ICANN logo beside a screen listing generic top-level domains, illustrating ICANN's Registration Data Policy on domain ownership

ICANN: Critical changes to Domain Name Ownership from August 21, 2025

ICANN’s Registration Data Policy, in force since August 21, 2025, changed how domain ownership is determined: if the “Organization” field on a domain registration names a company, that company, not the individual listed as registrant, counts as the legal owner. This piece explains the rule, what it means under Cypriot law, and the practical steps worth taking to check your own domains.

ICANN (Internet Corporation for Assigned Names and Numbers) is the non-profit organization, founded in 1998 and based in the United States, that administers the internet's Domain Name System (DNS) and allocates IP addresses. Unlike traditional international bodies such as the International Telecommunication Union (ITU), ICANN works through a "multi-stakeholder" model in which governments, the private sector, the academic community, and individual users all take part in internet governance.

Every domain name registered worldwide is subject to ICANN's rules and policies, which makes the organization's decisions directly relevant to any business or professional whose international transactions and e-commerce depend on a stable domain presence. For more on how ICANN came to hold this role, see my earlier piece on the founding of ICANN.

The new Registration Data Policy

The Registration Data Policy (RDP) took effect on August 21, 2025, the biggest restructuring of domain name ownership data management since 2018. It goes beyond a technical adjustment: it changes how the legal owner of a domain name is determined.

The central change concerns the hierarchy of ownership data. Under paragraph 6(6)(2) of the RDP, if the "Organization" field in the registrant's details names a company, that company is automatically treated as the legal owner of the domain. The individual named in the contact details becomes a point of contact only, with no ownership rights.

"6(6)(2) The Registrant Organization will be considered the Registered Name Holder."

Source: ICANN, Registration Data Policy (RDP)

This reverses the previous practice, under which the registrant's first and last name determined ownership. For example, a company director who registered a business domain under their own name but entered the company name in the "Organization" field will find that, since August 21, 2025, the company is the domain owner, regardless of whose name appears as registrant.

How domain ownership changes affect you

From a legal perspective, this change raises real issues that are worth attention. Under Cypriot law, domain names are treated as intangible assets with substantial commercial value, so an automatic transfer of ownership from an individual to a legal entity can affect contractual relationships, corporate agreements, and even divorce or inheritance proceedings.

The clearest example is the entrepreneur who registered a domain under their own name for convenience or control, but entered the company name in the "Organization" field. Since August 21, 2025, such domains belong to the company, which can complicate matters when a shareholder leaves, shares are sold, or a corporate dispute arises.

The change also affects the transfer process. Any modification to the "Organization" field now triggers a change-of-registrant procedure that requires email verification, and failing to complete that verification within the set timeframe can lead to domain suspension, which disrupts business operations.

GDPR and data protection

The Registration Data Policy is a direct result of the General Data Protection Regulation (GDPR), which took effect in 2018. ICANN had to redesign the WHOIS system, which had traditionally published domain holders' personal details freely, to meet GDPR's requirements.

The RDP restricts the collection and publication of personal data considerably. Mandatory fields for administrative and billing contacts are abolished, technical contacts become optional and can use generic email addresses, and Organization details will not appear in public WHOIS unless the holder gives explicit consent. This follows GDPR's data-minimization principle: only the information that is strictly necessary is collected and processed.

Practical steps to take

If you have not already done so, review your registered domains and check the "Organization" field on each one.

If you want personal ownership, leave the "Organization" field empty. If you want corporate ownership, make sure the company name is entered correctly there.

Domains held for investment purposes or as part of a personal portfolio deserve a closer look, since a company name sitting in the "Organization" field can create ownership consequences you did not intend.

Other technical changes

Beyond the change in ownership determination, the Registration Data Policy introduces three further technical changes that affect domain name management directly.

First, registrars are no longer required to collect Administrative, Billing, or Technical Contact fields. Since August 21, 2025, they collect only the "minimal data set", limited to the necessary Registrant details, which follows GDPR's data-minimization principle and reduces the administrative burden for businesses that manage several domains.

Second, and arguably more consequential for businesses, registrars must permanently delete all historical Administrative, Billing, and Technical contact data held in their systems.

Third, the Technical Contact field is now optional and can hold a generic address, such as "support@example.com", instead of an individual employee's personal details, which lets businesses keep a stable point of contact regardless of staff turnover.

ICANN Registration Data Policy Changes
Effective August 21, 2025
Registrant (Domain Owner)
REQUIRED
Public Display: Tiered access
Note: The only necessary element. This field identifies the legal owner of the domain.
Organization (Company/Entity)
OPTIONAL
Public Display: Shown if present
Important: If filled, the organization will be considered the legal owner, not the individual registrant.
Administrative (Admin Contact)
DISCONTINUED
Public Display: No longer collected
Note: All existing administrative contact data will be permanently deleted.
Billing (Financial Contact)
DISCONTINUED
Public Display: No longer collected
Note: All existing billing contact data will be permanently deleted.
Technical (Tech Support)
EXCEPTIONS*
Public Display: Rarely shown
Note: Only required for specific TLDs. May use generic email addresses instead of personal information.
* Exceptions: Some country-code TLDs and specialized domains may have different requirements. The policy applies to all generic TLDs (.com, .net, .org, etc.) but certain extensions like .asia may maintain additional contact requirements.

 

From WHOIS to RDAP

Alongside the Registration Data Policy, ICANN retired the WHOIS protocol on January 28, 2025, and replaced it with the Registration Data Access Protocol (RDAP). WHOIS had been running since 1982 and carried real weaknesses: no standard data format and no support for international characters. RDAP addresses both, delivering structured data in JSON, requiring HTTPS, and allowing tiered access depending on who is asking.

For legal professionals and domain management specialists, the practical effect is that access to non-public registration data now requires identity verification and a documented legitimate interest. ICANN launched the Registration Data Request Service (RDRS) in November 2023 as a two-year pilot to standardize such requests, particularly for law enforcement, intellectual property protection, and cybersecurity cases. The pilot concluded on 30 November 2025; on 30 October 2025 the ICANN Board had already resolved to keep RDRS running as an ongoing service through December 2027 while the community works on a permanent successor, so it is no longer experimental, just not yet final.

A further revision to the Registration Data Policy on 12 May 2026 added a fast track for urgent disclosure requests: acknowledgement within two hours and a substantive response within 24 hours, for cases involving an imminent threat to life, serious bodily injury, critical infrastructure, or child exploitation. That fast track applies only to an "Authenticated Requestor", and ICANN has tied its effective date to an authentication mechanism for law enforcement that is still being finalized, so the ordinary 30-day response window remains the one to plan around for now. This creates procedural requirements worth keeping in mind when seeking information for a domain dispute or a trademark infringement investigation.

Upcoming reforms to domain transfers

Beyond the Registration Data Policy, ICANN is working through a separate reform of the Transfer Policy. The GNSO Council approved the Transfer Policy Review Working Group's 47 recommendations in March 2025, and under ICANN's Bylaws the Board is obliged to adopt them unless a two-thirds majority finds against doing so, so implementation is now a matter of timing rather than outcome. The most consequential change would cut the lock period from 60 to 30 days for both new registrations and inter-registrar transfers, and remove entirely the lock that currently follows a change to registrant details, which would make portfolio consolidation and corporate restructuring considerably easier.

The reform also standardizes procedures for bulk domain transfers (Bulk Transfer After Partial Portfolio Acquisition, or BTAPPA), capping the registry charge at $50.000 for portfolios over 50.000 domains, and updates the valid grounds for denying a transfer to include DNS abuse as ICANN defines it. Once adopted, these changes should simplify transfer procedures while narrowing the room for fraud and abuse.

Dates to note:

  • May 28, 2025: Email notifications begin
  • August 21, 2025: Official implementation of the new policy
  • After 8/21: Permanent deletion of old contact data

 

Bottom line

The August 21, 2025 deadline has now passed, and the Registration Data Policy is the framework registrars apply today. If you have not yet checked the "Organization" field on your domains, it is worth doing now: correcting it after the fact still works, it just takes you through the same registrant-change verification as any other update. The RDRS and the pending urgent-request authentication mechanism discussed above are worth watching too, since they will determine how quickly you can obtain non-public registration data if a dispute or an infringement issue comes up.

Further reading on digital governance and technology policy

Readers interested in internet governance, data protection, and digital market regulation may find these related pieces useful. Most are my own writing; one is a third-party guide I am linking to because it corrects and extends a point made above: