- A regulation written for Europe changed WHOIS privacy defaults for domain owners worldwide, including in Nepal.
- Here is what actually changed, and what it means for you.
The EU's General Data Protection Regulation (GDPR), introduced in 2018, fundamentally changed how domain registrars handle the personal information traditionally displayed in public WHOIS records โ a change that affected domain privacy practices globally, not just within Europe.
What Changed
Before GDPR, WHOIS records commonly displayed a domain owner's full name, address, phone number and email publicly, searchable by anyone. Following GDPR, most major registrars now mask this personal information by default for all customers, regardless of location, rather than maintaining separate systems for EU and non-EU registrants.
Why This Benefits Nepali Domain Owners Too
- Reduced exposure to spam, scam targeting and unsolicited marketing based on publicly available WHOIS contact details.
- Lower risk of harassment or unwanted contact tied to a personal address associated with a public domain.
- Applied as an industry-wide default by most major international registrars, benefiting customers globally.
What Is Still Visible
Even with privacy protection active, certain technical information remains publicly visible: registration and expiry dates, the registrar name, and nameserver information โ sufficient for legitimate technical and dispute purposes without exposing personal contact details.
Practical Steps for Nepali Domain Owners
- Confirm your registrar has WHOIS privacy protection enabled โ most apply it by default, but verify directly.
- Understand that some registries, including certain ccTLDs, may have different privacy defaults โ check specifically for .com.np if this matters to you.
- Know that privacy protection does not affect your legal ownership or control of the domain, only what is publicly visible.
When Privacy Protection Can Be Legitimately Bypassed
Legal processes โ trademark disputes, law enforcement requests, court orders โ can still access the underlying registrant information through the registrar even when public WHOIS is masked, since the data still exists and is retained, just not publicly displayed.
Frequently Asked Questions
Do I need to be an EU citizen for GDPR-driven privacy to apply to me?
No โ most major registrars apply the privacy-by-default approach globally as their standard practice, regardless of the registrant's actual location.
Does WHOIS privacy cost extra?
Many registrars now include it free by default; some still offer it as a low-cost add-on โ check your specific registrar's current policy.
Questions about your domain's privacy settings? See our domain services or ask our team.