Category
Data protection & Domain Law
Topic
NIS2 & DENIC-WHOIS
Audience
Associations, NGOs & domain holders
Reading time
approx. 7 minutes

With effect from 6 December 2025, new legal requirements regarding the provision of domain registration data came into force in Germany. These are based on the national implementation of the European NIS-2 directive and aim to enhance the transparency, security and traceability of digital infrastructures. The new regulations directly affect the DENIC domain lookup (WHOIS) for .de domains and result in the expanded public display of certain registration details. Prior to 2018/2019, this was the norm; however, partly due to the GDPR, there had long been no detailed disclosure of WHOIS data for .de domains, and this is now being reversed.

Domain holders, particularly organisations and legal entities, are affected by the changes to varying degrees. DENIC explains these changes in a recent blog post, and this post assesses the implications for the privacy of those affected.

Why is this change being made, and how might it affect privacy?

The NIS-2 directive aims to increase the resilience of digital services and enable a more effective response to security incidents, legal infringements and misuse. A key component of this objective is improving the accessibility of controllers in relation to internet domains. The new regulations are intended to ensure that a clearly identifiable and contactable controller is designated for every .de domain, without disproportionately restricting the data protection of natural persons.

Regardless of whether a domain is registered to a natural person or a legal entity, a uniform principle has applied since 6 December 2025:

For every .de domain, the DENIC member responsible for its administration is publicly listed.

The DENIC member responsible for administration is the provider through which the domain was registered and which is responsible for its administrative management. This means that at least one specific point of contact is publicly designated for every domain.

Differentiation by type of domain holder

The specific implications of the new regulations depend largely on whether the domain is registered to a legal entity or a natural person.

Domains held by legal entities

For domains whose owner is a legal entity
, the following details will in future be made publicly available as part of the DENIC domain lookup:

– Name of the domain owner
– Address of the domain owner
– Email address
– Telephone number
– Date of domain registration
– Name and contact details of the DENIC member responsible for administration

Legal entities include not only commercial enterprises but also, amongst others:

– Registered associations (e. V.)
– Foundations
– Associations
– Church organisations
– Numerous non-governmental organisations (NGOs) and other non-profit organisations

Details im Webwhois der DENIC

Particular relevance for NGOs and associations

For NGOs, associations and other civil society organisations, the new regulations pose a particular risk of unintentional data disclosure. Many of these organisations are unaware that they are legally classified as legal entities and are therefore subject to the same disclosure obligations as commercial enterprises.

In practice, this can result in the following becoming publicly accessible via a Whois query, provided this data was provided as part of the domain registration:
– Private addresses of board members
– Personal email addresses
– Private telephone numbers of volunteers Smaller associations and volunteer-run NGOs in particular should therefore carefully check whether the contact details currently on file are suitable for public disclosure.

Domains registered to natural persons

For domains registered to natural persons, the protection of personal data remains guaranteed. In such cases, no personal details of the registrant are displayed publicly.

The following information is publicly available:

– The date of domain registration
– The name and contact details of the DENIC member responsible for administration

This ensures that, even for domains registered to natural persons, a responsible contact point is designated without breaching data protection principles.

Access to non-public data

The new regulations do not result in the complete isolation of unpublished registration data. Rather, there are still graduated levels of access:

domain holders can view their own data stored with DENIC, for example following appropriate verification as part of a domain enquiry. Third parties, such as rights holders, security researchers or government bodies, may be granted access to data not visible to the public provided there is a legitimate interest and following a case-by-case assessment.

“Any association or NGO that is unaware that it is legally recognised as a legal entity will find out at the latest the next time it checks the public WHOIS.”
Mint Secure GmbH

Assessment and recommended actions

The implementation of the NIS-2 directive enhances transparency and accountability within the German domain space. At the same time, it increases the requirements on organisations to manage their domain registration data in a responsible manner and in compliance with data protection regulations.

This results in a specific need for action, particularly for associations, NGOs and other non-commercial organisations:

1

Review contact details

Review the contact details provided during domain registration.

2

Use functional addresses

Use functional addresses and organisational contacts instead of personal details.

3

Raise awareness amongst board members

Raise awareness of the topic amongst board members and those responsible for administration.

4

Seek advice

Where necessary, consult with the domain provider or seek consulting services.

By carefully structuring the registration data, you can avoid the unintended disclosure of data without breaching legal requirements.

How Mint Secure supports you

Whether it’s domain registration data, contact processes or awareness raising amongst your data controllers: we help you with the implementation of the new WHOIS regulations in a way that complies with data protection laws.

📋

Security consulting

We’ll work with you to review which registration details are currently on file and how you can structure them in a way that complies with data protection regulations.

🔎

Vulnerability & Domain Management

We keep a close eye on your domains and their registration status to ensure no data is inadvertently disclosed.

Not sure whether your charity or NGO’s data is affected?

We’ll take a look at the WHOIS with you. Get in touch.

Conclusion

The implementation of the NIS-2 directive enhances transparency in the German domain space, but also raises requirements for the responsible handling of registration data.

Associations, NGOs and other non-commercial organisations in particular should now check whether their stored contact details are suitable for public display.

Mint Secure can help you avoid the unintentional disclosure of data. Talk to us.