to individual contracted parties who would retain decision-making authority. Ultimately, the EPDP Working Group recommended a decentralized model, where contracted parties would continue to evaluate disclosure requests on a case-by-case basis while ICANN Org would operate the technical infrastructure to process and route requests. This compromise reflected the legal reality that contracted parties are directly responsible for GDPR compliance and therefore must retain control over disclosure decisions.

Following the adoption of the Phase 2 Final Report, ICANN initiated an Operational Design Phase (ODP) to assess the feasibility, costs, and implementation requirements of the proposed SSAD model. The ODP concluded that building and operating the SSAD would entail significant financial investment and raised questions about the system’s long-term sustainability, efficiency, and effectiveness. Concerns about high costs, limited automation, and the potential for uneven disclosure decisions across contracted parties have led to ongoing community discussions about whether the proposed model delivers sufficient public benefit to justify its complexity.

In parallel to the EPDP, ICANN has initiated the EPDP Phase 2A to address remaining issues related to legal vs. natural person data and the role of anonymized contact information. However, consensus on mandatory differentiation requirements remains elusive, reflecting the persistent tension between privacy protection and transparency that lies at the heart of the registration data debate.

The EPDP on gTLD Registration Data has become a defining example of the ICANN multi-stakeholder model grappling with real-world legal and policy challenges. It demonstrates both the strengths and limitations of a global governance system that must reconcile widely divergent stakeholder interests, cultural values, and regulatory regimes while preserving the technical stability of the DNS. The policy outcomes of the EPDP will have far-reaching implications for domain name registrants, internet users, law enforcement, cybersecurity operations, intellectual property protection, and the broader global internet community for years to come.

In conclusion, the EPDP has provided a legal framework that brings ICANN’s policies into closer alignment with global data protection norms, but it has also revealed the considerable difficulties inherent in balancing privacy rights with the legitimate need for access to registration data. As implementation efforts continue and new legal developments emerge, the global internet community will need to remain engaged to ensure that gTLD registration data policies continue to evolve in a way that supports both the security and openness of the DNS while respecting fundamental privacy principles in an increasingly complex regulatory environment.

The Expedited Policy Development Process, or EPDP, on gTLD Registration Data is one of the most consequential and complex policy initiatives undertaken within the ICANN multi-stakeholder model. Emerging in response to sweeping changes in global data protection regulations, particularly the European Union’s General Data Protection Regulation (GDPR), the EPDP represents a comprehensive effort to modernize…

Leave a Reply

Your email address will not be published. Required fields are marked *