Privacy Act 2020 & WHOIS
The impact of the NZ Privacy Act 2020 on WHOIS mandates that personal contact information for individual domain registrants must be protected from public access, shifting the default from transparency to privacy. While corporate entities generally remain visible to ensure consumer trust, individuals can now withhold their address and phone number from the public .nz register to prevent data misuse.
For decades, the WHOIS database served as the phonebook of the internet, providing unrestricted access to the personal details of domain name owners. However, the introduction of the Privacy Act 2020 in New Zealand fundamentally altered this landscape, prioritizing the protection of personal data over the historical precedent of open registries. For stakeholders in the New Zealand premium domain brokerage and valuation sector, understanding these nuances is critical for compliance, asset acquisition, and valuation accuracy.
Table of Contents
- Summary of the Privacy Act 2020 for Domain Holders
- Individual vs. Corporate Privacy Rights in NZ
- The Role of the Domain Name Commission (DNC)
- How to Redact Personal Information from the Register
- Implications for Premium Domain Brokerage and Valuation
- The Risks of Non-Compliance
- Frequently Asked Questions
Summary of the Privacy Act 2020 for Domain Holders
The Privacy Act 2020 came into force on December 1, 2020, replacing the 1993 Act to better address the complexities of the digital age. Its primary objective regarding digital registries is to strengthen the control individuals have over their personal information. For the .nz domain space, this legislation triggered a significant policy shift by the Domain Name Commission (DNC).
Under the new Act, the indiscriminate publication of an individual’s physical address, email, and telephone number on a public database like WHOIS is viewed as a potential breach of Information Privacy Principle 11, which limits the disclosure of personal information. Consequently, the default setting for individual registrants has moved from “public” to “private.”

Key Changes for Registrants
The most immediate impact of the NZ Privacy Act 2020 on WHOIS is the distinction between data collection and data publication. Registrars are still required to collect accurate, verified contact details to ensure the stability of the Domain Name System (DNS). However, the publication of that data is now strictly regulated. Key changes include:
- Data Minimization: Only essential information required for the technical operation of the domain is made public for individuals.
- Mandatory Breach Reporting: If a registrar accidentally exposes private WHOIS data, and it poses a risk of harm, it must be reported to the Privacy Commissioner.
- Cross-Border Protections: Data sent overseas (e.g., to international registries) must be protected by safeguards comparable to NZ law.
Individual vs. Corporate Privacy Rights in NZ
One of the most confusing aspects of the impact of the NZ Privacy Act 2020 on WHOIS is the bifurcation of rights based on the registrant’s legal status. The Act protects personal information about identifiable individuals. It does not, generally, protect information about corporate entities, trusts, or incorporated societies.
The Individual Registrant
An “Individual Registrant” is defined as a natural person who is not using the domain primarily for trade or commercial purposes. For these users, the privacy shield is robust. The public WHOIS search will typically display the registrant’s name (though even this can sometimes be masked under specific proxy services, albeit less common in .nz) but will redact the address, phone number, and direct email address.
Instead of direct contact details, the WHOIS result often provides a generated “masked” email or a web-based contact form. This allows legitimate inquiries (such as brokerage offers or copyright notices) to reach the owner without exposing their private residence.
The Corporate Entity
For businesses, the rules are different. Transparency is a cornerstone of New Zealand corporate law. If a domain is registered to a Limited Company (Ltd) or is used for significant commercial activity, the expectation is that the entity must be reachable by consumers and legal authorities.

Therefore, a domain registered to “Wellington Widgets Ltd” will likely still show the registered office address and a contact number. The Privacy Act 2020 does not extend the same protections to legal entities because a business address is public record via the Companies Office. However, if a business uses a personal home address as their registered office, this creates a gray area where the DNC often advises registrants to use a PO Box or virtual office to maintain privacy while satisfying corporate transparency requirements.
The Role of the Domain Name Commission (DNC)
The Domain Name Commission (DNC) is the regulatory body responsible for the .nz domain space. They act as the bridge between the Privacy Act 2020 legislation and the technical reality of the DNS.
Following the enactment of the Privacy Act 2020, the DNC updated its policies to ensure the .nz registry was compliant. They introduced the Individual Registrant Privacy Option (IRPO). This policy framework dictates that:
- Registrars must offer privacy options to individuals at the point of registration.
- The withholding of data must be the default or an easily accessible opt-in for non-trading individuals.
- There must be a mechanism to “unmask” data if there is a legitimate legal reason (e.g., a court order or a breach of the Harmful Digital Communications Act).
The DNC also conducts audits to ensure that domains marked as “individual” are not actually large corporations trying to hide their ownership to avoid scrutiny or intellectual property enforcement. This validation process is crucial for maintaining the integrity of the .nz namespace.
How to Redact Personal Information from the Register
For domain holders concerned about their data exposure, understanding how to operationalize the Privacy Act’s protections is vital. If you are an individual registrant, your data should be protected, but legacy domains registered before 2020 may sometimes slip through the cracks if not updated.

Step-by-Step Guide for Redaction
If your personal information is currently visible on the WHOIS lookup tool, follow these steps to leverage your rights under the Privacy Act 2020:
1. Verify Your Registrant Status
Log in to your domain registrar’s portal (e.g., Crazy Domains, GoDaddy, Metronet). Check the “Registrant Name” field. Ensure you are listed as an individual, not a business entity, if you are indeed not trading. If you are listed as a business, you may not be eligible for privacy unless you change the legal registrant.
2. Select the Privacy Option
Look for settings labeled “WHOIS Privacy,” “ID Protection,” or “Individual Registrant Privacy Option (IRPO).” In the .nz market, many registrars now apply this automatically for individuals, but some require a manual toggle. Unlike generic top-level domains (.com), where privacy often costs extra, .nz privacy for individuals is a policy right and should typically be free of charge.
3. Update Contact Details
If you are a business operating out of a home, you cannot simply hide. To protect your home address:
- Rent a PO Box: Use this for your postal address.
- Virtual Office: Use a service that provides a physical commercial address.
- Dedicated Business Email: Use an admin@yourbusiness.nz email rather than your personal Gmail to separate identities.
4. Contact the DNC (If Issues Persist)
If a registrar refuses to hide your personal data despite you meeting the criteria of an individual non-trading registrant, you can lodge a complaint with the Domain Name Commission. They have the authority to intervene to ensure the Privacy Act is being respected.
Implications for Premium Domain Brokerage and Valuation
For professionals in the premium domain brokerage space, the impact of the NZ Privacy Act 2020 on WHOIS has significantly altered acquisition strategies and valuation metrics. The days of easily scraping WHOIS data to cold-call owners of high-value domains are largely over.
The Acquisition Challenge
In the past, a broker identifying a premium domain like insurance.co.nz or property.nz could often find the owner’s mobile number immediately. Now, with privacy redaction:
- Contact Friction: Brokers must rely on web-based contact forms. These forms often have CAPTCHAs and character limits, and messages frequently end up in spam folders.
- Verification Difficulty: It is harder to verify if a seller is the legitimate owner without seeing the underlying WHOIS data. Brokers must now perform more rigorous due diligence, often requiring the seller to perform a DNS verification (adding a TXT record) to prove ownership.
Privacy as a Valuation Component
Interestingly, privacy has become a factor in valuation. Domains that have been historically private and have clean history (no spam records) are seen as premium assets. Furthermore, for high-net-worth individuals or controversial industries, the ability to hold a .nz domain privately is a tangible benefit.
However, for corporate buyers, transparency adds value. A domain with a long, transparent history of ownership by a reputable entity is easier to audit and valuate than one hidden behind privacy shields, which might mask a history of drop-catching or blacklisting.

Brokerage Protocols for “Hidden” Owners
Successful brokers in the post-2020 landscape have adapted by:
- Using the DNC Message Delivery Service: The DNC provides a mechanism to forward messages to the registrant of a .nz domain name, even if their details are withheld. This is often more reliable than registrar-specific forms.
- Leveraging Historical Data: Brokers often utilize historical WHOIS databases (DomainTools, etc.) to find ownership records from before 2020, although this data degrades in accuracy over time.
- Escrow Services: The reliance on trusted escrow services has increased. Since buyers cannot easily verify the seller’s identity via WHOIS, the intermediary role of the escrow service in holding funds until domain transfer is complete is more critical than ever.
The Risks of Non-Compliance
Ignoring the Privacy Act 2020 carries significant risks for all parties involved in the domain ecosystem.
For Registrars and Resellers
Registrars who fail to redact individual data face legal action from the Privacy Commissioner. Under the new Act, the Commissioner has the power to issue compliance notices. Failure to comply can result in fines of up to $10,000 per offense, and class-action lawsuits for privacy breaches are becoming a more realistic threat in New Zealand. Furthermore, a registrar found in breach risks losing their accreditation with the DNC.
For Registrants (Domain Owners)
While the Act protects privacy, it also penalizes deception. If a registrant provides false contact details to maintain privacy (e.g., “Mickey Mouse” at “123 Fake Street”), they risk having their domain cancelled. The DNC policy requires data to be accurate even if it is private. If a domain is involved in a dispute and the contact details are proven false, the registrant may lose the domain immediately without a refund.
Furthermore, businesses attempting to masquerade as “individuals” to hide their ownership can face penalties under the Fair Trading Act for misleading conduct, in addition to losing their domain rights.
The impact of the NZ Privacy Act 2020 on WHOIS is a balancing act between the right to privacy and the necessity of accountability. For the premium domain market, it necessitates a more professional, diligent approach to brokerage, where verification and trusted intermediaries replace the ease of open-access data.
People Also Ask
Can I hide my address on WHOIS NZ if I run a business from home?
Generally, no. If you are trading, your address is public. However, you can protect your home privacy by registering the domain to a PO Box or a Virtual Office address, which satisfies the requirement for a contactable address without revealing your residence.
Does the Privacy Act 2020 cover business email addresses?
The Privacy Act primarily protects “personal information” about identifiable individuals. A generic business email like info@company.nz is not usually protected. However, an email like firstname.lastname@company.nz could be considered personal information depending on the context, though in a business setting, the expectation of privacy is lower.
How do I contact a domain owner with hidden details?
You can use the online enquiry form provided on the WHOIS search result page. Alternatively, the Domain Name Commission (DNC) offers a message delivery service that forwards your communication to the registrant’s private email address.
What is the fine for breaching the Privacy Act 2020 regarding domain data?
The Privacy Commissioner can issue compliance notices. Failure to follow a compliance notice can result in a fine of up to $10,000. Additionally, serious breaches causing harm can lead to proceedings in the Human Rights Review Tribunal, where damages can be awarded.
Is WHOIS privacy free for .nz domains?
For individual registrants not using the domain for trade, the privacy option (IRPO) is a policy right and is typically provided free of charge by registrars. Some international registrars may try to upsell privacy packages, but for .nz individuals, the redaction should be standard.
Can the DNC release my private details?
Yes, in specific circumstances. The DNC can release withheld information if there is a Memorandum of Understanding (MoU) with a law enforcement agency, a court order, or if the requester proves they have a legitimate need (e.g., enforcing intellectual property rights or serving legal documents) that outweighs the privacy interest.

