Changes introduced as European countries implement the NIS2 Directive are altering the way domain registration information is collected, checked and made available. For some domains registered to companies and other legal entities, this can mean the organisation’s name, telephone number and business email address appearing in publicly accessible domain registration records.
For UK businesses, however, the situation is a little more complicated than simply saying that “WHOIS details are now public”.
NIS2 is an EU cybersecurity directive designed to improve the security and resilience of networks and information systems across the European Union.
Much of the Directive is concerned with the cybersecurity obligations of organisations operating important or essential services. However, Article 28 specifically deals with domain name registration data.
It requires top-level domain registries and businesses providing domain registration services to maintain accurate and complete information that can be used to identify and contact domain holders. The required information includes the registrant’s name, email address and telephone number.
NIS2 also requires registration information that is not personal data to be made publicly available. Its accompanying guidance makes an important distinction between individuals and legal entities such as companies. For legal entities, the expectation is that at least the registrant’s name and telephone number should be public, together with an email address where that address does not itself contain personal data.
NIS2 is an EU Directive, so individual EU countries have had to introduce their own national legislation to implement it.
Germany introduced its NIS2 implementation legislation in December 2025. Under the German legislation, domain registries and domain registration service providers were required to have their policies and procedures for maintaining and disclosing domain registration information publicly available by 6 March 2026.
As a result, some domain registrars operating under German law, including major providers like IONOS, changed how they handle registration information from that date.
For these services, new registrations, and in some cases domains transferred into the registrar, can therefore be treated differently from older registrations.
It is worth noting that 6 March 2026 is not a universal date. Different EU countries have implemented NIS2 at different times and individual registries can have their own policies.
The most significant change concerns domains registered to a legal entity rather than an individual.
This can include limited companies, LLPs, incorporated organisations and other organisations with their own legal personality.
If the domain’s registrant record identifies an organisation as the holder, business contact information associated with that organisation may be considered non-personal information and can therefore be published.
Importantly, this does not mean your business suddenly falls within all of the wider cybersecurity requirements of NIS2 simply because it owns a domain name.
The obligations under Article 28 primarily fall upon domain registries and domain registration providers. NIS2 specifically brings entities providing domain registration services within its scope regardless of their size. Domain owners are affected because those providers must collect, verify and, where appropriate, publish their registration information.
This also means a UK company can be affected, even though the UK is no longer part of the EU, where its domain is registered through a provider whose registration services are subject to an EU country’s NIS2 legislation.
For a company or other legal entity, the information potentially made publicly accessible can include:
There is an important privacy distinction here.
An address such as info@example.com or domains@example.com is normally an organisational contact address.
An address belonging to an identifiable member of staff, such as firstname.lastname@example.com, can still constitute personal data.
The same consideration should be given to telephone numbers. A company’s main office number is very different from publishing an individual director’s or employee’s personal mobile number.
EU data protection law applies to information concerning identifiable natural people even where that information is being used in a professional capacity.
Businesses should therefore think carefully about which contact details they use for their domain registrations.
For the changes being introduced by German-based registrars from March 2026, the most noticeable impact is on generic top-level domains (gTLDs).
These include long-established extensions such as .com, .org and .net, as well as newer generic extensions sometimes referred to as new gTLDs, such as .online, .shop, .store, .tech, .digital, .agency and many others.
There are now hundreds of generic domain extensions, so it is not practical to provide a complete list here. The important point is that the rules applying to a domain can depend on both the extension itself and the registrar or registry responsible for it.
The NIS2 Directive is EU legislation and does not directly apply to the UK’s .uk domain registry.
Domains such as .uk, .co.uk, .org.uk and .me.uk are operated under the rules of Nominet, the UK domain registry.
Nominet currently states that its public domain lookup does not display a registrant’s name or address unless the registrant has given permission for those details to be published. Non-public registration information can still be released where there is an appropriate legitimate reason, such as law enforcement or the enforcement of legal rights.
Therefore, a UK company registering a .co.uk domain should not assume that the March 2026 changes affecting certain generic domains also apply to its .co.uk registration.
No. This is one of the areas where it is easy for information about NIS2 to become misleading.
A country-code extension such as .uk is not affected by EU NIS2 legislation because it is operated in the UK. However, country-code registries within the EU can themselves be subject to national laws implementing NIS2.
For example, Austria’s .at registry has announced changes under Austria’s NIS2 legislation that will require contact information belonging to legal entities to be published from October 2026.
The .eu registry also treats companies and individuals differently. Its current policy publishes additional registration information where the holder is a legal entity while limiting the information displayed for individual registrants.
So it would be incorrect to assume that every country-code domain is private simply because it is not a generic extension.
NIS2 does not require the personal contact details of natural people to be freely published simply because they own a domain name.
Personal information remains subject to EU data protection legislation. This distinction is particularly relevant to sole traders, as a sole trader and their business are not separate legal persons in the same way that a limited company is.
NIS2 does, however, require registrars and registries to maintain accurate information about domain owners. It also establishes procedures through which non-public information can be supplied following a lawful and properly substantiated request from a legitimate party. Under Article 28, these requests are generally required to be answered within 72 hours.
Private registration data is therefore non-public, rather than necessarily anonymous or inaccessible.
For some registrar implementations introduced in response to the German legislation, domains registered or transferred before 6 March 2026 have not had previously private company contact information automatically published simply because of the change.
New registrations and transfers made from that date can be handled under the newer rules.
However, this should not be regarded as a permanent NIS2-wide exemption for older domains. The Directive itself does not establish a universal “grandfathering” date of 6 March 2026, and policies can differ between registrars, registries and EU countries.
An existing domain could also become subject to different handling following a future transfer or other change to its registration.
There is no reason to panic, but businesses should take the opportunity to review the details held against their domains.
No. These changes concern the registration information associated with the domain name itself.
They do not make information stored in your website, hosting account or email account public, and they do not change how your website or email service operates.
Domain registrant information is also not necessarily the same as the contact and billing information held within your account with your hosting or domain provider.
NIS2 is bringing greater accountability and transparency to domain name registrations, particularly where domains are owned by companies and other legal entities.
For businesses using generic domains such as .com, .org, .net or one of the many newer extensions, it is increasingly important to understand that some company registration information may be publicly accessible.
At the same time, the change should not be overstated. It does not mean every domain owner’s personal information is becoming public, it does not apply identically to every domain extension, and UK extensions such as .uk and .co.uk are not subject to the German NIS2 changes introduced in March 2026.
The sensible approach is simply to make sure your domains are registered to the correct owner and that the contact details supplied are accurate, appropriate and suitable for publication where the rules require it.
If you’re unsure about your domain’s registration we can help.