Privacy and data
- Version
- v1
- In force since
- Not yet
- Next review
- At adoption
- Snapshot
- None yet
- Adopted by
- Proposed for founding adoption
- Signature
- At adoption
- Log entry
- Not appended yet
- Binding text
- English
Proposed, not in force
Open for comment until 28 October 2026, 00:00 UTC. Nothing here binds anyone until it is adopted.
Scope
This policy binds everything Tier 0 and the hosted TLDs process about people. A TLD collects more only under P-4 4.4.
Minimisation
Collect only what a function needs, and document the purpose and legal basis of every field beyond an account's verified email address. No GOpenCDR site or client carries trackers, analytics, advertising or fingerprinting.
Application logs never contain an email address or registrant data. Request logs drop cookies and authorisation headers before anything is written.
The transparency log holds identifiers only: the account ids of root role holders and of whoever proposed or decided a change, and the domain names and TLD strings an entry concerns. It never holds an email address, a name or an IP address.
Retention
Account data is kept while the account exists and for 12 monthsfixed after it is closed; then the email address and every credential are deleted.
Registration data is kept while the registration exists and for 12 monthsfixed after it ends.
The raw client address of an audit record is kept for 90 daysfixed; after that only its keyed hash remains.
Request logs are kept for 14 daysfixed.
Abuse cases are kept for 12 monthsfixed after they close.
A record that lets a retried request return its first answer is kept for 24 hoursfixed.
A mirror operator's enrolment data and conformance results are kept while the mirror is enrolled and for 12 monthsfixed after.
Audit records and the transparency log are kept for as long as the registry exists. Once an account is erased, they name only its identifier.
Every retention period is enforced by a scheduled job that records what it deletes. A statutory retention period, such as for invoices, applies instead where it is longer. Backups are not edited: they expire on their own cycle and are restored only to recover the service.
Rule retention.jobs.
Location
Personal data, logs and backups are stored and processed only in the EU, by providers established in the EU. The one exception is error reports to Sentry's EU data region, with every category of personal data switched off and under a data processing agreement, until error tracking is self-hosted.
Rights and requests
People can export and delete their data themselves in the portal, and every other request about their data is answered within 30 daysfixed. Every request and its outcome is logged.
A request for redacted registration data is acknowledged within 24 hoursfloor and decided by a person within 72 hoursfloor of a complete request, after weighing it. Every request is logged with its purpose and outcome, and counted in the transparency report.
Where the law requires fuller registration data, including under Article 28 of the NIS2 Directive as transposed into German law, GOpenCDR collects what it requires from the date it requires it, and tells registrants before it starts.