Sign in
P-6ProposedGlobal, Registry Council

Privacy and data

Version
v1
In force since
Not yet
Next review
At adoption
Snapshot
None yet
Adopted by
Proposed for founding adoption
Signature
At adoption
Log entry
Not appended yet
Binding text
English

Proposed, not in force

Open for comment until 28 October 2026, 00:00 UTC. Nothing here binds anyone until it is adopted.

1

Scope

1.1
Bindingp6-c1

This policy binds everything Tier 0 and the hosted TLDs process about people. A TLD collects more only under P-4 4.4.

2

Minimisation

2.1
Bindingp6-c2

Collect only what a function needs, and document the purpose and legal basis of every field beyond an account's verified email address. No GOpenCDR site or client carries trackers, analytics, advertising or fingerprinting.

2.2
Bindingp6-c3

Application logs never contain an email address or registrant data. Request logs drop cookies and authorisation headers before anything is written.

2.3
Bindingp6-c4

The transparency log holds identifiers only: the account ids of root role holders and of whoever proposed or decided a change, and the domain names and TLD strings an entry concerns. It never holds an email address, a name or an IP address.

3

Retention

3.1
Enforced settingp6-c5Not enforced yet

Account data is kept while the account exists and for 12 monthsfixed after it is closed; then the email address and every credential are deleted.

3.2
Enforced settingp6-c6Not enforced yet

Registration data is kept while the registration exists and for 12 monthsfixed after it ends.

3.3
Enforced settingp6-c7

The raw client address of an audit record is kept for 90 daysfixed; after that only its keyed hash remains.

3.4
Enforced settingp6-c8Not enforced yet

Request logs are kept for 14 daysfixed.

3.5
Enforced settingp6-c9Not enforced yet

Abuse cases are kept for 12 monthsfixed after they close.

3.6
Enforced settingp6-c10

A record that lets a retried request return its first answer is kept for 24 hoursfixed.

3.7
Enforced settingp6-c11Not enforced yet

A mirror operator's enrolment data and conformance results are kept while the mirror is enrolled and for 12 monthsfixed after.

3.8
Bindingp6-c12

Audit records and the transparency log are kept for as long as the registry exists. Once an account is erased, they name only its identifier.

3.9
Enforced rulep6-c13Enforced in part

Every retention period is enforced by a scheduled job that records what it deletes. A statutory retention period, such as for invoices, applies instead where it is longer. Backups are not edited: they expire on their own cycle and are restored only to recover the service.

Rule retention.jobs.

4

Location

4.1
Bindingp6-c14

Personal data, logs and backups are stored and processed only in the EU, by providers established in the EU. The one exception is error reports to Sentry's EU data region, with every category of personal data switched off and under a data processing agreement, until error tracking is self-hosted.

5

Rights and requests

5.1
Enforced settingp6-c15Not enforced yet

People can export and delete their data themselves in the portal, and every other request about their data is answered within 30 daysfixed. Every request and its outcome is logged.

5.2
Enforced settingp6-c16Not enforced yet

A request for redacted registration data is acknowledged within 24 hoursfloor and decided by a person within 72 hoursfloor of a complete request, after weighing it. Every request is logged with its purpose and outcome, and counted in the transparency report.

5.3
Bindingp6-c17

Where the law requires fuller registration data, including under Article 28 of the NIS2 Directive as transposed into German law, GOpenCDR collects what it requires from the date it requires it, and tells registrants before it starts.