ICANN: Critical changes to Domain Name Ownership from August 21, 2025
ICANN’s Registration Data Policy, in force since August 21, 2025, changed how domain ownership is determined: if the “Organization” field on a domain registration names a company, that company, not the individual listed as registrant, counts as the legal owner. This piece explains the rule, what it means under Cypriot law, and the practical steps worth taking to check your own domains.
ICANN (Internet Corporation for Assigned Names and Numbers) is the non-profit organization, founded in 1998 and based in the United States, that administers the internet's Domain Name System (DNS) and allocates IP addresses. Unlike traditional international bodies such as the International Telecommunication Union (ITU), ICANN works through a "multi-stakeholder" model in which governments, the private sector, the academic community, and individual users all take part in internet governance.
Every domain name registered worldwide is subject to ICANN's rules and policies, which makes the organization's decisions directly relevant to any business or professional whose international transactions and e-commerce depend on a stable domain presence. For more on how ICANN came to hold this role, see my earlier piece on the founding of ICANN.
The new Registration Data Policy
The Registration Data Policy (RDP) took effect on August 21, 2025, the biggest restructuring of domain name ownership data management since 2018. It goes beyond a technical adjustment: it changes how the legal owner of a domain name is determined.
The central change concerns the hierarchy of ownership data. Under paragraph 6(6)(2) of the RDP, if the "Organization" field in the registrant's details names a company, that company is automatically treated as the legal owner of the domain. The individual named in the contact details becomes a point of contact only, with no ownership rights.
"6(6)(2) The Registrant Organization will be considered the Registered Name Holder."
This reverses the previous practice, under which the registrant's first and last name determined ownership. For example, a company director who registered a business domain under their own name but entered the company name in the "Organization" field will find that, since August 21, 2025, the company is the domain owner, regardless of whose name appears as registrant.
How domain ownership changes affect you
From a legal perspective, this change raises real issues that are worth attention. Under Cypriot law, domain names are treated as intangible assets with substantial commercial value, so an automatic transfer of ownership from an individual to a legal entity can affect contractual relationships, corporate agreements, and even divorce or inheritance proceedings.
The clearest example is the entrepreneur who registered a domain under their own name for convenience or control, but entered the company name in the "Organization" field. Since August 21, 2025, such domains belong to the company, which can complicate matters when a shareholder leaves, shares are sold, or a corporate dispute arises.
The change also affects the transfer process. Any modification to the "Organization" field now triggers a change-of-registrant procedure that requires email verification, and failing to complete that verification within the set timeframe can lead to domain suspension, which disrupts business operations.
GDPR and data protection
The Registration Data Policy is a direct result of the General Data Protection Regulation (GDPR), which took effect in 2018. ICANN had to redesign the WHOIS system, which had traditionally published domain holders' personal details freely, to meet GDPR's requirements.
The RDP restricts the collection and publication of personal data considerably. Mandatory fields for administrative and billing contacts are abolished, technical contacts become optional and can use generic email addresses, and Organization details will not appear in public WHOIS unless the holder gives explicit consent. This follows GDPR's data-minimization principle: only the information that is strictly necessary is collected and processed.
Practical steps to take
If you have not already done so, review your registered domains and check the "Organization" field on each one.
If you want personal ownership, leave the "Organization" field empty. If you want corporate ownership, make sure the company name is entered correctly there.
Domains held for investment purposes or as part of a personal portfolio deserve a closer look, since a company name sitting in the "Organization" field can create ownership consequences you did not intend.
Other technical changes
Beyond the change in ownership determination, the Registration Data Policy introduces three further technical changes that affect domain name management directly.
First, registrars are no longer required to collect Administrative, Billing, or Technical Contact fields. Since August 21, 2025, they collect only the "minimal data set", limited to the necessary Registrant details, which follows GDPR's data-minimization principle and reduces the administrative burden for businesses that manage several domains.
Second, and arguably more consequential for businesses, registrars must permanently delete all historical Administrative, Billing, and Technical contact data held in their systems.
Third, the Technical Contact field is now optional and can hold a generic address, such as "support@example.com", instead of an individual employee's personal details, which lets businesses keep a stable point of contact regardless of staff turnover.
| ICANN Registration Data Policy Changes Effective August 21, 2025 |
|
|---|---|
|
Registrant (Domain Owner)
REQUIRED |
Public Display: Tiered access
Note: The only necessary element. This field identifies the legal owner of the domain. |
|
Organization (Company/Entity)
OPTIONAL |
Public Display: Shown if present
Important: If filled, the organization will be considered the legal owner, not the individual registrant.
|
|
Administrative (Admin Contact)
DISCONTINUED |
Public Display: No longer collected
Note: All existing administrative contact data will be permanently deleted. |
|
Billing (Financial Contact)
DISCONTINUED |
Public Display: No longer collected
Note: All existing billing contact data will be permanently deleted. |
|
Technical (Tech Support)
EXCEPTIONS* |
Public Display: Rarely shown
Note: Only required for specific TLDs. May use generic email addresses instead of personal information. |
From WHOIS to RDAP
Alongside the Registration Data Policy, ICANN retired the WHOIS protocol on January 28, 2025, and replaced it with the Registration Data Access Protocol (RDAP). WHOIS had been running since 1982 and carried real weaknesses: no standard data format and no support for international characters. RDAP addresses both, delivering structured data in JSON, requiring HTTPS, and allowing tiered access depending on who is asking.
For legal professionals and domain management specialists, the practical effect is that access to non-public registration data now requires identity verification and a documented legitimate interest. ICANN launched the Registration Data Request Service (RDRS) in November 2023 as a two-year pilot to standardize such requests, particularly for law enforcement, intellectual property protection, and cybersecurity cases. The pilot concluded on 30 November 2025; on 30 October 2025 the ICANN Board had already resolved to keep RDRS running as an ongoing service through December 2027 while the community works on a permanent successor, so it is no longer experimental, just not yet final.
A further revision to the Registration Data Policy on 12 May 2026 added a fast track for urgent disclosure requests: acknowledgement within two hours and a substantive response within 24 hours, for cases involving an imminent threat to life, serious bodily injury, critical infrastructure, or child exploitation. That fast track applies only to an "Authenticated Requestor", and ICANN has tied its effective date to an authentication mechanism for law enforcement that is still being finalized, so the ordinary 30-day response window remains the one to plan around for now. This creates procedural requirements worth keeping in mind when seeking information for a domain dispute or a trademark infringement investigation.
Upcoming reforms to domain transfers
Beyond the Registration Data Policy, ICANN is working through a separate reform of the Transfer Policy. The GNSO Council approved the Transfer Policy Review Working Group's 47 recommendations in March 2025, and under ICANN's Bylaws the Board is obliged to adopt them unless a two-thirds majority finds against doing so, so implementation is now a matter of timing rather than outcome. The most consequential change would cut the lock period from 60 to 30 days for both new registrations and inter-registrar transfers, and remove entirely the lock that currently follows a change to registrant details, which would make portfolio consolidation and corporate restructuring considerably easier.
The reform also standardizes procedures for bulk domain transfers (Bulk Transfer After Partial Portfolio Acquisition, or BTAPPA), capping the registry charge at $50.000 for portfolios over 50.000 domains, and updates the valid grounds for denying a transfer to include DNS abuse as ICANN defines it. Once adopted, these changes should simplify transfer procedures while narrowing the room for fraud and abuse.
Dates to note:
- May 28, 2025: Email notifications begin
- August 21, 2025: Official implementation of the new policy
- After 8/21: Permanent deletion of old contact data
Bottom line
The August 21, 2025 deadline has now passed, and the Registration Data Policy is the framework registrars apply today. If you have not yet checked the "Organization" field on your domains, it is worth doing now: correcting it after the fact still works, it just takes you through the same registrant-change verification as any other update. The RDRS and the pending urgent-request authentication mechanism discussed above are worth watching too, since they will determine how quickly you can obtain non-public registration data if a dispute or an infringement issue comes up.
Further reading on digital governance and technology policy
Readers interested in internet governance, data protection, and digital market regulation may find these related pieces useful. Most are my own writing; one is a third-party guide I am linking to because it corrects and extends a point made above:
- ICANN's Registration Data Policy: Critical Domain Ownership Changes Greek Version: the Greek edition of this article, with additional context on ICANN's historical development and its effect on digital policy across Europe.
- The Consent Paradox: How EU Regulations Enabled Corporate Data Harvesting: a close look at how GDPR's cookie consent rules inadvertently built a surveillance infrastructure run by 8 to 10 Consent Management Platform companies. Privacy regulation, in this case, expanded data collection rather than limiting it.
- Apple v. Pepper: Robbing Developers of Their Autonomy Greek Version: an analysis of the landmark U.S. Supreme Court case on whether iPhone users can sue Apple for monopolistic practices in the App Store, and what it means for developer independence and marketplace competition.
- Facebook Welcomes Us to the Post-Data Era & Why GDPR is Dangerous Nonsense Greek Version: a critique of GDPR's limitations. Traditional data protection frameworks, I argue, cannot keep up with modern platforms' data-inference capabilities or the rise of "post-data" surveillance techniques.
- When the GDPR Goes Wrong: a case study of the Cyprus Data Protection Authority's misapplication of GDPR to labor relations, and what it shows about the risks when a data protection authority strays beyond its mandate.
- The Founding of ICANN: A Historical and Political Approach Greek Version: how ICANN was created in 1998, the political forces that shaped internet governance, and the continuing tension between technical administration and geopolitical interests.
- Why Is WHOIS Data Redacted? GDPR and ICANN Explained 3rd Party Article: Chris Morris of Full Cycle Development Group explains why WHOIS records were redacted after GDPR, and how the Registration Data Policy and the Registration Data Request Service now govern access to that data. He flagged the RDRS correction reflected above.