Whois and GDPR: the US response is underway

Since the GDPR took effect in May 2018, WHOIS databases have gone dark, to the dismay of investigators and right holders. The article reports the American counter-offensive: on 26 February 2020, Congressman Bob Latta introduced a resolution urging that WHOIS records — 'the identity card of a website' — remain accessible, in the name of national and economic security, intellectual property, cybersecurity, health and privacy itself. The difficulty is squaring such legislation with the GDPR: American registries and registrars would face contradictory obligations. The author sketches possible compromises — disclosing professional contact data only, or withholding data solely for EU-domiciled registrants — while doubting the European Commission would embrace them. The transatlantic tug-of-war over WHOIS access was only beginning.

DNS Abuse: How Can Domain Names Linked to the Same Actor Be Connected?

On 18 August 2026, ICANN published for public comment the Initial Report of its DNS Abuse Mitigation Policy Development Process (PDP 1). Among its proposals are Associated Domain Checks: when a registrar acts on an abuse report, it should also examine the other domain names held by the same customer. In its comments of 25 September 2026, the WIPO Arbitration and Mediation Center supports the approach but points out its main limitation: the checks stop at the edge of a single registrar's portfolio. Bad actors know this and spread their registrations across several registrars, which hampers consolidated UDRP proceedings. WIPO suggests exploring cross-registrar mechanisms without saying which data could link the names. The article argues that payment data, pseudonymised, could serve as that common denominator, while acknowledging its limits (prepaid cards, fraud, multiple payment methods): an indicator rather than proof. It marks a shift from a one-domain, one-investigation logic to a network approach.

28 September 2026
Initially published on iptwins.com

New gTLDs: first revocation of a dotBRAND for breach of the registry agreement

On 25 June 2020, ICANN terminated with immediate effect the Registry Agreement for .AIGO, the dotBrand of Aigo Digital Technology Co., Ltd, a Chinese electronics manufacturer which had obtained the extension in 2016 to support its expansion beyond Chinese-speaking markets. From 30 March 2018, ICANN's compliance department had notified breaches — unpaid fees and missing mandatory notices on the institutional website — to which Aigo never responded. ICANN then triggered the mediation-arbitration mechanism provided for in the Registry Agreement and its Specification 13; Aigo did not take part in the proceedings. As Aigo was the sole registrant of all .AIGO domain names, no successor registry operator was needed. DotBrand extensions are regularly abandoned voluntarily (.DODGE, .CHRYSLER, .TELEFONICA), but .AIGO is the first to be revoked at the end of a formal contractual dispute with ICANN.

9 July 2020
Initially published on iptwins.com

DNS Abuse: How Can Domain Names Linked to the Same Actor Be Connected?

On 18 August 2026, ICANN published for public comment the Initial Report of its DNS Abuse Mitigation Policy Development Process (PDP 1). Among its proposals are Associated Domain Checks: when a registrar acts on an abuse report, it should also examine the other domain names held by the same customer. In its comments of 25 September 2026, the WIPO Arbitration and Mediation Center supports the approach but points out its main limitation: the checks stop at the edge of a single registrar's portfolio. Bad actors know this and spread their registrations across several registrars, which hampers consolidated UDRP proceedings. WIPO suggests exploring cross-registrar mechanisms without saying which data could link the names. The article argues that payment data, pseudonymised, could serve as that common denominator, while acknowledging its limits (prepaid cards, fraud, multiple payment methods): an indicator rather than proof. It marks a shift from a one-domain, one-investigation logic to a network approach.

28 September 2026
Initially published on iptwins.com

DNS and Web3: How Can We Avoid Importing Cryptosquatting into the DNS?

The DNS and blockchain-based alternative naming systems are converging, with projects such as .BLOCKCHAIN and the .ROBOT cryptoTLD seeking to operate the same string in both worlds. In August 2026, ICANN's Technical Study Group released an Initial Report on integrating gTLDs with alternative naming systems, built on a "string + controller" principle: the same name must remain under the same control across systems, with its status kept in sync. In September 2026, the SSAC supported this synchronisation but noted that applying the UDRP and the URS becomes difficult when a registrant exists only in an alternative system, without conventional registration data. The WIPO Arbitration and Mediation Center warns that cybersquatting is already widespread in these systems: mapping names automatically into the DNS would import existing infringements. Trademark owners therefore need functionally equivalent protection mechanisms, including a way to prevent infringing names from being activated, as initiatives like Unstoppable Domains joining GlobalBlock have begun to show.

24 September 2026
Initially published on iptwins.com

Article Information

Author

Emmanuel Gillet

Publication Date

18 March 2020

Industry

Related Decision(s)

Please select listing to show.

Filter articles

Filter for Topics
Filter for Industries
Filter for Jurisdictions