Latest news of the domain name industry

Recent Posts

As .spa launches, former partner pisses in the champagne

The world’s newest gTLD is due to hit its landrush launch phase tomorrow, but a disgruntled former business partner is warning that it plans to get all the registrations cancelled.

DotPH, the ccTLD registry for the Philippines, reckons it is owed half of the equity in .spa under a 2012 agreement, and has been warning registrars that to sell .spa domains would be to breach three injunctions it has secured through a Hong Kong court.

The latest such injunction (pdf), dated April 23, in part prevents the registry, Asia Spa and Wellness Promotion Council:

(whether directly or indirectly and whether by itself or via its agents or service providers (viz. registrars and registry backend) (“Agents/Service Providers”), employees and/or associated corporate entities whatsoever) be restrained from entering into any agreements for the sale, lease or other use or disposal of any .spa sub-domains (“Launch Agreements”) and/or causing, procuring or giving consent to the Agents/Service Providers to enter into any Launch Agreements

The injunctions are being interpreted differently by DotPH and ASWPC.

DotPH told participating registrars — there are at least 36 of them, according to the ASWPC web site — in a May 12 letter (pdf) from its lawyers:

ASWPC must stop selling .spa domains – by itself, or by or through its agents including Registrars… ASWPC cannot allow or permit any of its Registrars to sell any .spa domains.

It goes on to say:

Our clients will seek orders to cancel all registrations accepted by the .Spa Registry in breach of the Court order. You should alert any existing registrants, and any intending registrants of the Court order, and of the likelihood that any .spa domains registered are likely to be cancelled – unless they have a contract dating before 19 April 2021 requiring ASWPC, or you, to register their domains.

ASWPC’s interpretation appears to differ, in that it does not believe registrars are bound by the injunction, due to the chain of contracts between registry and registrant.

DotPH says that the Hong Kong High Court is next due to consider the case in August.

The .spa landrush phase is due to run from 1600 UTC May 26 until October 1. It’s ostensibly a community-based gTLD, but has eligibility policies that make it open to essentially anyone.

Facebook gunning for Web.com in latest $27 million-plus cybersquatting lawsuit

Kevin Murphy, April 16, 2021, Domain Registrars

Facebook has sued what it believes is a Web.com subsidiary, claiming the company has been engaged in wholesale cybersquatting for well over a decade.

The complaint, filed in a Pennsylvania District Court, alleges that New Venture Services Corp current owns 74 domains, and has previously owned 204 more, that infringe its Facebook, Instagram and WhatsApp trademarks.

While no other named defendants are listed, the complaint makes it abundantly clear that it believes NVSC is a subsidiary of Web.com and a sister of Network Solutions, Register.com, SnapNames and Perfect Privacy.

Facebook is suing partly under the Anti-Cybersquatting Consumer Protection Act, allowing it to claim $100,000 damages per infringing domain, so we’re looking at a floor of $27.8 million of potential damages should the lawsuit be successful.

But it’s also looking for NVSC to hand over any profits it’s made from the domains in question, which are generally parked with ads and listed for sale via the SnapNames network for premium fees.

While NVSC is registered in the British Virgin Islands and uses a Pennsylvania post office box as its mailing address, there’s a wealth of evidence going back to 2007 that it’s been affiliated first with NetSol and then Web.com.

Web.com’s last regulatory filing before it went private in 2017 lists NVSC as a subsidiary, which is probably the most compelling piece of evidence establishing ownership.

It appears that NVSC is a shell company that Web.com uses to hold potentially valuable or traffic-rich domains that its customers have allowed to expire. The names are then parked and put up for resale.

Example domains listed in the complaint include httpinstagram.com, faceebbok.com, facebooc.net, instagram-login.com, and installwhatsapps.com.

One would have to assume these names were captured using a fully automated process; even a cursory human review would clock that they’re useful only to bad actors.

The lawsuit is the latest in Facebook’s crusade against mainstream registrars it believes are profiting by infringing its trademarks, which has already ensnared Namecheap a year ago and OnlineNIC in October 2019.

Namecheap recently filed a counterclaim in which it tries to get some of Facebook’s trademarks cancelled.

Facebook has all but admitted that putting legal pressure on registrars is part of its strategy when it comes to getting the policies it wants out of ICANN on privacy and Whois access, where there’s currently an impasse.

Here’s the complaint (pdf).

Schreiber really did sue you all, sorry

Kevin Murphy, August 31, 2020, Domain Policy

It seems the aggrieved domain registrant and troll Graham Schreiber really has filed a lawsuit against scores of current and former domain name industry and ICANN community members.

You may recall that last week I blogged about a purported lawsuit by Schreiber against many industry professionals, as well as people who’ve been heavily involved in ICANN over the last couple decades.

I noted that there was no independent confirmation that any complaint has actually been filed in any court, but it turns out a complaint has now actually been filed.

A search on the Canadian Federal Court system reveals:

Schreiber

That appears to be an intellectual property lawsuit filed August 25 by Schreiber against “Jeffrey Levee et al”.

That’s five days after the document started circulating among defendants and my original coverage.

Levee is the long-time outside counsel for ICANN, working for Jones Day for two decades. In the org’s early days, his name often popped up in conspiracy theories.

The Schreiber document that was circulated last week just happened to name Levee as his first defendant, followed by several dozen more, often far less influential, individuals and companies.

To see my original coverage of the pretty much incomprehensible complaint, along with a link to the document, go here.

It’s a CONSPIRACY! Canadian registrant “sues” pretty much everybody

Kevin Murphy, August 20, 2020, Domain Policy

Canadian domain registrant and noted industry troll Graham Schreiber has sued, or at least claims to have sued, just about every notable figure in the ICANN community.

A document purporting to be a lawsuit is being circulated today among some of the dozens of named defendants, which include several people who’ve not been involved with ICANN for many years.

It names 27 volunteers from ICANN’s Intellectual Property Constituency, 21 current and former senior executives of registries and registrars, several members of the US and UK governments, an FBI agent, an unnamed “White House Conspirator”, as well as lawyers for LinkedIn, Facebook, Twitter, ICANN, Google and the UK Intellectual Property Office.

It’s my job to tell you in simple terms what the alleged lawsuit alleges, but I’m afraid I’m at an utter loss with this one. It reads like the fever dream of a conspiracy theorist that would make the average Qanon believer appear the model of reason and clarity.

Schreiber variously refers to his defendants as “Kingpins” involved in a “Cartel” or “Conspiracy”, the factual details of which he never quite gets to.

Here’s a representative sample paragraph, unedited:

If and when, the “Defensive Registrations” obliged by ICANN’s R[r]egistry & R[r]egistrar “Stakeholders” = “Kingpins” and specifically CentralNic [ weren’t purchased ] assailants would strike; and Infringe, Dilute, Blur and Pass-Off as our online business, individually with identical and confusingly similar domain name, faking to be appointed or an authorized agent of the primary Registrant, in a country’s entrepreneurs Intellectual Property may or may not have been protectable at Common Law Trademark, under Madrid Protocol Rules, as it / they fulfilled the obligations of local National laws, to become a Registered Trademark, as I secured in the USA with USPTO, after the CIPO did their work.

At one point, he admits to trolling the defendants on social media since 2012, and points to their failure to sue him as evidence of a conspiracy:

I’ve made statements via those Social Media resources which would, if they were untrue, subject me to a singular lawsuit or multiple lawsuits from the Defendants listed, for: Defamation, Slander and Libel.

As yet, these well taunted Defendants have all conspired together, in collective silence, anticipating that their grandeur and my insignificance would, maintain safe passage, for them to continue.

As the vast majority of the Defendants are well schooled, powerful U.S. Attorneys, it’s my expectation that the Court oblige them to address the charges here stated, or collectively for their defence, they must File a lawsuit with this Court, charging me for what could be [ but aren’t ] remarks constituting Defamation, Slander & Libel against them, which again, I’ve posted on some of the Defendants own clients, Social Media Platforms

Schreiber was once a regular fixture in DI’s comments section too. Thankfully, we’ve not heard from him in years.

The root cause of the “lawsuit” appears to be an old beef Schreiber has with CentralNic.

He says he owns what he calls a “common law trademark” on the term “Landcruise” and he once used the matching .com domain to operate a motor-home rental business.

At some point in 2011, he became aware that a British registrant had registered landcruise.co.uk and landcruise.uk.com.

At the time, CentralNic was primarily in the business of selling domains at the third level in pseudo-gTLDs such as uk.com, gb.com and us.com.

Schreiber tried and failed (twice) to get the .uk domain transferred under Nominet’s Dispute Resolution Service, and then he took his beef to the courts.

In 2012, he sued CentralNic, ICANN, Verisign, eNom, and Network Solutions in a complaint that barely made much more sense than the “lawsuit” being circulated today.

That case was thrown out of court in 2013.

I expect the same fate to befall the current lawsuit, if indeed it has even been filed in a court.

Schreiber wants $5 million from every defendant.

If you want to check whether you’re one of them, read the PDF “complaint” here.

US officials gunning for coronavirus domains

Kevin Murphy, March 24, 2020, Domain Registrars

US state and federal law enforcement are pursuing domain names being used to push bogus products and misinformation related to coronavirus Covid-19.

In separate actions, the US Department of Justice forced Namecheap to take down a scam site that was allegedly using fear of coronivirus to hoodwink visitors out of their cash, while the New York Attorney General has written to registrars to demand they take action against similar domains.

The DoJ filed suit (pdf) against the anonymous “John Doe” registrant of coronavirusmedicalkit.com on Saturday and on Sunday obtained a temporary restraining order obliging Namecheap to remove the DNS from the domain and lock it down, which Namecheap seems to have done.

Namecheap is not named as a defendant, but the complaint notes that the DoJ had requested the domain be taken down on March 19 and no action had been taken by the evening of March 21.

The web site in question allegedly informed visitors that the World Health Organization was giving away free coronavirus vaccines to anyone prepared to pay a $4.95 shipping fee by handing over their credit card details.

This is an identity theft scam and wire fraud, the complaint says.

Meanwhile, NYAG Letitia James has sent letters, signed by IT chief Kim Berger, to several large US registrar groups — including GoDaddy, Dynadot, Name.com, Namecheap, Register.com, and Endurance — to ask them to “stop the registration and use of internet domain names by individuals trying to unlawfully and fraudulently profit off consumers’ fears around the coronavirus disease”.

In the letter to GoDaddy (pdf), Berger asks for a “dialogue” on the following preventative measures:

  • The use of automated and human review of domain name registration and traffic patterns to identify fraud;
  • Human review of complaints from the public and law enforcement about fraudulent or illegal use of coronavirus domains, including creating special channels for such complaints;
  • Revising your terms of service to reserve aggressive enforcement for the illegal use of coronavirus domains; and
  • De-registration of the domains cited in the articles identified above that were registered at GoDaddy, and any holds in place on registering new domains related to coronavirus, or similar blockers that prevent rapid registration of coronavirus-related domains.

In other words: try to stop these domains being registered, and take them down if they are.

No specific malicious sites are listed in the letter. Rather, Berger cites a study by Check Point Software that estimates that something like 3% of the more than 4,000 coronavirus-related domains registered between January and March 5 are “malicious” in nature.

Facebook WILL sue more registrars for cybersquatting

Kevin Murphy, March 13, 2020, Domain Registrars

Facebook has already sued two domain name registrars for alleged cybersquatting and said yesterday that it will sue again.

Last week, Namecheap became the second registrar in Facebook’s legal crosshairs, sued in in its native Arizona after allegedly failing to take down or reveal contact info for 45 domains that very much seem to infringe on its Facebook, Instagram and WhatsApp trademarks.

In the complaint (pdf), which also names Namecheap’s Panama-based proxy service Whoisguard as a defendant, the social media juggernaut claims that Whoisguard and therefore Namecheap is the legal registrant for dozens of clear-cut cases of cybersquatting including facebo0k-login.com, facebok-securty.com, facebokloginpage.site and facebooksupport.email.

In a brief statement, Facebook said these domains “aim to deceive people by pretending to be affiliated with Facebook apps” and “can trick people into believing they are legitimate and are often used for phishing, fraud and scams”.

Namecheap was asked to reveal the true registrants behind these Whoisguard domains between October 2018 and February 2020 but decline to do so, according to Facebook.

The complaint is very similar to one filed against OnlineNIC (pdf) in October.

And, according to Margie Milam, IP enforcement and DNS policy lead at Facebook, it won’t be the last such lawsuit.

Speaking at the second public forum at ICANN 67 yesterday, she said:

This is the second in a series of lawsuits Facebook will file to protect people from the harm caused by DNS abuse… While Facebook will continue to file lawsuits to protect people from harm, lawsuits are not the answer. Our preference is instead to have ICANN enforce and fully implement new policies, such as the proxy policy, and establish better rules for Whois.

Make no mistake, this is an open threat to fence-sitting registrars to either play ball with Facebook’s regular, often voluminous requests for private Whois data, or get taken to court. All the major registrars will have heard her comments.

Namecheap responded to its lawsuit by characterizing it as “just another attack on privacy and due process in order to strong-arm companies that have services like WhoisGuard”, according to a statement from CEO Richard Kirkendall.

The registrar has not yet had time to file its formal reply to the legal complaint, but its position appears to be that the domains in question were investigated, found to not be engaging in nefarious activity, and were therefore vanilla cases of trademark infringement best dealt with using the UDRP anti-cybersquatting process. Kirkendall said:

We actively remove any evidence-based abuse of our services on a daily basis. Where there is no clear evidence of abuse, or when it is purely a trademark claim, Namecheap will direct complainants, such as Facebook, to follow industry-standard protocol. Outside of said protocol, a legal court order is always required to provide private user information.

UDRP complaints usually take several weeks to process, which is not much of a tool to be used against phishing attacks, which emerge quickly and usually wind down in a matter of a few days.

Facebook’s legal campaign comes in the context of an ongoing fight about access to Whois data. The company has been complaining about registrars failing to hand over customer data ever since Europe’s GDPR privacy regulation came into effect, closely followed by a new, temporary ICANN Whois policy, in May 2018.

Back then, its requests showed clear signs of over-reach, though the company claims to have scaled-back its requests in the meantime.

The lawsuits also come in the context of renewed attacks at ICANN 67 on ICANN and the domain industry for failing to tackle so-called “DNS abuse”, which I will get to in a follow-up article.

Exclusive: Tiny island sues to take control of lucrative .nu

Kevin Murphy, November 28, 2018, Domain Registries

The tiny Pacific island of Niue has sued the Swedish ccTLD registry to gain control of its own ccTLD, .nu, DI has learned.

The lawsuit, filed this week in Stockholm, claims that the Internet Foundation In Sweden (IIS) acted illegally when it essentially took control of .nu in 2013, paying its American owner millions of dollars a year for the privilege.

Niue wants the whole ccTLD registry transferred to its control at IIS’s expense, along with all the profits IIS has made from .nu since 2013 — many millions of dollars.

It also plans to file a lawsuit in Niue, and to formally request a redelegation from IANA.

While .nu is the code assigned to Niue, it has always been marketed in northern Europe, particularly Sweden, in countries where the string means “now”.

It currently has just shy of 400,000 domains under management, according to IIS’s web site, having seen a 50,000-name slump just a couple weeks ago.

It was expected to be worth a additional roughly $5 million a year for the registry’s top line, according to IIS documents dated 2012, a time when it only had about 240,000 domains.

For comparison, Niue’s entire GDP has been estimated at a mere $10 million, according to the CIA World Factbook. The island has about 1,800 inhabitants and relies heavily on tourism and handouts from New Zealand.

According to documents detailing its 2013 takeover, IIS agreed to pay a minimum of $14.7 million over 15 years for the right to run the ccTLD, with a potential few million more in performance-related bonuses.

The Niue end of the lawsuit is being handled by Par Brumark, a Swedish national living in Denmark, who has been appointed by the Niuean government to act on its behalf on ICANN’s Governmental Advisory Committee, where he is currently a vice-chair.

Brumark told DI that IIS acted illegally when it took over .nu from previous registry, Massachusetts-based WorldNames, which had been running the ccTLD without the consent of Niue’s government since 1997.

The deal was characterized by WorldNames in 2013 as a back-end deal, with IIS taking over administrative and technical operations.

But IIS documents from 2012 reveal that it is actually more like a licensing deal, with IIS paying WorldNames the aforementioned minimum of $14.7 million over 15 years for the rights to manage, and profit from, the TLD.

The crux of the lawsuit appears to be the question of whether .nu can be considered a “Swedish national domain”.

IIS is a “foundation”, which under Swedish law has to stick to the purpose outlined in its founding charter.

That charter says, per IIS’s own translation, that the IIS “must particularly promote the development of the handling of domain names under the top-level domain .se and other national domains pertaining to Sweden.”

Brumark believes that .nu is not a national domain pertaining to Sweden, because it’s Niue’s national ccTLD.

One of his strongest pieces of evidence is that the Swedish telecoms regulator, PTS, refuses to regulate .nu because it’s not Swedish. PTS is expected to be called as a witness.

But documents show that the Stockholm County Administrative Board, which regulates Foundations, gave permission in 2012 for IIS to run “additional top-level domains”.

Via Google Translate, the Board said: “The County Administrative Board finds that the Foundation’s proposed management measures to administer, managing and running additional top-level domains is acceptable.”

Brumark thinks this opinion was only supposed to apply to geographic gTLDs such as .stockholm, and not to ccTLD strings assigned by ISO to other nations.

The Stockholm Board did not mention .nu or make a distinction between ccTLD and gTLDs in its letter to IIS, but the letter was in response to a statement from an IIS lawyer that .nu, with 70% of its registrations in Sweden, could be considered a Swedish national domain under the IIS charter.

Brumark points to public statements made by IIS CEO Danny Aerts to the effect that IIS is limited to Swedish national domains. Here, for example, he says that IIS could not run .wales.

IIS did not respond to my requests for comment by close of business in Sweden today.

Niue claims that if .nu isn’t Swedish, IIS has no rights under its founding charter to run it, and that it should be transferred to a Niuean entity, the Niue Information Technology Committee.

That’s a governmental entity created by an act of the local parliament 18 years ago, when Niue first started its campaign to get control of .nu.

The history of .nu is a controversial one, previously characterized as “colonialism” by some.

The ccTLD was claimed by Boston-based WorldNames founder Bill Semich and an American resident of the island, in 1997. That’s pre-ICANN, when the IANA database was still being managed by Jon Postel.

At the time, governments had basically no say in how their ccTLDs were delegated. It’s not even clear if Niue was aware its TLD had gone live at the time.

The official sponsor of .nu, according to the IANA record, is the IUSN Foundation, which is controlled by WorldNames.

Under ICANN/IANA policy, the consent of the incumbent sponsor is required in order for a redelegation to occur, and WorldNames has been understandably reluctant to give up its cash cow, despite Niue trying to take control for the better part of two decades.

The 2000 act of parliament declared that NITC was the only true sponsor for .nu, but even Niuean law has so far not proved persuasive.

So the lawsuit against IIS is huge twist in the tale.

If Niue were to win, IIS would presumably be obliged to hand over all of its registry and customer data to Niue’s choice of back-end provider.

Both Afilias and Danish registrar One.com have previously expressed an interest in running .nu, providing a share of the revenue to Niue, according to court documents.

Brumark said that a settlement might also be possible, but that it would be very costly to IIS.

Readers might also be interested in my 2011 article about Niue, which was once widely referred to as the “WiFi Nation”.

Donuts loses to ICANN in $135 million .web auction appeal

Kevin Murphy, October 16, 2018, Domain Registries

Donuts has lost a legal appeal against ICANN in its fight to prevent Verisign running the .web gTLD.

A California court ruled yesterday that a lower court was correct when it ruled almost two years ago that Donuts had signed away its right to sue ICANN, like all gTLD applicants.

The judges ruled that the lower District Court had “properly dismissed” Donuts’ complaint, and that the covenant not to sue in the Applicant Guidebook is not “unconscionable”.

Key in their thinking was the fact that ICANN has an Independent Review Process in place that Donuts could use to continue its fight against the .web outcome.

The lawsuit was filed by Donuts subsidiary Ruby Glen in July 2016, shortly before .web was due to go to an ICANN-managed last-resort auction.

Donuts and many others believed at the time that one applicant, Nu Dot Co, was being secretly bankrolled by a player with much deeper pockets, and it wanted the auction postponed and ICANN to reveal the identity of this backer.

Donuts lost its request for a restraining order.

The auction went ahead, and NDC won with a bid of $135 million, which subsequently was confirmed to have been covertly funded by Verisign.

Donuts then quickly amended its complaint to include claims of negligence, breach of contract and other violations, as it sought $22.5 million from ICANN.

That’s roughly how much it would have received as a losing bidder had the .web contention set been settled privately and NDC still submitted a $135 million bid.

As it stands, ICANN has the $135 million.

That complaint was also rejected, with the District Court disagreeing with earlier precedent in the .africa case and saying that the covenant not to sue is enforceable.

The Appeals Court has now agreed, so unless Donuts has other legal appeals open to it, the .web fight will be settled using ICANN mechanisms.

The ruling does not mean ICANN can go ahead and delegate .web to Verisign.

The .web contention set is currently “on-hold” because Afilias, the second-place bidder in the auction, has since June been in a so-called Cooperative Engagement Process with ICANN.

CEP is a semi-formal negotiation-phase precursor to a full-blown IRP filing, which now seems much more likely to go ahead following the court’s ruling.

The appeals court ruling has not yet been published by ICANN, but it can be viewed here (pdf).

The court heard arguments from Donuts and ICANN lawyers on October 9, the same day that DI revealed that ICANN Global Domains Division president Akram Atallah had been hired by Donuts as its new CEO.

A recording of the 32-minute hearing can be viewed on YouTube here or embedded below.

Afilias sues India to block $12 million Neustar back-end deal

Kevin Murphy, August 27, 2018, Domain Registries

Afilias has sued the Indian government to prevent it awarding the .in ccTLD back-end registry contract to fierce rival Neustar.

The news emerged in local reports over the weekend and appears to be corroborated by published court documents.

According to Moneycontrol, the National Internet Exchange of India plans to award the technical service provider contract to Neustar, after over a decade under Afilias, but Afilias wants the deal blocked.

The contract would also include some 15 current internationalized domain name ccTLDs, with another seven on the way, in addition to .in.

That’s something Afilias reckons Neustar is not technically capable of, according to reports.

Afilias’ lawsuit reportedly alleges that Neustar “has no experience or technical capability to manage and support IDNs in Indian languages and scripts and neither does it claim to have prior experience in Indian languages”.

Neustar runs plenty of IDN TLDs for its dot-brand customers, but none of them appear to be in Indian scripts.

NIXI’s February request for proposals (pdf) contains the requirement: “Support of IDN TLDs in all twenty two scheduled Indian languages and Indian scripts”.

I suppose it’s debatable what this means. Actual, hands-on, operational experience running Indian-script TLDs at scale would be a hell of a requirement to put in an RFP, essentially locking Afilias into the contract for years to come.

Only Verisign and Public Interest Registry currently run delegated gTLDs that use officially recognized Indian scripts, according to my database. And those TLDs — such as Verisign’s .कॉम (the Devanagari .com) — are basically unused.

Neither Neustar nor Afilias have responded to DI’s requests for comment today.

.in has over 2.2 million domains under management, according to NIXI.

Neustar’s Indian subsidiary undercut its rival with a $0.70 per-domain-year offer, $0.40 cheaper than Afilias’ $1.10, according to Moneycontrol.

That would make the deal worth north of $12 million over five years for Afilias and over $7.7 million for Neustar.

One can’t help but be reminded of the two companies’ battle over Australia’s .au, which Afilias sneaked out from under long-time incumbent Neustar late last year.

That handover, the largest in DNS history, was completed relatively smoothly a couple months ago.

In GDPR case, ICANN ready to fight Tucows to the bitter end

Kevin Murphy, June 14, 2018, Domain Policy

ICANN has appealed its recent court defeat as it attempts to force a Tucows subsidiary to carry on collecting full Whois data from customers.

The org said yesterday that it is taking its lawsuit against Germany-based EPAG to a higher court and has asked it to bounce the case up to the European Court of Justice, as the first test case of the new General Data Protection Regulation.

In its appeal, an English translation (pdf) of which has been published, ICANN argues that the Higher Regional Court of Cologne must provide an interpretation of GDPR in order to rule on its request for an injunction.

And if it does, ICANN says, then it is obliged by the GDPR itself to refer that question to the ECJ, Europe’s highest judicial authority.

The case concerns Tucows’ refusal to carry on collecting contact information about the administrative and technical contacts for each domain name it sells, which it is contractually obliged to do under ICANN’s Whois policy.

These are the Admin-C and Tech-C fields that complement the registrant’s own contact information, which Tucows is of course still collecting.

Tucows says that these extra fields are unnecessary, and that GDPR demands it minimize the amount of data it collects to only that which it strictly needs to execute the registration contact.

It also argues that, if the Admin-C and Tech-C are third parties, it has no business collecting any data on them at all.

According to Tucows legal filings, more than half of its 10 million domains have identical data for all three contacts, and in more than three quarters of cases the registrant and Admin-C are identical.

In its appeal, ICANN argues that the data is “crucial for the objectives of a secure domain name system, including but not limited to the legitimate purposes of consumer protection,
investigation of cybercrime, DNS abuse and intellectual property protection and law enforcement needs”.

ICANN uses Tucows’ own numbers against it, pointing out that if Tucow has 7.5 million domains with shared registrant and Admin-C data, it therefore has 2.5 million domains where the Admin-C is a different person or entity, proving the utility of these records.

It says that registrars must continue to collect the disputed data, at the very least if it has secured consent from the third parties named.

ICANN says that nothing in the Whois policy requires personal data to be collected on “natural persons” — Admin-C and Tech-C could quite easily be legal persons — therefore there is no direct clash with GDPR, which only covers natural persons.

Its appeal, in translation, reads: “the GDPR is irrelevant if no data about natural persons are collected. In this respect, the Defendant is contractually obliged to collect such data, and failure to do so violates its contract with the Applicant.”

It goes on to argue that even if the registrant chooses to provide natural-person data, that’s still perfectly fine as a “legitimate purpose” under GDPR.

ICANN was handed a blow last month after a Bonn-based court refused to give it an injunction obliging EPAG (and, by inference, all registrars) to continue collecting Admin-C and Tech-C.

The lower court had said that registrants would be able to continue to voluntarily provide Admin-C and Tech-C, but ICANN’s appeal points out that this is not true as EPAG is no longer requesting or collecting this data.

In ICANN’s estimation, the lower court declined to comment on the GDPR implications of its decision.

It says the appeals court, referred to in translation as the “Senate”, cannot avoid interpreting GDPR if it has any hope of ruling on the injunction request.

Given the lack of GDPR case law — the regulation has only been in effect for a few weeks — ICANN reckons the German court is obliged by GDPR itself to kick the can up to the ECJ.

It says: “If the Senate is therefore convinced that the outcome of this procedure depends on the interpretation of certain provisions of the GDPR, the Senate must refer these possible questions to the ECJ for a preliminary ruling”.

It adds that should a referral happen it should happen under the ECJ’s “expedited” procedures.

An ECJ ruling has been in ICANN’s sights for some time; late last year CEO Goran Marby was pointing out that a decision from the EU’s top court would probably be the only way full legal clarity on GDPR’s intersection with Whois could be obtained.

It should be pointed out of course that this case is limited to the data collection issue.

The far, far trickier issue of when this data should be released to people who believe they have a legitimate purpose to see it — think: trademark guys — isn’t even up for discussion in the courts.

It will be, of course. Give it time.

All of ICANN’s legal filings, in the original German and unofficial translation, can be found here.