From WHOIS to WHOWAS: A Large-Scale Measurement Study of Domain Registration Privacy under the GDPR
Chaoyi Lu, Baojun Liu, Yiming Zhang, Zhou Li, Fenglu Zhang, Haixin Duan, Ying Liu, Joann Qiongna Chen, Jinjin Liang, Zaifeng Zhang, Shuang Hao, Min Yang
Abstract
—When a domain is registered, information about the registrants and other related personnel is recorded by WHOIS databases owned by registrars or registries (called WHOIS providers jointly), which are open to public inquiries. However, due to the enforcement of the European Union’s General Data Protection Regulation (GDPR), certain WHOIS data (i.e., the records about EEA, or the European Economic Area, registrants) needs to be redacted before being released to the public. Anec-dotally, it was reported that actions have been taken by some WHOIS providers. Yet, so far there is no systematic study to quantify the changes made by the WHOIS providers in response to the GDPR, their strategies for data redaction and impact on other applications relying on WHOIS data. In this study, we report the first large-scale measurement study to answer these questions, in hopes of guiding the enforcement of the GDPR and identifying pitfalls during compliance. This study is made possible by analyzing a collection of 1.2 billion WHOIS records spanning two years. To automate
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext 6b3cc8df-0335-4760-b83f-288bc09d5f7dCited by top-tier papers10
- "Get in Researchers; We're Measuring Reproducibility": A Reproducibility Study of Machine Learning Papers in Tier 1 Security ConferencesDaniel Olszewski, Allison Lu, Carson Stillman, Kevin Warren et al.CCS 2023 · 19 citations
- SoK: Technical Implementation and Human Impact of Internet Privacy RegulationsEleanor Birrell, Jay Rodolitz, Angel Ding, Jenna Lee et al.S&P 2024 · 11 citations
- CSChecker: Revisiting GDPR and CCPA Compliance of Cookie Banners on the WebMingxue Zhang, Wei Meng, You Zhou, Kui RenICSE 2024 · 5 citations
- Welcome to the Dark Side: Analyzing the Revenue Flows of Fraud in the Online Ad EcosystemEmmanouil Papadogiannakis, Nicolas Kourtellis, Panagiotis Papadopoulos, Evangelos P. MarkatosWWW 2025 · 3 citations
- PrivDNFIS: Privacy-preserving and Efficient Deep Neuro-Fuzzy Inference SystemHao Ren, Xiao Lan, Rui Tang, Xingshu ChenAAAI 2025 · 3 citations
Builds on35
- Dark Patterns after the GDPR: Scraping Consent Pop-ups and Demonstrating their InfluenceMidas Nouwens, Ilaria Liccardi, Michael Veale, David R. Karger et al.CHI 2020 · 491 citations
- (Un)informed Consent: Studying GDPR Consent Notices in the FieldChristine Utz, Martin Degeling, Sascha Fahl, Florian Schaub et al.CCS 2019 · 429 citations
- A Comprehensive Measurement Study of Domain Generating MalwareDaniel Plohmann, Khaled Yakdan, Michael Klatt, Johannes Bader et al.USENIX Security 2016 · 252 citations
- Do Cookie Banners Respect my Choice? : Measuring Legal Compliance of Banners from IAB Europe's Transparency and Consent FrameworkCélestin Matte, Nataliia Bielova, Cristiana Teixeira SantosS&P 2020 · 212 citations
- You've Got Vulnerability: Exploring Effective Vulnerability NotificationsFrank Li, Zakir Durumeric, Jakub Czyz, Mohammad Karami et al.USENIX Security 2016 · 149 citations
Related papers
- We Value Your Privacy ... Now Take Some Cookies: Measuring the GDPR's Impact on Web PrivacyMartin Degeling, Christine Utz, Christopher Lentzsch, Henry Hosseini et al.NDSS 2019
- Unveiling and Quantifying Facebook Exploitation of Sensitive Personal Data for Advertising PurposesJosé González Cabañas, Ángel Cuevas, Rubén CuevasUSENIX Security 2018 · 54 citations
- The DSA Transparency Database: Auditing Self-reported Moderation Actions by Social MediaAmaury Trujillo, Tiziano Fagni, Stefano CresciCSCW 2025 · 16 citations
- Human-GDPR Interaction: Practical Experiences of Accessing Personal DataAlex Bowyer, Jack Holt, Josephine Go Jefferies, Rob Wilson et al.CHI 2022 · 51 citations
- Retrofitting GDPR Compliance onto Legacy DatabasesArchita Agarwal, Marilyn George, Aaron R. Jeyaraj, Malte SchwarzkopfVLDB 2022 · 16 citations
