Cops get special Whois access rights
Law enforcement agencies will be able to get access to private Whois records in under 24 hours under ICANN policy introduced yesterday, but the powers are toothless for now.
ICANN has updated its Registration Data Policy to add a section handling “urgent requests” for Whois data, normally redacted in the public RDAP databases due to privacy laws and ICANN policy.
Normally, registrars have as much as 30 days to respond to disclosure requests, but they will only have 24 hours when the request relates to “circumstances that pose an imminent threat to life, of serious bodily injury, to critical infrastructure, or of child exploitation in cases where disclosure of the data is necessary in combatting or addressing this threat”.
Because it’s a formal Consensus Policy, it’s already binding on all contracted parties.
But it’s currently pretty useless. The policy only requires the fast disclosure when the requestor is an “authenticated” law enforcement agency, and as of today ICANN has no mechanism to authenticate LEAs.
Figuring out how to authenticate requestors has been under discussion privately in the Governmental Advisory Committee’s Public Safety Working Group for some time, with ideas about domain-based authentication being floated.
But it seems the real work will be carried out by the GNSO Council’s forthcoming Supplementation Recommendations on the EPDP Phase 2 working group, which will be tasked with revisiting earlier, subsequently rejected, work on Whois access.
The pencilled-in deadline for that working group to reach recommendations is January 2027, a lot faster (but critics say less democratic) than a full-blown Policy Development Process, which would take years.






Recent Comments