WhoIs data: new response from ICANN to the European Commission

Since the GDPR forced the redaction of WhoIs records in 2018, rights holders have struggled to identify domain registrants — and the dialogue between ICANN and the European Commission has become a running saga. The article analyses ICANN's April 2022 response to the Commission, whose November 2020 IP Action Plan (COM(2020) 760 final) called for stronger cooperation from registries and registrars against IP infringements. ICANN recalls its 2018 Temporary Specification reconciling gTLD registration data with GDPR, stresses that it has no authority over ccTLD operators, and points to the suspension powers of its WhoIs Accuracy Program. The forward-looking piece is the NIS2 directive: by designating registries and registrars as 'essential entities', it would oblige them to maintain accurate registration data and to answer authorities' requests 'as soon as possible' — a shift towards strict accuracy obligations that the article sees as the real game-changer for enforcement access.

COSHIELD: The Scope of the UDRP in Trademark Disputes

Not every dispute involving a trade mark and a domain name amounts to cybersquatting. In Polyco Healthline Limited v. David Beatson (WIPO Case No. D2026-1893), the panelist denied the complaint brought against coshield.com, a domain used since 2020 to sell personal protective equipment in the very sector where the complainant has exploited its SHIELD trade mark since 1997, and despite a settlement agreement concluded between the parties in 2021. The decision turns on the moment of acquisition: created in 2014, the domain name appears to have changed hands in May 2020, at the outset of the COVID-19 pandemic, and the combination of “Co” and “Shield” could describe the business rather than target Polyco. The evidence being “finely balanced”, bad faith was not established. This article examines why trade mark infringement and cybersquatting are two paths that do not necessarily converge.

23 August 2026
Initially published on iptwins.com

Football Clubs and Cybersquatting: When a Domain Name Becomes the Infrastructure of Abuse

Football clubs have become prime targets for cybersquatters, but abusive domain names are no longer used merely to divert web traffic or exploit a club's reputation. Increasingly, they form part of a broader criminal infrastructure supporting phishing campaigns, counterfeit merchandise, fake ticket sales, fraudulent streaming platforms, cryptocurrency scams and other forms of online fraud. Drawing on an analysis of more than one hundred UDRP decisions involving football clubs from around the world, this article identifies the principal patterns of abuse, the domain name strategies adopted by cybersquatters, and the legal reasoning developed by UDRP panels. It highlights how attackers exploit supporters' trust by combining famous club names with terms relating to tickets, official stores, memberships, academies, streaming services or digital assets. Beyond the case law, the article argues that domain names have become a critical component of cybercrime ecosystems. It therefore examines the practical implications for brand owners and rights holders, emphasizing the importance of proactive domain name strategies, continuous monitoring and rapid enforcement mechanisms. The article concludes with practical recommendations to help football clubs and other rights holders strengthen their online brand protection in an increasingly complex digital environment.

19 July 2026
Initially published on iptwins.com

Tracing and Disclosure: Belgium Enlists Registrars in the Fight Against Sports Piracy

Registrars are no longer asked only who holds a domain name, but how that holder pays. On 19 August 2026, Belgium’s Department for Combating Online Infringements of Copyright (BAPO) issued five decisions ordering Hosting Concepts, Hostinger, Key Systems and one registry to disclose, within ten working days, data on the holders of domain names used by illegal sports streaming sites. Implementing orders obtained by DAZN and The 12th Player before the French-speaking Business Court of Brussels, and relying on Article 10 of the Digital Services Act and Articles XVII.34/1 et seq. of the Code of Economic Law, the request goes far beyond WHOIS: identities, full IBANs, crypto wallets, IP addresses and twelve months of connection logs, under a strict duty of silence. Measured against the case law of the Court of Justice (Promusicae, Mircom, Coty Germany, La Quadrature du Net), this “follow the money” turn raises questions of territoriality, proportionality and data protection, and opens a path that online brand protection may one day borrow.

22 September 2026
Initially published on iptwins.com

Lacoste v Shein: When a Platform Can No Longer Hide Behind Hosting Status

A platform is not one legal object. In Lacoste v Roadget Business Pte. Ltd. and Infinite Styles Services Co. Ltd. (Paris, Pôle 5 ch. 1, 8 July 2026, RG 25/12454), the Court of Appeal refused to let the operators of shein.com shelter behind the hosting exemption of Article 6 of the Digital Services Act: goods “sold by Shein”, Shein labels and packaging, and the Commission’s designation of the service as a very large online platform revealed a hybrid activity, and the characterisation attached not to the platform as a whole but to the role actually played in the disputed transactions. The judgment reaches beyond the twenty offending products. “Lacoste”, typed into the internal search engine, infringes the word marks; “crocodile”, a free word, grounds unfair competition and parasitism. Interim damages rise from €30,000 to €300,000 — the defendants’ own failure to disclose their turnover counting against them — and the measures run across the European Union.

28 August 2026
Initially published on iptwins.com

Article Information

Author

Emmanuel Gillet

Publication Date

25 April 2022

Jurisdiction

Industry

Related Decision(s)

Please select listing to show.

Filter articles

Filter for Topics
Filter for Industries
Filter for Jurisdictions