Domain Names and Privacy: GDPR Implications for Owners and Brokers in Norway
GDPR has fundamental implications for domain name owners and brokers in Norway. Understanding these regulations is critical to avoid breaches and ensure proper handling of personal data.
Domain Names and Privacy: GDPR Implications for Owners and Brokers in Norway
In an increasingly digital world, domain names are not just website addresses but also valuable digital assets. With value comes significant responsibility, especially concerning privacy. The General Data Protection Regulation (GDPR) has fundamentally altered the landscape of data protection in Europe, and this profoundly includes how domain names are registered, owned, and traded in Norway.
What is GDPR and why is it relevant for domain names?
GDPR is an EU regulation that came into force in 2018 and has been implemented into Norwegian law through the Personal Data Act. Its purpose is to strengthen the privacy of individuals within the EU/EEA area by giving them more control over their data and imposing strict requirements on organisations that process personal data.
The relevance for domain names lies in the fact that registering a domain name often involves processing personal data. Traditionally, the WHOIS database, which contains information about domain name owners, has been publicly accessible. Following the advent of GDPR, this has changed dramatically, as much of the personally identifiable information (PII) such as names, addresses, emails, and phone numbers of private individuals can no longer be freely published without a legal basis.
Implications for Domain Name Owners in Norway
1. Reduced Visibility in WHOIS
For private individuals who own domain names, GDPR has led to their contact information largely being anonymised or hidden in public WHOIS lookups. This means it is more difficult for third parties to directly identify a private owner. While this strengthens privacy for individuals, it can also create challenges for those wishing to contact a domain name owner, for example, with a purchase offer or a dispute.
However, the same rules do not apply to businesses to the same extent. Legal entities (companies) do not have the same privacy rights as individuals. Therefore, company information such as firm name, organisation number, and business address will often still be visible in WHOIS, although the names of contact persons may be hidden.
2. Responsibility for Data Processing when Operating a Website
As a domain name owner, you are often also responsible for the content of the website to which the domain points. If the website collects personal data (e.g., via contact forms, analytics tools, or e-commerce), you are considered a 'data controller' under GDPR. This entails a number of obligations:
- Consent: You must have valid consent from users to collect and process personal data, unless another legal basis exists.
- Information Duty: You must clearly inform users about what data is collected, why, how it is used, and how long it is stored (typically via a privacy policy).
- Data Security: You must implement appropriate technical and organisational measures to protect the collected data against unauthorised access, loss, or destruction.
- Individual Rights: You must have procedures in place to handle users' rights, such as the right to access, rectification, erasure, and data portability.
Example: A Norwegian online store (domain name owner) collects customers' names, addresses, and payment information. The online store must have a clear privacy policy, ensure that the payment solution is GDPR-compliant, and have procedures for deleting customer data upon request after the retention period has ended.
Implications for Domain Brokers in Norway
Domain brokers act as intermediaries in the buying and selling of domain names. In this role, they often process personal data from both buyers and sellers. This makes them 'data controllers' or 'data processors' under GDPR, depending on the specific agreement and service.
1. Processing Client Data
Brokers collect personal data from their clients to perform their services, such as names, contact information, bank details, and identification documents. The broker must then:
- Have a Legal Basis: Typically, this will be to fulfil a contract (brokerage agreement) or a legal obligation (e.g., anti-money laundering laws).
- Data Minimisation: Only collect personal data that is strictly necessary to carry out the assignment.
- Secure Storage: Ensure that client data is stored securely and is only accessible to authorised personnel.
- Deletion Procedures: Have clear procedures for when and how personal data should be deleted after the assignment is completed and any statutory retention periods have expired.
2. Challenges with Anonymised WHOIS
The anonymisation of WHOIS data has made the broker's work more complex. Previously, a broker could easily find contact information for a domain name owner in WHOIS to initiate a dialogue. Now, the broker often has to use other methods, such as contacting the registrant via forms on registrars' websites or via generic email addresses that may be listed.
This requires more time and resources and can delay brokerage processes. Brokers must also be careful about how they obtain and use such information, as unlawful collection can lead to GDPR breaches.
3. Transparency and Information
Brokers must be transparent with clients about how their personal data is processed. A clear privacy policy on the broker's own website is mandatory. This policy should detail:
- What data is collected.
- The purpose of the collection.
- Who the data is shared with (e.g., registrars, escrow services).
- How the data is protected.
- Clients' rights.
What Happens in Case of a Breach?
Breaches of GDPR can result in significant sanctions. The Norwegian Data Protection Authority (Datatilsynet) can impose administrative fines of up to 20 million euros, or 4% of the company's global annual turnover, whichever is higher. In addition, there is reputational damage and potential claims for compensation from affected individuals.
Case: A Norwegian domain broker lost an unsecured USB drive containing contact information for 500 potential buyers and sellers of domain names. This constitutes a data breach. The broker is obliged to notify the Data Protection Authority within 72 hours and inform the affected individuals if the breach poses a high risk to their rights and freedoms. Failure to do so can result in significant fines.
Conclusion
GDPR has fundamentally changed the rules of the game for domain name owners and brokers in Norway. It is no longer just about owning or trading a domain, but also about understanding and complying with strict privacy requirements. For owners, it means responsibility for the website's data processing, while for brokers, it involves proper handling of client data and adapting to a more anonymised WHOIS landscape. By prioritising privacy and implementing robust procedures, both owners and brokers can navigate this complex landscape safely and legally, thereby building trust in the market.
Need help with a domain?
Domenemegler brokers the purchase, sale and leasing of domain names.