On 21 August 2025, the Registration Data Policy (Policy) went into effect and revised requirements related to processing generic top-level domain (gTLD) Registration Data. How and under what conditions ICANN-accredited registrars and gTLD registry operators (contracted parties) must respond to requests to disclose previously public Registration Data continues to be a major topic of interest in the community. This blog provides an overview of ICANN Contractual Compliance enforcement of the obligations related to disclosure requests.
Compliance Observations and Enforcement
External complaints drive much of ICANN's Contractual Compliance enforcement efforts related to Disclosure Request requirements. The most common issues reported involve failure to provide a response; missing detail required within a denial response; failure to publish a compliant mechanism and process; and/or disagreement with a disclosure decision. A complaint based only on dissatisfaction with the result of a request will be closed because ICANN is unable to reexamine a contracted party's disclosure decision.
Compliance will initiate an investigation when we identify that a contracted party may not have met its obligations under the Policy, either through an evidence-based complaint, or through our proactive review of disclosure-related publication requirements on a contracted party's website. As part of our investigations, we will contact the contracted party, request evidence of compliance or remediation, and track the resolution.
The most common compliance issues we are seeing include:
- Failure to publish a compliant mechanism and process for the submission of Disclosure Requests (for example, these materials are not published, they are not linked from the contracted party's website homepage, or minimum required content is missing).
- Restricting Disclosure Request submissions by certain requestor types, for example, by only accepting and responding to requests from law enforcement.
- Failure to include required detail in a denial, including a clear explanation of how a decision was reached, sufficient for a requestor to objectively understand the reasons for the decision, and if a legitimate interest balancing test was performed, an analysis and explanation of how the balancing test was applied.
During the first eight months of enforcement, ICANN Compliance initiated 29 contracted party investigations related to compliance with Disclosure Request obligations. This resulted in 15 contracted parties remediating their disclosure-related publication requirements, which ensures third parties have access to information necessary to submit properly formed Disclosure Requests. Three contracted parties have updated their review and response processes, which ensures responses are provided for all properly formed Disclosure Requests and that any denials include the necessary rationale.
Overall, complaints regarding Disclosure Request obligations remain relatively low, and 65 percent of such complaints were closed as out of scope, without initiating a compliance investigation. While details of individual complaints received and contracted party investigations are not made public, aggregated data can be found in our monthly reporting.
Disclosure Request obligations were also included in the most recent Registrar Audit launched on 16 July 2025, including those related to publication and registrar processes for reviewing and responding to Disclosure Requests. Upon detection of any noncompliance, registrars are requested to implement necessary remediation(s). A final report will be published after the Audit is concluded.


