During an audit, we have discovered that, since April 2024, more registration data was being made available via our public RDAP service than we intended. The data in question was the same data that is normally available from the public Whois on sidn.nl, in line with existing policy and in compliance with the GDPR. The issue has now been resolved and reported to the Data Protection Authority (DPA). We have so far found nothing to suggest that any data has been abused.
What happened?
Certain registration data was available via the public RDAP service, which it is not our policy to make available via that channel.
RDAP stands for Registration Data Access Protocol: the modern successor to the traditional Whois protocol for looking up registration data on domain names, IP addresses and autonomous system numbers (ASNs). RDAP enables you to get information about a domain name, such as:
Registration status
Managing registrar
Registration date and expiry date
Name servers
Contact details for the registrant or the registrant’s contact person (if public)
What data was involved?
The following data was available:
Names of business registrants of .nl domain names
Addresses of business registrants who explicitly chose to have their addresses published (fewer than 1 per cent)
E-mail addresses of registrants’ administrative contacts (admin-cs)
E-mail addresses of registrants’ technical contacts (tech-cs)
The data in question is the same data that is normally available from the Whois on sidn.nl.
What are the possible consequences?
The Whois on sidn.nl is designed for looking up domain names one at a time, whereas RDAP enables automated look-ups. However, the automated retrieval of registration data on a (large) number of .nl domain names by anyone other than their registrants or registrars is not straightforward, because SIDN does not publish a list of registered .nl domain names. We have so far found nothing to suggest that the data has been abused.
What remedial action have we taken?
We have:
Modified our RDAP service
Ensured that the available data is limited to what our policy states should be available
Reported the matter to the Data Protection Authority
Tightened up our internal checks
What can you do?
Most registrants don’t need to do anything. We nevertheless advise keeping an eye out for suspicious e-mails.
We’re actively informing you about this matter because we believe in being transparent about any situation where our services do not operate as intended.
Feel free to get in touch if you've got a question
You can reach us on working days between 8:30am and 5pm (Dutch time) by calling +31 26 352 5555 or mailing support@sidn.nl.
What data was involved?
Names of business registrants, opt-in address data and e-mail addresses of admin-cs and tech-cs.
Were any personal adresses involved?
No, this applies only to business address information and only if the registrant had explicitly chosen to publish their address. Fewer than 1 per cent actually chose to do so.
Were any passwords or payment data involved?
No.
Has any data been abused?
We haven’t found any evidence of abuse so far.
Has the issue been resolved?
Yes. The RDAP service has been modified so that data availability now correctly reflects our policy.
Do I need to do anything?
Most people affected don’t need to do anything. All the same, we advise keeping an eye out for suspicious communications.