Home / Industry

Thoughts on RDRS for Brand Owners

This month, Stephanie Driver, CSC’s marketing manager, spoke with Patrick Hauss, head of Corporate Development and Strategic Alliances EMEA, about the Internet Corporation for Assigned Names and Numbers (ICANN) Registration Data Request Service (RDRS) as part of an ongoing a series of interviews with CSC’s Digital Brand services business experts, where we talk about industry issues across cybersecurity, domains, brand protection, and fraud protection.


It’s a Monday morning, and with a mug in hand, I’m speaking to Patrick Hauss. These chats are all about discussing industry issues, and today, Patrick wants to share some thoughts on RDRS. But first up, what is RDRS? I ask Patrick to give me a quick overview.

“RDRS stands for Registration Data Request Service. It’s a tool from ICANN aimed at helping to solve the data access restrictions that came about because of the redaction of personal data on WHOIS records, which happened when GDPR came into force. WHOIS lookups are used by cybersecurity investigators, trademark experts, and brand protection service providers like CSC—as well as brands and their security, IP, and legal teams—as part of the enforcement process against third parties registering fraudulent domains,” he explains.

Before GDPR, accessing full WHOIS data formed an essential part of investigations to inform enforcement actions against intellectual property (IP) infringements and domain name system (DNS) abuse. Since many online brand abuse cases start with a deceptive domain name registration, registrant information can be used to track down bad actors and take infringing content offline. But it’s also exactly the personal data that GDPR aims to protect.

Enforcement became more challenging once redactions happened, and ICANN responded to the need for access to such data from those with legitimate access requests by introducing RDRS for an initial period of two years, starting on November 28, 2023. But gaining access to WHOIS data, even with RDRS, is still a bumpy road, so where do the issues lie for brand owners?

“Part of the challenge is that RDRS is optional and requires domain registrars to sign up to the service. It means that the number of domains eligible to an RDRS request are somewhat limited.” So, the full top-level domain (TLD) landscape isn’t covered, and bad actors spread their registrations far and wide across multiple TLDs, including country-code TLDs (ccTLDs), which are out of the RDRS scope.

There may be good reason for this low uptake from registrars. The threat of GDPR fines looms large. Many registrars may be reticent to share redacted WHOIS information unless they consider the request for access to be 100% watertight, legally. And with good reason—the risk of a GDPR fine would strike fear into the hearts of most. Unfortunately, less than 15% of information requests through RDRS are granted; in December 2023, it was as low as 7%. The result is that it takes longer for brand abuse investigations to conclude, and for enforcement action to be taken.

So, what does Patrick see as the way forward to improve things for registrars and brand owners?

“On a very practical level, encouraging as many registrars as possible to sign up would expand the TLD coverage,” he says. But perhaps the real issue, he ponders, requires a more rounded look at policies concerning online abuse. Policy-wise, there’s a big distinction between what constitutes DNS abuse and IP abuse and infringements. “There’s work being done currently by the European Commission to recommend that the definition of DNS abuse be expanded to include IP abuse. Online brand abuse would benefit from a better definition in and of itself. If that were to happen, there would be clearer legal perimeters of what constitutes abuse, making it easier for registrars to identify legitimate requests for WHOIS information, that is, those with a clear legal basis for requesting—giving them the reassurance that they won’t be breaching GDPR.”

Feel free to reach out to us if you have questions regarding online brand enforcement.

By CSC, We are the business behind business

We help effectively manage, promote, and secure our clients’ valuable brand assets against the threats of the online world. Leading companies around the world choose CSC as their trusted partner to gain control of their digital assets, maximize their online potential, and increase online security against brand risks.

Visit Page

Filed Under

Comments

Commenting is not available in this channel entry.
CircleID Newsletter The Weekly Wrap

More and more professionals are choosing to publish critical posts on CircleID from all corners of the Internet industry. If you find it hard to keep up daily, consider subscribing to our weekly digest. We will provide you a convenient summary report once a week sent directly to your inbox. It's a quick and easy read.

I make a point of reading CircleID. There is no getting around the utility of knowing what thoughtful people are thinking and saying about our industry.

VINTON CERF
Co-designer of the TCP/IP Protocols & the Architecture of the Internet

Related

Topics

IPv4 Markets

Sponsored byIPv4.Global

Domain Names

Sponsored byVerisign

Brand Protection

Sponsored byCSC

Threat Intelligence

Sponsored byWhoisXML API

New TLDs

Sponsored byRadix

Cybersecurity

Sponsored byVerisign

DNS

Sponsored byDNIB.com