The General Data Protection Regulation (GDPR) has applied since 25 May 2018. It protects the personal data of people in the European Union, and it changed what a public WHOIS lookup shows.
What changed
Before the GDPR, anyone could look up a domain and see the owner's name, address, email and phone number. Now, for most generic extensions, the personal details of an individual owner are withheld from the public record by default. Registries and registrars still hold the full details and still use them — for transfers, renewals and verification.
What you still control
- Your details must be accurate. The GDPR does not change the requirement to keep the owner's contact details correct. See Edit your domain's contact details.
- WHOIS privacy still helps. Not every extension withholds data, and an organisation's name is usually published. WHOIS privacy replaces what would be shown with forwarding contacts.
- People can still reach you. A WHOIS lookup on a protected domain shows a way to contact the owner without revealing who they are.
Note
Country extensions (.uk, .de, .fr and others) follow their own registry's policy on what is published. Check the extension before relying on the default.